Oracle Fusion Claw Explained: OpenClaw's Agent Idea, Rebuilt for the Enterprise
Oracle announced Fusion Claw on September 29, 2026: a governed agent runtime inspired by OpenClaw, with an Enterprise Operating Envelope, an isolated runtime that keeps the model away from business records, and an Outcome Receipt for every task. Here's how it works, the 25 launch apps, the open questions, and a propose-validate-apply pattern you can copy.
- Published
- Reading time
- 9 min read

On this page
TL;DR: Oracle Fusion Claw is a governed agent runtime Oracle announced on September 29, 2026. It's inspired by the open-source OpenClaw agent, but Oracle built its own. It launched with 25 Claw-powered applications across finance, HR, supply chain and sales, bringing Oracle's Fusion Agentic Applications to 75. Three ideas make it worth studying: an Enterprise Operating Envelope (objectives, permissions, risk thresholds and approval rules set before the agent acts), an isolated runtime that stops the language model from directly changing business records, and an Outcome Receipt for every task. It runs on Oracle Cloud Infrastructure with Gemini and OpenAI models. Below: how it works, what OpenClaw has to do with it, the open questions, and a propose-then-apply pattern you can use in your own agents.

This is one of four deep dives that follow my overview, Agentic AI in October 2026: Agents Now Need Owners. The others cover OpenAI Dots, Atlassian AMP and the agentic commerce trust gap.
First, What Is OpenClaw?
You can't understand the name without the original. OpenClaw is a free, MIT-licensed AI agent you run on your own machine. You message it through apps like Telegram, WhatsApp, Discord or Slack, and it keeps running in the background, remembers context and carries out tasks instead of only replying [5][6]. Austrian developer Peter Steinberger started it in late 2025 under the name Clawdbot. It became Moltbot after Anthropic raised trademark concerns, then OpenClaw in January 2026, and it's now run by an independent foundation [5]. It's one of the most-starred projects on GitHub [5].
OpenClaw made the idea of "an agent that does things" real for millions of developers. It also showed the downside: an agent that can run commands and read your files and email is a serious security risk if it goes wrong [5].
Fusion Claw takes the idea and wraps it in enterprise controls. Forbes' Victor Dey describes it as adapting OpenClaw's approach for enterprises [7], and Oracle says it built Fusion Claw from scratch, with its own architecture and IP [8]. Oracle told The Letter Two it found that other Claw implementations didn't meet its criteria, which were "security, safety, and trust" and "the ability to execute enterprise workflows deterministically" [8].
How Fusion Claw Works
Oracle introduced it as an extension of its Fusion Agentic Applications [4], and Futurum calls it a "governed agentic execution runtime" [1]. It has four parts:
| Part | What it does |
|---|---|
| Enterprise Operating Envelope | Customers set objectives, policies, permissions, risk thresholds, decision rights and approval rules before any agent acts [1][2] |
| Outcome Trust Harness | Enforces that governance while the task runs [1] |
| Isolated runtime | Keeps the language model from directly updating Fusion business objects [2][3] |
| Outcome Receipt | A record of each completed task: the policies applied, the decisions made and the transactions performed [1][2] |
The core design choice: Fusion Claw pairs AI reasoning with deterministic enterprise computation [1]. The model plans and adapts, and ordinary, testable code performs the calculations and makes the changes.
Two Execution Modes
Customers choose how much autonomy to grant [2]:
- Review mode: an employee reviews the agent's plan before anything happens.
- Delegated mode: the application acts on its own, within the authority the customer has granted.
Natalia Rachelson, Oracle's SVP of Fusion Applications, expects customers to start with more human review and automate more over time. She also said, "Honestly, any task can be in full auto mode" [2]. That's technically true, but the hard part is deciding which tasks should run without review, and that's still your call.
What Shipped: 25 Applications
Oracle launched 25 Claw-powered applications, including [1][2]:
- Ledger (finance close): investigating accounting exceptions
- Workforce Staffing (HR): building staffing plans
- Shipping Consolidation (supply chain): combining shipments
- Account Territory Growth Plan (sales): planning sales territories
The staffing example shows the pattern well. The agent weighs employee qualifications, availability, labor rules and cost targets, proposes schedules, and makes changes in the system of record if authorized. If an employee calls in sick, it can reopen the plan [2]. Rachelson framed the gap Claw fills: "We did not previously have solutions for advanced optimization" [2].
