/ Desktop trust layer for AI agents

Control whatyour agentscan access.

Control Claw runs on your desktop and sits between AI agents and apps like Gmail and Calendar. Instead of handing over your whole account, you grant a narrow, revocable set of permissions. Every request is checked before it happens.

01

Connect

Link your apps and the agents that need them.

02

Configure

Set the scopes, approvals, and limits per connection.

03

Control

Watch every request, approve or block in real time.

Scroll to the simulator
01How it works

A local gateway between your agent and the apps it uses.

Control Claw runs on your machine. Every request an agent makes flows through it and is checked against your rules on the way in and on the way back. Only the allowed parts get through. Your inbox and credentials stay on your device.

Your machineProvider APIs
Agent 1
Agent 2
Agent 3
Agents
Rules · web app
Control ClawCLI · runs locally0 allowed
Gmail
Calendar
Apps
Allowed through
Blocked at the gate
Filtered result returns

Everything inside the dashed box runs on your computer. Your email, calendar, and credentials never leave it. Control Claw calls the provider APIs directly.

01

Intercept, locally

Control Claw runs on your computer as a command-line tool. Your agent talks to it instead of to Gmail or Calendar. The account credentials stay inside Control Claw and are never handed to the agent.

02

Check before it runs

Before any request reaches a provider, it's matched against your rules: which labels, which calendars, which recipients, how much, and whether this action needs your explicit approval first.

03

Check what comes back

The response is inspected too. Sensitive fields are redacted or filtered on your machine before the agent ever sees them. Out-of-scope requests are blocked, risky ones pause for approval, and all of it is logged.

Your private data never leaves your computer.

The contents of your emails, your calendar, and your account credentials stay on your machine. Control Claw connects to Gmail and Calendar directly from your device. None of that content is routed through our servers or any third party. Only the rules you write and a short activity log sync, and you choose what that log records.

Works with the agents you already run.

Control Claw is a CLI, so it works alongside your existing setup, including OpenClaw, Hermes, Claude, Codex, and any other agent provider.

OpenClawHermesClaudeCodex+ more
02The simulator

Change a policy. Watch the agent's view change with it.

Toggle a rule on the left and the same request returns a different result on the right. Some data is unlocked, some is redacted, and some sends are held for your approval. This uses the same logic Control Claw runs against real accounts.

RequestPolicy checkScoped result

Control ClawSimulator

Live demo
A

Connected

Claude Agent
Connected
Gmail
Connected
Google Calendar
Connected
B

Your policies

Toggle to change access
Recruiting inbox onlyAllowed

Only emails tagged Recruiting are visible to the agent

Last 30 days onlyAllowed

Anything older than a month stays out of reach

Work calendar onlyAllowed

The agent can read and schedule on your work calendar

External sends need approvalAsk first

Messages to outside recipients wait for your sign-off

Private events blockedBlocked

Personal, private events are never exposed

C

Ask the agent

D

What the agent sees

Pick a request to run it through your policies.

You'll see exactly what comes back and what stays hidden.

03Why it exists

Connecting an agent shouldn't mean handing over the keys.

Today

Agent access is all-or-nothing.

Most integrations are a single switch. Connect the agent and it can read every email, every event, and every private appointment, and act on all of them. For tools as personal as your inbox and calendar, one careless prompt or a single prompt-injection is enough to cause harm.

Connected means full access. No scopes, no approvals, no way to see what it did.

With Control Claw

A control layer you set the rules for.

Route the agent through Control Claw instead. You define the scopes it can reach, set approval gates on sensitive actions, and block private data outright. The agent stays useful and cannot go past the limits you set.

Connected, but constrained. Your agent only ever sees what you unlock.

04What it enforces

Six kinds of boundary, one place to set them.

Policies combine per connection. Set them to define exactly what an agent can reach through that connection and what it must ask about first.

Scoped inbox access

Limit which labels, senders, or time ranges the agent can read.

Calendar boundaries

Choose which calendars are visible and which events it can change.

Approval gates

Require your sign-off for risky moves like sending to outsiders.

Private data protection

Keep private events and sensitive threads entirely off-limits.

Visible audit trail

Review exactly what was allowed, blocked, or approved over time.

Time-based access

Grant expiring permissions that revoke themselves automatically.

What the agent can do

Observe

Read the emails and view the events inside its scope

See recruiting mail, check availability

Prepare

Draft replies and propose meeting times

Write reply drafts, suggest schedule slots

Change

Edit its own drafts and reschedule events it can touch

Update meeting times, revise draft content

Commit

Send mail and confirm changes within the rules you set

Send messages, book meetings

How each request resolves

Allowed

Runs automatically because it falls inside scope

Ask first

Pauses for your one-tap approval before it happens

Blocked

Refused outright. The data never leaves your machine

Example policy set: a recruiting agent

  • Reads the Recruiting label only
  • Suggests times on the Work calendar only
  • Drafts outbound replies freely
  • Needs approval to email external recipients
  • Can never open private events
  • Access expires after the hiring sprint
05The hierarchy

Five layers, stacked from your apps up to your oversight.

Each layer narrows what the one above it can do. Together they make every connection scoped and reviewable.

L1

Connected apps

Gmail and Calendar are registered with the local gateway. They are reached directly from your machine and never exposed to the agent.

L2

Connected agents

OpenClaw, Hermes, Claude, Codex, or any other agent is pointed at the Control Claw CLI instead of at your raw accounts.

L3

Policies

You define the scopes, rules, and boundaries that shape every request.

L4

Approvals

Sensitive actions pause and wait for your explicit, one-tap sign-off.

L5

Auditability

Everything allowed, blocked, or approved is recorded for you to review later.

06Questions

Frequently asked questions.

Answers about security, privacy, and what Control Claw can and cannot access.

/ Get early access

Keep your agentsuseful andscoped.

Put Control Claw between your agents and your sensitive tools. Set the boundaries once. Every request is then checked, logged, and reversible.

No spam. We'll email you once when early access opens.

Or try the simulator