OpenClaw multi-user mode
Ownership, presence, per-person model accounts, and the boundary it does not give you
Multi-user mode lets several trusted people operate the same OpenClaw agent, and the docs open the page with the boundary rather than the features: everyone who can operate an agent can make it do anything that agent can do, and ownership, sidebar visibility and presence are usability features, not security. People who must not reach each other’s sessions, tools, credentials or files need separate agents or separate Gateways. With that stated, here is what the mode adds: three layers of attribution, assignment, public links, and per-person model accounts.
Session ownership, visibility in the sidebar, and presence indicators are usability features, not security boundaries.
Three ownership layers
- Creator, immutable: new sessions record who caused them when the creation path can prove it, a verified Gateway profile, a channel sender or an unknown historical attribution; sharing and visibility authority stays anchored on the creator even after the owner changes.
- Owner, assignable: the person or agent currently responsible, in the style of an issue assignee; it defaults to the creator, can be reassigned at any time with a record of who did it, and drives the sidebar avatar and the owner filter.
- Participants, history: authenticated people, channel senders and requesting agents whose accepted input targeted the session, bounded at thirty-two records, recorded in the background so it never delays a turn.
Assigning, sharing, and public links
The session menu offers assign to me and assign to anyone registered, and agents can reassign through the sessions tool; both call the same Gateway method, need an identified caller and are authorized by session visibility. Reassigning changes responsibility and display only, never sharing authority or access. Visibility settings, shared, read-only, suggest and draft, control signed-in people and never create a public link; public access is a separate, explicit choice by the creator or an admin that yields a bearer URL for the conversation text only, with tools, reasoning, files and hidden messages excluded, and disabling it revokes every URL while downloaded copies cannot be recalled.
Per-person model accounts
- Each person can sign in to a model account for their Gateway profile, and new sessions they start prefer that account over the Gateway default; there are two sign-ins, the Gateway identifying you and the provider authorizing your account.
- Accounts are added under the profile’s connected accounts: an API key for Anthropic, not a subscription token; an API key, ChatGPT browser sign-in or device code for OpenAI; a key or device sign-in for Grok; only methods enabled for personal accounts on that Gateway appear.
- A chat’s account is chosen in the model menu, applies to that session, and shows other people a person-level label rather than a private email; configured shared failover accounts can still be used, so the label is not a billing receipt.
OpenClaw sessions is the routing and isolation model underneath, and OpenClaw security best practices the checklist that includes the audit these settings belong to.
Administrators and automations
An authenticated Control UI administrator can manage any automation on the Gateway conversationally, including jobs another person created, without matching channel identities to profiles; the authority comes from the admitted administrator turn and does not transfer the job’s creator attribution. OpenClaw sub-agents covers the other place ownership shows up, in thread-bound and visible sessions.
On Diali
On Diali the boundary the docs ask for is the default: each assistant is its own isolated instance, so a team that needs real separation gets one assistant per person or per role rather than one shared agent with owner avatars. Hosted OpenClaw on Diali is the assistant and Diali pricing counts assistants per plan.
- Creator, owner, participants: attribution, not access control.
- Public links are a separate explicit choice, revocable but not recallable.
- Personal model accounts sign in twice: the Gateway, then the provider.
Stop reading about it, build one
Set up an agent, pick a channel, and have it working inside the app you already keep open.
