GatekeeperOS
An agent may need one resource, not every credential its operator owns. GatekeeperOS separates resource access from the decision to make a change real.
Read the case study
The problem
Tool access often hides several decisions: which resource, which agent, which operation, and who approves the effect. A useful permission model needs to make those decisions explicit.
My contribution
Developing an independent operations layer around OpenClaw, with scoped grants, gatekeeper drivers, pending actions, and reviewable audit records. Work is AI-assisted; upstream platforms and dependencies are credited separately.
The design choice
Keep authorization in the kernel and resource behavior in typed drivers. A pending action can be inspected before application; a proposed effect is not represented as a completed external change.
Evidence & scope
Public source and dated acceptance records. Release compatibility and driver coverage are explicit in the project documentation. This is an operations layer—not a Linux distribution or a sandbox for hostile same-user code.
Explore source & acceptance records ↗