Orchestrator Zero runs AI agents on the machines you own, in every site and every network, and keeps them in line. Package an agent once and any machine in the fleet can run it. Every step is saved, every model call is metered and nothing risky happens without a yes.
How teams use it
Join your machines
Servers, laptops, GPU boxes and devices in every site, with one command each.
oz0-node join --token …
Install agents from Git
Agents, tools and skills come as plugins, rolled out to the nodes that need them.
Laptops, GPU workstations and cloud VMs join with one command. They only dial out, so there is nothing to open in a firewall.
A small Go supervisor keeps the agent runtime and every plugin running, and restarts them if they crash.
Labels such as gpu=a100 decide which jobs a node takes.
A blocked node is refused on its very next call.
dev-laptopagent=pr-reviewer
gpu-boxgpu=a100
vm-eu-northregion=eu-north
edge
Each node opens the connection itself. The machine needs no inbound ports.
The edge is the only door in
Nodes talk to the edge and nothing else. It proxies Temporal, serves the runtime API and meters every model call.
Every call is checked over mTLS against the registry.
The model gateway prices each call and stops a job at its budget.
Start jobs over REST or gRPC, with clients for Python, TypeScript and Go.
node-7f3acalls the model gateway
Certificate is validmTLS
Node is allowedregistry
Job is within budget$1.62 left
Temporal
Model gateway
Runtime API
Example call. Every request from a node passes the same checks before it goes anywhere.
Servers keep every run durable
Each agent run is a Temporal workflow: embedded, on your own cluster or on Temporal Cloud. It survives crashes and can wait for days.
Each model and tool call is its own step, so a run picks up after the last finished one.
Waiting for a human approval holds no machine.
Schedules keep firing even when management is down.
node-7f3anode-21c9planrun_testsnode lostresumereviewdoneExample run. The second node starts after the last finished step, so no work is repeated.
Management stays above it all
Web UI, registry, certificates, rollouts and cost reports. It runs on its own, so it can go down without stopping a single job.
Its certificate authority issues node certificates that renew every 24 hours.
New plugin versions roll out to a few nodes first, then to the rest.
Secrets are never decrypted here, only at the edge and on the node that needs them.
Cost by agent, last 7 days
Example data
pr-reviewer
$41.8052% of spend
test-runner
$23.1529% of spend
code-explainer
$9.4012% of spend
triage-bot
$6.258% of spend
$80.60 across 4 agents this week. Budgets stop a job before it overspends.
Built on Temporal The open-source durable execution engine. Every agent run is a Temporal workflow, so it survives crashes and can wait for days. .Works with the tools your team already uses.
Claude
Model Context Protocol
Ollama
Pydantic
PostgreSQL
OpenTelemetry
GitHub
Python
Go
uv
Claude
Model Context Protocol
Ollama
Pydantic
PostgreSQL
OpenTelemetry
GitHub
Python
Go
uv
Claude
Model Context Protocol
Ollama
Pydantic
PostgreSQL
OpenTelemetry
GitHub
Python
Go
uv
Claude
Model Context Protocol
Ollama
Pydantic
PostgreSQL
OpenTelemetry
GitHub
Python
Go
uv
Start jobs from wherever work begins.
People use the web UI and the CLI, your apps call the runtime API, and other services post a webhook. Every way starts the same durable job, with the same budget, approvals and history.
Web UIhttps://<server>:8443
Approvals 2 waiting
change-runner wants junos.commit
site got-2 · waiting 4m
ApproveDeny
containment wants host.isolate
fin-ws-042 · waiting 12m
Run pr-reviewer
{"repo": "acme/api", "pr": 42}
$2.00
Run
From zero to a fleet in four commands.
Start one server. Then install the node on every machine you want to use and join it with a token.
Start the server
Management, edge and Temporal start together in one process.
$ oz0 server start
Create a join token
Give it labels and an expiry. Machines that join with it are let in straight away.
$ oz0 token create --label gpu=a100 --ttl 24h
Install the node
Run the install script on any machine you want in the fleet.
$ curl -sfL https://oz-edge:7443/install.sh | sh
Join with the token
The node checks the server, gets its certificate and starts taking jobs. It only ever dials out.
Example: a team adds its own risk model and a review hook. Edge locks the commit, runs the evals, and rolls it out to 10% of nodes first.
Built on Temporal, because agents fail.
Agent runs are long, expensive and break halfway. Temporal is the open-source engine made for exactly that kind of work, so we built on it instead of reinventing it.
It is MIT-licensed and written in Go, so it ships inside the server. Rather not run it yourself? Point Orchestrator Zero at your own cluster or at Temporal Cloud.
Embedded in the server
Your own cluster
Temporal Cloud
Durable execution
A crash, a deploy or a lost node never throws away a run. It continues after the last finished step.
Timers and signals
A run can wait days for a human approval and hold no machine while it waits.
Task queues
Each job lands on a node that has the right agent and capabilities.
Child workflows
Agents hand work to other agents on other machines, under one budget.
Worker Versioning
New agent versions roll out while runs are in flight, without breaking the ones already running.
Schedules
Recurring jobs keep firing, even while management is down.
Others cover part of it. Orchestrator Zero covers all seven.
Durable runs on machines you own, run as a fleet from a control plane you host, with no inbound ports, budgets that stop a run and tenants built in.
How Orchestrator Zero compares with other agent platforms
From each product's public documentation, 2 October 2026. Partial means part of the capability, or only in a paid tier. Not documented means we found nothing either way.
And beyond the table
Plugins in any language
MCP for tools, gRPC for hooks and harnesses, installed from any git repo.
Five gates on every agent
Contracts, policies, approvals, evals and quality gates.
Your code stays on your nodes
Servers and Temporal only coordinate. Agents and tools run on the machines you choose.
A neutral core
Claude first, any model through one gateway, nothing vendor-specific built in.
Meet Rev
Every job leaves a trail of light.
In Nordic folklore the northern lights are sparks from an arctic fox’s tail as it runs across the snow. In Finland they are still called revontulet: fox fires.
Rev is our fox. A small arctic fox with an aurora for a tail, it runs from machine to machine and lights up the sky with every job it finishes.
Name
Rev, from räv, Swedish for fox
Ears
Small and round, like a real arctic fox
Tail
Pure aurora
Home
Every machine you own
Free for private use.
Self-hosted on your own machines. Companies run it under an enterprise agreement.