OS-level block: the sandboxed build/task user cannot open these localhost ports.
Read-only by design — edit scripts/tenant-firewall.sh to change the list.
Loading…
Memory Provider
Channels
Channel Gates
Gmail Mailbox Manager
Loading…
Include additional context (cross-channel) for the email classifier
Loading…
Corporate Mailbox Manager
Loading…
Include additional context (cross-channel) for the email classifier
Loading…
Daily Briefing Manager
Category-level controls for the daily Telegram briefings. Saving any
unified row (Comment / Message / Chat / Email) broadcasts the same
Top N + filter to every per-platform / per-mailbox row in the matching
manager card.
Post Top N → caps posts shown per platform in the Daily Social Media Briefing & Recommendations.
Comment → caps + filters comments per platform in the Daily Social Media (Comment) Briefing.
Message → caps + filters inbound DMs per platform in the Daily Social Media (Message) Briefing.
Chat → caps + filters customer turns per channel in the Daily Messaging Briefing & Recommendations.
Email → caps + filters emails per mailbox in the Daily Email Briefing & Recommendations; filter is also consumed live by the email worker for response-policy gating.
Loading…
Social Media (Comment) Manager
Guide:
Action policies (what to do per comment):
• no_reply — ignore
• draft_reply — generate draft + Telegram approval link
• reply_comment — auto-post a public reply via webhook
• send_comment — forward the comment to Telegram (notification only)
Sentiment gating: account-level filter (none, positive, neutral, negative) applies to all enabled policies. Per-policy overrides take precedence. draft_reply + reply_comment can coexist if their sentiment gates don't overlap.
Click Edit on a platform row to configure with checkboxes.
Loading…
Include additional context (cross-channel) for the comment classifier
Loading…
Memory Architecture
Loading…
Task Role Policy (WhatsApp non-admin)
Controls which worker roles non-admin WhatsApp Cloud senders can dispatch tasks to. Admin contacts are uncapped. Non-admin senders are also rate-limited at 10 task creates/hour. Unknown roles default to admin-only.
Loading…
Channel Default Role
Per-channel default for the SENDER-ROLE marker the dispatch wrapper injects. contact-lookup resolves the sender's contact and uses is_admin (only manual rows). admin / standard always inject the same role regardless of sender. Used by /api/orchestrator/tasks for all channels and by the WhatsApp Cloud worker.
Loading…
Social Media (Message) Manager
Guide:
Action policies (what to do per inbound DM):
• no_reply — ignore
• draft_reply — generate draft + Telegram approval link
• reply_message — auto-send a private reply via Graph API
• send_message — forward the DM to Telegram (notification only)
Sentiment gating: account-level filter (none, positive, neutral, negative) applies to all enabled policies. Per-policy overrides take precedence. draft_reply + reply_message can coexist if their sentiment gates don't overlap.
Click Edit on a platform row to configure with checkboxes.
Loading…
Include additional context (cross-channel) for the DM classifier
Loading…
Customer Chat Manager
Guide:
Channel handled: whatsapp-cloud (customer side only — admin-owner turns are filtered out at briefing time).
Action policies (what to do per inbound chat turn):
• no_reply — ignore
• draft_reply — generate draft + Telegram approval link
• reply_message — auto-send a reply via the channel
• send_message — forward the turn to Telegram (notification only)
Sentiment gating: account-level filter (none, positive, neutral, negative) applies to all enabled policies. Per-policy overrides take precedence. draft_reply + reply_message can coexist if their sentiment gates don't overlap.
Click Edit on a channel row to configure with checkboxes. Used by Daily Messaging Briefing + Daily Messaging Recommendation.
Loading…
Include additional context (cross-channel) for the chat classifier
The model a new chat uses when you don't pick one. This is Model Chat's own setting — separate from DevOps.
Editing the fallback inherited by every agent without an override.
Claude Code
Codex
Qwen Code (prepaid API)
OpenClaw Gateway
Uses the selected agent’s configured model
Uses gateway authentication
Reasoning and speed are remembered separately per provider. Unsupported controls contain only Provider default.
Config
Persistent instructions and settings for autonomous (goal) runs in Model Chat.
Admin editor only. Saves to the database; chat runtimes always read the database directly. Applied before each surface's Support text. Empty means off.0 / 8000
Applied after protected platform rules and before the current message. Empty means off. Changes apply from the next message; use New chat after replacing core instructions.0 / 8000
The most work→verify passes an autonomous goal runs before it stops if not achieved. Default 10 (max 50).
Chat
Chat directly with the model on your existing Claude / OpenAI plan. Full access: web search, and it can read, write and run commands on the server (admin-only). Attach a file (📎) to drop its contents into the conversation. Pick who you're talking to; start a New chat to switch model.
📋 Plan ready — review & edit, then approve
Your edits here become the plan the model runs.
Context for the agent (include with your message)
Loading…
Command Line Interface (CLI)
Runs shell commands on the server (admin). Enter to run · ↑/↓ history · the working directory persists (cd sticks). nano FILE/vim FILE opens an editor.
The shared live browser for this agent. Watch/drive it here; with 🖥️ Browser on, every open tab is fed to the model as context each turn.
RSI Code Factory Request
If the request names an exact registered DevOps app name, app ID, or GitHub repository URL, RSI uses only that repository. Otherwise it searches the repositories selected below and keeps every proven owner. Each immutable default-branch commit comes from the canonical DevOps Git checkout; RSI never clones a second copy.
Admin direct authority: the queue provides intake and tracking only. App selection, frozen PRD, repository isolation, outer validation and delivery checkboxes do not apply. The executor may modify, test, commit, merge, restart and deploy when reasonably authorized by the request.
