/ Desktop trust layer for AI agents
Control whatyour agentscan access.
Control Claw runs on your desktop and sits between AI agents and apps like Gmail and Calendar. Instead of handing over your whole account, you grant a narrow, revocable set of permissions. Every request is checked before it happens.
Connect
Link your apps and the agents that need them.
Configure
Set the scopes, approvals, and limits per connection.
Control
Watch every request, approve or block in real time.
A local gateway between your agent and the apps it uses.
Control Claw runs on your machine. Every request an agent makes flows through it and is checked against your rules on the way in and on the way back. Only the allowed parts get through. Your inbox and credentials stay on your device.
Everything inside the dashed box runs on your computer. Your email, calendar, and credentials never leave it. Control Claw calls the provider APIs directly.
Intercept, locally
Control Claw runs on your computer as a command-line tool. Your agent talks to it instead of to Gmail or Calendar. The account credentials stay inside Control Claw and are never handed to the agent.
Check before it runs
Before any request reaches a provider, it's matched against your rules: which labels, which calendars, which recipients, how much, and whether this action needs your explicit approval first.
Check what comes back
The response is inspected too. Sensitive fields are redacted or filtered on your machine before the agent ever sees them. Out-of-scope requests are blocked, risky ones pause for approval, and all of it is logged.
Your private data never leaves your computer.
The contents of your emails, your calendar, and your account credentials stay on your machine. Control Claw connects to Gmail and Calendar directly from your device. None of that content is routed through our servers or any third party. Only the rules you write and a short activity log sync, and you choose what that log records.
Works with the agents you already run.
Control Claw is a CLI, so it works alongside your existing setup, including OpenClaw, Hermes, Claude, Codex, and any other agent provider.
Change a policy. Watch the agent's view change with it.
Toggle a rule on the left and the same request returns a different result on the right. Some data is unlocked, some is redacted, and some sends are held for your approval. This uses the same logic Control Claw runs against real accounts.
Control ClawSimulator
Connected
Your policies
Only emails tagged Recruiting are visible to the agent
Anything older than a month stays out of reach
The agent can read and schedule on your work calendar
Messages to outside recipients wait for your sign-off
Personal, private events are never exposed
Ask the agent
What the agent sees
Pick a request to run it through your policies.
You'll see exactly what comes back and what stays hidden.
Connecting an agent shouldn't mean handing over the keys.
Agent access is all-or-nothing.
Most integrations are a single switch. Connect the agent and it can read every email, every event, and every private appointment, and act on all of them. For tools as personal as your inbox and calendar, one careless prompt or a single prompt-injection is enough to cause harm.
Connected means full access. No scopes, no approvals, no way to see what it did.
A control layer you set the rules for.
Route the agent through Control Claw instead. You define the scopes it can reach, set approval gates on sensitive actions, and block private data outright. The agent stays useful and cannot go past the limits you set.
Connected, but constrained. Your agent only ever sees what you unlock.
Six kinds of boundary, one place to set them.
Policies combine per connection. Set them to define exactly what an agent can reach through that connection and what it must ask about first.
Scoped inbox access
Limit which labels, senders, or time ranges the agent can read.
Calendar boundaries
Choose which calendars are visible and which events it can change.
Approval gates
Require your sign-off for risky moves like sending to outsiders.
Private data protection
Keep private events and sensitive threads entirely off-limits.
Visible audit trail
Review exactly what was allowed, blocked, or approved over time.
Time-based access
Grant expiring permissions that revoke themselves automatically.
What the agent can do
Observe
Read the emails and view the events inside its scope
See recruiting mail, check availability
Prepare
Draft replies and propose meeting times
Write reply drafts, suggest schedule slots
Change
Edit its own drafts and reschedule events it can touch
Update meeting times, revise draft content
Commit
Send mail and confirm changes within the rules you set
Send messages, book meetings
How each request resolves
Allowed
Runs automatically because it falls inside scope
Ask first
Pauses for your one-tap approval before it happens
Blocked
Refused outright. The data never leaves your machine
Example policy set: a recruiting agent
- Reads the Recruiting label only
- Suggests times on the Work calendar only
- Drafts outbound replies freely
- Needs approval to email external recipients
- Can never open private events
- Access expires after the hiring sprint
Five layers, stacked from your apps up to your oversight.
Each layer narrows what the one above it can do. Together they make every connection scoped and reviewable.
Connected apps
Gmail and Calendar are registered with the local gateway. They are reached directly from your machine and never exposed to the agent.
Connected agents
OpenClaw, Hermes, Claude, Codex, or any other agent is pointed at the Control Claw CLI instead of at your raw accounts.
Policies
You define the scopes, rules, and boundaries that shape every request.
Approvals
Sensitive actions pause and wait for your explicit, one-tap sign-off.
Auditability
Everything allowed, blocked, or approved is recorded for you to review later.
Frequently asked questions.
Answers about security, privacy, and what Control Claw can and cannot access.
/ Get early access
Keep your agentsuseful andscoped.
Put Control Claw between your agents and your sensitive tools. Set the boundaries once. Every request is then checked, logged, and reversible.



