OpenClaw Workspace Governance Installer
Ship safer OpenClaw operations from day one.
This installer gives you a repeatable governance path instead of ad-hoc prompt edits.
Why this is popular
- Prevents "edit first, verify later" mistakes.
- Gives one predictable setup/upgrade/audit flow.
- Makes changes traceable for review and handover.
- Works for both beginners and production workspaces.
60-second quick start
First-time install:
# 1) Install plugin (first time only)
openclaw plugins install @adamchanadam/openclaw-workspace-governance@latest
# 2) Enable plugin
openclaw plugins enable openclaw-workspace-governance
# 3) Verify skills
openclaw skills list --eligible
In OpenClaw chat:
/gov_help
/gov_setup quick
# if quick output says allowlist is not ready (for example plugins.allow needs alignment):
/gov_openclaw_json
/gov_setup quick
# manual fallback (step-by-step):
/gov_setup install
prompts/governance/OpenClaw_INIT_BOOTSTRAP_WORKSPACE_GOVERNANCE.md
# if this workspace was already active before first governance adoption:
/gov_migrate
/gov_audit
Already installed users (upgrade path):
# Do NOT run install again if plugin already exists
openclaw plugins update openclaw-workspace-governance
openclaw gateway restart
Then in OpenClaw chat:
/gov_setup quick
# if quick output says allowlist is not ready (for example plugins.allow needs alignment):
/gov_openclaw_json
/gov_setup quick
/gov_setup upgrade
/gov_migrate
/gov_audit
# manual fallback:
/gov_setup upgrade
/gov_migrate
/gov_audit
What you get
gov_help — see all commands and recommended entry points at a glance.
gov_setup quick|check|install|upgrade — deploy, upgrade, or verify governance in one step.
gov_migrate — align workspace behavior to the latest governance rules after install or upgrade.
gov_audit — verify 12 integrity checks and catch drift before declaring completion.
gov_uninstall quick|check|uninstall — clean removal with backup and restore evidence.
gov_openclaw_json — safely edit platform config (openclaw.json) with backup, validation, and rollback. Includes pre-modification config reference verification: scans local workspace docs before changes, falls back to official web docs, and degrades gracefully when neither is available.
gov_brain_audit — review and harden Brain Docs quality with preview-first approval and rollback.
gov_boot_audit — scan for recurring issues and generate upgrade proposals (read-only diagnostic).
gov_apply <NN> — apply a single BOOT upgrade proposal with explicit human approval (Experimental, controlled UAT only).
Feature maturity (important)
- GA flow for production rollout:
gov_setup -> gov_migrate -> gov_audit, plus gov_uninstall, gov_openclaw_json, gov_brain_audit, gov_boot_audit.
- Experimental flow:
gov_apply <NN> (BOOT controlled apply) is included in deterministic runtime regression baseline, but remains controlled-UAT scope.
- If you use
gov_apply <NN>, keep it in controlled UAT and always close with /gov_migrate then /gov_audit.
- All
/gov_* command outputs use branded format: 🐾 header, emoji status indicators (✅/⚠️/❌), structured bullets, and 👉 next-step guidance.
When to use which command (quick map)
- Need command list fast:
gov_help
- Daily default path:
gov_setup quick (one-click chain)
- Readiness decision first (manual path):
gov_setup check
- First deployment path (manual):
gov_setup install
- Existing deployment update (manual):
gov_setup upgrade
- Policy alignment after deploy/update:
gov_migrate
- Final verification before claiming done:
gov_audit
- Cleanup workspace governance artifacts safely:
gov_uninstall quick
- Edit OpenClaw platform config safely:
gov_openclaw_json
- Review/harden Brain Docs safely:
gov_brain_audit -> gov_brain_audit APPROVE: ... -> gov_brain_audit ROLLBACK (if needed)
- Scan for recurring issues and get upgrade proposals:
gov_boot_audit
- Apply approved BOOT menu item only (Experimental):
gov_apply <NN>
First-run status map
After /gov_setup quick:
- if output says allowlist is not ready -> run
/gov_openclaw_json, then rerun /gov_setup quick
- if output is
PASS -> lifecycle is aligned
- if output is
FAIL/BLOCKED -> follow returned next-step commands
- manual fallback remains available:
check -> install/upgrade -> migrate -> audit
Important update rule
If openclaw plugins install ... returns plugin already exists, use:
openclaw plugins update openclaw-workspace-governance
openclaw gateway restart
/gov_setup check (if needed, align allowlist via /gov_openclaw_json)
/gov_setup quick (or manual /gov_setup upgrade -> /gov_migrate -> /gov_audit)
- If
/gov_setup check says READY, that does not cancel an explicitly requested /gov_setup upgrade during update flow.