No RSI target selected
🧭 Repository discovery: an exact registered app name, app ID, or repository URL wins and is exclusive. With no exact identity, RSI searches every repository in the live DevOps App ID list for the active Agent/User—one or multiple proven owners may be returned. Apps added to or removed from that list take effect automatically; other principals are never enumerated. GitHub or Git-refresh failure stops the request.
🧭 Repository scope: loading live selector…
Populated from the active Agent/User’s DevOps App ID selector, not a hardcoded repository list. Scope is used only when the request has no exact registered app name, app ID, or repository URL; an exact identity is always exclusive.
Questions required before the PRD
Submitted request
📋 PRD
Approval locks this PRD revision and governance version.
Factory Queue
Requests
Open this panel to load requests…
🚫 Blocked submissions
No guardrail blocks loaded yet.
RSI Code Factory Settings
Select the OpenClaw DevOps app that RSI may improve. Settings and governance live in RSI's own protected tables; Code Factory settings are not overwritten.
App selection & operating settings
This setting is the single execution-mode source for new requests. Code Factory and Executor use the frozen PRD, selected repository and RSI enforcement. Direct Execution uses Request & Queue for intake and tracking, then runs with admin/root authority without app, PRD, validator or delivery enforcement.
Server state not loaded
Repository request access
Applies only to the repositories in the main/main platform selector. The list is populated from that selector, and each repository stores its own request policy. Other apps retain access to their own repository. This does not change dashboard login access.
Open this section to load repositories.
Execution permissions & auto-approvals
Saved per app and snapshotted when a PRD is approved. Merge and Deploy are separate God-mode approvals and default off. A frozen Deploy approval may bypass deployment_locked for that request only; it never removes the persistent lock. Privileged runtime changes and gateway reload/restart are also separate, default-off approvals for both adapters and never authorize secret disclosure or unrelated host changes.
Permission state not loaded
Protected platform trust kernel
Applies above Global Rules to every RSI planning and lane prompt. Changes take effect on the next request/lane start; a save archives the previous text.
Governance definitions
Main Brain
The strategic layer for the whole operation — set the direction here.
Manage insights & goals
Loading…
Business Brain
Tunes the live chat agent's system prompts from its own conversations — a second brain that improves itself.
Manage agent setup & business sections
Agent Runtime
Processes
Start / stop / restart each live agent process. A prompt change only takes effect after the
matching process is restarted. Stop & restart ask for confirmation.
Agent connection (the web hosting vm, docker container; synced directly over SSH)
WebHosting Server Settings
SSH host (Files)
Brands (each runs chat/voice/whatsapp/ticket workers — the key is the stable system identifier, the display name is what dropdowns show; adding, removing or renaming a brand needs app-side setup, ask Foxy)
Browse & edit server files
Browse and edit the back-end source/text files in the Server Directory. Saving backs up the file (.bak.<timestamp>) then overwrites it. Python files are syntax-checked before the swap (a broken file is rejected, never saved), and since the workers run with auto-reload a saved .py takes effect on the next reload. Heavy/secret trees (.venv, __pycache__, data, .env) are hidden. Editing back-end code can break the live agent — change carefully.
Browse & edit client files
Browse and edit the front-end widget files in the Client Directory. These are static assets served to browsers — saving backs up the file (.bak.<timestamp>) and overwrites it in place; no process restart needed (visitors get the new file on next load).
Browse & edit widget files
Browse and edit the front-end files in the Widget Directory. These are static assets served to browsers — saving backs up the file (.bak.<timestamp>) and overwrites it in place; no process restart needed (visitors get the new file on next load).
NextCloud Server Settings
SSH host (DB — Postgres/pgvector)
Chat sync: status loads with this agent's config
Browse business chat
Live view of the business-chat table on the Nextcloud Postgres. 10 per page — use the filters to narrow, and First/Prev/Next/Last to move through the record.
From
To
Open a range or press Apply to load.
–
SSH host (DB — MySQL/MariaDB)
Browse tickets
Live view of the configured MySQL table (e.g. helpdesk tickets) on the managed MariaDB. 10 per page — use the filters to narrow, and First/Prev/Next/Last to move through the record.
From
To
Open a range or press Apply to load.
–
Agent System Prompt (per-channel)
Auto-tune (refine these prompts from recent chat)
A daily pass reads recent business chat and proposes improved per-channel prompts. The tuner has its own sample controls (independent of the Daily Briefing insight).
Per-channel prompts
Agent Knowledge Base
Manage knowledge base
Knowledge Base0 entries
Operator-curated content the customer agent searches via the search_knowledge_base tool. Entries live in the unified Knowledge Base store, stamped with the brand selected above — every add/edit/upload is embedded on save and is live to customers within seconds (no rebuild, no restart). Apply to live agents is only needed after code/config changes, not for knowledge edits. Applying restarts the workers and briefly interrupts live chats.
Add to Knowledge Base
+ Add knowledge entry
⬆ Upload file (PDF / Word / text / Excel / CSV / image / ZIP)
PDFs are text-extracted (with OCR fallback for scans); audio/video is transcribed (can take a while for long media).
🎵 Upload media file (audio / video)
Transcribed via the selected STT model, then saved as a brand KB entry — live to customers within seconds. With summary checked, a second "{title} — summary" entry is also saved. Allow 30 s – 3 min per minute of media.
Q&A pairs from past chats that scored well as reusable FAQ material. Click Promote to add a candidate to the KB, or Dismiss to drop it. Click "Scan now" to force a fresh pass. Min score sets the floor — only pairs scoring ≥ it are collected and shown here. Turn on Auto-approve to skip the manual step — pairs scoring ≥ Auto-approve min score are promoted automatically.
Promotion Candidates
0 selected
Knowledge Graph0 entities · 0 relations
Entities + relations extracted from the knowledge entries, pushed to the live agent so it can answer multi-hop questions ("what does X support?", "what connects to Y?"). Click an entity to see its connections; Rebuild after changing entries.