Customers can build more apps on the same runtime through Oracle AI Agent Studio, with no-code and pro-code options. Accenture, Deloitte, KPMG and PwC endorsed the platform at launch [1].
Models and Limits
- Models: Gemini and OpenAI models at launch, running on Oracle Cloud Infrastructure, with more promised [1][2].
- No bring-your-own small model yet: you can't currently choose open, lower-cost models for Claw tasks [2].
- No published results: Oracle gave no measured cost savings or production performance data [2].
- Supervision cost: analysts point out that the cost of human review could eat into the savings, and customers still have to decide what good execution looks like and when to stop [7].
Futurum's open questions are the right ones to watch [1]: will regulated customers accept Outcome Receipts as compliance evidence, will the system-integrator endorsements turn into named customer deployments, and how will SAP, Workday and Salesforce respond?
The Pattern Worth Copying: Propose, Validate, Apply
Fusion Claw's best idea doesn't need Oracle. The model proposes a plan as data, deterministic code checks it against policy, and only that code changes records. Every run produces a receipt.
Here it is with the staffing example. It runs with npx tsx claw-propose-apply.ts on Node 22+:
// claw-propose-apply.ts: run with `npx tsx claw-propose-apply.ts` (Node 22+)
// The model proposes a plan as data. Deterministic code validates it against
// policy, applies it, and writes a receipt. The model never touches the records.
type Shift = { employee: string; day: string; hours: number };
interface Plan {
goal: string;
shifts: Shift[];
}
interface Policy {
maxHoursPerShift: number;
maxWeeklyHoursPerEmployee: number;
hourlyCost: number;
budget: number;
mode: "review" | "delegated";
}
interface Receipt {
goal: string;
policiesChecked: string[];
violations: string[];
totalCost: number;
status: "applied" | "awaiting_review" | "rejected";
}
// Pretend this JSON came back from an LLM call with structured output.
const proposedByModel: Plan = {
goal: "Cover the warehouse for Monday and Tuesday",
shifts: [
{ employee: "ana", day: "mon", hours: 8 },
{ employee: "ben", day: "mon", hours: 8 },
{ employee: "ana", day: "tue", hours: 12 },
{ employee: "cho", day: "tue", hours: 8 },
],
};
function validate(plan: Plan, policy: Policy): Receipt {
const violations: string[] = [];
const weekly = new Map<string, number>();
for (const s of plan.shifts) {
if (s.hours > policy.maxHoursPerShift) {
violations.push(`${s.employee} ${s.day}: ${s.hours}h is over the ${policy.maxHoursPerShift}h shift limit`);
}
weekly.set(s.employee, (weekly.get(s.employee) ?? 0) + s.hours);
}
for (const [employee, hours] of weekly) {
if (hours > policy.maxWeeklyHoursPerEmployee) {
violations.push(`${employee}: ${hours}h this week is over ${policy.maxWeeklyHoursPerEmployee}h`);
}
}
const totalCost = plan.shifts.reduce((sum, s) => sum + s.hours * policy.hourlyCost, 0);
if (totalCost > policy.budget) violations.push(`cost ${totalCost} is over the ${policy.budget} budget`);
const status = violations.length > 0 ? "rejected" : policy.mode === "review" ? "awaiting_review" : "applied";
return {
goal: plan.goal,
policiesChecked: ["maxHoursPerShift", "maxWeeklyHoursPerEmployee", "budget", `mode=${policy.mode}`],
violations,
totalCost,
status,
};
}
const policy: Policy = { maxHoursPerShift: 10, maxWeeklyHoursPerEmployee: 40, hourlyCost: 25, budget: 1000, mode: "delegated" };
console.log(JSON.stringify(validate(proposedByModel, policy), null, 2));
// The model gets the violations back and revises the plan.
const revised: Plan = {
...proposedByModel,
shifts: proposedByModel.shifts.map((s) => (s.hours > 10 ? { ...s, hours: 8 } : s)),
};
console.log(JSON.stringify(validate(revised, policy), null, 2));Output:
{
"goal": "Cover the warehouse for Monday and Tuesday",
"policiesChecked": [
"maxHoursPerShift",
"maxWeeklyHoursPerEmployee",
"budget",
"mode=delegated"
],
"violations": [
"ana tue: 12h is over the 10h shift limit"
],
"totalCost": 900,
"status": "rejected"
}
{
"goal": "Cover the warehouse for Monday and Tuesday",
"policiesChecked": [
"maxHoursPerShift",
"maxWeeklyHoursPerEmployee",
"budget",
"mode=delegated"
],
"violations": [],
"totalCost": 800,
"status": "applied"
}Why this works:
- The model never holds write access. It returns JSON, and the validator decides. A bad plan becomes a rejected receipt, not a corrupted schedule.
