Decision Execution Governance
Documentation that gets you to first success fast
Choose the dexgate adapter for your runtime, start with Agent Execution Governance for AI agents, and add governed action control and decision records when you need them.
Start with OpenClaw or Codex docs. See Get started and Adapters for the path chooser.
Current availability
Free adapters: available now on npm
Paid governed workflows: early-access pilot
Coverage last validated: July 30, 2026
Validated free packages:
@dexgate/openclaw-trusted-mode@1.0.18,
@dexgate/codex-trusted-mode@0.1.16
See the compatibility matrix for coverage, limitations, and current versions.
Decision Execution Governance is the broader control layer. Docs lead with OpenClaw (recommended free path) and Codex; roadmap adapters share the same product model when published.
These docs show how to start with the free local hard gate and how to move to dexgate when you need governed control.
Protected deployment: one governed deployment boundary, usually one runtime integration serving a specific team, application path, or environment set. (Technical configure fields may still use names such as gatewayId.)
Public dexgate tiers are Production at 1 protected deployment / 2 environments, Team at 3 protected deployments / 3 environments, Business at 10 protected deployments / 5 environments, and Enterprise by custom annual agreement.
Start with your adapter
10-15 min
CLI required
Best for first-time setup
OpenClaw adapter quickstart
Install the plugin and run the free local-hardening check. Default free mode is ALLOWLIST_ONLY: only read_file, list_files, and search_files are allowed unless you expand the list.
High-consequence actions such as shell, writes, deletes, and git push stay blocked free by default.
- Install the plugin
- Verify default protections
- See blocked high-risk actions
Start Quickstart
Interactive demo
View Compatibility
10-15 min
CLI required
Best for first-time setup
Codex adapter quickstart
Start with the free local hard gate: conservative read-only shell from a fixed allowlist. apply_patch, broad interpreters, chaining, redirection, and mutating commands are blocked by default.
Run the free check, then use the paid pilot hosted path when you need live destructive-action enforcement and readonly governance-gap detection.
- Run the free demo
- Evaluate a sample event
- Review generated evidence
Start Quickstart
Interactive demo
View Compatibility
Enterprise & pilot
Enterprise rollout guidance
Pilot-first path for platform and security: free evaluation, one-runtime paid pilot, change management, then expand.
Open rollout guide
Minimum Production setup
One Linux Docker host + one agent host for paid first success. Not the multi-VM lab.
Minimum setup
Setup prompts for your agent
Copy-ready prompts for free install, paid wire-up, dashboard observe-then-configure, and Day-2 verify—use with your OpenClaw/Codex/Grok/etc. agent.
Open setup prompts
How to use these docs
Choose your adapter path.
Start with the free local hard gate and verify the default protections.
For company rollout, use the enterprise pilot guide before multi-runtime expansion.
Free local hard gate vs dexgate
Free local hard gate
Safer defaults
Fastest way to get started
Best for evaluation and early rollout
dexgate (paid pilot)
Monitor and record governed action requests
Governed action control + decision records
Best for production-bound pilot review (early access)
For review teams