enterprise data management

Give your AI agents room to act without handing over the keys.

In a groundbreaking partnership, NanoCo and Vercel have unveiled NanoClaw 2.0, a transformative framework that enhances the safety and usability of autonomous AI agents across 15 messaging platforms. This innovation…

4 min readVentureBeat
Give your AI agents room to act without handing over the keys.

For the past year, the choice facing anyone who wanted to use an autonomous AI agent has been stark and unsatisfying: you could keep it on a leash so short it was useless, or you could hand over the keys and pray. Neither option was acceptable for serious work. The announcement from NanoCo, alongside Vercel and OneCLI, finally breaks that deadlock. By moving approval authority out of the model's hands and into the infrastructure itself, NanoClaw 2.0 gives you the productivity of an agent that can actually act without pretending it can be trusted not to make a catastrophic mistake. That is not a minor technical tweak. It is the difference between hiring a capable but unproven assistant and hiring one who physically cannot open the safe without you.

The practical shift here is that the agent no longer asks for permission because it is polite. It asks because the request never reaches the outside world until you approve it. The OneCLI gateway sits between the agent and your APIs, and it enforces your policies at the point of execution. If the agent tries to send an email, delete a file, or spin up a cloud instance, the action is paused, a native card appears in Slack or WhatsApp, and a single tap from you either lets it through or kills it. This is not a softer version of the old sandbox. It is a structural guarantee that the agent's reach is limited to what you have explicitly allowed, and that every sensitive action leaves a trail you can audit. For IT teams that have spent months blocking agent adoption over credential risk, that is the missing piece.

What makes this workable, rather than just secure on paper, is the integration with Vercel's Chat SDK. Approval systems are only useful if people actually use them, and people will not use them if they require a separate dashboard or a command line. By rendering approval requests as rich, native cards inside the messaging apps where teams already live, NanoClaw turns oversight from a chore into a reflex. The same interface that lets you approve a calendar invite now lets you approve a payment batch or a production deployment. That is not a gimmick. It is the difference between a control that gets ignored and one that becomes part of the daily rhythm of work. For finance teams, DevOps engineers, and anyone else handling high-stakes writes, the friction of approval drops to nearly zero without reducing the rigor.

The deeper point is that this model reframes what an AI agent is for. You are not betting on a model's judgment to handle your most sensitive operations. You are giving it the ability to propose, to draft, to prepare, and to execute only the steps you have pre-approved. That is a far more honest and useful division of labor. The agent becomes a junior staffer who can triage your inbox, draft responses, and prepare a cloud migration plan, but who has to knock on your door before hitting send on anything that matters. For organizations that have been waiting for a reason to trust autonomous systems, this is the reason. The infrastructure now enforces the trust you already wanted to place. The rest is just a matter of deciding where to draw the line, and NanoClaw 2.0 gives you the tools to draw it precisely.

From VentureBeat

For the past year, early adopters of autonomous AI agents have been forced to play a murky game of chance: keep the agent in a useless sandbox or give it the keys to the kingdom and hope it doesn't hallucinate a catastrophic "delete all" command.

To unlock the true utility of an agent—scheduling meetings, triaging emails, or managing cloud infrastructure—users have had to grant these models raw API keys and broad permissions, raising the risk of their systems being disrupted by an accidental agent mistake.

Read the original at VentureBeat