NexusClaw
NexusClawEnterprise Applications & Digital Employee Platform
← All capabilities

Governance / Runtime Control Plane

Governance is not an after-the-fact log.It controls every execution before it runs.

Before information enters context, a tool runs, or business data is written, NexusClaw determines who is acting, what they may read, the action risk, and whether a person must approve.

After execution or blocking, the same chain preserves trace, tool calls, approvals, risk, cost, and outcome evidence. Governance is part of runtime, not a side report.

Product UI · Guardrail rulesNexusClaw Product UI
NexusClaw guardrail rules and risk levels
Define allow, review, confirmation, approval, and blocking policy by object, operation, and risk.

01 / Permission-aware Context

Unauthorized content is not hidden after retrieval. It never enters Agent context.

Knowledge retrieval checks workspace, role, object-read permission, and content access level for every candidate. If any condition fails, the candidate is denied by default and cannot influence later tool use.

01

Workspace isolation

Candidate content must belong to the current task workspace.

02

Authorization subject

Independent employees use their role; assistants inherit the real caller’s role.

03

Object read access

Business objects and related records must be readable by that subject.

04

Content access level

Private, organization-node, and global knowledge are evaluated individually.

Product UI · Knowledge access levelsNexusClaw Product UI
NexusClaw knowledge center content access levels
Knowledge fragments carry private, organization-node, or global access levels that are checked per retrieval candidate.

02 / Guardrails & Risk Levels

The same action can be allowed, reviewed, confirmed, approved, or blocked by risk

Guardrails turn “should not” prompt advice into system policy. Rules can target objects, operations, sensitive fields, tools, and learning usage with deterministic priority.

L0

Allow

Low-risk reads or verified actions run and remain traced.

L1

Review

Extra checks or result review without necessarily pausing the flow.

L2

Confirm

Explicit confirmation before a sensitive action runs.

L3

Approve

Pause execution and route the decision to an accountable person.

L4

Block

Deny the action with no bypass path.

Policy ownership

Guardrail release and rollback have registered owners. An Agent cannot disable, rewrite, or bypass policy at runtime.

03 / Human Approval

Human takeover happens before the sensitive action runs

The approval center gives the approver the object, execution ID, current step, submission time, and recent action. The person reviews context and approves or rejects before execution.

01

Explicit object

Know which business record the action affects.

02

Explicit step

See where execution paused and what it intends to do.

03

Explicit ownership

The real approver identity enters the audit chain.

Product UI · Sensitive Agent action approvalNexusClaw Product UI
NexusClaw sensitive Agent action approval center
Pending actions expose object, execution ID, status, step, time, recent action, and approve or reject controls.

04 / Trace, Cost & Audit

Start from a business outcome and reconstruct every tool call, cost, and control decision

Execution detail preserves input, output, status, duration, model and token usage, tool-call chain, and ReAct step timeline. Audit connects risk, object, action, approval, PII, and learning-use state.

Execution trace

Trigger source, step timeline, and final output.

Tool calls

Which tools ran, with parameters and result state.

Model and cost

Model, tokens, duration, and spend by step.

Approval and blocking

Which policy matched, who decided, and final state.

Product UI · Execution detail and tool chainNexusClaw Product UI
NexusClaw Agent execution detail, token cost, and tool-call chain
Input, output, token cost, tool chain, and ReAct step timeline stay together on one evidence page.

Audit turns runtime control into searchable evidence

Filter by execution ID, trace, object, risk, action, and time to see how reads, writes, creates, or blocks happened and whether evidence entered learning.

Product UI · Audit eventsNexusClaw Product UI
NexusClaw audit log risk and blocking records
Object, operation, risk, blocking, approval, PII, and learning-use state form a queryable governance record.

Customer Evaluation Checklist

When validating governance, actively try to make the system refuse you

01

Request sensitive knowledge as an unauthorized user

Confirm it never enters context instead of being masked after generation.

02

Trigger L3 and L4 actions

Confirm L3 pauses for approval and L4 blocks without a bypass.

03

Replay execution from a business result

Inspect input, tools, model, cost, approval, and outcome as one chain.

04

Return from an audit event to the real object

Verify linkage to execution, business object, owner, and learning-use state.

Current capability boundary

Governance depends on explicit identity, roles, object access, guardrails, and approval configuration. It does not define your compliance policy for you or imply undeclared certifications; it enforces configured boundaries and preserves evidence.

Bring one high-risk business action to the demo

We will test permission context, guardrail matching, human approval, execution or blocking, then replay the complete audit evidence from the outcome.