Version check (operator-side):
- Installed:
openclaw plugins info openclaw-workspace-governance
- Latest:
npm view @adamchanadam/openclaw-workspace-governance version
Runtime gate behavior (important)
- Read-only diagnostics/testing commands are allowed and should not be blocked.
- Normal writes (skills/, projects/, code): always advisory — write proceeds with a logged warning, never hard-blocked.
- High-risk writes (Brain Docs,
openclaw.json, _control/*, governance prompts): advisory on 1st-2nd attempt, hard block on 3rd+ without evidence.
- If blocked by runtime gate, this usually means governance guard worked (not a system crash). Include your plan and list of files read, then retry.
- If blocked 3+ times: use
/gov_brain_audit force-accept to clear all gates (with audit trail).
- All
gov_* responses use branded output: 🐾 header, emoji status prefix (✅ PASS/READY, ⚠️ WARNING, ❌ BLOCKED/FAIL), structured • bullets, 👉 next-step, and ───── dividers.
- Tool-exposure root-fix is enabled by default: governance plugin tools require explicit
/gov_* intent (or /skill gov_*) in the current turn window.
If slash routing is unstable
Use fallback commands:
/skill gov_setup check
/skill gov_setup install
/skill gov_setup upgrade
/skill gov_migrate
/skill gov_audit
/skill gov_uninstall quick
/skill gov_openclaw_json
/skill gov_brain_audit
/skill gov_brain_audit APPROVE: APPLY_ALL_SAFE
/skill gov_brain_audit ROLLBACK
/skill gov_boot_audit
# Experimental only:
/skill gov_apply 01
Or natural language:
Please use gov_setup in check mode (read-only) and return workspace root, status, and next action.
Who this is for
- New OpenClaw users who want a guided install path.
- Teams operating long-running workspaces.
- Users who need auditable, low-drift maintenance.
Learn more (GitHub docs)
- Main docs: https://github.com/Adamchanadam/OpenClaw-WORKSPACE-GOVERNANCE
- English README: https://github.com/Adamchanadam/OpenClaw-WORKSPACE-GOVERNANCE/blob/main/README.md
- 繁體中文版: https://github.com/Adamchanadam/OpenClaw-WORKSPACE-GOVERNANCE/blob/main/README.zh-HK.md
- Governance handbook (EN): https://github.com/Adamchanadam/OpenClaw-WORKSPACE-GOVERNANCE/blob/main/WORKSPACE_GOVERNANCE_README.en.md
- Governance handbook (繁中): https://github.com/Adamchanadam/OpenClaw-WORKSPACE-GOVERNANCE/blob/main/WORKSPACE_GOVERNANCE_README.md
- Positioning (EN): https://github.com/Adamchanadam/OpenClaw-WORKSPACE-GOVERNANCE/blob/main/VALUE_POSITIONING_AND_FACTORY_GAP.en.md
- Positioning (繁中): https://github.com/Adamchanadam/OpenClaw-WORKSPACE-GOVERNANCE/blob/main/VALUE_POSITIONING_AND_FACTORY_GAP.md
1---2name: openclaw-workspace-governance-installer3description: Install OpenClaw WORKSPACE_GOVERNANCE in minutes. Get guided setup, upgrade checks, migration, and audit for long-running workspaces.4---56# OpenClaw Workspace Governance Installer78Ship safer OpenClaw operations from day one.9This installer gives you a repeatable governance path instead of ad-hoc prompt edits.1011## Why this is popular121. Prevents "edit first, verify later" mistakes.132. Gives one predictable setup/upgrade/audit flow.143. Makes changes traceable for review and handover.154. Works for both beginners and production workspaces.1617## 60-second quick start18First-time install:19```bash20# 1) Install plugin (first time only)21openclaw plugins install @adamchanadam/openclaw-workspace-governance@latest2223# 2) Enable plugin24openclaw plugins enable openclaw-workspace-governance2526# 3) Verify skills27openclaw skills list --eligible28```2930In OpenClaw