Private operations agent · Always-on Mac Mini

One private agent.
Clear boundaries around every action.

OpenClaw helps Drew research, monitor, prepare and review everyday work without turning a personal assistant into an unattended administrator.

Useful by design

A quiet operating layer for personal systems.

OpenClaw brings approved signals together, prepares useful context and stops at the boundary where a person should decide.

01

Personal briefings

Builds bounded daily and weekly summaries from approved, read-only inputs.

02

Research and monitoring

Finds meaningful changes, checks system health and suppresses unchanged noise.

03

Knowledge support

Reads approved context and prepares captures without silently rewriting the canonical record.

04

Reviewable hand-offs

Can prepare bounded coding or operational work, with external side effects held for approval.

Security model

Permission is enforced by the system, not promised by a prompt.

Approved inputs Read-only sources Bounded collectors and fixed wrappers
Private control plane OpenClaw Loopback Gateway and isolated agent work
Review surface Proposals first Owner approval before side effects

Autonomous

Read, research, monitor, summarise, classify and draft within approved bounds.

Owner-gated

Messages, account writes, publishing, infrastructure changes and destructive actions.

Never broad

No public Gateway, unrestricted host access, credential exposure or arbitrary administration.

Production status · August 2026

The core is live. New authority still earns its way in.

Live

Private runtime

The pinned OpenClaw runtime operates on Drew's Mac Mini behind a loopback-only, authenticated Gateway.

Held at canary

Owner Gate Queue

The reviewed queue and repository-radar release candidate is installed, but production activation remains blocked until its credential consumer passes verification.

Public

This documentation

This site explains the purpose and safety model. It is not an OpenClaw login, control panel or data endpoint.

Privacy posture

The public story stops before private context begins.

Credentials, messages, schedules, account identifiers, personal reports, prompts, live configuration and runtime state stay out of this site and its source.