Company profile · 3 min read
Clawvisor: task-scoped authorization for AI agents
Clawvisor gives agents need-to-know access to connected apps, with per-task policy checks, credential isolation and audit trails.
Published · Updated
Clawvisor is trying to make the unit of trust an agent task, not a standing credential.
What it does
The current Clawvisor homepage describes a gateway between agents and services such as Gmail, Slack and Google Drive. A user approves a task once; Clawvisor checks each request against that task, injects credentials without exposing them to the agent, records the decision and revokes access when the work ends.
That is a more useful frame than “AI permissions.” The problem is that OAuth scopes and connected tools are often broader than the job the agent is doing. Clawvisor’s public examples contrast a calendar briefing with an agent that tries to read years of calendar history, and a task-specific boundary with access to every tool a server exposes.
Why I’d look closer
The pricing page gives the product a concrete operating model. Free includes 1,000 protected calls per month. Pro is listed at $120/month with 20,000 calls, extended log retention and priority support. Additional request packs are listed at $0.025 per call before volume discounts. Self-hosting is described as free under the Elastic License 2.0, with the customer operating its own infrastructure. Those terms are published by Clawvisor.
Eric Levine’s public profile is relevant: the company says he previously co-founded Berbix, later acquired by Socure, and led trust-and-safety engineering at Airbnb. That does not certify Clawvisor’s controls, but it explains why the product starts with containment, credential isolation, risk scoring and audit history.
What I’d ask
I would ask how a task is written, how scope drift is detected, what the audit record contains, how self-hosted upgrades work, and what happens when a request pack runs out. The product’s claim is strongest when the team can show the approved purpose, requested action, injected credential boundary and final decision in one trace.
My editorial take
Shortlist Clawvisor if your agents need real accounts but your team is not willing to grant them broad standing access. It is less useful for a toy agent with no sensitive tools. The key decision is whether task-level policy is enough of a control surface to justify another gateway in the stack.
Quick facts
| Field | Sourced detail |
|---|---|
| Product | Task-scoped agent authorization, credential vault and audit layer |
| Buyer | Teams connecting agents to sensitive business tools |
| Pricing | Free 1,000 calls/month; Pro $120/month; self-hosted option stated |
| Security posture | Company says credentials stay in a vault and requests are policy-checked |
| Main question | Can the task policy express your real approval boundary? |
Sources checked
| Source | Checked |
|---|---|
| YC company profile | 2026-09-19 |
| Clawvisor homepage | 2026-09-19 |
| Clawvisor pricing | 2026-09-19 |
| Clawvisor about | 2026-09-19 |
Cohort context
Clawvisor is listed in Spring 2026. In our 2026-09-18 directory snapshot, 112 of 193 listed companies in that cohort have YC’s primary industry label B2B (58.0%). This is a current-directory comparison, not an original intake count or a performance ranking. Nine-cohort dataset.
Public website snapshot
Observed 2026-09-19T16:16:10.193Z in raw homepage HTML. This records visible metadata and advertised links, not agent execution or product quality.
| Signal | Homepage observation |
|---|---|
| Product description metadata | Observed |
| Canonical link | Observed |
| H1 or H2 heading | Observed |
| Typed structured data | Observed |
| Docs/developer link | Not observed in this response |
| Pricing link | Observed |
| llms.txt link | Not observed in this response |
| Markdown alternate | Not observed in this response |
Public observations · Collection method. Missing links here do not establish that a capability or file is absent elsewhere.
