Fusion Claw is the right home for SOPs, risk thresholds and decision rights, and the wrong home for cross-boundary state and compensation. A placement decision, not a product comparison.
Last Updated: October 7, 2026
Oracle Fusion Claw is a genuinely good place to put standard operating procedures, risk thresholds, decision rights and approval routing — because those policies belong next to the records they govern. It is structurally the wrong place to put cross-boundary run state, compensation logic and exception escalation, because the Claw runtime executes inside an isolated container against Oracle's own data and role model. Split the six coordination responsibilities rather than standardising on one layer: policy and in-suite execution inside the ERP, the long-running case that spans CRM, 3PL, banking rails and email outside it.
Every ERP, CRM and ITSM vendor will ship something that looks like an agent orchestration layer within two quarters. The buying question is not which product is better. It is which of the coordination responsibilities you currently hold in an external tool can legitimately move inside a suite, and which cannot move no matter how good the suite gets. That answer is architectural, and it does not change when the next vendor announces.
What Oracle actually shipped on September 29
The announcement date matters because a lot of the secondary coverage has drifted. Oracle announced Fusion Claw from Austin on September 29, 2026, describing it as a governed agentic execution runtime that pairs frontier-model reasoning with deterministic enterprise computation, delivered through 25 new Claw-powered applications on top of an existing portfolio of 75 agentic applications.
Three components carry the architecture. The Enterprise Operating Envelope holds objectives, standard operating procedures, policies, constraints, permissions, risk thresholds, decision rights, approval requirements and escalation boundaries. The Outcome Trust Harness applies that envelope per run across identity, capabilities, data and actions. The Outcome Receipt is the post-run audit artifact: authority applied, evidence used, decisions made, transactions executed, result. Reasoning runs on Gemini and OpenAI models on OCI, with more frontier models promised over time.
Two details from the launch coverage matter more than the branding. First, the runtime is deliberately walled: analysts briefed on it described Claw tasks running in container isolation without open access to the internet or APIs, with role-based permissions. That is the right security posture and it is also the boundary of the product. Second, Oracle EVP Chris Leone told Forbes that reusing approved plans can cut reasoning cost by “50%-plus”, and Forbes noted Oracle supplied neither benchmarks nor Claw-specific pricing. Oracle SVP Natalia Rachelson said the apps ship in Q4, included with Agentic Applications subscriptions that are priced separately from Fusion Cloud Applications and metered in AI units.
So: a strong governance model, a real execution runtime, unpriced consumption, and an intentional wall between the runtime and everything Oracle does not own. Hold that last point.
Six coordination responsibilities, and where each one belongs
“Orchestration” is one word covering six separable jobs. Vendors sell them as a bundle because they are bundled in their product. They are not bundled in your estate.
| Responsibility | ERP-native (Fusion Claw and its coming equivalents) | External layer (n8n, LangGraph, Temporal) | Where we would put it |
|---|---|---|---|
| Identity & authority | Strong. The agent inherits existing role-based access control and cannot exceed it. Per-run authority is explicit. | Weak by default. Usually a service account with broad scope and credentials in a vault. | Inside, for every write to the suite. Outside identities stay outside. |
| Decision rights & SOPs | Strong. Thresholds and approval requirements sit next to the ledger, the supplier master and the employee record they govern. | Possible but fragile. Policy ends up as if-nodes and prompt text, duplicated per workflow. | Inside. One authoritative copy. |
| Run state | Good for an outcome that begins and ends in Fusion. No visibility into steps executed elsewhere. | Designed for it, if you use a durable store rather than in-memory state. | Split by scope: in-suite run state inside, case state outside. |
| Retry & compensation | Can retry and reverse its own transactions deterministically. | Where saga-style compensation across systems has to live. | Outside, whenever a failure spans two systems of record. |
| Cross-system handoff | Structurally constrained: the runtime is isolated from open internet and API access by design. | The whole point of the category. | Outside. This is not a maturity gap, it is the security model. |
| Audit | Excellent inside its scope — Outcome Receipts are a better artifact than most teams build themselves. | Only as good as your logging discipline and run retention. | Both, joined by one correlation ID. |
Read the table as a placement map, not a scorecard. Oracle wins four of six on quality and loses one on structure — and the one it loses is the one that generates most of your incidents.
The expensive seams are not inside the ERP
Pick any process the suite vendors demo. Order-to-cash: the order originates in a CRM, credit and pricing live in the ERP, fulfilment happens at a 3PL over EDI or REST, the carrier confirms by webhook, cash arrives as a bank file, remittance advice arrives as a PDF attached to an email, and the dispute lands in a shared inbox. Procure-to-pay adds a third-party risk tool, a capture vendor, a banking rail and a sanctions provider. Close adds a warehouse, three spreadsheets and a subledger from an acquisition you have not migrated.
The ERP owns the record. It does not own the seams. And the failures that cost real money are seam failures.
