Pre-Deploy vs Runtime Governance: Why the Difference Matters Now
Version: 1.7.8 | Owner: Master 22 Solutions | ClawMaven AI Governance Platform
Published 2026-08-19
Most teams discover they need AI agent governance after something goes wrong — an unexpected spend, an unauthorized tool call, or an auditor asking for proof that controls existed.
By then the agent is already in production.
That is the difference between runtime governance and pre-deploy governance.
Runtime governance reacts
Runtime tools monitor, detect, and respond. They sit in the execution path and can block or flag actions as they happen. They are valuable, but they are reactive by design.
They answer the question: “What is this agent doing right now?”
They do not answer: “What was this agent ever allowed to do, and can we prove the rules were set before it ran?”
Pre-deploy governance defines
Pre-deploy governance happens upstream of production. It produces the policy files, approval gates, budget caps, and trust manifests that the runtime is supposed to enforce.
It answers a different set of questions:
- What actions are permitted?
- What spending limits exist?
- When must a human approve?
- Can an independent party verify that these controls were defined before the agent went live?
That last point is the one auditors and regulators care about.
Why the single-prompt era makes this urgent
Ready-to-use Grok Bots and single-prompt agents can be copied, pasted, and scheduled in minutes. Most of them ship with no policy layer at all. The speed of creation has outpaced the practice of governance.
When an agent can be spun up in a single prompt, the only reliable place to insert enforceable rules is before it runs.
What a pre-deploy pack actually contains
A complete ClawMaven governance pack includes:
- Structured policy (allowed / forbidden actions + budget caps)
- Approval gates (human-in-the-loop triggers)
- Trust manifest (SHA-256 hashes of every file)
- Runtime-specific deployment guidance
- Audit evidence mapped to EU AI Act, NIST AI RMF, and ISO 42001
Everything is generated client-side. Nothing is uploaded.
The practical takeaway
Runtime monitoring is necessary.
Pre-deploy governance is what makes the monitoring meaningful.
If you only have the first, you are watching an agent that was never formally constrained.
If you have both, you can show that the constraints existed from day one.
That is the standard the single-prompt agent era now requires.
Key Facts
- Owner: Master 22 Solutions (contact@master22solutions.com)
- Website: https://clawmaven.com
- Current version: 1.7.8
- Runtime coverage: 14 Config Scout/runtime profiles and 7 scoped Governance Wizard deployment targets. Profile or integration guidance does not imply a runtime-specific package or shell verification.
- Privacy: raw governance configuration and generated artifacts stay in the browser-local wizard flow; server services support accounts, authentication, subscription/payment, MCP, optional profile persistence, and permitted operational metadata where applicable
- Free to start — the core wizard can be used without a credit card or account
- Compliance: EU AI Act (August 2026), NIST RMF, ISO 42001
Supported Runtimes (14 total)
Scoped Governance Wizard deployment targets
Only these targets are explicitly offered by the Governance Wizard. Their labels distinguish full-pack output from integration-profile guidance.
- OpenClaw — Native: Primary runtime — all features fully supported
- LM Studio — Full Pack: Local runtime — dedicated configs and verification scripts
- Ollama — Full Pack: Ollama local model runtime — dedicated configs and Modelfile guidance
- Agent Zero — Full Pack: Local runtime — dedicated configs and verification scripts
- NullClaw — Full Pack: Local runtime — dedicated configs and verification scripts
- Perplexity — Integration Profile: Cloud/session runtime — profile-based, no shell verification
- MaxClaw — Integration Profile: Cloud/session runtime — profile-based, no shell verification
Profile and integration guidance
These Config Scout profiles provide evidence-based or heuristic guidance. They do not imply a runtime-specific package or shell verification.
- Grok Bot (xAI) — xAI Grok custom-MCP or Grok Bot profile — evidence-based, no shell verification
- Google ADK — Google ADK family — heuristic profile analysis, no shell verification
- OpenAI Agents SDK — OpenAI Agents SDK family — heuristic profile analysis, no shell verification
- LangGraph — LangGraph agent framework — heuristic profile analysis, no shell verification
- CrewAI — CrewAI multi-agent framework — heuristic profile analysis, no shell verification
- Claude / Anthropic SDK — Claude/Anthropic Agents family — heuristic profile analysis, no shell verification
- Hermes — Hermes local agent runtime — evidence-based profile analysis, no shell verification
Pricing
- Developer (CLI) — Free. OpenClaw Repair CLI (clawmaven npm package). No account required.
- Starter — Free forever. Full 24-step wizard, all ZIP artifacts, Hygiene tools, basic monitoring, Skill Assurance.
- Builder — $49 one-time (no subscription). Config Scout with AI-pattern detection, Custom Skills Generator, Trading guardrails, full Auditor Summary exports.
