Files
Vincent KocandVincent Koc cf41c606df docs: close remaining one-way link findings in cli, plugins, tools, providers (#143855)
* docs: close remaining one-way link findings in cli, plugins, tools, providers

Adds the back-links and anchors that PR #143157 did not cover, and gives two
"see below" tables real headings to link to.

- Related back-links: cli/tui -> resume, cli/doctor -> status,
  configuration-reference -> configure, voice-call -> voicecall CLI,
  onepassword -> secrets CLI, acp-agents-setup -> acpx reference,
  llama-cpp -> llama-cpp reference, cli/policy -> policy reference,
  ollama -> LM Studio and Memory LanceDB, image/video generation -> OpenRouter,
  google-meet -> ElevenLabs, media-understanding -> Mistral,
  tts service links -> Fish Audio, tools/secrets -> ask_user.
- manifest/config-and-secrets: H3 headings for the dangerousFlags and
  secretInputs detail tables; the two "See below" cells now link to them.
- sdk-overview/capabilities: new "Worker providers" heading; the manifest
  worker-provider contract link now lands on it instead of 36 lines above.
- providers/openrouter: the model-list Note pointed at /concepts/model-providers,
  which carries no OpenRouter catalog; it now points at OpenRouter's own catalog
  and keeps a separate pointer to OpenClaw model selection.
- glossary.zh-CN: 7 sources for the new list-item link labels.

* docs(google): link the Gemini CLI runtime tab to the CLI backends page

r3-2107. `google-gemini-cli` is the CLI backend id the bundled Google plugin
registers, so the tab that configures it should point at the page documenting
its argv, JSONL dialect, and session behavior. The Related card alone left the
tab itself unlinked.

---------

Co-authored-by: Vincent Koc <vincent@openclaw.org>
2026-09-10 16:15:08 +08:00

4.7 KiB

summary, read_when, title
summary read_when title
CLI reference for `openclaw policy` conformance checks
You want to check OpenClaw settings against an authored policy.jsonc
You want policy findings in doctor lint
You need a policy attestation hash for audit evidence
Policy

openclaw policy

openclaw policy is provided by the bundled Policy plugin. It is an enterprise conformance layer over existing OpenClaw settings, not a second configuration system. You author requirements in policy.jsonc; OpenClaw observes the active workspace as evidence; policy reports drift through doctor --lint. Policy does not enforce tool calls or rewrite runtime behavior at request time, and it does not attest per-agent credential stores such as openclaw-agent.sqlite.

Policy checks configured channels, MCP servers, model providers, network SSRF posture, ingress/channel access, Gateway exposure and node command posture, authored message-routing probes, agent workspace access, sandbox posture, data-handling posture, secret provider/auth profile posture, and governed tool metadata (the ## Tools section of AGENTS.md). Use it when a workspace needs a durable, checkable statement such as "Telegram must not be enabled" or "governed tools must declare risk and owner metadata." If you only need local behavior with no attestation or drift detection, plain config is enough.

Separately, openclaw agent exec applies an isolated implicit policy config for each run: the agent sandbox is off, Gateway-host execution is fully allowed, and filesystem tools are restricted to --cwd.

Detailed topics

Enable the plugin and write `policy.jsonc`, with an example covering every section. Every rule namespace, the OpenClaw state it observes, and when to use it. Hold named agents or channels to stricter rules than the baseline. `policy check`, `policy compare`, and the plugin config behind them. Evidence, attestation hashes, and `policy watch` drift detection. Every check id, what `doctor --fix` repairs, and exit codes.