chat:31```text32/gov_help33/gov_setup quick34# if quick output says allowlist is not ready (for example plugins.allow needs alignment):35/gov_openclaw_json36/gov_setup quick37# manual fallback (step-by-step):38/gov_setup install39prompts/governance/OpenClaw_INIT_BOOTSTRAP_WORKSPACE_GOVERNANCE.md40# if this workspace was already active before first governance adoption:41/gov_migrate42/gov_audit43```4445Already installed users (upgrade path):46```bash47# Do NOT run install again if plugin already exists48openclaw plugins update openclaw-workspace-governance49openclaw gateway restart50```5152Then in OpenClaw chat:53```text54/gov_setup quick55# if quick output says allowlist is not ready (for example plugins.allow needs alignment):56/gov_openclaw_json57/gov_setup quick58/gov_setup upgrade59/gov_migrate60/gov_audit61# manual fallback:62/gov_setup upgrade63/gov_migrate64/gov_audit65```6667## What you get681. `gov_help` — see all commands and recommended entry points at a glance.692. `gov_setup quick|check|install|upgrade` — deploy, upgrade, or verify governance in one step.703. `gov_migrate` — align workspace behavior to the latest governance rules after install or upgrade.714. `gov_audit` — verify 12 integrity checks and catch drift before declaring completion.725. `gov_uninstall quick|check|uninstall` — clean removal with backup and restore evidence.736. `gov_openclaw_json` — safely edit platform config (`openclaw.json`) with backup, validation, and rollback. Includes pre-modification config reference verification: scans local workspace docs before changes, falls back to official web docs, and degrades gracefully when neither is available.747. `gov_brain_audit` — review and harden Brain Docs quality with preview-first approval and rollback.758. `gov_boot_audit` — scan for recurring issues and generate upgrade proposals (read-only diagnostic).769. `gov_apply <NN>` — apply a single BOOT upgrade proposal with explicit human approval (**Experimental**, controlled UAT only).7778## Feature maturity (important)791. GA flow for production rollout: `gov_setup -> gov_migrate -> gov_audit`, plus `gov_uninstall`, `gov_openclaw_json`, `gov_brain_audit`, `gov_boot_audit`.802. Experimental flow: `gov_apply <NN>` (BOOT controlled apply) is included in deterministic runtime regression baseline, but remains controlled-UAT scope.813. If you use `gov_apply <NN>`, keep it in controlled UAT and always close with `/gov_migrate` then `/gov_audit`.824. All `/gov_*` command outputs use branded format: `🐾` header, emoji status indicators (✅/⚠️/❌), structured bullets, and `👉` next-step guidance.8384## When to use which command (quick map)851. Need command list fast: `gov_help`862. Daily default path: `gov_setup quick` (one-click chain)873. Readiness decision first (manual path): `gov_setup check`884. First deployment path (manual): `gov_setup install`895. Existing deployment update (manual): `gov_setup upgrade`906. Policy alignment after deploy/update: `gov_migrate`917. Final verification before claiming done: `gov_audit`928. Cleanup workspace governance artifacts safely: `gov_uninstall quick`939. Edit OpenClaw platform config safely: `gov_openclaw_json`9410. Review/harden Brain Docs safely: `gov_brain_audit -> gov_brain_audit APPROVE: ... -> gov_brain_audit ROLLBACK (if needed)`9511. Scan for recurring issues and get upgrade proposals: `gov_boot_audit`9612. Apply approved BOOT menu item only (Experimental): `gov_apply <NN>`9798## First-run status map99After `/gov_setup quick`:1001. if output says allowlist is not ready -> run `/gov_openclaw_json`, then rerun `/gov_setup quick`1012. if output is `PASS` -> lifecycle is aligned1023. if output is `FAIL/BLOCKED` -> follow returned next-step commands1034. manual fallback remains available: `check -> install/upgrade -> migrate -> audit`104105## Important update rule106If `openclaw plugins install ...