Your agent can work. MarketingOS tells it what the work is for.

Architectural MarketingOS product installation in black metal, smoked glass and technical ivory modulesMarketingOS Today view of the synthetic Velunor Bikes showcase on desktopMarketingOS Today view of the synthetic Velunor Bikes showcase on a phone

MarketingOS brings marketing context into the agent runtime you already operate. OpenClaw receives a guided team with one orchestrator and eleven specialists. Hermes separates role logic from data access. Twelve skills and a team bundle carry the roles while a native plugin limits data access to exactly eleven tools. The managed Google connector is implemented as a review candidate for exactly eight incrementally selected GSC, GA4 and GTM capability groups, but it is not a generally available customer release.

01

What you already have

OpenClaw or Hermes takes care of models, compute, sessions, memory, tools and channels.

02

What MarketingOS adds

Business context, a guided OpenClaw team, separate Hermes role and data layers, and clear records for every local step.

Runs in your agent runtimeSiteOne includedHermes sees exactly eleven tools8 Google groups in review candidate

The difference

A capable agent is not yet a marketing team.

Ask a general agent for a marketing strategy and the answer will often sound reasonable. Tomorrow the conversation starts again. The offer that matters now, the voice of the brand, the last decision and the actual business goal are missing. MarketingOS keeps that connection intact.

01

Your business becomes the starting point

You capture the brand, offers, audiences, markets, goals and accountable people once. Every assignment begins with that version.

02

Each task reaches the right role

The orchestrator sends technical checks to Technical SEO, measurement questions to Measurement, and editorial work to Content and GEO.

03

Results keep their origin

Source, decision, local work and receipt stay connected. You can still understand later what actually happened.

One assignment in MarketingOS

A vague idea becomes a properly managed piece of work.

  1. 01

    Context

    You name the business goal

    Not simply more visibility, but qualified enquiries for a specific offer within a clear period.
  2. 02

    Orchestrator

    MarketingOS checks the context

    Offer, audience, website, market, KPI and owner are bound to the assignment. Missing information remains visible.
  3. 03

    Specialists

    The specialists take over

    SiteOne crawls the website. Technical SEO assesses its condition. GEO, Content, Demand and Measurement add their findings.
  4. 04

    Approval

    You receive a decision, not a wall of text

    The orchestrator combines the work and shows what to do next, which evidence supports it and what is still missing.
  5. 05

    Receipt

    The agent path remains a local draft

    Target system, content, risk and review step sit beside the decision. OpenClaw, Hermes and models receive no general external write path. Google actions run only inside the separate managed connector.
  6. 06

    Outcome

    The local step remains reviewable

    A receipt records what MarketingOS checked or created on the computer. Only a later approved real action and suitable measurements could support an impact claim.

Fictional product showcase

The connection stays visible, from the brief to approval.

Velunor Bikes is an invented company. These captures come from a reproducible product state with synthetic domains, goals and metrics. They demonstrate how MarketingOS works, not customer impact.

01 / Context

The team does not work from an empty chat.

Company, brand, audiences, offers, websites and markets share one version. Revision, hash and save state remain visible.
  • Five core areas
  • Revision 1
  • Hash and save state
MarketingOS Strategy and Context for the synthetic Velunor Bikes showcaseMarketingOS Strategy and Context for Velunor Bikes on mobile

02 / Goal

Activity starts with a business goal.

The goal carries the metrics. Source, time window, current value and target sit where the team reviews its priorities.
  • Fictional business goal
  • Synthetic source
  • Time window
  • Target
MarketingOS Goals and KPIs in the synthetic Velunor Bikes showcaseMobile MarketingOS Goals and KPIs view in the synthetic Velunor Bikes showcase

03 / Sources

GA4, GSC, Bing, website and crawl remain distinct.

The showcase presents five synthetic, separate source states. The displayed GA4 mapping is a disconnected fixture with an analytics.readonly label, not evidence of connector availability or a provider call. No green label becomes an invented conversion.
  • Synthetic GA4 fixture
  • Disconnected
  • GSC and Bing separated
  • SiteOne 2.5.1
MarketingOS Sources view with GA4, GSC, Bing, website and SiteOne in the synthetic Velunor Bikes showcaseMobile MarketingOS Sources view with an open GA4 property mapping in the synthetic Velunor Bikes showcase

04 / Decision

A decision remains bound to context and content.

