Filed separately from OpenClaw because the layering is the interesting part, and it is the same layering this glossary already names: Pi Agent Core is the harness, OpenClaw is the product built on it, and the model is a third thing again.
Its trust tiers are the idea most worth borrowing. Permission scoped to the channel a request arrived on — what Telegram may do versus what a local terminal may do — is a more honest model than a single allow-list, because it admits that an agent reachable from the internet and an agent you are sitting in front of are not the same agent.