Entities & Relations
Business Chat
Business Insight
A daily LLM pass reads the business-chat history (chat_history_business) and, in ONE pass, produces a single strategic read that fuses analysis (sentiment, themes, responsiveness) with prioritised recommended actions — the truest parallel to Unified / Social Media Insights for the business-chat channel. This complements (does not replace) the per-channel 💬 Daily Business Chat Briefing and 💡 Recommendations. Defaults to dashboard-only: turn on Send Alert / Send Email below to also push the daily digest.
(Enabled off skips the daily run; Send Alert / Send Email gate the daily push + email — both default OFF, dashboard-only)
Advice(optional — steers the LLM, e.g. "prioritise refund/token failures", "focus on churn-risk conversations")
Latest insight
Loading…
History
Business Ticket
Ticket Insight
A daily LLM pass reads the help-desk tickets (chat_histories · request_channel=ticket) and, in ONE pass, produces a single strategic read that fuses analysis (themes, ticket health, sentiment) with prioritised recommended actions — the ticket-channel parallel of Business Chat Insights. Defaults to dashboard-only: turn on Send Alert / Send Email below to also push the daily digest.
(Enabled off skips the daily run; Send Alert / Send Email gate the daily push + email — both default OFF, dashboard-only)
Advice(optional — steers the LLM, e.g. "prioritise unresolved/aging tickets", "focus on wallet/refund failures")
Latest insight
Loading…
History
Business Reports
RAG re-embed interval
seconds
Add / edit reports
Subscribe to live HTML business-report URLs (connected to your realtime data source). Each is re-fetched on your schedule, a full-text snapshot is recorded whenever the content changes, and every version is ingested into Foxy's private knowledge — so you can ask about current state, history, trends and general business intelligence from any channel, just like the email query.
Each report has its own refresh interval (default 5 min), history retention (default 30 days) and fetch timeout (default 60 s) — set any value per URL. The timeout is applied independently to each URL (not shared). The metric extraction checkbox pulls clean labelled figures for exact-number Q&A; uncheck it to ingest the raw report text only.
Subscribed reports
Loading reports…
Business Insight
A daily LLM pass reads every enabled report above — both the parsed statistics (totals, today-vs-yesterday) and the narrative knowledge — and produces a cross-report insight briefing with trend detection. The daily digest is delivered every day when Send Alert is on. Configuration (Enabled, Send Alert, Top N, data window, Advice) and Generate now now live in the Daily Briefing Manager → Business Report row; per-report guidance stays in each report's Advice box above. The latest insight + history display below.
Customize how your digital workforce communicates and completes tasks for you. These preferences are private to your signed-in account and apply to future tasks; they never change an employee's protected permissions or core role.
Manage employees
My global customization
Used for every employee unless that employee is set to replace it.
0 / 8000
Customize one employee
A display name for you only — tasks, transcripts and receipts keep the real name. Save empty to remove it.
0 / 8000
Effective customization preview
Loading…
Saving an empty box clears that customization. Saved changes affect newly requested tasks; tasks already queued keep the version captured when they were queued.
Manage the apps and websites your coding agent builds and deploys — repos, default models, and deploy targets.
Default models (per coding agent)
The model an app uses when its own Model field is left blank ("agent default"). Select a scope before editing; All agents changes the fleet fallback, while an agent selection saves an override for that agent's apps and workers.
Editing the fallback inherited by every agent without an override.
What apps with Coding Agent = "Auto — same as DevOps runs" (and their new chats) run on. Apps with an explicit engine keep it. Gateway routes to the app owner's own OpenClaw gateway, workspace, persona, tools and configured model; the CLI model selectors above are ignored. Sub-users stay on the isolated Qwen CLI.
Register a website or app for the software-developer agent to work on. The Repo Access Token is stored server-side and never shown back here — on edit, leave it blank to keep the saved one, or type a new value to replace it.
Database
Or fill the parts and I'll build the Database URL above for you:
Environment variables— API keys and settings your app reads at runtime.
This is the single configuration list injected when the app is deployed. A value can be
stored here encrypted or linked to Vault; linked values are resolved at deployment
without copying the secret and follow future Vault rotations automatically. If a literal and
matching Vault key both exist, the row is flagged and you choose whether Vault should replace it.
Tick Public only for values that are safe to show in a browser (they get copied to
VITE_/NEXT_PUBLIC_/NG_APP_ for frontend builds).
📧 Email sendingdaily limit
Android app— package this site as an installable Android app (APK + Play Store bundle).
The app wraps your live site, so updates you deploy here reach installed phones automatically.
It is signed with this app's own key, which you can download and take with you to publish
under your own Google Play account.
Package ID
Payers will be given the option to pay by bank transfer and your CK wallet will be
funded automatically (instantly).
Don't have a Paystack account yet? Sign up free, then come back and paste your keys here — enabling payments below works right away once they're connected.
—
Loading apps…
🗑 Recycle bin (deleted apps — recoverable files; permanently delete to purge)
A live browser you can watch and drive. Type a URL or a search to open it, and click/type directly in the view (Interact on).
Default models (per browser agent)
The model each engine uses when driving the browser. This is Browser Chat's own setting — separate from Model Chat & DevOps. (Admin only.)
Editing the fallback inherited by every agent without an override.
What the chat's Agent picker runs when it's on "Auto — same as browser runs".
Enable VPN Proxy (per agent)
Gate which agents may route their live browsing through the VPN proxy (residential exit IP). An agent only sees the "Use VPN proxy" toggle if allowed here. (Admin only — like Strict Orchestrator.)
VPN connection (L2TP/IPsec)
Saving rewrites the dialer's credentials and reconnects the tunnel (~10–20s). The key & password are stored write-only and shown masked.
