First Class Modules
GoClaw
Adds a dedicated virtual assistant to a user account that researches, summarizes, classifies, drafts, and proposes work without ever receiving more access or action authority than that user.
module.goclawUse GoClaw as the virtual assistant attached to each enabled user account. It helps that person work their permitted Inbox items and business records, but it is not a privileged service account and cannot step outside the user's existing authorization boundary.
The bundled renderer key is module.goclaw. First-class means BuildWithHQ supplies a native, typed, secured runtime experience inside normal app provisioning and the signed-in user's existing permissions.
What it does
Adds a dedicated virtual assistant to a user account that researches, summarizes, classifies, drafts, and proposes work without ever receiving more access or action authority than that user.
Key capabilities
- Read only records, fields, locations, and Inbox context the represented user may read—and only when AI access is also allowed.
- Research, classify, summarize, draft replies, and prepare structured next actions.
- Create suggestion batches whose evidence, risk, confidence, required permission, and inputs can be reviewed.
- Route material or customer-facing actions through configured policy or human approval before deterministic execution.
- Respect action budgets, leases, retries, stale-context fences, and idempotent execution.
- Record attribution, approval/refusal, tool/action evidence, results, failures, ratings, and correlation history.
Surface: Per-user account assistant. GoClaw is attached to the represented user and remains inside that user's tenant, DataRole, location, record, field, action, and AI-read boundaries.
Common uses
- Triage and response preparation for permitted Universal Inbox work.
- Account, case, project, support, or operations research and follow-up suggestions.
- A personal daily assistant that reduces preparation work while the user retains decision authority.
How it connects
GoClaw claims authorized Inbox work, prepares AiActionSuggestionBatches and AiActionSuggestions, and—after current permission/policy/approval checks—creates AiActionExecutions for deterministic executors. It uses native records and the secured AI retrieval plane rather than maintaining a shadow copy of the user's data.
Where applicable, its records use the universal RecordId conventions so they can participate in secured relationships, activity history, favorites, dynamic fields, notifications, Inbox attention, and global search without copying the source record.
Security and data boundary
GoClaw operates on behalf of one user. Its effective access is the intersection of that user's tenant, DataRole, record, field, location, and action permissions with AI-specific CanAiReadRecords, secure-field exclusions, tool policy, quotas, approval policy, and the current source/Inbox activity version. The result can be narrower than the user's normal access, never wider.
- The authenticated service derives the SaaS app, tenant account, user, DataRole, and location scope; browser identifiers are never authorization proof.
- The page editor composes React components with validated data bindings. Those bindings call typed runtime APIs, whose application services execute reviewed stored procedures.
- List, search, detail, relation, activity, favorite, and write operations reapply their required server-side permissions.
Add it to an app
- Enable the assistant for the intended user account and bind it to that user—do not create a wider shared service identity.
- Select the Inbox queues/channels and record contexts it may prepare, while preserving all normal user and AI-read checks.
- Configure reviewed action templates, required permissions, authority/approval policy, quotas, and exact behavior/harness versions.
- Begin with research and drafts; add deterministic actions one at a time with safe error, retry, and idempotency behavior.
- Test restricted records, secure fields, another location, stale Inbox activity, refused approval, quota exhaustion, and duplicate execution before widening use.
Copy/paste the native review surface
GoClaw remains an account-level tenant capability, and the same secured approval queue used by the top bar is now also registered as the real module.goclaw page block. Use the block in a native Builder page, or use the same reviewed React client integration in a custom/headless shell:
import {
GoClawApprovalQueue,
createApprovalQueueHttpClient,
} from "@buildwithhq/universal-inbox";
import { getTenantAccessToken, tenantSessionFetch } from "./api";
import { ensureCsrfToken } from "./webSecurity";
const goClawReviewClient = createApprovalQueueHttpClient({
accessToken: getTenantAccessToken,
csrfToken: ensureCsrfToken,
fetchImplementation: tenantSessionFetch,
});
type GoClawReviewSurfaceProps = {
readonly initialInboxItemId?: string;
readonly onClose?: () => void;
readonly onOpenInbox?: (inboxItemId: string) => void;
};
export function GoClawReviewSurface(props: GoClawReviewSurfaceProps) {
return <GoClawApprovalQueue client={goClawReviewClient} {...props} />;
}
Place this at the account shell level, such as an AI review top-bar action or a protected route. The package includes its production component CSS and provides the complete review, edit, approve, reject, take-over, retry, stale-context, and source-Inbox behavior.
