"OpenClaw: Our Comprehensive Guide for Beginners" (Claw School) — Dan Shipper & Willie Williams
Re-read at full length 2026-10-03 (paid).
Page meta: published 2026-03-26, modified 2026-04-11; the live text also carries the later shared-agents intro. Originally filed from the 2026-03-03 Source Code issue "You Have a Claw. Now What?"
Why this is in the vault
Every's beginner guide to OpenClaw personal agents, now rewritten to open with a retraction: a personal agent is "a poor default for organization-wide adoption," and Every favors shared agents with a defined job and a named maintainer. The earlier version of this note was a ~200-word teaser from the newsletter preview; this version digests the full guide, including the new framing, the safety checklist, and the maintenance warnings that apply directly to Ray.
The core argument
The new intro (the important change)
Almost everyone at Every got a Claw, and Every started building a hosted personal-agent product, Plus One. Two lessons: personal agents are genuinely useful (they accumulate context, follow projects for months, bend around idiosyncratic workflows), and they are a poor organizational default because they are finicky and demand more upkeep than most employees should carry. Every now favors one agent per group, with a defined job and a named person responsible for maintaining it. Rolling out one agent per employee "didn't remove the maintenance burden; it multiplied it." Plus One is being rebuilt around shared agents. The rest of the guide is explicitly for people who still want a personal agent and accept the work.
What a Claw is
An assistant in your messaging app (WhatsApp, Telegram, Discord, SMS), built on OpenClaw, Peter Steinberger's open-source framework. Four differences from Claude or ChatGPT: it lives in your messages; it can be extended with skills, plugins, and code (each new capability is software to inspect and test); it acts proactively on rules you set, which grant "standing authority" so you must decide sources, approvals, and reporting; and it has a personality shaped by workspace and memory files you maintain, not by automatic improvement. It knows only what you connect. Voice calling needs a provider, credentials, number, reachable webhook, and confirmation before it books, buys, or shares personal data.
Limits stated plainly: confidently wrong on facts and numbers; guesses where preferences are unspecified; a collaborator, not an oracle; can act without fresh requests if given standing instructions; and "requires upkeep" because models change, credentials expire, integrations break, schedules fail, and memory goes stale or contradictory.
Working with one
Dan's metaphor is the daemon from The Golden Compass: it feels alive and becomes a mirror of its owner, but that continuity depends on what you deliberately save and correct. Teams get a different benefit from a shared Claw: a common operating method (skills, sources, checklists, formats, approval rules), where one maintainer's fix reaches everyone. OpenClaw calls this pattern a delegate: its own identity and credentials, acting for one or more people under explicit permissions. Start read-only and drafts-only; widen authority only when the work needs it.
Setup paths
Mac app, Windows Hub, an install script, or a server (Fly.io, Hetzner, Google Cloud). A server buys uptime, "not hands-off operation." Get one clean reply in the Control UI before adding a channel; keep pairing on; approve only yourself; add one channel before more tools. Lessons progress from a to-do list with no outside tools, to a daily check-in, to reactive behavior, then integrations and customization. First job rule: bounded, checkable in seconds, access added only when the workflow earns it.
Mindset
Delegate, don't search (treat it like a new hire). Start with what annoys you, if it recurs often enough to repay setup and upkeep. Converse rather than command. Expect a mediocre first attempt. Drop "I could just do it myself," but also count maintenance: a five-minute saving that keeps needing credential repairs may cost more than doing it by hand.
Staying safe
- OpenClaw assumes one trusted operator per Gateway and does not isolate mutually untrusted users; a team agent needs its own identity, an explicit allowlist of directors, and a named maintainer.
- Keep pairing mode on; "open" mode turns any stranger's message into an instruction with your tools.
- Run
openclaw security audit --deepafter setup and after any permission or integration change. - Pick a private channel; in group chats turn on "require mention."