Dialer: …
Browser VPN (per agent)
WhatsApp-native VPN (per agent)
Only agents running WhatsApp-native are affected in practice. Toggling reconnects that agent's WhatsApp (~5s). Direct = the server's own IP.
Enable browser engine (per agent)
Chromium is fast & headless (default). Chrome + Xvfb runs real Google Chrome in a virtual display — it passes sites that block automated browsers, notably Google sign-in ("browser may not be secure"). Switching reloads that agent's live tabs. (Admin only.)
Web browser automation
A live browser on the server that the agent can watch and drive — open pages, click, type, fill forms. Sessions persist between turns, so a site you sign into by hand stays signed in. Saved logins are typed in by the platform; the agent never sees them.
Config
Settings for autonomous (goal) runs in Browser Chat.
Support text
Persistent owner guidance included with every Browser Chat turn. It cannot override authentication, authorization, tenant isolation, approvals, least privilege, or safety rules.
0 / 8000
The most work→verify passes an autonomous goal runs before it stops if not achieved. Default 10 (max 50).
Cookies
Some sites (e.g. Google) block sign-in from an automated browser. Instead: sign in on your normal browser, export the site's cookies with a "Cookie-Editor" extension (Export → JSON), and paste them here. The live browser then reuses that session — no fresh login needed. Cookies persist across restarts.
Tip: after importing, open the site in the live browser (it should already be logged in). Stealth hardening is also on, which helps many sites — but for Google, importing a signed-in cookie set is the reliable route.
VPN proxy
Route this browser's traffic through the VPN so sites see a residential exit IP (helps with Google's datacenter-IP block). Toggling reloads the live tabs.
Scheduled tasks
Run a plain-English browser instruction on a schedule — one-off or repeating — on a chosen tab. It runs autonomously (drives the browser, self-verifies) and alerts you with the result. Times are WAT.
Add Browser Task
Multiple instructions run in order as one task — each step runs as a turn on the same browser tab and sees the previous.
📅
until
📅
Scheduled Browser Tasks
Chat
Tell the agent what to do — e.g. "open google and search for dogs, then click the first result". It drives the live browser above while you watch. (Opens the live view automatically when you send.)
Files you download inside the live browser are saved to your Remote drive → Downloads folder (any size). Pull one onto your computer or delete it below.
Cross-Channel Context
Context prepended to inbound messages. Admin-only channels (Telegram, WhatsApp native) and WhatsApp Cloud's admin sender get free-form business context (reports / insights / goals / KB). A WhatsApp Cloud customer is sender-resolved and gets their own cross-channel history. (Live-Chat & Voice have their own card below.)
Per-Surface Context
Telegram (admin)
Loading…
WhatsApp native (admin)
Loading…
WhatsApp Cloud
Customer (sender-resolved)
Loading…
Admin (business context)
Loading…
Social Media (Post)
Configure Brand & Goal: Brand = hard constraint (voice + identity); Goal = soft direction (what we're pushing right now).
Posting Strategy
Brand
Goal
Auto Post Review Window (0 = publish immediately / no preview · 1–1440 = send Telegram preview, then wait N minutes before publishing — up to 24h)
minutes
Goal Targets (quantify the goal so the system can self-measure objectively; add up to 20 entries)
Your files on this server — browser downloads, email attachments, anything you upload — plus an agent that can work on them for you.
Default models (Remote Drive agent)
The model the drive agent uses for its Chat and Scheduled tasks — separate from the email, Telegram, Model Chat, DevOps & Browser Chat pickers. (Admin only.)
What the Chat's Auto setting and every scheduled Drive task run on. The file tools need a model that follows the tool protocol — if the agent starts answering from a shell instead of reading the drive, set a stronger model here.
Remote drive
The agent that works on these files for you — how it is set up, what it runs on a schedule, and a chat to ask it things.
Config
Loading…
Settings for autonomous (goal) runs in Chat and Scheduled tasks.
The most work→verify passes an autonomous goal runs before it stops if not achieved. Default 10 (max 50).
Scheduled tasks
Give the agent a plain-English instruction about your files on a schedule — one-off or repeating. Times are your local time.
Add Drive Task
Multiple instructions run in order as one task — step 2 sees step 1's result.
until 📅
Scheduled Drive Tasks
Chat
Ask about your files or tell the agent what to do with them — e.g. "how many files are in Downloads?", "summarise the newest PDF", "move last month's screenshots into an Archive folder".
Website logins your agent can use on your behalf without ever seeing the password — the platform types it into the live browser, and every use is logged.
Manage saved logins (add, approve, audit)
Logins your agent may use on your behalf — "log into facebook and check my last post". Passwords are stored encrypted and are never shown again, not on this page and not to the agent: it only sees the tag, site and username, and asks the platform to type the password into the browser. Every use is logged below. Usable in Model Chat, Browser Chat, DevOps chat and your own email/Telegram chats — never on customer-facing surfaces. DevOps: when an app requires a matching variable, its Environment list receives a durable link such as CLUBKONNECT_API_KEY → Vault: clubkonnect-api-key. Deployment resolves the current Vault value without copying it into app configuration. Ambiguous matches ask you to choose; approval-required entries are never auto-linked. Payment cards (₦ or $) can be saved too: the number is stored encrypted and typed only into a checkout on your instruction, every use passes a dedicated payment safety review, and every use waits for your approval (also pushed to your Telegram/email — pick below). The CVV is optional: leave it blank and the agent asks you for it at each purchase instead of storing it.
🔒 Saved payment cards are disabled for this account — enable “Saved payment card viable” in the Payments panel first.
Loading…
Merchant allow list & payment method
Pick which payment method the agent uses per website. A site with no rule uses the default — and its approval will explicitly ask you to confirm paying an unlisted merchant.