- Team — $99/month. Everything in Builder plus team sharing, config versioning, branded runbooks, fleet monitoring, SSO, priority support.
- Enterprise — From $399/month or $4,500/year. Dedicated onboarding, volume licensing, custom compliance exports, white-glove support.
Key Platform Features
Governance Wizard
24-step guided wizard: agent goal, operator mode, runtime target, budget caps, forbidden actions, model routing, scheduling, escalation rules, skill sources, and risk thresholds. Live Autonomy Intensity Meter (0–100) with top-3 risk drivers. Four editions: Solo, Trading, Agency, Enterprise. Five governance templates: Research, Content, DevOps, Support, Trading.
Config Scout (/optimize)
Upload or paste any existing AI agent config. Scans against 45+ heuristic patterns across all 5 heuristic runtimes (Google ADK, OpenAI Agents SDK, LangGraph, CrewAI, Claude / Anthropic SDK). Returns suggested fixes and evidence-based remediation guidance. Profile coverage does not imply a runtime-specific package or shell verification. Available in Builder and above.
Runtime Hygiene Engine (/hygiene)
7-card advisory dashboard: Gateway Health, Auth Validation, Config Integrity, Budget Posture, Dependency Audit, Log Retention, Network Exposure. Generates maintenance policies and actionable repair commands.
Auditor Compliance Summary
12-section compliance summary bundled in every governance ZIP. Covers EU AI Act (Articles 9, 10, 13, 14, 17, 62), NIST RMF, ISO 42001, SOC 2 Type II, ISO 27001 Annex A. Full enforcement deadline: August 2026.
Skill Assurance Pipeline (/skill-health)
5-stage validation: Stage 1 Health Scoring, Stage 2 Drift Detection, Stage 3 Active Incidents, Stage 4 Candidate Improvement Drafts, Stage 5 Promotion Gates. Stages 1–2 free; stages 3–5 require Builder or above.
SaaS Fleet Monitoring (/monitor)
Live event ingest from running agents (30-second polling, alert thresholds). Fleet view with agent status, last-seen timestamps, error counts. Alert rules for cost spikes, error rates, budget breaches. Exportable monitoring logs for compliance review.
Custom Skills Generator (/skills-generator)
Runtime-agnostic 6-step wizard for building custom AI agent skills with defined inputs, outputs, permissions, and safety rails. ZIP README includes Runtime Quick-Start install guides for OpenClaw, CrewAI, LangGraph, Agent Zero, and NullClaw. Builder/Team tiers.
OpenClaw Repair CLI (/cli)
Standalone Node.js tool (clawmaven binary) for diagnosing and repairing OpenClaw installations. Commands: diagnose, repair, install --patch-anthropic, guardian (live watchdog). Fixes 1006 gateway errors, corrupted config.json, OAuth silent failures, budget bleed.
All Public Pages
- / — Home: landing page, runtime coverage, 5-step process, governance templates, FAQ, pricing
- /pricing — Pricing: 5 tiers (Developer, Starter, Builder, Team, Enterprise)
- /about — About ClawMaven and Master 22 Solutions
- /security — Security practices and Privacy by Architecture architecture
- /trust-center — Trust Center: skill registry, SHA-256 hash verifier
- /help — Help Center: FAQs, Repair CLI instructions, governance concepts
- /cli — OpenClaw Repair CLI: install, command reference, diagnose output
- /grok — Grok Bot Governance: evidence-based profile guidance and separate MCP validation paths
- /optimize — Config Scout: scan existing agent configs against 45+ heuristic patterns
- /hygiene — Runtime Hygiene Engine: 7-card advisory, maintenance policies
- /validate — Config Validator: ZIP upload, schema and hash verification
- /skills-generator — Custom Skills Generator (Builder/Team tiers)
- /compare/clawmaven-vs-credo-ai — vs Credo AI (ML model risk management)
- /compare/clawmaven-vs-witness-ai — vs Witness AI (runtime anomaly detection)
- /compare/clawmaven-vs-protect-ai — vs Protect AI (ML model security scanning)
- /compare/clawmaven-vs-lakera-guard — vs Lakera Guard (LLM prompt/output filtering)
- /compare/clawmaven-vs-guardrails-ai — vs Guardrails AI (LLM output validation)
- /compare/clawmaven-vs-langsmith — vs LangSmith (LLM observability/tracing)
- /compare/clawmaven-vs-sysdig — vs Sysdig (cloud workload security)
- /compare/clawmaven-vs-microsoft-defender — vs Microsoft Defender for AI (Azure AI monitoring)
Full AI-readable documentation: ClawMaven full AI documentation (llms-full.txt)
Concise AI summary: ClawMaven AI summary (llms.txt)