…
Securing Agents · Going Further

Going Further

A real deployment adds its own data and users. You now need to choose where to deploy it, how to bring in your own knowledge, and which open problems matter once the basics hold.

Deploy what you built

Moving the exercises onto a real runtime

Continue with the NemoClaw Brev launchable used in Module 3. If you cannot use Brev, a compatible local deployment is the fallback. For either option, choose a model endpoint and decide how to retain sessions and workspace files.

Carry the interface forward

The browser artifact is a transferable agent surface

Each course page is both a lesson and a small application. The interface exposes state, controls, intermediate results, and approval points; JavaScript runs the local orchestration. That combination works well when the audience has a browser but no prepared development environment. It can explain a system interactively, drive a dynamic workflow, or provide a focused front end for general scripting over loaded data and allowed services.

Transfer the interface contract, then adapt the environment. HTML, CSS, JavaScript, visible state, and approval controls travel well. Authentication, cross-origin access, persistence, filesystem reach, backend tools, and host UI bridges do not. Keep those dependencies behind narrow adapters so the workflow can move without pretending every host grants the same authority.

Agent products now expose this form directly. Anthropic describes Cowork live artifacts as persistent interactive HTML pages that can refresh from connected apps and local files. OpenAI's preview Apps SDK lets an MCP-backed app define its chat behavior and interactive interface together. A static page, a hosted artifact, and an in-chat app use different host contracts, but all can present the same workflow as inspectable state plus bounded actions.

Add new knowledge

Bringing your data in

The Index Agent in Module 2b ran against a small in-page corpus. A production deployment needs more work and considerations, so the following references may be of interest.

Choose the next production axis to deepen?
Where to push next

Where production work diverges

Production projects usually deepen one of these areas:

  • The knowledge layer. Evaluate structural chunking, page-image retrieval, and answer faithfulness on the different kinds of documents in your corpus.
  • The substrate. Wire-format protocols (MCP, the Responses API, OTel GenAI conventions, A2A) that keep tool capabilities portable across providers and frameworks.
  • Fleet dynamics and containment. What changes when N agents run in parallel: each agent redundantly re-discovers the same context (rediscovery cost), topologies with too many hops lose coherence, and an agent grading a peer's output can shift its verdicts based on social context rather than content. How to bound any single agent in the fleet with kernel-level containment (Landlock, seccomp, network namespaces) when prompt rules and guardrails are not enough to limit blast radius.

Pick the axis that matches the problem your current project keeps running into. The NVIDIA Developer Blog tracks the latest reference work across them.

NVIDIA Developer Blog →
Open the full module-by-module reading list?
References hub

Reading list, organised by module

These references extend the module reading lists. Papers and documentation may be freely accessible; some books require purchase or institutional access.

The topic groups follow this course first, then extend into fleet and evaluation work.

Module 1 · Model and agent foundations

Module 1 · ReAct, tool use, and structured outputs

Module 2 · Workflow, retrieval, and deep research

Module 3 · Persistent runtimes and CLI agents

Module 4 · Evaluation and containment

Beyond this course: the final group extends the same design questions to fleets and model adaptation.

Going further · Multi-agent systems and adaptation

Learning path

Continue with the NVIDIA Agentic AI Learning Path

This course is the hands-on companion to Lesson 6 of NVIDIA's Agentic AI Learning Path, How to Build a Safer Autonomous Agent using OpenClaw. The full path begins with building a first agent and ends at the safety work this course covers in depth. In between it moves through retrieval, evaluation, model customization, and deep agents that delegate and persist memory. Each lesson below pairs a concept you met here with the place the path develops it further.

Lesson 1 · How to Build an AI Agent

The plan-act-observe loop you built from scratch in Module 1, here assembled with NVIDIA Nemotron models and LangGraph into a report-generation agent.

Start →

Lesson 2 · How to Build an Agentic RAG Application

The retrieval agent from Module 2b, scaled up: dense and sparse search, reranking, and a vector store wired into a ReAct agent that plans its own queries.

Start →

Lesson 3 · How to Evaluate AI Agents

The verification half of the loop. Measuring task success, tool-use quality, and trajectory efficiency with RAGAS metrics and LLM-as-judge pipelines, the discipline behind every reliability decision in this course.

Start →

Lesson 4 · How to Customize AI Agents

When prompting and skills hit their limit, this lesson writes domain knowledge into the weights themselves: synthetic data with NeMo Data Designer, then fine-tuning Nemotron with GRPO and LoRA.

Start →

Lesson 5 · How to Build Deep AI Agents

The planner, sub-agent delegation, and virtual-filesystem memory you hand-rolled in Module 2c, built here with LangChain's deepagents library and the NVIDIA AI-Q Blueprint.

Start →

Lesson 6 · How to Build a Safer Autonomous Agent using OpenClaw

This course. The containment work from Modules 3 and 4: deny-by-default network, Landlock filesystem, seccomp hardening, credential isolation, and continuous safety evaluation on a long-running claw.

Start →

Helper articles worth reading

Module connections

Connect the loop, workflow, runtime, and policy

The browser model route and the persistent agent runtime are configured separately. Their models can differ. The reusable part is the surrounding orchestration, whose behavior still needs testing with the model you choose.

These layers can carry forward across model upgrades. Retest tool arguments, output formats, context limits, cancellation, and task results on the replacement endpoint before relying on the same behavior.

When an agent repeatedly fails, inspect its inputs, model responses, tool results, and runtime constraints to locate the cause. Choose the repair from that evidence. The deployment considerations below provide further questions to test.

Lessons for deployment

What to remember when you ship one of these

Keep the Course Assistant with you

The Course Assistant behind the ✦ button is available on every English lesson. It preloads the current page. When a question crosses modules, the assistant can inspect the course map, search the lessons, and read the relevant pages. Browser-local persistence means sessions stay in this browser: return to one after navigating or reloading, or create another for a clean line of inquiry. As a session grows, the assistant compacts older turns into durable memory, keeps the recent exchange verbatim, and starts a fresh bounded agent thread from that state.

← Module 4b: Modern CLIs