Tell the agent to read, summarize, or reply to your email. It works on your configured mailbox — the agent's for you, each sub-user's for them.
Default models (per email agent)
The model each engine uses for email agent runs. This is Email Chat (customer)'s own setting — separate from Model Chat, DevOps & Browser Chat. (Admin only.)
Email runs on the selected CLI with its default model + auth. No silent fallback — if the CLI errors you'll see the error. Gateway = the agent's own openclaw (its workspace + configured model; ignores the models above), only if you pick it.
Email automation
Your CUSTOMER mailbox — the agent reads it, drafts replies from your knowledge base, and sends on your approval (or on its own when Auto-send is on). Scheduled tasks work the inbox unattended. Mail credentials are encrypted and never shown back.
Config
Your mailbox — SMTP to send, IMAP to receive. Gmail/Outlook: use an app-password, not your login password. The username IS your email address. SMTP and IMAP are saved & tested independently.
❓ How do I get my app-password (Gmail / Outlook / Namecheap)?
A Gmail app-password is a 16-character code that signs in without your real password. Needs 2-Step Verification on.
Microsoft 365 work/school accounts often have app-passwords disabled by the admin (they require OAuth) — ask your admin or use a personal Outlook.com account.
Namecheap Private Email has no separate app-password — use the mailbox's own password (IMAP/SMTP are on by default).
In the Private Email admin, confirm/reset the mailbox password for this address.
Use that password as the SMTP and IMAP password. Username = your full email address.
Settings for autonomous (goal) runs — used the same way as Browser Chat.
The most passes an autonomous email goal runs before it stops if not achieved. Default 10 (max 50).
Support context
Business notes included with every customer email reply — what you sell, hours, policies, tone. Same idea as the Telegram Chat (customer) support text. Turn it on/off with the "Support context" checkbox in the Chat context panel.
Mailbox
Email addressEnter the address first
SMTP (send)
IMAP (receive)
Tagused in alerts, e.g. 📧 Monnify → [mail3] — must be unique
saves SMTP and IMAP together — each is tested first; leave a section blank to skip it
Scheduled tasks
Give the agent a plain-English inbox instruction on a schedule — one-off or repeating. It runs autonomously (reads & acts on your mailbox), auto-sends, and records the result. Times are your local time.
Add Email Task
Multiple instructions run in order as one task — step 2 sees step 1's result.
until 📅
Scheduled Email Tasks
📬 Mailbox:chat, inbox, sent, drafts & trash all follow this
Chat
Tell the agent what to do with your email — e.g. "summarize my latest unread" or "reply to the last one saying I'll get back tomorrow". It reads your inbox above.
Emails you've sent from this mailbox, newest first.
Drafts
Replies your assistant drafted, and messages you saved to finish later. Edit to reopen in Compose, Send to deliver, or Delete to discard.
Trash
Deleted emails — Restore to move back, or delete forever. Kept until you delete them, unless auto-delete is on below.
afteroff
Downloads
Files — email attachments received in your inbox, plus anything downloaded in the live browser — are saved to your Remote drive → Downloads folder (any size). Pull one onto your computer or delete it below.
Your PERSONAL mailbox — the address configured here is injected as your OWNER email: “email me” / [[SEND]]-to-owner delivers HERE, never to the customer mailbox. The agent reads, summarizes and replies on your own inbox — yours for you, each sub-user’s own for them.
Default models (per email agent)
The model each engine uses for email agent runs. This is Email Chat (owner)'s own setting — separate from Model Chat, DevOps & Browser Chat. (Admin only.)
Editing the fallback inherited by every agent without an override.
Email runs on the selected CLI with its default model + auth. No silent fallback — if the CLI errors you'll see the error. Gateway = the agent's own openclaw (its workspace + configured model; ignores the models above), only if you pick it.
Email automation
Your OWN mailbox — a private assistant for your inbox: summarise, search, draft and send as you. Nothing here is customer-facing, and replies are never sent to a visitor. Mail credentials are encrypted and never shown back.
Config
Your mailbox — SMTP to send, IMAP to receive. Gmail/Outlook: use an app-password, not your login password. The username IS your email address. SMTP and IMAP are saved & tested independently.
❓ How do I get my app-password (Gmail / Outlook / Namecheap)?
A Gmail app-password is a 16-character code that signs in without your real password. Needs 2-Step Verification on.
Microsoft 365 work/school accounts often have app-passwords disabled by the admin (they require OAuth) — ask your admin or use a personal Outlook.com account.
Namecheap Private Email has no separate app-password — use the mailbox's own password (IMAP/SMTP are on by default).
In the Private Email admin, confirm/reset the mailbox password for this address.
Use that password as the SMTP and IMAP password. Username = your full email address.
Settings for autonomous (goal) runs — used the same way as Browser Chat.
The most passes an autonomous email goal runs before it stops if not achieved. Default 10 (max 50).
Support text
Persistent owner guidance included with every private Email (admin) agent run. Inbox content remains untrusted data.
0 / 8000
Mailbox
Email addressEnter the address first
SMTP (send)
IMAP (receive)
Tagused in alerts, e.g. 📧 Monnify → [mail3] — must be unique
saves SMTP and IMAP together — each is tested first; leave a section blank to skip it
KB by email
A second mailbox that feeds your Knowledge Base: every email received here becomes a KB entry — subject → title, body → note. Supported attachments are ingested too, like the Upload-file section (PDF, DOCX, TXT, MD, Excel/CSV, images — OCR'd, ZIPs — each supported file inside becomes its own entry, plus audio/video which get transcribed; max 25 MB each). It never shows in the inbox and is never auto-replied. Only mail arriving after you save is ingested (existing mailbox contents are skipped). Checked ~every 1 min. Auto-delete (optional, off by default): tick the box below to have already-ingested mail deleted from the mailbox after your chosen window (30/90/180/360 days or a custom number) so it never fills up — mail from before setup (or not yet ingested) is never touched.