The synthetic Technical SEO assignment shows its target system, business goal, risk, context revision and payload hash. This disconnected fixture reviews a local brief only and makes no provider call. It does not describe the availability of the separate managed Google review candidate.
  • Context revision
  • Risk 2
  • Payload hash
  • Fixture disconnected
MarketingOS approvals with a synthetic context bound Technical SEO assignmentMobile MarketingOS approval for the synthetic Velunor Bikes assignment

05 / Security

The interface also shows where MarketingOS deliberately stops.

The current capture keeps Direct, OpenClaw Secure and Hermes Secure visibly separate. Direct accepts trusted local work only. OpenClaw Secure is not approved for arbitrary untrusted input or production use. Hermes Secure is unavailable and never falls back silently to Direct. The image documents a synthetic product state, not a customer deployment.
  • Current UI state
  • Direct clearly bounded
  • Hermes Secure closed
  • Synthetic fixture disconnected
Current MarketingOS Security view in the synthetic Velunor Bikes showcaseCurrent mobile MarketingOS Security view in the synthetic Velunor Bikes showcase

06 / Outcome

The receipt is only half the truth.

The synthetic chain connects an action, receipt, evidence, observation and outcome. Its values demonstrate the product logic. They do not come from a real website or customer project.
  • Action and receipt
  • Synthetic comparison
  • Onpage Health 86 of 90
  • Confidence 40 percent
  • externalWrites 0
MarketingOS outcome view for the synthetic Velunor Bikes showcase with complete provenanceMobile MarketingOS outcome view with a synthetic comparison and complete provenance

Security that remains understandable

The agent may think. A Google write is never autonomous.

After authorization, three Google read capabilities may run. The five write capabilities require an exact target and payload preview, one-time approval, at most one provider attempt, a receipt, provider post-check and rollback where supported or explicit recovery. GTM version creation and publish remain separate approvals. Google tokens stay server-side in the managed connector and never reach the browser, Local Agent, OpenClaw, Hermes or a model. A dedicated reviewer deployment is undergoing live validation; Google review and general customer release remain open. General CMS, Bing and other external writes stay closed without their own connector contract.

READ

Inspect sources independently

The agent can collect findings and report missing access without changing the target system.

DECIDE

Make the proposal reviewable

You see the target, content and risk. A Google write then needs a one-time approval bound to that exact payload and never runs through the agent.

RECORD

Separate local work from impact

The receipt proves the local step. A later real action and observation would be required for an impact claim.

Good automation removes work. It does not remove your responsibility.

MarketingOS

A clear division of work

The runtime supplies the technology. MarketingOS runs the marketing operation.

Runtime

Where does it run?

Inside your existing OpenClaw or Hermes environment, with your model choice and compute.

Context

What is the work for?

For one business, its offers, audiences, goals, KPIs, voice and boundaries.

Team

Who does the work?

An orchestrator coordinates specialist roles and combines their results.

Record

What remains traceable?

Sources, decisions, local executions and later observations stay connected.

What the current source build contains

The first implemented MarketingOS addon scope focuses on SEO and GEO.

Implemented in the source build

  • A native OpenClaw orchestrator with eleven clearly separated marketing specialist roles
  • A Hermes role layer with twelve skills and a team bundle plus one native plugin with exactly eleven data tools
  • Business context, offers, audiences, goals and KPIs in one shared Control Surface
  • SiteOne as a fully integrated crawler for recurring onpage health checks and bounded external crawls
  • Separate website and Bing sources plus exactly eight incrementally selected GSC, GA4 and GTM groups in the managed Google review candidate
  • Approvals, receipts, light and dark interfaces, and a mobile view for the private network

Deliberately not promised yet

  • Social Media, CRM, Paid Performance, the Growth Bundle and Agency Pack will follow after the SEO/GEO addon
  • Hermes Direct is for trusted local work only. Hermes Secure is not available yet
  • OpenClaw Secure adds Docker protection but is not ready for untrusted or production use
  • The managed Google connector is undergoing live validation on dedicated reviewer infrastructure; Google review and general customer release remain open
  • There are no public customer claims yet for time saved, visibility, leads or revenue

The SEO/GEO addon

Four jobs that no longer disappear across separate chats.

