I watched all the OpenClaw videos, the breathless ones promising the personal assistant you always wanted. Run it on your machine, change your life, hands-free magic. And honestly, I was right there with them in the excitement for about five minutes.
But here’s the thing. The security guy in me couldn’t help but think, OK, so what’s the catch? What’s the issue? Every time the hype ratchets up, I start looking for the angle, the dark corners. It’s never only magic and rainbows, is it?
So I decided to try it out myself.
Not on a single one of my normal machines.
The promise is simple: an agent that can do things for you, not only suggest things. That sounds like productivity. In practice, it also means authority. Someone or something is now acting in your name.
That is not a technical detail. That is a leadership decision.
Not saying existing controls are no longer any good. Least privilege still applies, authentication still matters and logging is still critical. But our scoping assumptions need revision. If an agent can take action, we've already delegated authority whether we documented it or not.
If you lead a team, you already know how this plays out.
When something goes wrong, the post-incident question is never: which tool did it.
It’s: who approved this, what did we allow, and why did nobody notice sooner.
First go was Docker. Frustration is the only word for it. It wouldn’t play nice locally. Nothing smooth about that install process, and frankly, that’s a red flag in itself.
So I did what security folk do. I moved to a fresh VPS, no ties to anything real.
A clean environment gives you two huge leadership wins:
This is the rule I keep coming back to, whether I’m playing with agentic tools or signing off a business process change.
Always think, what is the very worst thing that could possibly happen?
And when that very worst thing happens, how can you get back from it?
And if you can’t get back from that very worst thing, then don’t do it.
If that feels slow, good. Speed is not the goal. Survivability is the goal.
Once it was up, it was not doing all the flashy, integrated stuff everyone shows on YouTube.
That was deliberate.
It doesn’t have my browser. It doesn’t touch my bank. It doesn’t touch my socials. I’m not handing an early-stage agent the keys to my life and hoping for the best.
Instead, I’m taking a service-by-service approach:
Here’s the leadership trap: most teams do the opposite.
They start with open access because it feels productive, then retrofit controls after the first scare.
The current AI playbook quietly inverted "least privilege" access. Every week I talk to teams deploying AI and almost none of them have thought through what “open by default” really means...As an industry we’ve spent decades building security around least privilege: only grant what’s needed, when it’s needed, for as long as it’s needed.
I keep hearing reports about OpenClaw having lots and lots of security things and stuff like Cisco. That’s not gossip. That’s your signal to stop treating this like a toy.
If you’re leading an organisation, you do not need to be the most technical person in the room to be effective here. You need to ask better questions, earlier.
Questions like:
And if you cannot answer those, the correct response is not to push ahead harder.
It’s to shrink the blast radius.
Slow steps, right? Slow steps.
You wouldn’t let a child loose in a place with sharp, sharp, sharp implements because it could hurt itself.
In the same way, don’t let your AI loose where it could land you in trouble.
Treat it like an intern. In your business, you wouldn’t give them access to every single thing at the beginning. You would slowly add as you trust, as you learn to trust someone, you then give them more information.
That mental model is more useful than any vendor pitch deck.
It keeps you anchored in:
Yes, I see why people want Telegram or WhatsApp style control. It’s familiar, low friction, and it feels like a personal assistant should live there.
But if you wire an agent into messaging without a plan, you’re creating a new path into your operations.
My leadership rule of thumb:
The goal is not paranoia. The goal is governance that matches the reality of how humans behave.
If you want the benefits of agentic workflows without rolling the dice on your business, do this in order:
None of this is hard. It is simply disciplined. That’s what leadership looks like here.
OpenClaw is useful, and it is exciting.
But excitement is not a control. It’s a feeling.
If you’re going to experiment, do it like you would onboard a junior hire into a regulated environment: with kindness, structure, boundaries, and a clear path to earned trust.
Slow steps are safer steps.