Custom unstyled approval queue
If you own the presentation, keep the official ApprovalQueueClient and render only the secured rows it returns. This bounded starter loads at most 100 review batches and makes stale lineage visible:
import { useEffect, useState } from "react";
import type {
ApprovalQueueClient,
ApprovalQueueItem,
} from "@buildwithhq/universal-inbox";
type UnstyledGoClawQueueProps = {
readonly client: ApprovalQueueClient;
readonly onSelect: (item: ApprovalQueueItem) => void;
};
const title = (item: ApprovalQueueItem) =>
item.subject?.trim() || item.summary?.trim() || item.sourceType;
export function UnstyledGoClawQueue({
client,
onSelect,
}: UnstyledGoClawQueueProps) {
const [items, setItems] = useState<readonly ApprovalQueueItem[]>([]);
const [loading, setLoading] = useState(true);
const [error, setError] = useState<string | null>(null);
useEffect(() => {
const request = new AbortController();
setLoading(true);
setError(null);
client.list(100, request.signal)
.then(setItems)
.catch((failure: unknown) => {
if (!(failure instanceof DOMException && failure.name === "AbortError")) {
setItems([]);
setError(failure instanceof Error ? failure.message : "Approval work is unavailable.");
}
})
.finally(() => {
if (!request.signal.aborted) setLoading(false);
});
return () => request.abort();
}, [client]);
return (
<section className="custom-goclaw" aria-busy={loading}>
<header>
<p>GoClaw</p>
<h1>Approval work</h1>
</header>
{loading && <p role="status">Loading approval work...</p>}
{error && <p role="alert">{error}</p>}
{!loading && !error && items.length === 0 && <p>No secured approval work is available.</p>}
<ol>
{items.map((item) => (
<li key={item.suggestionBatchId} data-stale={item.isStale || undefined}>
<button type="button" onClick={() => onSelect(item)}>
<strong>{title(item)}</strong>
<span>{item.batchStatus} / {item.riskLevel || "Unrated"} risk</span>
<span>{item.summary || item.previewText || "Prepared AI work"}</span>
<small>
Based on activity {item.basedOnActivityVersion};
current activity {item.activityVersion}
{item.isStale ? " / stale - prepare again" : ""}
</small>
</button>
</li>
))}
</ol>
</section>
);
}
Review and disposition helpers
A custom detail view can edit only the reviewed draft/action inputs and then call the typed client. It never supplies approver, tenant, role, location, or database identity:
import type {
ApprovalQueueClient,
ApprovalQueueItem,
} from "@buildwithhq/universal-inbox";
type ReviewedActionEdit = {
readonly aiActionSuggestionId: string;
readonly suggestedInput: Record<string, unknown>;
};
type ReviewedApproval = {
readonly reviewNotes?: string;
readonly editedDraftResponse?: Record<string, unknown>;
readonly actionEdits?: readonly ReviewedActionEdit[];
};
export async function approveReviewedWork(
client: ApprovalQueueClient,
item: ApprovalQueueItem,
reviewed: ReviewedApproval = {},
) {
if (item.isStale || item.activityVersion !== item.basedOnActivityVersion) {
throw new Error("Inbox activity changed. Re-run GoClaw before approving.");
}
return client.approve(item.suggestionBatchId, reviewed);
}
export const rejectPreparedWork = (
client: ApprovalQueueClient,
item: ApprovalQueueItem,
notes?: string,
) => client.reject(item.suggestionBatchId, notes);
export const takeOverPreparedWork = (
client: ApprovalQueueClient,
item: ApprovalQueueItem,
notes?: string,
) => client.takeOver(item.suggestionBatchId, notes);
export const requestFreshPreparation = (
client: ApprovalQueueClient,
item: ApprovalQueueItem,
notes?: string,
) => client.retry(item.suggestionBatchId, notes);
The browser check is helpful feedback, but the server is authoritative: it rechecks current source access, CanAiReadRecords, inbox.approve, every proposed action's permission, reviewed action schemas, and ActivityVersion inside the transaction. After an ambiguous network failure, reload the queue before repeating a decision.