Only accept mail from — one per line: a full address (vic@acme.com) or a whole domain (@acme.com). Leave blank to accept any sender.
after
Scheduled tasks
Give the agent a plain-English inbox instruction on a schedule — one-off or repeating. It runs autonomously (reads & acts on your mailbox), auto-sends, and records the result. Times are your local time.
Add Email Task
Multiple instructions run in order as one task — step 2 sees step 1's result.
until 📅
Scheduled Email Tasks
📬 Mailbox:chat, inbox, sent, drafts & trash all follow this
Chat
Tell the agent what to do with your email — e.g. "summarize my latest unread" or "reply to the last one saying I'll get back tomorrow". It reads your inbox above.
Emails you've sent from this mailbox, newest first.
Drafts
Replies your assistant drafted, and messages you saved to finish later. Edit to reopen in Compose, Send to deliver, or Delete to discard.
Trash
Deleted emails — Restore to move back, or delete forever. Kept until you delete them, unless auto-delete is on below.
afteroff
Downloads
Files — email attachments received in your inbox, plus anything downloaded in the live browser — are saved to your Remote drive → Downloads folder (any size). Pull one onto your computer or delete it below.
Media Transcriber (Video + Voice)
Paste public media URL (YouTube/video/audio), or upload/select a local media file (video/audio). Upload fills input automatically.
Foxy's own searchable memory — curated entries, the promotion queue and the knowledge graph, all managed below.
Manage knowledge base
Knowledge Base
Operator-curated content Foxy can search via the search_knowledge_base tool. Public entries are visible to customers (WhatsApp Cloud standard senders); Private entries are visible only to admin/owner channels (you on Telegram, voice, WA native, chat). Visibility is enforced at the SQL retrieval layer — private chunks never load into a customer prompt.
Drop a PDF / DOCX / TXT / MD / Excel / CSV / image (OCR) / ZIP here, or:
Readyvisibility: private
Confirm the visibility radio above is correct before tapping Upload.
🎵 Upload media file (audio / video)
Drop an audio / video file here, or:
Transcribed via the selected STT model, then indexed. With summary checked, a second "{title} — summary" entry is also saved. Allow 30 s – 3 min per minute of media.
Readyvisibility: private
Confirm STT settings + visibility above before tapping Upload.
🔗 Upload URL
STT settings + summary apply to YouTube + direct media URLs only — HTML pages ignore them.
HTML pages are scraped. YouTube links + direct audio/video URLs (.mp3/.mp4/etc) are transcribed first. Allow 1–3 min per minute of media.
🔄 URL refresh subscriptions (auto re-fetch on schedule)
Q&A pairs from past chats that scored well as reusable FAQ material. Choose visibility on each card (defaults to private), then click Promote to add it to the KB, or Dismiss to drop. Scanner runs on the Scan every cadence you set below; click "Scan now" to force a fresh pass. Min score sets the floor — only pairs scoring ≥ it are collected and shown here. Turn on Auto-approve to skip the manual step — pairs scoring ≥ Auto-approve min score are promoted automatically as Private.
Promotion Candidates
└
Learn from
Personal context
0 selectedvisibility:
Loading…
Knowledge Graph
Entities + relations auto-extracted from your KB documents on every ingest. Foxy uses these for multi-hop questions ("what does X sell?", "who works for Y?"). Click an entity to see its connections.
Every kind of work the fleet does — tasks, builds, chats, email, payments — is watched for friction: failures, timeouts, runs far slower than their own norm. Nightly, those runs are distilled into procedures you can approve. Approved ones are injected into the next matching run, in that lane only.
Manage my skills
Settings
These are this section's own settings. Changing anything on the Knowledge Base card does not touch them, and these do not touch it.
How often— used when nightly is off.
At mostnew skills per 24 hours (the budget), and at mostper pass (the pace) — 0 = half the budget. Stops one pass spending the whole day at once; the nightly pass ignores it and may use the full budget.
Merge similar at— above this similarity a new skill updates the existing one instead of becoming a second entry.
⚠ An approved skill becomes instructions your agent follows. Automatic approval only ever
grants private use, and never platform-wide reach — customer-facing (public) use and
platform scope still need you. Everything approved this way is marked auto in the list.
Tidy up approved skills
Two skills for the same job means the agent gets the same advice twice. This looks for duplicates among skills already approved and proposes which to keep — nothing is merged until you say so.
Loading…
Where the fleet struggles
Loading…
Pending review
Loading…
Approved skills
Loading…
Write your own skill
You know your business better than the machine does. A skill you write by hand works exactly like a learned one — and passes the same safety checks before it can be used.
Sub-user Access & API Settings (3rd-party register + login)viewing
Connect your own website to this agent — register and log in sub-users from any domain using the signup token, login links and SSO secrets below.
Let your own website register & log in sub-users under this agent, from any domain (Bearer-token auth, so CORS is open). Keep the signup token secret (use it server-side) and regenerate if it leaks — anyone with it can create sub-users under this agent.
Guardrail Settings (checks every sub-user request)viewing
Screens every sub-user request before the agent acts on it — a fast regex blocklist first, then an AI review using your instructions. Blocked requests get a polite refusal.
Configure guardrail rules (regex + AI review)
Two layers protect this agent's sub-user (customer) requests. Layer 1 is a fast regex blocklist (recommended defaults below). Layer 2 is an AI review using your instructions. Both are editable; a blocked request gets a polite refusal and never reaches the assistant.
Layer 1 — Regex blocklist
Layer 2 — Customer chat
Layer 2 — DevOps Chat
Layer 2 — Browser Use
Layer 2 — Inbound to your assistant
Layer 2 — Payments
Applies to build/task receipts for sub-users who asked in their sealed live chat. On Auto, a receipt already saved to their chat history is not repeated on Telegram.
