Skip to main content
RCOC Current-State Specification

The canonical shared RapidClaw foundation.

RapidClaw for OpenClaw is the customer-owned Azure-hosted operating environment for OpenClaw. RapidClaw for Business Central and RapidClaw for RapidStart Apps inherit this foundation and add only their product-specific extension layers.

Product: RCOCProduction release: 0.1.25Reviewed: 2026-08-18
01

Product Definition

RCOC packages deployment, identity, SI models, connectors, agents, governance, Microsoft Teams, email enablement, monitoring, and operator controls into a guided product. It has no Business Central or Dataverse host dependency.

Business Central and Dataverse connectors remain available for operator-led setup later, but they are not activated automatically in the Base composition.

02

Composition Contract

CapabilityCurrent responsibility
SetupShared hosted wizard, identity bootstrap, recovery, resume, and reset.
DeploymentCustomer-owned Azure resources and common deployment lifecycle.
RuntimeOpenClaw, memory, Microsoft Graph, secrets, governance, and shared services.
Command CenterCommon operator shell, Arcy, configuration, safety, and diagnostics.
TeamsApp packaging, tenant-catalog publication, readiness, and conversations.
Entitlement governanceServer-side subscription claim and fail-closed runtime controls.

The installed product profile is immutable. Product upgrades may update the selected profile, but an RCOC deployment is not converted in place into RCBC or RCRS.

03

Setup and Deployment

  • Checkout Session identifiers are claim hints, not authorization by themselves.
  • The deployment service verifies the session server-side, checks product and price, validates payment and subscription state, and binds entitlement to the authenticated tenant.
  • The shared six-stage wizard is Connect, Deploy, OpenClaw, Agents, Teams, and Command Center.
  • RCOC is sold as a monthly subscription with the first month free through the approved Stripe promotion flow.
SettingCurrent value
RegionsAustralia East, East US 2, South India, Sweden Central, West US 3
VM sizeStandard_D2as_v6
Runtime OSUbuntu 24.04 LTS Gen2
Pinned imageCanonical ubuntu-24_04-lts/server/24.04.202607140
OpenClaw channelLatest verified extended-stable release
04

SI Deployment Plan

  • Setup discovers the deployable GPT family and selects up to three compatible variants from the same version and SKU.
  • Variants are prioritized quality-first: sol, then terra, then luna.
  • Arcy and builder workflows prefer the quality tier; balanced workloads can use lower-cost tiers.
  • text-embedding-3-small supports memory search and indexing.
  • Foundry Model Router availability is detected and reported, but the verified direct-model plan remains the default deployment path.
05

Customer-Owned Runtime

The customer runtime is isolated in the customer Azure subscription and includes the Ubuntu VM, OpenClaw extended-stable runtime, nginx and OAuth protection, Command Center, Arcy, memory, Microsoft Graph MCP, connector registry, governance services, Teams forwarding, and email controls.

Installation artifacts are immutable and checksum-verified. Runtime operations are retry-safe, and teardown is manifest-driven.

06

Agents and Arcy

RCOC seeds two RapidClaw-managed agents: RapidClaw, the product orchestrator and general operating agent, and Arcy, the Command Center guide, builder, diagnostician, and governed operator assistant.

  • Create or edit an agent.
  • Create a skill.
  • Configure an MCP connector.
  • Draft a scheduled task.
  • Create or revise a prompt or policy.
  • Use live selectors for agents, models, data sources, connectors, tools, schedules, and policies.
07

Connectors, Email, and Teams

ConnectorRCOC default
Microsoft GraphFoundation connector, configured automatically.
Business CentralAvailable for operator-led setup, not active by default.
DataverseAvailable for operator-led setup, not active by default.
Registry/custom MCPAdded through governed Connector Setup.

Raw secrets do not enter Arcy chat, URLs, logs, persisted browser state, connector configuration, API responses, or dashboard rendering. Secret values are entered through protected dialogs and stored through Key Vault-backed handling.

Email infrastructure is shared Base capability. Mailbox creation occurs in Command Center, and external communications remain subject to policy and approval. Teams readiness remains false until publication and the forwarding path are functional.

08

State and Product Boundary

StoreAuthoritative responsibility
Azure TableSetup resume state, orchestration state, entitlement claim state, and deployment-service telemetry before runtime exists.
Azure PostgreSQL Flexible ServerNormalized runtime database for policies, approvals, audit, controls, handoffs, durable memory, and canonical deployment run, step, and event contract.
OpenClaw SQLiteOpenClaw-owned schedules and run history.
Azure Key VaultSecret values and protected signing or credential material.
Deployment manifestInventory of resources created by the selected composition for deterministic reset and teardown.
Boundary

RCOC does not include automatic Business Central binding, automatic Dataverse binding, RCBC finance agents, RCRS Agent Packs, a conversion path into an extension product, or product-specific host launchers and entitlements.