Founderland Logofounderland
the ★ top ★ 100 ★ marketers ★
SavedSearch
FoundersFounders
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Product Launches
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Investment News
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Research & Innovation
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
FoundersFounders
Return

Recommended Articles

SaaS iconSaaSOctober 4, 2026

DoD Solution raises $2M for AI drone navigation in war zones

DoD Solution raises $2M for AI drone navigation in war zones
Defense TechDrone Tech+3
SaaS iconSaaSOctober 3, 2026

DesignVerse raises $5.5M to automate enterprise software

DesignVerse raises $5.5M to automate enterprise software
Ai AutomationEnterprise Software+3
Media & Entertainment iconMedia & EntertainmentMay 14, 2026

YC-Backed Playabl.ai Launches AI Game Builder for No-Code Creators

YC-Backed Playabl.ai Launches AI Game Builder for No-Code Creators
YcGenerative Ai+3
Healthtech & Biotech iconHealthtech & BiotechMay 14, 2026

Arctic Health Launches AI Platform to Automate Healthcare Credentialing

Arctic Health Launches AI Platform to Automate Healthcare Credentialing
YcAi Agents+3

Founders Mentioned

Eric Levine

Clawvisor

saas icon
SaaS

Eric Levine

Clawvisor

saas icon
SaaS
SaaS iconSaaS
May 14, 2026
YcAi AgentsEnterprise SecurityAi Access ControlB2b Saas

Clawvisor Launches Authorization Layer to Keep AI Agents in Check

YC-backed startup tackles enterprise security gap with 'approve a purpose, not a permission' model as AI agents access Gmail, Slack, and Google Drive at scale.

Clawvisor Launches Authorization Layer to Keep AI Agents in Check

Your AI assistant needs to scan your inbox for that missing invoice. So you click "Allow" on Google's OAuth screen, and just like that, the agent has access to everything—every email you've ever sent, every draft you've abandoned, every calendar invite you've declined. There's no technical mechanism to verify it actually stopped at that invoice. The trust model is binary: either the agent gets nothing, or it gets the keys to the kingdom.

Eric Levine thinks this is backwards. "OAuth is broken for AI agents," he wrote in March, and he's not pulling punches. Traditional authorization assumes you're handing credentials to predictable software—a mobile app that refreshes your feed, maybe, or a CRM that syncs contacts. Agents don't work that way. They improvise, they iterate, they take detours you didn't anticipate. That "calendar.read" scope you granted? It could mean checking today's appointments. Or it could mean exfiltrating a decade of scheduling data, and OAuth wouldn't know the difference.

Levine's answer is Clawvisor, a YC-backed startup that launched publicly on May 7. The pitch is deceptively simple: instead of approving permissions upfront, you approve purposes at runtime. An agent declares what it intends to do—"check today's calendar"—and Clawvisor watches every API call that follows, killing anything that strays off script.

The Model: Approve the Task, Not the Token

Here's how it works in practice. An agent submits a task description and the actions it plans to take. You approve once. From that moment on, Clawvisor sits between the agent and every SaaS API it touches—Gmail, Slack, Google Drive, Dropbox—verifying each request against the stated purpose.

If the agent said it needed today's events but suddenly tries to pull ten years of history, the call gets blocked. Clawvisor maintains what the company calls "chain context verification," tying subsequent actions to entities the agent actually encountered along the way: specific email addresses, file IDs, contact records. The idea is to prevent scope creep in real time, not just at the moment you first grant access.

The product went live around May 7 with a Launch YC post. As of mid-May, the GitHub repo shows 173 stars and sits at version 0.9.2, released May 5. Features include risk scoring for each task (low, medium, high, critical), an evaluation suite with 249 test cases, and support for agents like OpenClaw, Claude Code, Hermes, and Perplexity Computer. Gmail, Slack, Google Drive, and Dropbox are integrated. SendGrid, Jira, Salesforce, and Airtable are marked "coming soon."

It's early. Very early, perhaps more than Levine might prefer to admit.

Vaulting Credentials, Air-Gapping Agents

Digital illustration for article section "Vaulting Credentials, Air-Gapping Agents" in "Clawvisor Launches Authorization Layer to Keep AI Agents in Check" - A conceptual, minimalist illustration of a stylized, secure vault safely enclosing an abstract golde...

The technical architecture centers on credential isolation. Agents never see the actual OAuth tokens or API keys. Clawvisor stores credentials in an encrypted vault—AES-256-GCM—and injects them server-side during execution. Responses get sanitized before reaching the agent. Every action generates an audit log.

Device authentication uses HMAC-SHA256. Optional end-to-end encryption leans on X25519, HKDF, and AES. Relay authentication involves Ed25519 signatures. The documentation explicitly recommends running Clawvisor on a separate host from the agent itself, creating something like an air gap between decision-making and credential access.

