governance-policies
AxonFlow Governance Policies for OpenClaw
Use when setting up or hardening an OpenClaw deployment with AxonFlow governance. This skill covers self-hosting AxonFlow, plugin installation, policy configuration, and risk mitigation.
AxonFlow is self-hosted. It runs on your infrastructure via Docker Compose. All policy evaluation, PII detection, and audit logging happens on your own AxonFlow instance. Credentials are only needed for enterprise mode — community mode requires no auth. An anonymous startup ping (version and basic deployment info) is sent by default for local, self-hosted, and remote deployments. Opt out globally with DO_NOT_TRACK=1 or AXONFLOW_TELEMETRY=off.
Self-Host AxonFlow
AxonFlow runs locally via Docker Compose. No LLM provider keys required — OpenClaw handles all LLM calls, AxonFlow only enforces policies and records audit trails.
Prerequisites: Docker Engine or Desktop, Docker Compose v2, 4 GB RAM, 10 GB disk.
Quick start: Clone the AxonFlow community repo, copy .env.example to .env, and run docker compose up -d. The Agent starts on port 8080 — all SDK and plugin traffic goes through this port.
Full setup instructions: Self-Hosted Deployment Guide
Install the Plugin
Install via OpenClaw's plugin manager and configure in your OpenClaw config with your AxonFlow endpoint, credentials, high-risk tool list, and optional requestTimeoutMs override. Set onError: block for production (fail-closed) or allow for development (fail-open). Increase requestTimeoutMs above the default 8000ms when AxonFlow is running remotely or behind a slow VPN.