OpenClaw Explained: The Open-Source AI Assistant That Went Viral
OpenClaw is a free, open-source AI assistant that runs on your own computer and meets you in chat apps. Learn what it does, what it costs, and setup reality.
Running OpenClaw or Hermes yourself? This security checklist covers isolation, permissions, approvals, logging, and updates to keep business data safe.
A self-hosted AI agent is the most capable assistant you can get for the least money, and the one whose failures are entirely your problem. OpenClaw and Hermes Agent can read your files, run shell commands, browse the web, message your team, and act on schedules. That power is the point. It is also why running one for business without a security routine is asking for an incident you will discover too late.
This checklist gives you that routine. It assumes you are a non-technical owner working with someone technical, or a technical owner setting this up yourself. Each item is small on its own; together they are the difference between an agent you trust and one you hope about.
Before any settings, get clear on what can go wrong. A self-hosted agent holds credentials to your accounts, can execute commands on a machine you own, reads untrusted content from the web and your inbox, and acts in chat platforms where your team trusts inside messages. The realistic incident list is short: stolen credentials, a destructive or expensive action it took alone, a hijacked instruction from something it read, and silent data exposure.
Everything below maps to those four. Work through the checklist in order the first time, then keep the weekly and quarterly habits at the end. For the general principles behind these rules, our small-business agent security guide covers the same ground for managed agents.
Isolation limits how far any single mistake or compromise can travel.
An agent with your admin login is you on your worst day, acting at machine speed. Our least-privilege setup guide goes into depth; the essentials for self-hosting are:
One OpenClaw gateway can serve a whole shared team across its 29 channels, which means one credential set guards everyone's data. Split gateways or scoped identities per function when the data differs.
Approvals are the cheapest incident prevention you have. Define three tiers and enforce them:
| Tier | Examples | Handling |
|---|---|---|
| Automatic | Reading files, searching the web, drafting text, summarizing | Allowed, logged |
| Notify | Sending routine messages, creating calendar events, filing reports | Allowed, you get a notice you actually read |
| Approve first | Spending money, contacting customers, deleting or publishing anything, changing access | Blocked until a named human approves |
Write down which actions sit in which tier, tell the team, and review the list whenever the agent gains a new capability. Anything that touches money, customers, or credentials starts in the approve-first tier and only moves down with evidence.
Prompt injection is the attack where hostile instructions hide in content the agent processes: a web page, an email, a pasted document, a calendar invite. Because self-hosted agents can act on what they read, browsing plus acting equals exposure. Defenses, in order of value:
Microsoft's Agent 365 control plane, generally available since May 1, 2026, packages this kind of discipline for enterprises with agent registries, lifecycle rules, and threat protection at $15 per user per month. You do not need the enterprise product to copy the habits: inventory your agents, expire what is idle, and audit what acted.
Self-hosted means you are the operations team. Both projects move quickly: OpenClaw sat at release v2026.9.4 in September 2026, and Hermes shipped voice, agent-to-agent protocol support, and grounded citations in its August v0.20.0 Herald release with more in the September v0.21 line. Fast-moving software has fast-moving fixes, including security ones.
Name one person who owns this. Shared ownership of a security routine means nobody does it.
Self-hosting is the wrong choice more often than enthusiasts admit. Do not self-host if nobody will apply updates, if logs will never be read, if the agent needs access to regulated data you cannot properly isolate, or if the business cannot tolerate the agent being down while someone debugs it. OpenClaw has no paid tier and no hosted service, and Hermes leaves every operational decision to you, so there is no vendor safety net behind either one.
The alternative is not giving up on agents. A managed internal assistant with a defined scope, or a narrow workflow like review requests or onboarding, gets you most of the value with the operations included. Self-host for the jobs where control is worth the upkeep; buy for everything else.
Is it safe to run OpenClaw or Hermes Agent for business work?
It can be, if you treat the agent like a privileged employee. Both run shell commands and read your files by design: OpenClaw offers full access or sandboxed execution, and Hermes runs across 7 terminal backends. Safety comes from sandboxing, scoped credentials, approval gates, logging, and updates, not from the software alone.
What is the single most important security setting?
Least privilege on credentials and tools. Give the agent its own accounts with the minimum permissions the job needs, run file and shell access sandboxed where possible, and require human approval before anything that spends money, contacts customers, or deletes data. Most incidents trace back to over-broad access.
How do I protect against prompt injection with a self-hosted agent?
Assume any web page, email, or message the agent reads could carry hostile instructions. Default web reads and research to read-only, restrict which sites and senders can trigger actions, keep an allowlist of permitted tools, and require approval for outbound messages, payments, and system changes. Log everything so you can reconstruct what happened.
When should a small business NOT self-host an AI agent?
Do not self-host if nobody will apply updates, review logs weekly, and own incidents. OpenClaw has no paid tier or hosted service, and Hermes leaves operations entirely to you. If that ownership has no name attached, use a managed service or an agency-built agent with defined scope instead.
Run the checklist against your setup this week, starting with isolation and credentials, and put a name next to the weekly review. If the ownership question has no good answer, that is your answer. The free six-step AI automation plan on our homepage shows which jobs fit managed automation: start your AI automation plan. To talk through the decision, book a call.
OpenClaw is a free, open-source AI assistant that runs on your own computer and meets you in chat apps. Learn what it does, what it costs, and setup reality.
Hermes Agent is an open-source, self-improving AI assistant from Nous Research. See how its memory, skills, and gateway work for small business teams.
An AI agent with your passwords can help or harm. These seven practical rules cover credentials, permissions, approvals, and logging for small teams.
More articles: browse the full Praktivo blog.