Optional starter styling
Use this only with the custom queue. The native component already imports its own production styles:
.custom-goclaw { width: 100%; max-width: none; }
.custom-goclaw > header { margin-bottom: 1rem; }
.custom-goclaw > header > * { margin-block: .25rem; }
.custom-goclaw ol {
display: grid;
gap: .75rem;
list-style: none;
margin: 0;
padding: 0;
}
.custom-goclaw li {
border: 1px solid var(--line, #d8dee8);
border-radius: .75rem;
}
.custom-goclaw li[data-stale="true"] {
border-color: var(--warning, #b86b00);
}
.custom-goclaw button {
background: var(--surface, #fff);
border: 0;
border-radius: inherit;
color: inherit;
display: grid;
gap: .35rem;
padding: 1rem;
text-align: left;
width: 100%;
}
.custom-goclaw button:hover,
.custom-goclaw button:focus-visible {
background: var(--surface-muted, #f7f9fc);
}
Exact browser and worker path
| Purpose | Method and route | Important contract |
|---|---|---|
| List review work | GET /api/goclaw/approvals?top=100 | Returns at most 500 currently authorized batches; the native UI requests 100 |
| Approve reviewed work | POST /api/goclaw/approvals/{suggestionBatchId}/approve | Optional review notes, draft edit, and at most 20 reviewed action-input edits |
| Reject proposal | POST /api/goclaw/approvals/{suggestionBatchId}/reject | Dismisses pending suggestions and records the human decision |
| Human take-over | POST /api/goclaw/approvals/{suggestionBatchId}/take-over | Returns ownership to the current authorized reviewer |
| Prepare again | POST /api/goclaw/approvals/{suggestionBatchId}/retry | Invalidates the old batch and queues a fresh fenced planning pass |
| Open source context | GET /api/inbox/items/{inboxItemId} | Loads the secured native source projection through Universal Inbox |
| Set authority policy | PUT /api/goclaw/agents/{goClawAgentId}/authority | Human account owner with inbox.approve; ResearchOnly, ApprovalRequired, or PolicyAuthorizedLowRisk |
The browser never creates arbitrary actions or writes directly to GoClaw tables. Inbound work first becomes a Universal Inbox item. A fenced worker claim loads authorized context, uses the centrally routed model capability, and persists canonical AiActionSuggestionBatches plus AiActionSuggestions. Approval creates AiActionExecutions; deterministic workers lease GoClawActionQueue work, recheck lineage and permission, and record the result. Outbound communication still flows through the communications worker.
The current deterministic action templates are SendConversationReply, CreateFollowup, LinkRecords, PostMessage, and UpdateRecordStatus. Add a new action only with a reviewed input schema, required permission, deterministic executor, idempotency/recovery behavior, and tests.
GoClaw work and its audit lineage live in the routed SaaS database; secured retrieval uses that SaaS's vector database, while the one central Platform Orchestration database resolves model endpoints and aggregates health. The client selects none of those databases.
See GoClaw in depth for the authority model, the React component catalog for the generated native and headless starters, or the headless application guide when the React application lives outside the BuildWithHQ tenant shell.
Build a professional GoClaw dashboard
These six registry-backed presentation blocks let a designer turn the secured GoClaw API into a complete admin page without writing a chart, grid, status badge, empty state, or timeline from scratch. The normal operational API begins at /api/goclaw/approvals; a dashboard-wide count or trend should come from a separate purpose-built presentation binding so the browser never downloads a broad record population to calculate one number.
The ZIP contains this feature's fictional design composition at pages/first-class/goclaw-sample.json, its executable authenticated page at pages/first-class/goclaw-live.json, and the catalog-driven FirstClassPresentationGallery.tsx. Use the sample only for visual design. The live page calls the real native API and reviewed stored procedures under the signed-in user's scope.
| Payload kind | Runtime block | Useful GoClaw projection |
|---|---|---|
metric-set | core.metric-strip | Review backlog, stale work, decisions, and execution success |
entity-list | core.entity-list | Current suggestion batches with source and risk |
progress-list | core.progress-list | Distribution by risk, state, or action outcome |
series-chart | core.series-chart | Prepared, approved, rejected, and executed work over time |
data-grid | core.presentation-grid | One bounded page of reviewable batches |
timeline | core.timeline | Preparation, human disposition, retry, execution, and failure evidence |
Copy/paste design preview: all six blocks
This complete static page document renders immediately in Puck/Monaco and is useful while styling a template. Its names, counts, dates, and IDs are fictional design fixtures; static preview values are not live tenant facts.
