Agent Plugin Approvals Flow
Overview
An operator selects Slack users for an Agent's plugin approvals. OpenClaw Control Plane (OCC) stores exact Slack user identities, freezes the policy in a deployment revision, and passes it to the selected PluginDriver. OpenClaw owns authorization of each later plugin approval request. The optional name lookup is described in the channel directory flow.
Entry Points
- Trigger: the Console Plugins editor or an authorized caller creates, updates, or deploys an Agent with plugin approvers.
- Assumptions: the actor has Agent create or exact Agent update permission, and the selected PluginDriver supports approvers.
- Source:
apps/controller/src/console/agents/slack-approvers.mjs:createSlackApproverField,packages/occ/src/index.ts:OpenClawController.updateAgent, andapps/controller/src/drivers/plugin/runtime-translator.ts:pluginApprovalOverlay.
Flow
graph TD
A["Operator selects Slack user IDs"] --> B["OCC validates approvers with PluginDriver"]
B -->|unsupported or invalid| X["Reject Agent save"]
B -->|valid| C["Agent stores default, plugin, and tool approvers"]
C --> D["Deployment freezes Agent policy in revision"]
D --> E["PluginDriver renders OpenClaw approval policy"]
E --> S{"Slack configured and enabled?"}
S -->|no| N["Retain stored policy without generating Slack configuration"]
S -->|yes| V["Selected gateway validates generated approval configuration"]
V -->|unsupported or unavailable| H["Hold startup unready with compatibility evidence"]
V -->|accepted| F["OpenClaw gateway owns request-time approval checks"]
N --> FExecution Trace
1. Save and freeze approver policy
packages/occ/src/index.ts:OpenClawController.updateAgent
Agent pluginApprovers supplies the default. A plugin's approvers replaces
the default; a tool's approvers replaces the plugin list. Omission inherits
and [] denies Slack approvers at that scope. The selected PluginDriver
validates supported identities before OCC saves the Agent. The Codex
PluginDriver rejects plugin and tool approvers because Codex approval requests
carry no plugin or tool identity; it accepts only the Agent default. Deploying the Agent
records the current default and selection map in an immutable AgentRevision.
Later edits do not change the admitted revision.
An Agent update sends pluginApprovers: null to remove a previously saved
default and return to omitted-policy behavior.
2. Hand off runtime enforcement
apps/controller/src/drivers/plugin/runtime-translator.ts:pluginApprovalOverlay
The PluginDriver renders raw or workspace-qualified Slack user IDs into the OpenClaw plugin approval configuration. It preserves unrelated approval settings and rejects native lists that conflict with an inherited managed list. An omitted Agent default leaves the runtime's legacy Slack account approval destinations in effect for scopes without an override; an explicit empty list denies them. The prepared gateway receives this configuration only for the admitted revision.
3. Check the selected gateway before launch
apps/controller/src/drivers/compute/kubernetes/runtime-entrypoints.ts:applyOpenClawPluginConfiguration
The shared Docker and Kubernetes gateway setup omits the generated Slack
approver overlay when channels.slack is absent or enabled: false. The
admitted policy remains unchanged, including explicit empty lists. Other native
approval settings remain in the effective configuration.
When Slack is configured and enabled, setup writes only the generated approval
policy into a private temporary file and runs the selected image's native
config validate --json. This tests the actual configuration contract without
a version cutoff or requiring external plugins to be installed first. The
probe has a 30-second timeout and removes the file afterward. Only a successful
validation permits the policy to be merged into the gateway configuration.
An unsupported policy or unavailable validator holds startup unready before
launching the gateway. Logs tell the operator to select a compatible gateway
image or remove the approver overrides. Kubernetes publishes
plugin-approvers / INCOMPATIBLE_RESPONSE startup evidence through its existing
runtime status endpoint. Revision admission still precedes this runtime check;
the worker reads startup evidence during reconciliation. A compatible runtime
owns each subsequent request-time approval decision.
Debugging and Verification
- Compare
Agent.pluginApprovers, nested selection overrides, and the admitted AgentRevision. A successful save does not prove the running gateway applies the new policy; check deployment status and use a real plugin approval request to verify the runtime image. - Raw Slack user IDs can be pasted when directory lookup is unavailable. Directory selection still stores workspace-qualified IDs.
- The channel directory flow describes Secret permissions and lookup failures. Approval enforcement needs a compatible runtime and an authorized test bot.
- For a gateway that remains unready, check its runtime startup evidence and
logs for
plugin-approvers. A capability failure leaves the native configuration unchanged and does not launch an invalid gateway.
