Oracle Fusion Claw Explained: OpenClaw's Agent Idea, Rebuilt for the Enterprise

    Oracle announced Fusion Claw on September 29, 2026: a governed agent runtime inspired by OpenClaw, with an Enterprise Operating Envelope, an isolated runtime that keeps the model away from business records, and an Outcome Receipt for every task. Here's how it works, the 25 launch apps, the open questions, and a propose-validate-apply pattern you can copy.

    Published
    Reading time
    9 min read
    Oracle Fusion Claw explained: a governed agent runtime for enterprise applications
    On this page

    TL;DR: Oracle Fusion Claw is a governed agent runtime Oracle announced on September 29, 2026. It's inspired by the open-source OpenClaw agent, but Oracle built its own. It launched with 25 Claw-powered applications across finance, HR, supply chain and sales, bringing Oracle's Fusion Agentic Applications to 75. Three ideas make it worth studying: an Enterprise Operating Envelope (objectives, permissions, risk thresholds and approval rules set before the agent acts), an isolated runtime that stops the language model from directly changing business records, and an Outcome Receipt for every task. It runs on Oracle Cloud Infrastructure with Gemini and OpenAI models. Below: how it works, what OpenClaw has to do with it, the open questions, and a propose-then-apply pattern you can use in your own agents.

    Oracle Fusion Claw explained: a governed agent runtime for enterprise apps
    Oracle Fusion Claw explained: a governed agent runtime for enterprise apps

    This is one of four deep dives that follow my overview, Agentic AI in October 2026: Agents Now Need Owners. The others cover OpenAI Dots, Atlassian AMP and the agentic commerce trust gap.

    First, What Is OpenClaw?

    You can't understand the name without the original. OpenClaw is a free, MIT-licensed AI agent you run on your own machine. You message it through apps like Telegram, WhatsApp, Discord or Slack, and it keeps running in the background, remembers context and carries out tasks instead of only replying [5][6]. Austrian developer Peter Steinberger started it in late 2025 under the name Clawdbot. It became Moltbot after Anthropic raised trademark concerns, then OpenClaw in January 2026, and it's now run by an independent foundation [5]. It's one of the most-starred projects on GitHub [5].

    OpenClaw made the idea of "an agent that does things" real for millions of developers. It also showed the downside: an agent that can run commands and read your files and email is a serious security risk if it goes wrong [5].

    Fusion Claw takes the idea and wraps it in enterprise controls. Forbes' Victor Dey describes it as adapting OpenClaw's approach for enterprises [7], and Oracle says it built Fusion Claw from scratch, with its own architecture and IP [8]. Oracle told The Letter Two it found that other Claw implementations didn't meet its criteria, which were "security, safety, and trust" and "the ability to execute enterprise workflows deterministically" [8].

    How Fusion Claw Works

    Oracle introduced it as an extension of its Fusion Agentic Applications [4], and Futurum calls it a "governed agentic execution runtime" [1]. It has four parts:

    PartWhat it does
    Enterprise Operating EnvelopeCustomers set objectives, policies, permissions, risk thresholds, decision rights and approval rules before any agent acts [1][2]
    Outcome Trust HarnessEnforces that governance while the task runs [1]
    Isolated runtimeKeeps the language model from directly updating Fusion business objects [2][3]
    Outcome ReceiptA record of each completed task: the policies applied, the decisions made and the transactions performed [1][2]

    The core design choice: Fusion Claw pairs AI reasoning with deterministic enterprise computation [1]. The model plans and adapts, and ordinary, testable code performs the calculations and makes the changes.

    Two Execution Modes

    Customers choose how much autonomy to grant [2]:

    • Review mode: an employee reviews the agent's plan before anything happens.
    • Delegated mode: the application acts on its own, within the authority the customer has granted.

    Natalia Rachelson, Oracle's SVP of Fusion Applications, expects customers to start with more human review and automate more over time. She also said, "Honestly, any task can be in full auto mode" [2]. That's technically true, but the hard part is deciding which tasks should run without review, and that's still your call.

