Skip to main content

Feature

Administration and access control in ClawAI

What an operator gets when running ClawAI for an organisation: role-based permissions, custom roles, user management, plan and gateway settings, and a filterable audit log.

All features · Last reviewed:

Roles and permissions you can reshape

Every account has a role, and every screen and API action checks a named permission rather than a hard-coded role. Administrators can change which permissions a role carries and create new roles of their own, so a read-only reviewer or a billing-only operator is a configuration change, not a code change.

Users, plans and payments

Administrators can activate or deactivate accounts, change a user’s role, set a temporary password that must be changed at the next sign-in, and see an individual user’s usage and plan. Plans, refunds, payment gateways, the smart router’s settings, webhook deliveries and deployment details each have their own admin screen.

An audit log, and your own infrastructure if you need it

Security-relevant actions are written to an audit log that administrators can filter and review, and audit records are kept rather than expired on the ordinary log schedule. Organisations that cannot send data to a third-party provider can run the whole platform on their own servers with local models only; that is a scoped deployment rather than a self-serve plan.

Questions people ask

Can I create my own roles?
Yes. Administrators can create roles and choose which permissions each role carries; every screen and API action checks a named permission, not a fixed role.
Does ClawAI have team workspaces, seats or single sign-on?
Not yet. There are no shared team workspaces, per-seat billing, email invitations or single sign-on today. Administration is per deployment: an operator manages users, roles and plans from the admin console.
Can we run ClawAI inside our own network?
Yes, as a scoped deployment on your own servers with local models only, so no prompt or document leaves your infrastructure. The private-deployment page describes what that involves.

Try it rather than take our word for it

Role-based permissions, custom roles, user management and the audit log are shipped in the admin console; team workspaces, seat billing, invitations and single sign-on are not.