The first addon connects technical site health, search data, editorial work and local decision briefs in one operating flow.

CRAWL

Read the website regularly

SiteOne checks technical foundations, changes and onpage health. A crawl describes the current state, not automatically its cause or impact.

SEARCH

Interpret search data

Search Console, GA4 and Bing remain separate sources. MarketingOS shows where a claim comes from and which data is still missing.

GEO

Improve answerability

Specialists review whether offers, entities, decision questions and evidence make sense to people and answer systems.

ACTION

Turn findings into work

A prioritised assignment gets a goal, accountable owner, approval and later review date instead of remaining an isolated recommendation.

Technical evidence

What has been tested appears in the Proof Ledger. Open boundaries sit beside it.

View the Proof Ledger

Before installation

The questions worth settling before the first real assignment.

01What exactly gets installed?
MarketingOS extends the runtime you already operate. OpenClaw receives the marketingos orchestrator, eleven named specialist agents and the native MarketingOS plugin. Hermes receives two separate layers. Twelve skills, twelve slash commands and one team bundle carry the role logic. A native plugin exposes exactly eleven bounded data tools. Models, compute and sessions remain in your runtime.
02Does MarketingOS need its own AI model?
No. MarketingOS does not prescribe a provider or model. The existing agent runtime supplies model access, compute, memory, schedules and channels. MarketingOS adds business context, specialist operating logic, SiteOne, evidence and the local Control Surface.
03Has the OpenClaw path actually been tested?
Yes, for the current source state. An isolated OpenClaw 2026.6.10 run installed the orchestrator and all eleven specialists and exercised every specialist route against a synthetic .example source. It produced eleven matching actions, receipts and evidence records. SiteOne was available to every route, 55 invalid variants were rejected and externalWrites remained 0. This proves the local source state, not a publicly signed customer package or customer impact.
04How complete is Hermes support?
Hermes Agent 0.18.2 was tested on two separate layers. The native plugin sees exactly eleven MarketingOS data tools and no general system tools. In addition, all eleven installed specialist roles ran through native delegate_task leaf sessions against a synthetic .example source. The run produced eleven matching actions, receipts and evidence records, rejected 55 invalid variants and kept externalWrites at 0. Hermes therefore reaches every specialist route, but does not have full OpenClaw runtime parity because the roles are not persistent named agents. Direct is not process containment. Hermes Secure stops with hermes-secure-whole-process-unavailable.
05May MarketingOS change my website on its own?
No. OpenClaw, Hermes and models receive no general website write access. The separate managed Google connector is implemented as a review candidate for exactly eight incrementally selected GSC, GA4 and GTM groups: after authorization, three reads may run; the five writes are never autonomous and require an exact target and payload preview, one-time approval, at most one provider attempt, a receipt, provider post-check and rollback where supported or explicit recovery. GTM version creation and publish remain separate approvals. Google tokens stay server-side and never reach the browser, Local Agent, OpenClaw, Hermes or a model. A dedicated reviewer deployment is undergoing live validation; Google review and general customer release remain open. General CMS, Bing and other writes stay closed without their own connector contract.
06Are OpenClaw and Hermes safe environments for arbitrary input?
No. Direct accepts trusted local workloads only and is not a boundary against a compromised host. OpenClaw Secure adds a Docker protection layer with no network, a read only filesystem and dropped Linux capabilities. Complete workload containment is not yet proven, so the profile is not ready for untrusted or production use. Hermes Secure is unavailable and never falls back silently to Direct. Thirteen adversarial tests cover the Audit Witness. The dedicated reviewer deployment runs it under a second operating system identity; that evidence applies only to the reviewer host and is not customer release evidence.
07When is an outcome actually proven?
A receipt proves technical execution, not impact. Impact needs a baseline, an action that actually ran, a suitable measurement window and later data from the right source. Every public example uses invented companies with .example domains only.

Already using OpenClaw? You do not need another SaaS. You need marketing context.

Start with one business, one offer and one clear goal. MarketingOS turns them into the first bounded assignment for your agent team.

See the installation