---
title: "🦞 Set Up Example NemoClaw Agents 🦞 — NemoClaw Policy Setup"
canonical: "https://build.nvidia.com/spark/nemoclaw-applications/policy-setup.md"
---

# NemoClaw Policy Setup

This tab covers the **shared sandbox configuration** that two of the applications in this playbook (the [Daily Personal News Digest](https://build.nvidia.com/spark/nemoclaw-applications/news-digest) and the [Calendar Negotiator](https://build.nvidia.com/spark/nemoclaw-applications/calendar-negotiator)) require, and that the other two ([Software Development Agent](https://build.nvidia.com/spark/nemoclaw-applications/developer-agent) and [Deck Reviewer](https://build.nvidia.com/spark/nemoclaw-applications/deck-reviewer)) can optionally use for "ready for review" notifications. Each application tab has its **own** policy setup section for the filesystem mounts and network egress that workflow needs — this page only covers Telegram, which is shared.

Set your sandbox name once so the commands below read cleanly:

```bash
export SANDBOX_NAME=my-assistant   # replace with the name you chose at NemoClaw onboard
```

# Step 1. Set up the Telegram channel

The NemoClaw onboard wizard already wires the **Telegram channel plugin** into the sandbox when you select `telegram` at the *Messaging channels* prompt. If you did not, recreate the sandbox via the installer with Telegram enabled — `policy-add` alone cannot wire the channel plugin.

Add the Telegram **network egress preset** so the sandbox can reach `api.telegram.org`:

```bash
nemoclaw $SANDBOX_NAME policy-add
```

When prompted, type `telegram` and press **Y** to confirm. This is a hot-reload — the sandbox stays up.

Confirm the policy now allows Telegram egress:

```bash
openshell policy get $SANDBOX_NAME --full | grep -A2 telegram
```

You should see one or more entries with `host: api.telegram.org` and `port: 443` under `network_policies`.

**Install `cloudflared` (one-time, required for the tunnel)** — DGX Station does **not** include `cloudflared` by default. `nemoclaw tunnel start` needs it to expose the bot webhook publicly; without it the next command will silently print `cloudflared not found — no public URL` and `nemoclaw status` will report `● cloudflared (stopped)`. Skip this block if `command -v cloudflared` already returns a path.

```bash
curl -L --output cloudflared.deb https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-arm64.deb
sudo dpkg -i cloudflared.deb
cloudflared --version   # confirm it installed; expect a version banner like "cloudflared version 2024.x.x"
```

Start the public webhook tunnel so Telegram can deliver messages to your bot:

```bash
nemoclaw tunnel start
nemoclaw status
```

Expected: `● cloudflared` with a `*.trycloudflare.com` URL.

> [!IMPORTANT]
> If you skipped Telegram at the NemoClaw onboard step, `nemoclaw $SANDBOX_NAME policy-add` will open the egress preset but the bot will still reply `Error: Channel is unavailable: telegram`. The channel **plugin** is wired in at sandbox creation, not by `policy-add`. Re-run the NemoClaw installer and pick `telegram` at the **Messaging channels** prompt to recreate the sandbox with the plugin attached.
>
> **Download, verify, then execute** — never pipe a remote installer straight into a shell:
>
> ```bash
> # 1. Download the installer to a local file
> curl -fsSL -o nemoclaw.sh https://www.nvidia.com/nemoclaw.sh
>
> # 2. Verify it against the published checksum from the NemoClaw release notes
> #    (replace <expected-sha256> with the value from https://github.com/NVIDIA/NemoClaw/releases)
> echo "<expected-sha256>  nemoclaw.sh" | sha256sum --check
>
> # 3. Inspect the script you're about to run (optional but recommended)
> less nemoclaw.sh
>
> # 4. Only then execute it
> bash nemoclaw.sh
> ```
>
> If the checksum does not match, **do not run the script** — re-download or open an issue against the NemoClaw repository.

Once the tunnel reports a public URL, open Telegram, find your bot, and send `hello`. You should get a reply from the local model within 30–90 seconds (first-response cold start on a 120B model is slow). After that, hand off to the application tab you want to set up.