Where an order-to-cash run actually crosses boundaries
Owned by a system the ERP agent cannot roll back. Already outside the envelope.
Credit threshold, approval route, pricing exception. This is exactly the work an Enterprise Operating Envelope is built for.
At-least-once delivery. Without an idempotency key you will eventually ship twice.
The run is now suspended in a system that holds no state about steps 1 and 3.
Cancel at the 3PL, reverse the ERP entry, notify the CRM owner, hold the invoice. Four systems, four different reversal semantics, no distributed transaction.
Who is in Slack or Outlook, not in Fusion, and who needs the whole case — not one system's slice of it.
Deloitte's framing of why agentic programmes stall is almost entirely about these seams: legacy integration, data architecture that agents cannot consume, and governance frameworks that were never designed for systems that act. Their read of the Gartner cancellation prediction is that projects fail because legacy systems cannot support modern AI execution demands — not because the model reasoned badly. That matches what breaks in practice. We have never had a production incident caused by a model failing to understand a credit policy. We have had plenty caused by a webhook replay, a token expiry at 3am, a partial write committed before a downstream call failed, and a human approval that was requested in a channel nobody was watching.
The split we would ship
Inside the suite: SOPs, risk thresholds, decision rights, approval routing, and the deterministic execution of transactions against the suite's own data under its own RBAC. If you already run Fusion, there is no good argument for re-implementing a credit-limit threshold or a journal approval chain in an external workflow tool. The policy drifts from the data, and you inherit the audit burden Oracle will hand you for free in an Outcome Receipt.
Outside the suite: the case. One durable, long-running state machine that knows every step across every system, owns idempotency keys, owns compensation, owns the escalation channel, and owns the evaluation harness you replay regressions against. In practice that is LangGraph or Temporal with a Postgres-backed checkpointer, or n8n in queue mode with Postgres and a real dead-letter path — not the default single-instance deployment, which will happily lose an in-flight execution on restart.
The interface between them should be boring: the ERP agent is a callable capability with a typed contract, an idempotency key, a correlation ID and a bounded execution time. It is not the top-level coordinator.
Promoting the ERP agent to top-level orchestrator
It happens because the ERP demo is the most impressive thing in the evaluation and because the suite holds the most valuable data. Then the first cross-boundary exception arrives — a 3PL rejects a pick after the ERP has already committed the shipment — and the orchestrator cannot see, retry or reverse the step that failed. Teams respond by bolting a second coordinator outside, and now two systems believe they own the run.
Encoding the same threshold in two places
A $50k approval limit lives in the Enterprise Operating Envelope and, because the external flow needs to branch on it, in a comparison node and a prompt. Finance raises the limit to $75k in the ERP. Nobody updates the other two. The divergence is invisible until an auditor asks why two runs with identical inputs took different routes.
The lock-in math nobody prices
Vendor-native orchestration is not expensive because of licence cost. It is expensive because of what it does to three independent decisions you will want to make again within 36 months.
Model choice stops being yours. Claw reasoning runs on the frontier models Oracle has qualified — today Gemini and OpenAI, with more planned. That is a reasonable list. It is not your list, and the routing logic that decides which model handles which step is Oracle's, not yours. If your own evaluations say a different model is materially better on invoice-exception reasoning, you cannot act on that inside the envelope. Teams who care about this keep model selection in a layer they control; it is the main reason we keep a routing abstraction in front of providers rather than hard-binding to one (model coverage).
Policy becomes a vendor artifact. Decision rights expressed as an Enterprise Operating Envelope are expressed in Oracle's schema, enforced by Oracle's harness, evidenced in Oracle's receipts. There is no export format that another vendor consumes. If you later move a process — or acquire a business running SAP — you re-author, re-test and re-certify the policy, which is usually the expensive half of the work. Mitigate it by keeping the human-readable source of truth for each SOP in version control and treating the envelope as a compiled target, not the original.
Autonomy becomes metered. Agentic Applications are priced separately from Fusion Cloud Applications and consumption is tied to AI units. There was no Claw-specific pricing at launch. Consumption pricing is defensible for work that was previously done by specialists, but it changes your architecture incentives: anything you push inside the envelope has a marginal cost per run, and the obvious optimisation — move high-volume, low-judgement steps to deterministic code you own — is exactly the optimisation the pricing model discourages inside the suite and rewards outside it.
The honest counter-position, because the automation platforms deserve the same scrutiny: most external orchestration deployments we see are worse on governance than what Oracle shipped. A single n8n instance with SQLite, a shared admin login, workflow versions that exist only in the UI, no dead-letter queue and no replay capability is not an architecture. It is a liability with a nice canvas. If your current external layer looks like that, the ERP-native option is genuinely safer for policy-bearing work, and you should take the free governance while you fix your own house. That assessment is the first thing worth doing before any 12-month commitment, and the core of how we scope integration work.
A migration-safety checklist if you already run external orchestration
You do not need to choose a side this quarter. You need to make sure the choice stays reversible.