` returns `plugin already exists`, use:1071. `openclaw plugins update openclaw-workspace-governance`1082. `openclaw gateway restart`1093. `/gov_setup check` (if needed, align allowlist via `/gov_openclaw_json`)1104. `/gov_setup quick` (or manual `/gov_setup upgrade` -> `/gov_migrate` -> `/gov_audit`)1115. If `/gov_setup check` says `READY`, that does not cancel an explicitly requested `/gov_setup upgrade` during update flow.112113Version check (operator-side):1141. Installed: `openclaw plugins info openclaw-workspace-governance`1152. Latest: `npm view @adamchanadam/openclaw-workspace-governance version`116117## Runtime gate behavior (important)1181. Read-only diagnostics/testing commands are allowed and should not be blocked.1192. **Normal writes** (skills/, projects/, code): always advisory — write proceeds with a logged warning, never hard-blocked.1203. **High-risk writes** (Brain Docs, `openclaw.json`, `_control/*`, governance prompts): advisory on 1st-2nd attempt, hard block on 3rd+ without evidence.1214. If blocked by runtime gate, this usually means governance guard worked (not a system crash). Include your plan and list of files read, then retry.1225. If blocked 3+ times: use `/gov_brain_audit force-accept` to clear all gates (with audit trail).1236. All `gov_*` responses use branded output: `🐾` header, emoji status prefix (✅ PASS/READY, ⚠️ WARNING, ❌ BLOCKED/FAIL), structured `•` bullets, `👉` next-step, and `─────` dividers.1247. Tool-exposure root-fix is enabled by default: governance plugin tools require explicit `/gov_*` intent (or `/skill gov_*`) in the current turn window.125126## If slash routing is unstable127Use fallback commands:128```text129/skill gov_setup check130/skill gov_setup install131/skill gov_setup upgrade132/skill gov_migrate133/skill gov_audit134/skill gov_uninstall quick135/skill gov_openclaw_json136/skill gov_brain_audit137/skill gov_brain_audit APPROVE: APPLY_ALL_SAFE138/skill gov_brain_audit ROLLBACK139/skill gov_boot_audit140# Experimental only:141/skill gov_apply 01142```143144Or natural language:145```text146Please use gov_setup in check mode (read-only) and return workspace root, status, and next action.147```148149## Who this is for1501. New OpenClaw users who want a guided install path.1512. Teams operating long-running workspaces.1523. Users who need auditable, low-drift maintenance.153154## Learn more (GitHub docs)1551. Main docs: https://github.com/Adamchanadam/OpenClaw-WORKSPACE-GOVERNANCE1562. English README: https://github.com/Adamchanadam/OpenClaw-WORKSPACE-GOVERNANCE/blob/main/README.md1573. 繁體中文版: https://github.com/Adamchanadam/OpenClaw-WORKSPACE-GOVERNANCE/blob/main/README.zh-HK.md1584. Governance handbook (EN): https://github.com/Adamchanadam/OpenClaw-WORKSPACE-GOVERNANCE/blob/main/WORKSPACE_GOVERNANCE_README.en.md1595. Governance handbook (繁中): https://github.com/Adamchanadam/OpenClaw-WORKSPACE-GOVERNANCE/blob/main/WORKSPACE_GOVERNANCE_README.md1606. Positioning (EN): https://github.com/Adamchanadam/OpenClaw-WORKSPACE-GOVERNANCE/blob/main/VALUE_POSITIONING_AND_FACTORY_GAP.en.md1617. Positioning (繁中): https://github.com/Adamchanadam/OpenClaw-WORKSPACE-GOVERNANCE/blob/main/VALUE_POSITIONING_AND_FACTORY_GAP.md