OpenClaw Made Crystal Clear · chapter 2: The Mental Model

What runs as whom

2026-09-29

One process holds both the reasoning and the tools it can call. The line between them is where sandboxing, when enabled, actually cuts.

Below: the paragraph from the book that builds this idea, then the diagram itself (Figure 2.2), and a recap. About a minute of reading.

The gateway listens on a WebSocket, bound by default to 127.0.0.1:18789, meaning it only accepts connections from the machine it runs on unless you deliberately widen that. Inside the process, an internal boundary separates the agent's reasoning from the tools it calls: exec, filesystem read and write, browser control, web access, media handling. That internal split is the other half of the "trusted gateway, untrusted execution" design philosophy from Chapter 1: the gateway itself is meant to be trusted, while tool execution is the part meant to be constrained, ideally sandboxed. Whether it actually is sandboxed on your install is a setting, not a given, and Chapter 3 covers exactly what that setting does and does not protect you from.

Figure 2.2: What runs as whom. One process holds both the reasoning and the tools it can call. The line between them is where sandboxing, when enabled, actually cuts.
Figure 2.2: What runs as whom. One process holds both the reasoning and the tools it can call. The line between them is where sandboxing, when enabled, actually cuts.

Recap

  • The idea: One process holds both the reasoning and the tools it can call.
  • The picture: Figure 2.2, from chapter 2 ("The Mental Model") of OpenClaw Made Crystal Clear.
  • Go deeper: the chapter builds this step by step, with recipes and sources at the end.

This diagram is one of many in OpenClaw Made Crystal Clear.

Every chapter opens with the gist, draws the hard ideas, and ends with recipes and sources.

Get the book

All diagrams