    What Shipped: 25 Applications

    Oracle launched 25 Claw-powered applications, including [1][2]:

    • Ledger (finance close): investigating accounting exceptions
    • Workforce Staffing (HR): building staffing plans
    • Shipping Consolidation (supply chain): combining shipments
    • Account Territory Growth Plan (sales): planning sales territories

    The staffing example shows the pattern well. The agent weighs employee qualifications, availability, labor rules and cost targets, proposes schedules, and makes changes in the system of record if authorized. If an employee calls in sick, it can reopen the plan [2]. Rachelson framed the gap Claw fills: "We did not previously have solutions for advanced optimization" [2].

    Customers can build more apps on the same runtime through Oracle AI Agent Studio, with no-code and pro-code options. Accenture, Deloitte, KPMG and PwC endorsed the platform at launch [1].

    Models and Limits

    • Models: Gemini and OpenAI models at launch, running on Oracle Cloud Infrastructure, with more promised [1][2].
    • No bring-your-own small model yet: you can't currently choose open, lower-cost models for Claw tasks [2].
    • No published results: Oracle gave no measured cost savings or production performance data [2].
    • Supervision cost: analysts point out that the cost of human review could eat into the savings, and customers still have to decide what good execution looks like and when to stop [7].

    Futurum's open questions are the right ones to watch [1]: will regulated customers accept Outcome Receipts as compliance evidence, will the system-integrator endorsements turn into named customer deployments, and how will SAP, Workday and Salesforce respond?

    The Pattern Worth Copying: Propose, Validate, Apply

    Fusion Claw's best idea doesn't need Oracle. The model proposes a plan as data, deterministic code checks it against policy, and only that code changes records. Every run produces a receipt.

    Here it is with the staffing example. It runs with npx tsx claw-propose-apply.ts on Node 22+:

    typescript
    // claw-propose-apply.ts: run with `npx tsx claw-propose-apply.ts` (Node 22+)
    // The model proposes a plan as data. Deterministic code validates it against
    // policy, applies it, and writes a receipt. The model never touches the records.
    
    type Shift = { employee: string; day: string; hours: number };
    
    interface Plan {
      goal: string;
      shifts: Shift[];
    }
    
    interface Policy {
      maxHoursPerShift: number;
      maxWeeklyHoursPerEmployee: number;
      hourlyCost: number;
      budget: number;
      mode: "review" | "delegated";
    }
    
    interface Receipt {
      goal: string;
      policiesChecked: string[];
      violations: string[];
      totalCost: number;
      status: "applied" | "awaiting_review" | "rejected";
    }
    
    // Pretend this JSON came back from an LLM call with structured output.
    const proposedByModel: Plan = {
      goal: "Cover the warehouse for Monday and Tuesday",
      shifts: [
        { employee: "ana", day: "mon", hours: 8 },
        { employee: "ben", day: "mon", hours: 8 },
        { employee: "ana", day: "tue", hours: 12 },
        { employee: "cho", day: "tue", hours: 8 },
      ],
    };
    
    function validate(plan: Plan, policy: Policy): Receipt {
      const violations: string[] = [];
      const weekly = new Map<string, number>();
    
      for (const s of plan.shifts) {
        if (s.hours > policy.maxHoursPerShift) {
          violations.push(`${s.employee} ${s.day}: ${s.hours}h is over the ${policy.maxHoursPerShift}h shift limit`);
        }
        weekly.set(s.employee, (weekly.get(s.employee) ?? 0) + s.hours);
      }
      for (const [employee, hours] of weekly) {
        if (hours > policy.maxWeeklyHoursPerEmployee) {
          violations.push(`${employee}: ${hours}h this week is over ${policy.maxWeeklyHoursPerEmployee}h`);
        }
      }
    
      const totalCost = plan.shifts.reduce((sum, s) => sum + s.hours * policy.hourlyCost, 0);
      if (totalCost > policy.budget) violations.push(`cost ${totalCost} is over the ${policy.budget} budget`);
    
