The canonical shared RapidClaw foundation.
RapidClaw for OpenClaw is the customer-owned Azure-hosted operating environment for OpenClaw. RapidClaw for Business Central and RapidClaw for RapidStart Apps inherit this foundation and add only their product-specific extension layers.
Product Definition
RCOC packages deployment, identity, SI models, connectors, agents, governance, Microsoft Teams, email enablement, monitoring, and operator controls into a guided product. It has no Business Central or Dataverse host dependency.
Business Central and Dataverse connectors remain available for operator-led setup later, but they are not activated automatically in the Base composition.
Composition Contract
| Capability | Current responsibility |
|---|---|
| Setup | Shared hosted wizard, identity bootstrap, recovery, resume, and reset. |
| Deployment | Customer-owned Azure resources and common deployment lifecycle. |
| Runtime | OpenClaw, memory, Microsoft Graph, secrets, governance, and shared services. |
| Command Center | Common operator shell, Arcy, configuration, safety, and diagnostics. |
| Teams | App packaging, tenant-catalog publication, readiness, and conversations. |
| Entitlement governance | Server-side subscription claim and fail-closed runtime controls. |
The installed product profile is immutable. Product upgrades may update the selected profile, but an RCOC deployment is not converted in place into RCBC or RCRS.
Setup and Deployment
- Checkout Session identifiers are claim hints, not authorization by themselves.
- The deployment service verifies the session server-side, checks product and price, validates payment and subscription state, and binds entitlement to the authenticated tenant.
- The shared six-stage wizard is Connect, Deploy, OpenClaw, Agents, Teams, and Command Center.
- RCOC is sold as a monthly subscription with the first month free through the approved Stripe promotion flow.
| Setting | Current value |
|---|---|
| Regions | Australia East, East US 2, South India, Sweden Central, West US 3 |
| VM size | Standard_D2as_v6 |
| Runtime OS | Ubuntu 24.04 LTS Gen2 |
| Pinned image | Canonical ubuntu-24_04-lts/server/24.04.202607140 |
| OpenClaw channel | Latest verified extended-stable release |
SI Deployment Plan
- Setup discovers the deployable GPT family and selects up to three compatible variants from the same version and SKU.
- Variants are prioritized quality-first: sol, then terra, then luna.
- Arcy and builder workflows prefer the quality tier; balanced workloads can use lower-cost tiers.
- text-embedding-3-small supports memory search and indexing.
- Foundry Model Router availability is detected and reported, but the verified direct-model plan remains the default deployment path.
Customer-Owned Runtime
The customer runtime is isolated in the customer Azure subscription and includes the Ubuntu VM, OpenClaw extended-stable runtime, nginx and OAuth protection, Command Center, Arcy, memory, Microsoft Graph MCP, connector registry, governance services, Teams forwarding, and email controls.
Installation artifacts are immutable and checksum-verified. Runtime operations are retry-safe, and teardown is manifest-driven.
Agents and Arcy
RCOC seeds two RapidClaw-managed agents: RapidClaw, the product orchestrator and general operating agent, and Arcy, the Command Center guide, builder, diagnostician, and governed operator assistant.
- Create or edit an agent.
- Create a skill.
- Configure an
MCPconnector. - Draft a scheduled task.
- Create or revise a prompt or policy.
- Use live selectors for agents, models, data sources, connectors, tools, schedules, and policies.
Connectors, Email, and Teams
| Connector | RCOC default |
|---|---|
| Microsoft Graph | Foundation connector, configured automatically. |
| Business Central | Available for operator-led setup, not active by default. |
| Dataverse | Available for operator-led setup, not active by default. |
Registry/custom MCP | Added through governed Connector Setup. |
Raw secrets do not enter Arcy chat, URLs, logs, persisted browser state, connector configuration, API responses, or dashboard rendering. Secret values are entered through protected dialogs and stored through Key Vault-backed handling.
Email infrastructure is shared Base capability. Mailbox creation occurs in Command Center, and external communications remain subject to policy and approval. Teams readiness remains false until publication and the forwarding path are functional.
State and Product Boundary
| Store | Authoritative responsibility |
|---|---|
| Azure Table | Setup resume state, orchestration state, entitlement claim state, and deployment-service telemetry before runtime exists. |
| Azure PostgreSQL Flexible Server | Normalized runtime database for policies, approvals, audit, controls, handoffs, durable memory, and canonical deployment run, step, and event contract. |
| OpenClaw SQLite | OpenClaw-owned schedules and run history. |
| Azure Key Vault | Secret values and protected signing or credential material. |
| Deployment manifest | Inventory of resources created by the selected composition for deterministic reset and teardown. |
RCOC does not include automatic Business Central binding, automatic Dataverse binding, RCBC finance agents, RCRS Agent Packs, a conversion path into an extension product, or product-specific host launchers and entitlements.