Picture this: you've just given an AI agent access to your Gmail. Maybe it's scheduling meetings for you, or summarizing threads, or pulling together a weekly digest. Convenient, right? Except now that agent has the same access you do—every email, every contact, every archived conversation going back years. And there's no straightforward way to claw back that permission or audit exactly what it's reading.
Eric Levine has been thinking about this problem. The founder of Berbix, an identity verification startup that Socure acquired for around $70 million in June 2023, recently emerged from Y Combinator with a new project called Clawvisor. It's an authorization layer—think of it as a security checkpoint—designed to sit between AI agents and the enterprise software they need to use. The premise sounds almost too simple: approve a specific task once, and Clawvisor enforces that purpose on every subsequent request, swapping in temporary credentials server-side so the agent never actually sees your password.
"You approve a purpose, not a permission," the company's launch materials read. Clawvisor went public earlier this year, positioning itself as the missing infrastructure piece for AI agents operating across Gmail, Slack, Google Drive, and other workplace staples. Whether that pitch resonates—or whether enterprises decide they'd rather build these controls themselves—remains to be seen.
How It Works (In Theory)
Clawvisor functions as a gateway. When an agent declares an intent—something like "send a summary of today's Slack messages to my manager"—a human reviews and approves it. After that initial sign-off, Clawvisor intercepts every API call the agent makes, checking it against what was approved. The system layers two types of verification: deterministic scoping to enforce technical boundaries, and an LLM-based intent checker (reportedly using Anthropic Claude Haiku 4.5+ and Claude Sonnet 4.6+, and Google Gemini 2.5 Flash-Lite+ models hosted on GCP Vertex AI) to flag whether the agent's behavior is drifting from its stated purpose.
The actual credentials live in an encrypted vault. Instead of raw tokens or passwords, agents get short-lived, narrowly scoped handles that Clawvisor swaps in at the last second. Every call is logged. Every action ties back to the original approval and the person who granted it. The company assigns a "blast radius" score—low, medium, high—to each task before approval, supposedly pausing risky requests for human review.
Integrations include the usual suspects: Gmail, Google Calendar, Slack, GitHub, Notion, Linear, Stripe. Fourteen in total, according to the company's materials. Several more—Jira, Salesforce, Airtable—are listed as coming soon, though timelines are vague.
It works with a range of agent frameworks—OpenClaw, Claude Code, others—essentially anything that can speak HTTP. At least that's the claim.
The Fine Print

Clawvisor offers three deployment options. Self-hosted is free, built on an open-source core under the Elastic License. Cloud Solo, also free to start, adds managed infrastructure and risk scoring. Cloud Org, the enterprise tier, is priced on request and includes team seats, SSO, role-based access, and extended log retention.
The GitHub repository has drawn some early traction—a few hundred stars, a few dozen forks—but the README carries a blunt disclaimer: "experimental, not security-audited; do not use as sole safeguard." Third-party reviews haven't been shy about pointing out the risks, either. HokAI's assessment noted the absence of public compliance certifications and flagged what it called a "concentration risk"—namely, that this is currently a one-person operation.
That's not necessarily disqualifying. Plenty of security tools start small. But it does raise questions about how much enterprises should lean on a product that's still, by its own admission, experimental.
A Suddenly Crowded Field

Clawvisor isn't alone. Noma launched a competing product earlier this year focused on agent access control. Ory announced something similar not long after. Trust3 AI unveiled its own take on MCP security in the spring. The timing isn't coincidental—these products are all responding to the same inflection point. As AI agents move from individual experiments to cross-functional deployments, someone needs to own the authorization problem.
The urgency is real. Researchers disclosed critical vulnerabilities in Anthropic's Model Context Protocol earlier this year, highlighting potential remote code execution vectors. OpenClaw had its own security issues. An Okta whitepaper emphasized the need for identity-layer controls as agent adoption scales. The market, in other words, is being catalyzed by alarm.
Levine's background in identity verification—Berbix specialized in biometric ID checks before the Socure acquisition—gives him some credibility here. But Clawvisor is still very early. Founded in 2026, the Y Combinator company listing shows a team size of one. Funding appears limited to the accelerator's standard check. Third-party databases note no publicly announced customers yet.
What Comes Next

The product exists. The problem is undeniable. The competitive landscape is forming fast. What isn't clear is whether purpose-based authorization will become the standard pattern, or whether large enterprises will decide to roll their own solutions rather than trust a third-party gateway with credentials across their entire stack.
Clawvisor is betting that as agent deployments mature—moving from individual developers tinkering in sandboxes to production systems handling sensitive data—someone will need to own this layer. For now, that someone is a solo founder with a vault full of encrypted secrets and a GitHub repo tagged "experimental."
Perhaps that's exactly how these things start. Or perhaps it's a reminder that the infrastructure for AI agents is still being figured out in real time, by people working faster than the established players can move. Either way, the question of who gets to approve what an AI agent does—and who's responsible when it goes off script—is no longer theoretical.