      const status = violations.length > 0 ? "rejected" : policy.mode === "review" ? "awaiting_review" : "applied";
      return {
        goal: plan.goal,
        policiesChecked: ["maxHoursPerShift", "maxWeeklyHoursPerEmployee", "budget", `mode=${policy.mode}`],
        violations,
        totalCost,
        status,
      };
    }
    
    const policy: Policy = { maxHoursPerShift: 10, maxWeeklyHoursPerEmployee: 40, hourlyCost: 25, budget: 1000, mode: "delegated" };
    
    console.log(JSON.stringify(validate(proposedByModel, policy), null, 2));
    
    // The model gets the violations back and revises the plan.
    const revised: Plan = {
      ...proposedByModel,
      shifts: proposedByModel.shifts.map((s) => (s.hours > 10 ? { ...s, hours: 8 } : s)),
    };
    console.log(JSON.stringify(validate(revised, policy), null, 2));

    Output:

    text
    {
      "goal": "Cover the warehouse for Monday and Tuesday",
      "policiesChecked": [
        "maxHoursPerShift",
        "maxWeeklyHoursPerEmployee",
        "budget",
        "mode=delegated"
      ],
      "violations": [
        "ana tue: 12h is over the 10h shift limit"
      ],
      "totalCost": 900,
      "status": "rejected"
    }
    {
      "goal": "Cover the warehouse for Monday and Tuesday",
      "policiesChecked": [
        "maxHoursPerShift",
        "maxWeeklyHoursPerEmployee",
        "budget",
        "mode=delegated"
      ],
      "violations": [],
      "totalCost": 800,
      "status": "applied"
    }

    Why this works:

    • The model never holds write access. It returns JSON, and the validator decides. A bad plan becomes a rejected receipt, not a corrupted schedule.
    • Violations go back to the model as feedback. The model revises, and the second plan passes. That's the "reason, compute, adapt" loop Oracle describes.
    • The receipt is your audit log. It records which policies were checked, what failed, the cost and the final status, which is what an auditor will ask for.
    • Switching mode to "review" turns the same plan into awaiting_review instead of applied, so you can raise autonomy one task type at a time.

    In a real system, get the plan from the model with structured output (JSON schema), and run the apply step in a transaction. My guide on Claude agentic workflows in production shows how to wire structured output and tool calls together.

    My Take

    Fusion Claw is the most architecturally honest launch of the four. Oracle didn't promise that the model would always be right. It designed for the model being wrong: isolation, deterministic computation, approval modes and receipts. That's the right default for anything that touches a general ledger or a payroll.

    It's also a strong signal of where agent infrastructure is heading. Analysts at Forkast argue the application layer is absorbing agent infrastructure and leaving less room for standalone agent middleware [3]. If your agents run inside Oracle, SAP or Workday, governance increasingly comes from the vendor. If you build your own, you need to build the envelope, validator and receipt yourself. As the code above shows, that's not much code.

    For how Fusion Claw compares with OpenAI Dots, Atlassian AMP and SAP, read the agentic AI October 2026 overview.

    References

    1. 01Futurum Group, "Oracle Fusion Claw: From AI Assistance to Governed Autonomous Execution." futurumgroup.com
    2. 02SiliconANGLE, "Oracle expands AI agent features with Fusion Claw," September 29, 2026. siliconangle.com
    3. 03Forkast, "The Application Layer Is Absorbing Agent Infrastructure: Oracle Fusion Claw Signals the End of Standalone Middleware." forkast.news
    4. 04Oracle, "Oracle Extends Fusion Agentic Applications with Introduction of Fusion Claw," September 29, 2026. oracle.com
    5. 05Neurohive, "OpenClaw: the lobster that took over the world." neurohive.io
    6. 06Operator, "What is OpenClaw? The open source AI agent, explained." operator.io
    7. 07Victor Dey, "Oracle Fusion Claw Adapts OpenClaw's Agentic AI Approach For Enterprises," Forbes, September 29, 2026. forbes.com
    8. 08The Letter Two, "Fusion Claw Lets Oracle's AI Apps Act Within Company Rules," September 29, 2026. thelettertwo.com

    Harsh Rastogi is an AI Product Engineer at Modelia, building production generative-AI systems for fashion commerce, and the creator of carcode. He writes about AI systems, developer tooling and production engineering at harshrastogi.tech.