Copy the complete six-block page JSON
{
"blocks": [
{
"_id": "goclaw-metrics",
"_type": "core.metric-strip",
"props": {
"title": "GoClaw review center",
"asOfUtc": "2026-09-04T18:00:00Z",
"items": [
{
"key": "review",
"label": "Awaiting review",
"value": 17,
"format": "number",
"tone": "warning"
},
{
"key": "stale",
"label": "Stale batches",
"value": 2,
"format": "number",
"tone": "danger"
},
{
"key": "approved",
"label": "Approved today",
"value": 26,
"format": "number",
"tone": "success"
},
{
"key": "success",
"label": "Execution success",
"value": 97.4,
"format": "percent",
"tone": "primary"
}
]
},
"children": []
},
{
"_id": "goclaw-recent",
"_type": "core.entity-list",
"props": {
"title": "Prepared work",
"hasMore": true,
"items": [
{
"id": "goclaw-sample-1",
"recordId": "goclaw-record-1",
"primary": "Draft reply for SUP-000482",
"secondary": "Universal Inbox - low risk",
"status": {
"key": "approval-required",
"label": "Approval required",
"tone": "warning"
},
"trailing": "3 actions"
},
{
"id": "goclaw-sample-2",
"recordId": "goclaw-record-2",
"primary": "Draft reply for SUP-000482 - Follow-up",
"secondary": "Universal Inbox - low risk - Updated two hours ago by the assigned owner",
"status": {
"key": "in-review",
"label": "In review",
"tone": "primary"
},
"trailing": "Today"
},
{
"id": "goclaw-sample-3",
"recordId": "goclaw-record-3",
"primary": "Draft reply for SUP-000482 - West region",
"secondary": "Universal Inbox - low risk - Related to three visible records at the Reno location",
"status": {
"key": "on-track",
"label": "On track",
"tone": "success"
},
"trailing": "3 related"
},
{
"id": "goclaw-sample-4",
"recordId": "goclaw-record-4",
"primary": "Draft reply for SUP-000482 - Customer response",
"secondary": "Universal Inbox - low risk - Waiting for an external response before work can continue",
"status": {
"key": "scheduled",
"label": "Scheduled",
"tone": "warning"
},
"trailing": "Tomorrow"
},
{
"id": "goclaw-sample-5",
"recordId": "goclaw-record-5",
"primary": "Draft reply for SUP-000482 - Regional operations review with a deliberately long title",
"secondary": "Universal Inbox - low risk - This deliberately longer supporting line verifies wrapping, truncation, responsive spacing, and dense dashboard behavior.",
"status": {
"key": "needs-attention",
"label": "Needs attention",
"tone": "danger"
},
"trailing": "Review",
"tertiary": "Long-content fixture: verify keyboard focus, wrapping, narrow columns, and mobile overflow before publishing."
},
{
"id": "goclaw-sample-6",
"recordId": "goclaw-record-6",
"primary": "Draft reply for SUP-000482 - Completed preview",
"secondary": "Universal Inbox - low risk - Closed after review with its related evidence retained",
"status": {
"key": "complete",
"label": "Complete",
"tone": "success"
},
"trailing": "Closed"
}
]
},
"children": []
},
{
"_id": "goclaw-bystatus",
"_type": "core.progress-list",
"props": {
"title": "Review queue by risk",
"items": [
{
"key": "low",
"label": "Low risk",
"value": 11,
"maximum": 17,
"displayValue": "11",
"tone": "success",
"status": {
"key": "low",
"label": "Low risk",
"tone": "success"
}
},
{
"key": "medium",
"label": "Medium risk",
"value": 5,
"maximum": 17,
"displayValue": "5",
"tone": "warning",
"status": {
"key": "medium",
"label": "Medium risk",
"tone": "warning"
}
},
{
"key": "high",
"label": "High risk",
"value": 1,
"maximum": 17,
"displayValue": "1",
"tone": "danger",
"status": {
"key": "high",
"label": "High risk",
"tone": "danger"
}
}
]
},
"children": []
},
{
"_id": "goclaw-trend",
"_type": "core.series-chart",
"props": {
"title": "Preparation and execution",
"variant": "bar",
"defaultPeriodKey": "d7",
"periods": [
{
"key": "d7",
"label": "7 days",
"labels": [
"Fri",
"Sat",
"Sun",
"Mon",
"Tue",
"Wed",
"Thu"
],
"series": [
{
"key": "primary",
"label": "Prepared",
"tone": "primary",
"values": [
8,
5,
4,
12,
15,
11,
17
]
},
{
"key": "secondary",
"label": "Executed",
"tone": "success",
"values": [
6,
4,
3,
9,
12,
10,
14
]
}
]
}
]
},
"children": []
},
{
"_id": "goclaw-table",
"_type": "core.presentation-grid",
"props": {
"title": "Authorized suggestion batches",
"columns": [
{
"key": "work",
"label": "Prepared work",
"type": "text",
"align": "left"
},
