Roadmap

From an implemented SEO/GEO scope to a defensible agent pack.

Business context, the Control Surface, SiteOne, the Hermes role and plugin layers, and the OpenClaw agent structure are built. All eleven specialist routes are verified in both runtimes against the current source. The installed Product Manager understands workspace binding and ownership. A final signed customer artifact and defensible isolation for untrusted workloads remain open.

BUILT

One installed product path for both runtimes

The later customer path verifies the Acquisition Receipt first, installs MarketingOS through Install-MarketingOS, and then attaches OpenClaw or Hermes with exact host paths through the stable MarketingOS-Manage launcher. SiteOne and runtime mutation form one transaction.

DONE

Versioned business context and Control Surface

Company, brand, offer, audiences, markets, goals and KPIs live in a versioned local workspace. New actions bind revision and hash. Light mode, dark mode and independent mobile layouts are implemented.

DONE

Separate Hermes role logic from data tools

Twelve skills, slash commands and the team bundle keep the role layer. One native plugin exposes exactly eleven data tools. The real runtime inspection proves the tool surface and controlled uninstall.

DONE

Verify every specialist route in the current source

OpenClaw executes eleven named specialists. The dedicated local Hermes 0.18.2 proof build with one deliberately carried compatibility commit executes eleven installed roles through native delegate_task leaf sessions. Its exact identity is recorded in the hash bound receipt. Both runs bind context, source, action, receipt, evidence and SiteOne with externalWrites at 0.

NEXT

Carry the source record into a signed release

The tool bridge, runtime identity, workspace binding, ownership markers, SiteOne and all eleven specialist routes must be verified together from the final signed package on a fresh machine.

DONE

Connect Action, Observation and Outcome

The API and Control Surface expose complete provenance from a verified action through its receipt and observation to the outcome. The synthetic example.com run confirms HTTP 200 and deliberately remains inconclusive about business impact.

NEXT

Prove the current Windows release lifecycle

A newly built and signed customer package must complete installation, start, status, stop and removal on a fresh Windows machine. Existing automated tests in isolated directories are not sufficient for that claim.

NEXT

Prove isolation and more platforms

OpenClaw Secure needs complete workload evidence. Hermes Secure needs a wrapper around the whole process. The separate Witness evidence from the reviewer host must be established again for each later customer target. macOS and Linux need real release lifecycle runs.

NEXT GATE

Prove the managed Google connector live

The contract for exactly eight incremental GSC, GA4 and GTM groups is being validated on dedicated reviewer infrastructure. Real provider canaries, reviewer journeys and Google review must complete before any customer release. Each of the five writes needs an exact preview, one-time approval, at most one attempt, a receipt, provider post-check and rollback or recovery; GTM version and publish remain separate.

AFTER

More safe live connectors

General CMS, Bing and other external writes stay closed until each path has its own connector contract. General write access for OpenClaw, Hermes or a model is not planned.

PILOT

Derive claims from real customer runs

Pilot partners bring a domain, sources, accountable owners and a recurring marketing workflow. We measure handover quality, cycle time, errors, executions and later outcomes. Public product claims will come only from those observations.

Continue

Start with the bounded alpha path

The OpenClaw guide explains the Local Agent, workspace binding, dry run and open revalidation.

Open the OpenClaw setup