- Violations go back to the model as feedback. The model revises, and the second plan passes. That's the "reason, compute, adapt" loop Oracle describes.
- The receipt is your audit log. It records which policies were checked, what failed, the cost and the final status, which is what an auditor will ask for.
- Switching
modeto"review"turns the same plan intoawaiting_reviewinstead ofapplied, so you can raise autonomy one task type at a time.
In a real system, get the plan from the model with structured output (JSON schema), and run the apply step in a transaction. My guide on Claude agentic workflows in production shows how to wire structured output and tool calls together.
My Take
Fusion Claw is the most architecturally honest launch of the four. Oracle didn't promise that the model would always be right. It designed for the model being wrong: isolation, deterministic computation, approval modes and receipts. That's the right default for anything that touches a general ledger or a payroll.
It's also a strong signal of where agent infrastructure is heading. Analysts at Forkast argue the application layer is absorbing agent infrastructure and leaving less room for standalone agent middleware [3]. If your agents run inside Oracle, SAP or Workday, governance increasingly comes from the vendor. If you build your own, you need to build the envelope, validator and receipt yourself. As the code above shows, that's not much code.
For how Fusion Claw compares with OpenAI Dots, Atlassian AMP and SAP, read the agentic AI October 2026 overview.
References
- 01Futurum Group, "Oracle Fusion Claw: From AI Assistance to Governed Autonomous Execution." futurumgroup.com
- 02SiliconANGLE, "Oracle expands AI agent features with Fusion Claw," September 29, 2026. siliconangle.com
- 03Forkast, "The Application Layer Is Absorbing Agent Infrastructure: Oracle Fusion Claw Signals the End of Standalone Middleware." forkast.news
- 04Oracle, "Oracle Extends Fusion Agentic Applications with Introduction of Fusion Claw," September 29, 2026. oracle.com
- 05Neurohive, "OpenClaw: the lobster that took over the world." neurohive.io
- 06Operator, "What is OpenClaw? The open source AI agent, explained." operator.io
- 07Victor Dey, "Oracle Fusion Claw Adapts OpenClaw's Agentic AI Approach For Enterprises," Forbes, September 29, 2026. forbes.com
- 08The Letter Two, "Fusion Claw Lets Oracle's AI Apps Act Within Company Rules," September 29, 2026. thelettertwo.com
Harsh Rastogi is an AI Product Engineer at Modelia, building production generative-AI systems for fashion commerce, and the creator of carcode. He writes about AI systems, developer tooling and production engineering at harshrastogi.tech.
Frequently asked questions
What is Oracle Fusion Claw?
Fusion Claw is a governed agent runtime Oracle announced on September 29, 2026. It pairs AI reasoning with deterministic enterprise computation, runs in an isolated environment that keeps the language model from directly changing business records, and produces an Outcome Receipt for every task. It launched with 25 applications, bringing Oracle's Fusion Agentic Applications to 75.
Is Fusion Claw based on OpenClaw?
It is inspired by OpenClaw, the open-source self-hosted agent, but Oracle says it built Fusion Claw from scratch with its own architecture and IP. Oracle said other Claw implementations didn't meet its criteria for security, safety and trust, and for executing enterprise workflows deterministically.
What is the Enterprise Operating Envelope?
It is where customers define objectives, policies, permissions, risk thresholds, decision rights and approval rules before a Fusion Claw agent acts. An Outcome Trust Harness enforces it during execution.
What models does Fusion Claw use?
At launch it runs on Oracle Cloud Infrastructure with Google Gemini and OpenAI models. Oracle plans to support more models, and customers can't yet choose their own open, lower-cost models.
What is the difference between review mode and delegated mode?
In review mode, an employee reviews the agent's plan before it runs. In delegated mode, the application executes on its own within the authority the customer has granted.
- Oracle
- AI Agents
- Agentic AI
- Enterprise AI
- AI Governance
- OpenClaw
Written by Harsh Rastogi, AI Product Engineer and Business AI Head at Modelia. More on AI products, agents and production engineering on LinkedIn.