{
"key": "source",
"label": "Source",
"type": "text",
"align": "left"
},
{
"key": "risk",
"label": "Risk",
"type": "status",
"align": "left"
},
{
"key": "status",
"label": "State",
"type": "status",
"align": "left"
},
{
"key": "updated",
"label": "Updated",
"type": "date",
"align": "left"
}
],
"rows": [
{
"id": "goclaw-row-1",
"recordId": "goclaw-record-1",
"cells": {
"work": "Draft reply for SUP-000482",
"source": "Universal Inbox",
"risk": {
"key": "low",
"label": "Low",
"tone": "success"
},
"status": {
"key": "pending",
"label": "Awaiting review",
"tone": "warning"
},
"updated": "2026-09-04T17:42:00Z"
}
},
{
"id": "goclaw-row-2",
"recordId": "goclaw-record-2",
"cells": {
"work": "Draft reply for SUP-000482 - Follow-up",
"source": "Universal Inbox",
"risk": {
"key": "in-review",
"label": "In review",
"tone": "primary"
},
"status": {
"key": "in-review",
"label": "In review",
"tone": "primary"
},
"updated": "2026-09-04T15:42:00Z"
}
},
{
"id": "goclaw-row-3",
"recordId": "goclaw-record-3",
"cells": {
"work": "Draft reply for SUP-000482 - West region",
"source": "Universal Inbox",
"risk": {
"key": "on-track",
"label": "On track",
"tone": "success"
},
"status": {
"key": "on-track",
"label": "On track",
"tone": "success"
},
"updated": "2026-09-04T12:18:00Z"
}
},
{
"id": "goclaw-row-4",
"recordId": "goclaw-record-4",
"cells": {
"work": "Draft reply for SUP-000482 - Customer response",
"source": "Universal Inbox",
"risk": {
"key": "scheduled",
"label": "Scheduled",
"tone": "warning"
},
"status": {
"key": "scheduled",
"label": "Scheduled",
"tone": "warning"
},
"updated": "2026-09-03T21:07:00Z"
}
},
{
"id": "goclaw-row-5",
"recordId": "goclaw-record-5",
"cells": {
"work": "Draft reply for SUP-000482 - Regional operations review with a deliberately long title",
"source": "Universal Inbox - This deliberately longer supporting line verifies wrapping, truncation, responsive spacing, and dense dashboard behavior.",
"risk": {
"key": "needs-attention",
"label": "Needs attention",
"tone": "danger"
},
"status": {
"key": "needs-attention",
"label": "Needs attention",
"tone": "danger"
},
"updated": "2026-09-03T16:31:00Z"
}
},
{
"id": "goclaw-row-6",
"recordId": "goclaw-record-6",
"cells": {
"work": "Draft reply for SUP-000482 - Completed preview",
"source": "Universal Inbox",
"risk": {
"key": "complete",
"label": "Complete",
"tone": "success"
},
"status": {
"key": "complete",
"label": "Complete",
"tone": "success"
},
"updated": "2026-09-02T19:14:00Z"
}
}
],
"page": {
"pageNumber": 1,
"pageSize": 6,
"totalRecords": 17,
"totalIsExact": true,
"hasMore": true
}
},
"children": []
},
{
"_id": "goclaw-timeline",
"_type": "core.timeline",
"props": {
"title": "GoClaw decisions and outcomes",
"hasMore": true,
"items": [
{
"id": "goclaw-event-1",
"recordId": "goclaw-record-1",
"occurredUtc": "2026-09-04T17:58:00Z",
"title": "Suggestion batch prepared",
"description": "Evidence and three proposed actions are ready for review.",
"actor": "GoClaw",
"tone": "primary"
},
{
"id": "goclaw-event-2",
"recordId": "goclaw-record-2",
"occurredUtc": "2026-09-04T15:42:00Z",
"title": "Suggestion batch prepared - Follow-up",
"description": "Evidence and three proposed actions are ready for review. Updated two hours ago by the assigned owner.",
"actor": "Avery Patel",
"tone": "primary"
},
{
"id": "goclaw-event-3",
"recordId": "goclaw-record-3",
"occurredUtc": "2026-09-04T12:18:00Z",
"title": "Suggestion batch prepared - West region",
"description": "Evidence and three proposed actions are ready for review. Related to three visible records at the Reno location.",
"actor": "Sam Rivera",
"tone": "success"
},
{
"id": "goclaw-event-4",
"recordId": "goclaw-record-4",
"occurredUtc": "2026-09-03T21:07:00Z",
"title": "Suggestion batch prepared - Customer response",
"description": "Evidence and three proposed actions are ready for review. Waiting for an external response before work can continue.",
"actor": "Maya Chen",
"tone": "warning"
},
{
"id": "goclaw-event-5",
"recordId": "goclaw-record-5",
"occurredUtc": "2026-09-03T16:31:00Z",
"title": "Suggestion batch prepared - Regional operations review with a deliberately long title",