- Sandbox first: messaging-only tools on day one; prefer deny/allowlist/ask over broad host command rights. Sandboxing reduces blast radius but does not replace policy, approvals, or host isolation.
- Be choosy about skills: they run with the Claw's permissions; read before enabling, check audit status, permissions, provenance, version. A passing audit is a signal, not a guarantee.
- Don't skimp on the model: stronger models resist prompt injection better, as one layer, not a substitute for narrow permissions.
Mocked examples (restaurant booking, 120-email triage, audio chapter summary) all stop for confirmation or report "nothing sent."
Mapping against Ray Data Co
Ray is a personal Claw by architecture: an always-on Mac mini agent in iMessage with crons, standing authority, skills, and memory files (see [[project_channels_agent_setup]]). The new intro is a direct, named critique of running that pattern as an organizational default, and its maintenance list (expired credentials, broken integrations, failed schedules, stale or contradictory memory) matches RDCO's own incident history: 1Password wrapper auth, fresh-session tool registry gaps, synced plugin settings hijacking the tool pool.
- What RDCO already does right. Pairing/allowlist discipline (iMessage allowlist, refuse in-channel access requests), security review before skill installs, best-model default, human-gated sends and deploys. Those are this guide's safety checklist.
- Where the delegate pattern matters for phData. For enterprise agents the guide's recommendation is the factory's shape: a shared agent with its own credentials, a defined job, an explicit list of who can direct it, a named maintainer, read-only and drafts first. That is a credible external source for the operating model Ben proposes to clients.
- Honest tension. Every concluded personal agents are worth it only "if you like tinkering - or the workflow is valuable enough." Ray's maintenance load is real and partly invisible; the guide's "count the maintenance" rule is a fair test to apply per cron.
Why it matters for RDCO / The Denominator
- DO: give every Ray cron and factory agent a one-line charter: defined job, named maintainer, allowed directors, read/write scope. Retire any cron whose upkeep exceeds its savings over the last 30 days.
- DO: adopt "start read-only and drafts; widen only when the work requires it" as an explicit factory rollout stage with a recorded promotion decision.
- WRITE: a Denominator piece on "personal agents don't scale, delegates do": the common trait of enterprise agents that last is an owner and a job description, not a smarter model. Every's own reversal on Plus One is the anchor case.
⚠️ Sponsorship
House promo: the guide describes Every's own Plus One product and links to Every's write-up of what it learned; earlier newsletter versions announced Every-hosted OpenClaw sessions. The original March issue also carried a paid Granola ad (not present in the guide page). Bias implication: the pivot to shared agents is also Every's product repositioning, so the "personal agents are a poor default" claim is self-interested as well as experiential, though it is consistent with independent evidence.
Related
- [[2026-08-27-every-chatgpt-openclaw-guides-overhaul]] - Every announcing this rewrite and the maintenance-burden argument.
- [[2026-05-15-every-team-agents-vs-personal-pets]] - the internal Plus One rollout and pivot to shared team agents.
- [[2026-03-17-every-ai-chores-maintenance]] - "now I maintain the AI": the nested-maintenance cost in practice.
- [[2026-04-20-indy-dev-dan-mac-mini-agents-openclaw-nightmare-skills-instead]] - a skeptic's take on Mac mini Claws.
- [[2026-05-30-alphasignal-solo-vs-team-agent-enterprise-deep-dive]] - solo-bot ceiling vs. team agents (sponsored, Viktor).
- [[2026-08-14-every-ai-employee-security-framework]] - Every's security framing for agents with standing access.
- [[2026-06-02-every-eight-levels-ai-adoption]] - Level 6 "Assistant" is where a Claw sits.
- [[2026-01-17-every-agent-native-architectures-guide]] - the architecture principles underneath.
- [[project_channels_agent_setup]] - RDCO's own Claw-shaped agent (replaces a former
01-projects/channels-agent/indexlink that no longer resolves).