Set up your agent safely

Your AI agent (OpenClaw or Picoclaw) can handle sensitive data and run autonomous actions. Setting it up safely protects your accounts and keeps your bot from leaking information. Follow these practices so you don't get compromised.

1

Run on a dedicated computer

Install your agent on a dedicated machine-for example a Mac Mini or an old MacBook-rather than your main laptop or shared computer. The bot needs to stay running 24/7 so it can respond when you message it, so use a machine you can leave on. On Mac, you can use a free app (e.g. Amphetamine) to prevent sleep if needed.

2

Sign up with its own credentials

Give your agent its own Apple ID and Gmail account. The bot should not have access to your main Gmail except for the specific files and calendars you choose to share with it. That way a compromise of the bot does not expose your primary account.

3

Run the security audit (self-hosted)

If you run your agent yourself (self-hosted, e.g. OpenClaw), run the built-in security audit so it hardens the setup. In a terminal on the machine where your agent runs (OpenClaw):

claudebot security audit --deep

It will walk through steps to make the installation more secure. On ClawNode, security is managed by the platform; you don't need to run this command on a hosted instance.

4

Give read access to your account, write to select files only

Use least privilege: let the bot read what it needs (e.g. your personal calendar) and write only to specific files you've shared with it. For example, it can read your calendar and edit only the Google Docs and Sheets you've explicitly shared with the bot's Gmail. It should not have access to your entire Google Drive. For the exact steps to connect calendar and docs, see Connect your agent to Google Workspace.

5

Never share your bot with anyone else

Do not add your bot to group chats or put it on a public website. Your bot should talk only to you. If you make it truly personal, you'll share sensitive information with it; sharing the bot with others can lead to that information leaking. Keep it single-user only.

Important

Bots that are shared in group chats or on public sites have been known to leak confidential information. Never share your personal agent-only you should be able to interact with it.

Next: Connect your agent to Google Workspace, or use your agent for calendar, docs, voice, and briefings.

Sign up

Welcome to ClawNode

Pick a plan: OpenClaw (bring your own API key) or a Node (Ollama + open-source LLM preinstalled).

or

By selecting Agree and continue, I agree to ClawNode's Terms of Service and Privacy Policy.

or

Already have an account? Log in