    Frequently asked questions

    What is Oracle Fusion Claw?

    Fusion Claw is a governed agent runtime Oracle announced on September 29, 2026. It pairs AI reasoning with deterministic enterprise computation, runs in an isolated environment that keeps the language model from directly changing business records, and produces an Outcome Receipt for every task. It launched with 25 applications, bringing Oracle's Fusion Agentic Applications to 75.

    Is Fusion Claw based on OpenClaw?

    It is inspired by OpenClaw, the open-source self-hosted agent, but Oracle says it built Fusion Claw from scratch with its own architecture and IP. Oracle said other Claw implementations didn't meet its criteria for security, safety and trust, and for executing enterprise workflows deterministically.

    What is the Enterprise Operating Envelope?

    It is where customers define objectives, policies, permissions, risk thresholds, decision rights and approval rules before a Fusion Claw agent acts. An Outcome Trust Harness enforces it during execution.

    What models does Fusion Claw use?

    At launch it runs on Oracle Cloud Infrastructure with Google Gemini and OpenAI models. Oracle plans to support more models, and customers can't yet choose their own open, lower-cost models.

    What is the difference between review mode and delegated mode?

    In review mode, an employee reviews the agent's plan before it runs. In delegated mode, the application executes on its own within the authority the customer has granted.

    • Oracle
    • AI Agents
    • Agentic AI
    • Enterprise AI
    • AI Governance
    • OpenClaw

    Written by Harsh Rastogi, AI Product Engineer and Business AI Head at Modelia. More on AI products, agents and production engineering on LinkedIn.

    Share

    LinkedInX
    Portrait of Harsh Rastogi, AI Product Engineer

    Harsh Rastogi

    AI Product Engineer and Business AI Head at Modelia

    I build AI products and agents from the first sketch to production at Modelia, and I'm a Founding Engineer at SelfAgentic. Before that I built platforms at Asynq and Bharat Electronics Limited. I publish the agent skills I use every day, and you can see what I've shipped in my work.

    • Agentic AI in October 2026: Agents Now Need Owners (Dots, AMP, Fusion Claw, SAP)

      In two weeks, OpenAI, Atlassian, Oracle and SAP each shipped agents with named owners, scoped permissions, approval rules and audit logs, and America.gov tested whether citizens will let AI act for them. Here's what launched, why only 23% of consumers trust agents with payments, and a working TypeScript agent envelope you can copy.

      • Agentic AI
      • AI Agents
      • AI Governance
      • OpenAI
      AI & Machine Learning12 min read
    • Atlassian AMP Explained: The Agentic Multiplayer Protocol and AI Agents as Teammates

      Atlassian announced AMP, the Agentic Multiplayer Protocol, at Team '26 Europe on October 7, 2026. Every agent gets an owner and profile, works from the 250-billion-object Teamwork Graph and logs its actions. Here's how it works, what's shipped vs coming soon, an admin checklist, and a permission model you can copy.

      • Atlassian
      • AI Agents
      • Agentic AI
      • MCP
      AI & Machine Learning10 min read
    • OpenAI Dots Explained: Always-On ChatGPT Agents, What They Can Do, and What They Can't

      OpenAI Dots are persistent ChatGPT agents launched at DevDay on September 29, 2026. Each one runs on GPT-6 Astra with its own cloud computer, connects to 4,000+ apps and keeps working after you log off. Here's how they work, what they cost, what they can't do yet, and an undo-ledger pattern for long-running agents.

      • OpenAI
      • OpenAI Dots
      • AI Agents
      • Agentic AI
      AI & Machine Learning9 min read

    Get the next article by email.

    New articles and AI Pulse editions. Nothing else.