"description": "Evidence and three proposed actions are ready for review. This deliberately longer supporting line verifies wrapping, truncation, responsive spacing, and dense dashboard behavior.",
"actor": "Automation",
"tone": "danger"
},
{
"id": "goclaw-event-6",
"recordId": "goclaw-record-6",
"occurredUtc": "2026-09-02T19:14:00Z",
"title": "Suggestion batch prepared - Completed preview",
"description": "Evidence and three proposed actions are ready for review. Closed after review with its related evidence retained.",
"actor": "Jordan Lee",
"tone": "success"
}
]
},
"children": []
}
]
}Copy/paste React composition
Copy InteractivePresentationComponents.tsx and its optional CSS from the Professional Foundation Developer Kit, then add this module-specific composition. It is semantic and unstyled by default; pass styled after importing interactive-presentation-components.css for the supplied polished foundation. Either version accepts only a bounded already-authorized document and fails closed through the shared strict parsers.
import {
EntityList,
MetricStrip,
PresentationGrid,
ProgressList,
SeriesChart,
Timeline,
} from "./InteractivePresentationComponents";
export interface GoClawPresentationData {
readonly metrics: unknown;
readonly recent: unknown;
readonly byStatus: unknown;
readonly trend: unknown;
readonly table: unknown;
readonly timeline: unknown;
}
export interface GoClawPresentationProps {
/** Pass only the already-authorized presentation document returned by the API. */
readonly data?: GoClawPresentationData | null;
readonly loading?: boolean;
readonly error?: boolean;
readonly styled?: boolean;
/** Record identity is navigation context; the detail API must authorize it again. */
readonly onOpenRecord?: (recordId: string) => void;
}
export function GoClawPresentation({
data,
loading = false,
error = false,
styled = false,
onOpenRecord,
}: GoClawPresentationProps) {
if (error) return <p role="alert">The GoClaw presentation could not be loaded.</p>;
if (loading || !data) return <p role="status">Loading GoClaw presentation...</p>;
return (
<main className={styled ? "bwhq-api-example" : undefined}>
<header>
<p>GoClaw</p>
<h1>GoClaw review center</h1>
<p>Prepared work, risk, approval state, execution outcomes, and stale-context visibility.</p>
</header>
<MetricStrip data={data.metrics} styled={styled} />
<div className={styled ? "bwhq-api-example__split" : undefined}>
<ProgressList data={data.byStatus} styled={styled} />
<EntityList data={data.recent} styled={styled} onOpenRecord={onOpenRecord} />
</div>
<SeriesChart data={data.trend} styled={styled} />
<PresentationGrid data={data.table} styled={styled} onOpenRecord={onOpenRecord} />
<Timeline data={data.timeline} styled={styled} onOpenRecord={onOpenRecord} />
</main>
);
}
Copy the live, authenticated module page
This document has no placeholder key and needs no invented endpoint. Save it to a page and add that page to a User Type menu. The registered native component calls /api/goclaw/approvals, uses the current tenant session, and preserves the module's real list, detail, create/update, pagination, empty, loading, and error behavior. Dynamic Records discovers the organization's real tenant-owned modules when no module key is configured.
Copy the executable live page
{
"blocks": [
{
"_id": "goclaw-live",
"_type": "module.goclaw",
"props": {},
"children": []
}
]
}The server derives SaaS app, organization, user, DataRoles, locations, module-specific membership/privacy, and any AI-read gate from verified identity. A returned identifier can select a detail target, but the detail or write endpoint authorizes it again. Page layout, status, tone, totals, action names, and identifiers never grant authority.
Start each assistant with read-only preparation and one narrow approved action. Expand only after acceptance, edit, refusal, and outcome evidence show the behavior is trustworthy.
A renderer being bundled in the tenant application does not make its data visible in every app. The server returns only components and records authorized for the current app and signed-in user; unavailable or unauthorized blocks fail closed.
Capability review: 2026-09-14. For exact current technical availability, use the generated API Map and first-class module inventory.