Model Token Prices (USD per 1M tokens — admin)viewing
What each model costs you. Every turn is priced from this table, so it feeds wallet billing, the
subscription allowance and the token credit unit. Leave cache read/write blank to use the
standard ratios (read = 10% of input, write = 125%). A model with no row bills $0 — nothing is
guessed from its provider any more, so an unpriced model is called out below until you give it a rate.
Model prices
Model
30-day use
Input $/1M
Output $/1M
Cache read $/1M
Cache write $/1M
Legacy / unused models
KB models & prices (embedding + RAG utility)
Role
Model
Input $/1M
30-day use
Voice models & prices (realtime + speech-to-text)
Model
Used by
Text in $/1M
Text out $/1M
Audio in $/1M
Audio out $/1M
30-day use
Billing Plans (subscription tiers)viewing
Set each tier's monthly price (₦ and $), the token spend it includes, and daily build/task caps. Usage beyond the included amount bills to the user's wallet (0 = unlimited). Direct billing meters every turn. Saving applies the new build/task caps to this agent's existing subscribers immediately — prices and included spend still take effect at each user's next charge.
Plan tiers
Tier
Price ₦/mo
Price $/mo
Included ₦/mo
Included $/mo
Builds/day
Tasks/day
Wallet/Token Usage Settings (display currency & discount)⧉ Open soloviewing
How usage is priced and shown — display currency (₦/$), discount or markup, and the prepaid wallet users spend from.
Per-agent. A new agent starts from main's values, then can differ. Use the agent picker in the heading to view/edit each agent. The discount is a percentage off the shown cost.
Wallet (prepaid balance, per user)
When ON, a build or task is blocked unless the user has enough balance, and all token usage is billed to their wallet in ₦. Off by default — nothing changes until you enable it. Top-ups happen strictly via the API below.
Payments (which providers this agent's tenant may use)
This does not connect anything — it only decides what shows up as a choice. Every agent and sub-user connects their own Paystack account, and Nellobyte's recipient username, from their own app's Payments panel.
Locked — ask to re-enable before changing. Saved with the Save button below, along with currency/wallet/token-credit settings.
Token credit + openclaw model
Token credit (display unit for allowance & usage)
Users see their token allowance and usage in credits rather than currency. One credit = this many cache-read tokens on the reference model. Raise it for smaller, coarser numbers; lower it for finer ones. This is display granularity only — it re-bases every plan's credit allowance the moment you save, but never changes what anyone is charged.
Credit reference modelits cache-read price defines what one credit is worth
Default is auto: each agent's credit is pegged to its own gateway model, so changing that model in Team Manager re-bases its credits automatically — pick a model only to pin an override. Scoped to the agent in the viewing picker above. Credits stay stable in turns — a cheaper gateway model means a credit is worth less in USD but buys the same number of turns.
Q&A pairs from past chats that scored well as reusable FAQ material. Choose visibility on each card (defaults to private), then click Promote to add it to the KB, or Dismiss to drop. Scanner runs on the Scan every cadence you set below; click "Scan now" to force a fresh pass. Min score sets the floor — only pairs scoring ≥ it are collected and shown here. Turn on Auto-approve to skip the manual step — pairs scoring ≥ Auto-approve min score are promoted automatically as Private.
Promotion Candidates
└
Learn from
Personal context
0 selectedvisibility:
Loading…
Knowledge Graph
Entities & relations auto-extracted from your knowledge on every ingest. Click an entity to see its connections; × to remove one.
Entities & Relations
Loading…
Tenant Activity
A record of every app your sub-users built and every task they delegated — with per-user limits you can set.
Every app your sub-users built and every task they delegated to your workers through their sealed assistant — auto-dispatched within quota, so this is the record, not an approval queue. Pick a sub-user above to see just theirs and set a limit for them; otherwise you're viewing everyone and editing the account-wide default.
A support-ticket portal for your customers. They open tickets from a link you share, your agent (or you) replies, and the answer is emailed back to them.
Default models (per helpdesk portal)
The model this helpdesk portal uses to answer tickets — separate from the email, Telegram and live-chat pickers. (Admin only.)
Leave unset to use the agent's own default model. Applies to the next ticket reply.
A support portal you link from YOUR website — customers submit tickets by email, get answers from your knowledge base, and can come back to follow up. Unlike live chat, tickets persist and replies are emailed.
Loading…
Send customers to this link (or embed it in an iframe):
Context for the bot (what it knows when answering tickets)
Max messages injected into context
Scheduled tasks
Give the agent a plain-English customer-chat instruction on a schedule — one-off or repeating. By default it analyses/drafts and can notify you (it does NOT message customers unless you tick Auto-send). Times are your local time.
Add Help-Desk Task
Multiple instructions run in order as one task — step 2 sees step 1's result.
until 📅
Scheduled Help-Desk Tasks
Chat
Tell the agent what to do with your help-desk tickets — e.g. "summarize today's tickets", "any unanswered tickets?" or "summarise what customers asked today". With Auto-send off it drafts replies for your approval.
The chat bubble for your own website. Paste the embed snippet on any page and visitors can talk to your agent — every conversation shows up here.
Default models (per live-chat widget)
The model this website widget uses to answer visitors — separate from the email, Telegram and Model Chat pickers. (Admin only.)
Leave unset to use the agent's own default model. Applies to the next visitor message.
A chat bubble you place on YOUR website — visitors chat and get answers from your knowledge base, exactly like the Telegram customer bot. Each visitor is isolated; no signup, no access to your data.
