For platform, security, and DevEx
Enterprise rollout guidance
dexgate is designed to start with a pilot, then expand—not “every developer, every agent, day one.” This page is the recommended adoption path for OpenClaw, Codex, and other adapters.
Product posture: free adapters on npm and paid early access pilot. Treat this as a controlled security/platform program, not a silent plugin install.
Who this is for
- Platform / DevEx — owns install standards and support
- Security / AppSec — owns policy, audit expectations, and risk acceptance
- Team lead of a pilot team — owns day-to-day agent use under the free wall and paid path
Individual engineers should start from Get started for free install only. Enterprise-wide enablement should follow the phases below.
What not to do on day one
- Roll out every adapter (OpenClaw, Codex, Claude, Cursor, Copilot, Grok) at once
- Require multi–protected-deployment / multi-environment mesh before first Passport success
- Surprise engineers with free defaults—document that free mode is a conservative read-only allowlist (not full day-to-day edit/test coverage) and point them at Compatibility before rollout
- Promise generally available production SLAs while the product is still early access pilot
Recommended phases
Stage 1 — Free evaluation (days 0–3)
Goal: Prove the free local hard gate without a licensed Dexgate runtime.
- Scope: 1–3 engineers, one runtime only (recommended: OpenClaw)
- Optional self-check:
dexgate-assess/local-hardening-check— package self-check plus best-effort env inspect; not proof a real agent turn was intercepted - Success: free adapter installed and enabled per the OpenClaw free quickstart so free allowlist policy applies in real sessions
- Behavior: once installed, local adapter-specific hard gates with conservative read-only defaults; see Compatibility for the exact allowed tool surface. High-consequence actions (e.g.
git push, unrestricted shell, deploy-class, free-mode writes/patches) stay blocked with an upgrade CTA - Licensed Dexgate runtime required? No
OpenClaw free quickstart Codex free quickstart
Phase 1 — Paid pilot (about 1–2 weeks)
Goal: One real governed decision (policy decision + Passport evidence) for one team.
- Scope: one pilot team, one adapter, one Linux Docker host for the Dexgate policy runtime
- Topology: minimum pilot deployment only — see Minimum Production setup
- Observe before you tighten: after the licensed runtime is up and the adapter is connected, use the customer runtime dashboard (delivered with your runtime package) to review governed actions, policy outcomes, and evidence while the pilot team works. Expand policy only after you see real traffic.
- Success: adapter connects to a live licensed runtime; console Deployments healthy; at least one evidence/decision row after a gated action in the customer workspace
- Licensed runtime required? Yes (customer-hosted pilot)
- Owners: platform installs runtime; pilot team uses agent; security reviews activity then defines what must be Passport-gated
Minimum paid setup Pricing (early access / pilot)
Phase 2 — Expand carefully
Goal: Broader use without multiplying failure modes.
- Second environment (e.g. staging) only after Phase 1 success is consistent and repeatable
- Second adapter only with platform ownership (Codex available free; Claude/Cursor/Copilot/Grok on roadmap)
- Document policy: which action classes always need a policy decision and Action Passport vs free local allow
- Optional multi-environment topology: sign in for the operator multi-environment guide after first paid success
What engineers will feel (set expectations)
| Mode | Usually still works | Typically blocked / governed |
|---|---|---|
| Free local hard gate | Adapter-specific conservative read-only defaults only (OpenClaw: read_file / list_files / search_files; Codex: read-only shell allowlist). See Compatibility. |
Writes/edits, apply_patch (Codex free), tests/interpreters, chaining/redirection, git push, deploy-class, unrestricted shell — no Passport |
| Paid governed pilot | Same day-to-day work when policy allows; high-risk actions may require Passport / approval path | Production-bound change without entitled policy + evidence; incorrect workspace, runtime, or credential configuration |
Free mode is intentionally narrow (conservative read-only defaults). Document that clearly so engineers do not expect full day-to-day edit/test coverage free. Keep the free wall honest and the paid upgrade path obvious.
Change-management checklist (copy for your pilot kickoff)
- Name pilot owner (platform) + security reviewer + pilot team lead
- Publish one page: what stays free, what is blocked, how to get help
- Document agent host permission modes (ask / auto / unrestricted execution), including any fleet-wide remote or managed config. Treat unrestricted host execution as higher risk—not as “production is governed.”
- During paid pilot: review the customer runtime dashboard before locking managed policy
- Success criteria: free PASS; paid governed check; one evidence artifact in the customer workspace
- Rollback: uninstall adapter or return to free-only allowlist mode
- Support: pilot office hours / shared channel (early access pilot)
Host permission modes
Coding agents increasingly ship org-level defaults for how often humans approve tool calls (ask, auto/classifier, always-approve). Some hosts can push those defaults fleet-wide via remote or managed settings. That layer answers: “Should the harness prompt the user?”
dexgate answers a different question: “Should this proposed action run now with proof?” Free adapters still hard-gate high-consequence tools on the laptop. Paid pilot still sends governed action requests to the Dexgate policy runtime, issues Passports on allow-with-proof, and records decisions—even when the host would have auto-approved.
Roadmap example: Grok Build is listed as ROADMAP on the compatibility matrix. When its adapter ships, the same host-permission vs Dexgate-governance distinction applies; until then, treat Grok only as an illustration of host permission modes—not as a currently supported Dexgate integration.
- Do: align host fleet defaults with your risk posture (prefer ask or constrained auto in production-bound envs).
- Do: install the matching free adapter first, then connect entitled pilots to the Dexgate policy runtime.
- Don’t: treat host unrestricted execution as a substitute for Passport fail-closed or shared governed-action evidence.
More on Passports: What is an Action Passport? · Supported vs roadmap adapters: Adapters and the compatibility matrix.
Roles and systems
- Customer console — licenses, downloads, billing, deployments, and evidence for your organization
- Agent host — where OpenClaw, Codex, or another supported integration runs with the free or paid adapter
- Licensed Dexgate runtime — Linux Docker host for paid policy decisions and Action Passports (not required for free evaluation)
- Customer runtime dashboard — monitor deployment health, governed actions, policy outcomes, and evidence generation for your Dexgate environment
Observe agent activity, then configure
Free mode hard-gates on each laptop. Paid pilot gives platform and security a shared stream of what agents request—allow/deny, Passport presence, gaps—recorded as decisions you can review.
In a paid pilot, treat the customer runtime dashboard as your first operations surface:
- Stand up the minimum licensed runtime and connect one adapter.
- Open the customer runtime dashboard while the pilot team uses the agent normally.
- Note which tools and action classes appear, what is allowed vs denied, and where evidence is missing.
- Only then define the managed policy set, approvals, and console deployment checks—so configuration matches real traffic.
Free evaluation has no runtime dashboard: you only get the local hard gate. Shared governed-action monitoring starts once the paid runtime is connected.
Adapter maturity (for rollout planning)
Status and coverage details are in the compatibility matrix and on Adapters.
Related docs
- Get started — free path chooser
- Setup prompts for your agent — copy-ready free / paid / dashboard / Day-2 prompts
- Minimum Production setup — one Docker host paid pilot
- Multi-environment deployment — operator guide (sign-in required for full procedures)
- Compatibility — evidence-gated matrix
- Assurance — review materials
- Founding Customer Pilot — $3,500 guided one-workflow pilot