Skip to content
DnsLister Forum

Where domain hunters compare notes

Client onboarding automated through OpenClaw agents in a self-hosted CRM I built

I've been a developer for 30 years, and for the last stretch I've had OpenClaw running as the agent layer under a CRM I built called OpenOcti. Seeing this week's "is there ever going to be a stable branch" threads made me want to write up the actual workflow, since it runs on a pinned gateway and has been boring in the good way.

The workflow: OpenOcti ships six starter agents. When a new client signs up, I tell Maggie, the office coordinator agent, to onboard them. She collects the domain and company details, sets up the CRM account and a client portal, and gets the NDA out for e-signature — all routed through OpenClaw's tool-calling, with the actual writes and sends gated behind a human approval step, not just the model declaring itself done. When something breaks on the OpenClaw side, Craig is the troubleshooting agent.

Setup is three commands:

git clone https://github.com/carlucci001/open-octi.git openocti cd openocti && cp .env.example .env docker compose up -d --build 

That brings up OpenOcti and an OpenClaw gateway as a second container. It runs with no AI provider configured; one Anthropic, OpenAI, Gemini, or OpenRouter key turns the agents on. The key is encrypted in the app and handed to OpenClaw at runtime, so adding or swapping a provider doesn't restart the gateway container — that one decision saved me a lot of debugging time.

Three things I learned building on top of it. I pin the bundled OpenClaw to an extended-stable release rather than 2.0 — a fixed target beats chasing a moving one, and that's a tradeoff, not a shot at the project. Giving each agent its own named-tool allowlist instead of one shared dispatcher mattered once a security review went looking for ways around it. And approval has to come from a real human workflow — early on I had a build that trusted the model's own claim that something was approved, which is not a bug you want live.

On security: 1.1.2 generates unique machine secrets on first boot instead of shipping a default, verifies Twilio webhook signatures, and hardens against SSRF on anything that fetches external URLs. SECURITY.md is in the repo.

Disclosure: this is my own project, AGPL-3.0, github.com/carlucci001/open-octi.

Source: r/better_claw · by /u/PleasantBid4665

Leave a Reply

Your email address will not be published. Required fields are marked *