Loading…
Paste this ONE line into your website (before </body>):
Config
Support text
Scheduled tasks
Give the agent a plain-English customer-chat instruction on a schedule — one-off or repeating. By default it analyses/drafts and can notify you (it does NOT message customers unless you tick Auto-send). Times are your local time.
Add Customer-Chat Task
Multiple instructions run in order as one task — step 2 sees step 1's result.
until 📅
Scheduled Customer-Chat Tasks
Chat
Tell the agent what to do with your website-widget conversations — e.g. "summarize today's chats", "any unanswered visitors?" or "summarise what visitors asked today". With Auto-send off it drafts replies for your approval.
Context for the bot (what it knows when answering customers)
Reply manually to any visitor — click a message below to fill its id. Your reply reaches their chat bubble within ~12s. (Your widget already auto-answers unless you change Auto-reply.)
A public Telegram bot your customers can message. It answers from your public knowledge base, and each customer's chat is sealed from the others.
Default models (per telegram account)
The model the customer Telegram bot uses for its replies — separate from the email pickers, Model Chat, DevOps & Browser Chat. (Admin only.)
Runs on the selected CLI with its default model + auth. No silent fallback. Gateway = the agent's own openclaw (its workspace + configured model; ignores the models above), only if you pick it.
A PUBLIC Telegram channel — share its link and anyone can message it like a support line. Each visitor is isolated and answered from your knowledge base; no signup, no access to your data. Secrets are encrypted and never shown back.
Loading…
Support text
Business facts & answering guidance — injected into every reply: services & prices, support hours, escalation contact, tone, "if asked about X, say Y".
A bot token is a secret string (like 123456789:ABCdef...) that lets this dashboard run a Telegram bot. Use a NEW bot for this (not your private/owner bot). You get the token from Telegram's official @BotFather — it's free and takes a minute.
In Telegram, search @BotFather (the one with the blue ✓ verified badge) and open the chat.
Send /newbot.
Give it a display name (e.g. Acme Support).
Give it a username — it must end in bot (e.g. acme_support_bot) and be unique.
BotFather replies with your token. Copy the whole line after "Use this token…".
Paste it below → Save & validate. Then share t.me/your_bot_name anywhere — customers just tap it and chat.
Lost the token? Send BotFather /token to get it again; /revoke makes a new one (and disables the old).
Scheduled tasks
Give the agent a plain-English customer-chat instruction on a schedule — one-off or repeating. By default it analyses/drafts and can notify you (it does NOT message customers unless you tick Auto-send). Times are your local time.
Add Customer-Chat Task
Multiple instructions run in order as one task — step 2 sees step 1's result.
until 📅
Scheduled Customer-Chat Tasks
Chat
Tell the agent what to do with your customer conversations — e.g. "summarize today's chats", "any unanswered visitors?" or "reply to visitor 8123 that the invoice is ready". With Auto-send off it drafts replies for your approval.
Context for the bot (what it knows when answering customers)
Your private Telegram line to this agent — chat, assign tasks and get alerts from your own Telegram account. Admin only; customers use the customer bot instead.
Default models (per telegram account)
The model the owner Telegram bot uses for its replies — separate from the email pickers, Model Chat, DevOps & Browser Chat. (Admin only.)
Runs on the selected CLI with its default model + auth. No silent fallback. Gateway = the agent's own openclaw (its workspace + configured model; ignores the models above), only if you pick it.
Your OWN Telegram bot channel. Secrets are encrypted and never shown back.
Select a sub-user above to view and manage their personal channels.
Loading…
Config
✓ Auto-reply is always on
❓ How do I get a bot token from @BotFather?
A bot token is a secret string (like 123456789:ABCdef...) that lets this dashboard run your own Telegram bot. You get it from Telegram's official @BotFather — it's free and takes a minute.
In Telegram, search @BotFather (the one with the blue ✓ verified badge) and open the chat.
Send /newbot.
Give it a display name (anything, e.g. My Assistant).
Give it a username — it must end in bot (e.g. my_assistant_bot) and be unique.
BotFather replies with your token. Copy the whole line after "Use this token…".
Paste it below → Save & validate. Done.
In Telegram, search @your_bot_name (e.g. my_assistant_bot) and open the chat, then send it any message first — e.g. hi. A bot can only reply to chats that have messaged it.
Lost the token? Send BotFather /token to get it again; /revoke makes a new one (and disables the old).
Support text
Persistent owner guidance included with every private Telegram (admin) agent run, including the owner bot's authenticated replies.
0 / 8000
Trusted user list
Give trusted people (staff) or a GROUP chat the same access to your assistant as you — they message your bot and it answers with your full context. Once you add ANY entry, ONLY the listed chats get replies — add YOUR OWN chat first (one click below).
For a group: add the bot to the group, add the group's id here, and send BotFather /setprivacy → Disable so the bot hears all group messages.
Loading…
Recent chats seen by your bot — click Trust to allow one:
Scheduled tasks
Give the agent a plain-English instruction for your own Telegram channel on a schedule — one-off or repeating. By default it analyses/drafts and can notify you (it does NOT send Telegram messages unless you tick Auto-send). Times are your local time.
Add Owner-Chat Task
Multiple instructions run in order as one task — step 2 sees step 1's result.
until 📅
Scheduled Owner-Chat Tasks
Chat
Tell the agent what to do with your own Telegram conversations — e.g. "summarize this week's chats", "did I get any reminders about invoices?" or "send me the top 3 action items from my chats". With Auto-send off it drafts messages for your approval.
Received & sent (via bot webhook, auto-refreshes ~every 1 min).
Assistant: chat with your own assistant here. Pick any recent chat from the list to reply to that person via your bot (its chat id is preserved), or Custom to type an id — clicking a message below selects its chat.
Trigger Schedules (WAT)
Fire times for every scheduled job in West Africa Time (UTC+1) — edit and Save to reschedule the systemd timer instantly.