Decision Execution Governance

Documentation that gets you to first success fast

Choose the dexgate adapter for your runtime, start with Agent Execution Governance for AI agents, and add governed action control and decision records when you need them.

Start with OpenClaw or Codex docs. See Get started and Adapters for the path chooser.

Current availability

Free adapters: available now on npm

Paid governed workflows: early-access pilot

Coverage last validated: July 30, 2026

Validated free packages: @dexgate/openclaw-trusted-mode@1.0.18, @dexgate/codex-trusted-mode@0.1.16

See the compatibility matrix for coverage, limitations, and current versions.

Decision Execution Governance is the broader control layer. Docs lead with OpenClaw (recommended free path) and Codex; roadmap adapters share the same product model when published.

These docs show how to start with the free local hard gate and how to move to dexgate when you need governed control.

Protected deployment: one governed deployment boundary, usually one runtime integration serving a specific team, application path, or environment set. (Technical configure fields may still use names such as gatewayId.)

Public dexgate tiers are Production at 1 protected deployment / 2 environments, Team at 3 protected deployments / 3 environments, Business at 10 protected deployments / 5 environments, and Enterprise by custom annual agreement.

Start with your adapter

10-15 min CLI required Best for first-time setup

OpenClaw adapter quickstart

Install the plugin and run the free local-hardening check. Default free mode is ALLOWLIST_ONLY: only read_file, list_files, and search_files are allowed unless you expand the list.

High-consequence actions such as shell, writes, deletes, and git push stay blocked free by default.

  • Install the plugin
  • Verify default protections
  • See blocked high-risk actions

Start Quickstart Interactive demo View Compatibility

10-15 min CLI required Best for first-time setup

Codex adapter quickstart

Start with the free local hard gate: conservative read-only shell from a fixed allowlist. apply_patch, broad interpreters, chaining, redirection, and mutating commands are blocked by default.

Run the free check, then use the paid pilot hosted path when you need live destructive-action enforcement and readonly governance-gap detection.

  • Run the free demo
  • Evaluate a sample event
  • Review generated evidence

Start Quickstart Interactive demo View Compatibility

Enterprise & pilot

Enterprise rollout guidance

Pilot-first path for platform and security: free evaluation, one-runtime paid pilot, change management, then expand.

Open rollout guide

Minimum Production setup

One Linux Docker host + one agent host for paid first success. Not the multi-VM lab.

Minimum setup

Setup prompts for your agent

Copy-ready prompts for free install, paid wire-up, dashboard observe-then-configure, and Day-2 verify—use with your OpenClaw/Codex/Grok/etc. agent.

Open setup prompts

How to use these docs

Choose your adapter path.

Start with the free local hard gate and verify the default protections.

For company rollout, use the enterprise pilot guide before multi-runtime expansion.

Free local hard gate vs dexgate

Free local hard gate

Safer defaults

Fastest way to get started

Best for evaluation and early rollout

dexgate (paid pilot)

Monitor and record governed action requests

Governed action control + decision records

Best for production-bound pilot review (early access)

For review teams

Assurance

Understand what evidence is available in the local baseline and in dexgate.

Compatibility details

Review supported runtime versions and declared compatibility states.

Security

Review deployment boundaries, controlled updates, and vulnerability reporting.

Start Free Interactive demo Purchase

See Pricing