Keeping the placement decision reversible
Generated outside any vendor, stamped on every ERP call, every webhook, every escalation message. Without it you cannot reconstruct a run that spans an Outcome Receipt and three external systems.
Idempotency key on every ERP and third-party mutation, with a dedupe store you own. This is what makes retries safe and what makes moving a step between layers a non-event.
Thresholds, approval routes and escalation boundaries as data; sequencing as code. Only the first category is a candidate for the envelope.
If approvals arrive in Slack, Teams or email, the escalation channel is outside the suite and should stay there. Suite-native approval queues add a surface people forget to check.
Run the Claw outcome in research mode — staged actions, no execution — alongside your existing flow for a full close or billing cycle, and diff the decisions, not just the outputs.
Estimate AI-unit consumption per run at production volume. If a vendor cannot give you a per-outcome cost, cap autonomy at the volume you can afford to be wrong about.
What happens in the next two quarters
SAP's Autonomous Suite already overlaps Claw's ledger work with an Autonomous Close Assistant, and Workday, ServiceNow and Microsoft are making comparable claims about coordinating agents across systems. Expect three or four more native orchestration layers before mid-2027, each with its own policy schema, its own receipt format and its own consumption meter. None of them will solve the handoff to the systems they do not own, because none of them can.
Oracle adds workflow orchestration, contextual memory and an agent ROI dashboard to AI Agent Studio for Fusion Applications, at no additional cost.
Fusion Claw announced: 25 Claw-powered applications, Enterprise Operating Envelope, Outcome Trust Harness, Outcome Receipts, container-isolated execution.
Availability, bundled with separately priced Agentic Applications subscriptions and metered in AI units. First real consumption data appears on customer bills.
Gartner's predicted shakeout window closes: over 40% of agentic projects cancelled, mostly for cost, unclear value and inadequate risk controls.
The teams that come through that window intact will not be the ones who picked the right vendor. They will be the ones who could move a step from one layer to another in an afternoon because the correlation ID, the idempotency key and the policy store were theirs. If you want a second opinion on where your decision rights currently live, that is a short conversation: start here, or look at how we structure these builds under services.
Frequently Asked Questions
Should we cancel our n8n or LangGraph layer now that the ERP orchestrates agents natively?
No. Fusion Claw executes in a container deliberately isolated from open internet and API access, so anything that touches a CRM, a 3PL, a bank file or an email inbox still needs a layer outside the suite. What you should cancel is duplicated policy: approval thresholds, decision rights and escalation boundaries that you reimplemented in workflow nodes because the ERP previously had nowhere to put them.
What is an Enterprise Operating Envelope in practice?
It is Oracle's container for the rules an agent runs inside: objectives, standard operating procedures, policies, constraints, permissions, risk thresholds, decision rights, approval requirements and escalation boundaries. An Outcome Trust Harness enforces it per run across identity, capabilities, data and actions, and an Outcome Receipt records the authority applied, evidence used, decisions made and transactions executed. Functionally it is policy-as-configuration, enforced at execution rather than reviewed afterwards.
Which coordination responsibilities genuinely cannot move inside an ERP?
Cross-system handoff and compensation. A suite can retry and reverse its own transactions deterministically, but it cannot cancel a pick at a third-party logistics provider, recall a payment file already on a banking rail, or un-send an email. Saga-style compensation needs a coordinator that can see every step in the case. Cross-boundary run state follows for the same reason: state has to live where the whole case is visible.
How much does Fusion Claw cost?
Oracle has not published Claw-specific pricing. The Claw-powered applications are included with Agentic Applications subscriptions, which are priced separately from Fusion Cloud Applications, and consumption is tied to AI units. Oracle also claims reusing approved plans can cut reasoning costs by over 50%, without publishing benchmarks. Until you have per-outcome consumption data from your own volumes, treat autonomy scope as a cost decision, not only a risk decision.
Does keeping orchestration external mean weaker governance?
Usually yes, as deployed. A single-instance automation server with SQLite, shared credentials, UI-only workflow versions and no dead-letter queue has a materially worse audit story than Outcome Receipts. External does not have to mean weaker, but it requires deliberate work: durable state in Postgres, workflow definitions in version control, per-agent identities with scoped credentials, run retention and replay. If you will not do that work, the suite's governance is the safer choice.
What should we not automate yet?
Anything where a correct-by-policy decision can still be a bad business decision and the reversal is expensive or external. Consolidating shipments to cut cost can delay an order a customer urgently needs; the agent passes every rule and still damages the relationship. Keep those in staged or research mode, where actions are proposed and reviewed, until you have enough run history to characterise the failure distribution rather than guess at it.
Research digest
AI Research Briefing
Honest insights on AI agents, Small Language Models, and local RAG. No hype. Only when we have something worth sending.
- No hype, just measurable outcomes
- Read by 2,400+ engineers
- Unsubscribe anytime