That said, the README is honest about the risks. The software is "experimental" and "not audited for security." For enterprises weighing agent deployments, that's the kind of disclosure that matters—and to Levine's credit, it's front and center.

A Founder Who's Been Here Before

Levine isn't new to high-stakes verification problems. He co-founded Berbix, a YC Summer 2018 company focused on identity verification, which Socure acquired for around $70 million in June 2023. Before that, he spent time in Trust & Safety engineering at Airbnb. He's now listed as a Visiting Partner at Y Combinator, and the YC directory shows Clawvisor as a Spring 2026 batch company with a team size of one—though that figure may not reflect recent additions.

His March 5 blog post, "OAuth Is Broken for AI Agents," reads like a manifesto. Traditional OAuth assumes deterministic applications: you request a scope, you get a token, you use the token within that scope. Done. Agents are anything but deterministic. They explore. They backtrack. They make choices you didn't script. A single "calendar.read" scope might mean checking one appointment or vacuuming up years of data, and OAuth has no language to distinguish between the two.

Levine's argument: runtime enforcement is the only answer. Upfront permission grants don't cut it when the application itself doesn't know what it's going to do next.

A Crowded, Chaotic Market

Digital illustration for article section "A Crowded, Chaotic Market" in "Clawvisor Launches Authorization Layer to Keep AI Agents in Check" - A whimsical, modern watercolor illustration depicting a slightly chaotic but visually clean cluster ...

Clawvisor offers both a cloud version—with a free trial—and a self-host option via install script, Docker, or building from source. The license is Elastic License 2.0. There's no public pricing page yet, no customer logos, no named case studies visible as of mid-May. For teams and enterprises, the site mentions SSO/SAML, audit and compliance features, and dedicated support, but inquiries go through a sales contact.

The competitive landscape is filling up fast, maybe faster than anyone expected. SlashID announced AI Identity Governance on May 5, positioning around OAuth-connected apps and identity graph layers. Palo Alto Networks released Prisma AIRS 2.0 around the same time, targeting enterprise AI security more broadly. Smaller players—DeepInspect, PolicyLayer, Burrow, ThirdLaw, Authensor—are all staking claims in agent policy enforcement, runtime controls, or MCP-based governance.

Everyone's using the same vocabulary: policy, governance, identity. Clawvisor's angle is per-call purpose verification with server-side credential injection, distinguishing it from token-level or model-level controls. Whether that's a meaningful technical difference or just positioning is something enterprises will sort out over the next year.

Timing and Trust

Digital illustration for article section "Timing and Trust" in "Clawvisor Launches Authorization Layer to Keep AI Agents in Check" - A conceptual, minimalist representation of enterprise anxiety and fragile trust in multi-agent orche...

The timing reflects broader enterprise anxiety—warranted, probably. A May 14 report from The Hacker News highlighted a fast-exploited vulnerability in PraisonAI, a multi-agent framework (CVE-2026-44338), underscoring just how wide the attack surface is around agent orchestration. Research published in March argued for path-dependent runtime evaluation as a necessity for safe agent deployments. TechRadar Pro, writing in April, noted that enterprise agents are moving into production workflows in 2026, but trust and security remain the gating factors.

Clawvisor is positioning itself at that gate. The product doesn't prevent agents from making mistakes or hallucinating bad decisions—nothing can, really—but it does create a verifiable boundary around what those agents can actually do with your data once they have it.

Whether that's enough to unlock broader enterprise adoption is an open question. One that will hinge on who adopts first, what the security audits reveal, and how the broader agent security ecosystem shakes out over the next twelve months. Levine's made his bet. Now he's waiting to see if enterprises are ready to make theirs.

More stories

  • DoD Solution raises $2M for AI drone navigation in war zones
  • DesignVerse raises $5.5M to automate enterprise software
  • YC-Backed Playabl.ai Launches AI Game Builder for No-Code Creators
  • Arctic Health Launches AI Platform to Automate Healthcare Credentialing
  • EnteroBiotix Raises $25M to Launch Largest Microbiome Trial for IBS
  • YC-Backed Framewise Health Turns Medical Records Into Patient Videos
fintech icon
climate-social-tech icon
saas icon
healthtech-biotech icon
ecommerce icon
media-entertainment icon
Loading...

About

Dreamwell AIContact UsOur Story

Articles

Product LaunchesInvestment NewsResearch & Innovation

founderland

We Use Cookies

We baked up some cookies – the digital kind. They help Draper run like a well-oiled mid-century machine. Some are essential to the experience, others help us tailor things to your taste. We promise, no crumbs on your blazer. Take a moment to choose what works for you.