OpenClaw is designed around a trusted operator boundary. That means a business should not treat one shared gateway as a hard security wall between unrelated or adversarial users.
Before installation, decide whether this is a personal assistant, a business-scoped team agent, or a dedicated workflow agent. If different people, teams, or clients should not share access, use separate gateways, credentials, OS users, hosts, or agent workspaces rather than relying on prompts to separate them.