Skip to content

Mission control for AI agents

Run every agent as a durable workflow on the machines you already own. Routed, metered and kept inside the lines.

Your agents, on your machines, doing real work.

Orchestrator Zero runs AI agents on the machines you own, in every site and every network, and keeps them in line. Package an agent once and any machine in the fleet can run it. Every step is saved, every model call is metered and nothing risky happens without a yes.

How teams use it

  1. Join your machines

    Servers, laptops, GPU boxes and devices in every site, with one command each.

    oz0-node join --token …
  2. Install agents from Git

    Agents, tools and skills come as plugins, rolled out to the nodes that need them.

    oz0 plugin install https://github.com/acme/ops-agents
  3. Start jobs

    From the CLI, your apps or a schedule. Follow them live and see what each one cost.

    oz0 run outage-triage "Link down in got-2"

How it works

  1. Every machine is a node

    Laptops, GPU workstations and cloud VMs join with one command. They only dial out, so there is nothing to open in a firewall.

    • A small Go supervisor keeps the agent runtime and every plugin running, and restarts them if they crash.
    • Labels such as gpu=a100 decide which jobs a node takes.
    • A blocked node is refused on its very next call.
    • dev-laptopagent=pr-reviewer
    • gpu-boxgpu=a100
    • vm-eu-northregion=eu-north
    edge
    Each node opens the connection itself. The machine needs no inbound ports.
  2. The edge is the only door in

    Nodes talk to the edge and nothing else. It proxies Temporal, serves the runtime API and meters every model call.

    • Every call is checked over mTLS against the registry.
    • The model gateway prices each call and stops a job at its budget.
    • Start jobs over REST or gRPC, with clients for Python, TypeScript and Go.

    node-7f3acalls the model gateway

    1. Certificate is validmTLS
    2. Node is allowedregistry
    3. Job is within budget$1.62 left
    • Temporal
    • Model gateway
    • Runtime API
    Example call. Every request from a node passes the same checks before it goes anywhere.
  3. Servers keep every run durable

    Each agent run is a Temporal workflow: embedded, on your own cluster or on Temporal Cloud. It survives crashes and can wait for days.

    • Each model and tool call is its own step, so a run picks up after the last finished one.
    • Waiting for a human approval holds no machine.
    • Schedules keep firing even when management is down.
    node-7f3anode-21c9planrun_testsnode lostresumereviewdone
    Example run. The second node starts after the last finished step, so no work is repeated.
  4. Management stays above it all

    Web UI, registry, certificates, rollouts and cost reports. It runs on its own, so it can go down without stopping a single job.

    • Its certificate authority issues node certificates that renew every 24 hours.
    • New plugin versions roll out to a few nodes first, then to the rest.
    • Secrets are never decrypted here, only at the edge and on the node that needs them.

    Cost by agent, last 7 days

    Example data

    pr-reviewer
    $41.80
    test-runner
    $23.15
    code-explainer
    $9.40
    triage-bot
    $6.25
    $80.60 across 4 agents this week. Budgets stop a job before it overspends.

Built on Temporal The open-source durable execution engine. Every agent run is a Temporal workflow, so it survives crashes and can wait for days. .Works with the tools your team already uses.

Start jobs from wherever work begins.

People use the web UI and the CLI, your apps call the runtime API, and other services post a webhook. Every way starts the same durable job, with the same budget, approvals and history.

Web UIhttps://<server>:8443

Approvals 2 waiting

  • change-runner wants junos.commit

    site got-2 · waiting 4m

    ApproveDeny

  • containment wants host.isolate

    fin-ws-042 · waiting 12m

Run pr-reviewer

{"repo": "acme/api", "pr": 42}

$2.00

Run

From zero to a fleet in four commands.

Start one server. Then install the node on every machine you want to use and join it with a token.

  1. Start the server

    Management, edge and Temporal start together in one process.

    $ oz0 server start
  2. Create a join token

    Give it labels and an expiry. Machines that join with it are let in straight away.

    $ oz0 token create --label gpu=a100 --ttl 24h
  3. Install the node

    Run the install script on any machine you want in the fleet.

    $ curl -sfL https://oz-edge:7443/install.sh | sh
  4. Join with the token

    The node checks the server, gets its certificate and starts taking jobs. It only ever dials out.

    $ oz0-node join --server oz-edge:7443 --token K10b4e…::jt_7Qx…
  5. The machine is part of the fleet and picks up jobs that match its agents and labels.

No token? Approve by hand
The node waits until you let it in. oz0 node accept node-7f3a
Remove a machine
It is refused on its very next request. oz0 node block node-7f3a
Upgrade safely
Canary rollouts with health and quality gates, and automatic rollback.

Agents stay inside the lines.

You build the agents as plugins. The platform makes sure they behave, wherever they run.

Durable by default

Every run is a Temporal workflow. If a node dies, another node with the same agent picks it up where it stopped.

Example run: review-pr

  1. plannode-7f3adone
  2. run_testsnode-7f3adone
  3. heartbeatnode-7f3alost
  4. resumenode-21c9resumed
  5. reviewnode-21c9done

Five gates

A worse version of an agent never reaches production.

  • ContractsInputs and outputs checked against schemas
  • PoliciesOnly declared tools, with budgets and step limits
  • ApprovalsRisky tools wait for a human to say yes
  • EvalsTest cases run before every rollout
  • Quality gatesA worse version stops and rolls back

Metered to the token

Token and cost on every model call. A job tree shares one budget, with cost per branch.

review-pr$0.38 of $2.00
  • └ pr-reviewerlaptop$0.21
  • └ test-runnerGPU node$0.12
  • └ code-explainercloud VM$0.05

Routed by capability

A job lands on a node with the right agent and hardware.

agent=pr-reviewergpu=a100region=eu-north

Plugins in any language

Tools are MCP servers and hooks speak gRPC, so any language with an SDK for either works. Install from any git repo and ref.

  • Python
  • TypeScript
  • Go
  • Rust

Any model, Claude first

Claude, OpenAI and local models go through one gateway. Claude Agent SDK, Codex and OpenCode plug in as harnesses.

Pydantic AIClaude Agent SDKCodexOpenCodeMCP tools

Your Temporal, your call

Run it embedded in the server, point at your own cluster or use Temporal Cloud. The same plugins and nodes work on all three.

Tenants and central secrets

Secrets are stored centrally and only decrypted at the edge and on the node that needs them.

Build it in. The core stays the same.

Everything specific to your company ships as a plugin: a git repo with one manifest. Write it in any language that speaks MCP or gRPC.

  • Python
  • TypeScript
  • Go
  • Rust
  • and more
Tools
MCP servers, your own code or any existing package
Agents
A YAML file: instructions, model, tools and limits
Skills
SKILL.md folders that work across agent tools
Harnesses
Claude Agent SDK, Codex and OpenCode as adapters
Hooks
Allow, deny, change or escalate any tool or model call
Flows
Declarative steps that chain tools, agents and approvals
Evals
Test cases that gate every install and rollout
Apps
Anything on top, through the runtime API
oz0-plugin.yaml
# oz0-plugin.yaml
apiVersion: oz0/v1
name: risk-tools
version: 1.4.0
runtime: python          # python | node | go | binary
requires:
  secrets: [RISK_API_KEY]
tools:
  - id: risk
    mcp: ["python", "-m", "risk_tools.mcp"]
    requires_approval: [risk.override]
  - id: fetch
    package: pypi:mcp-server-fetch   # an existing package, no code
agents: [agents/credit-reviewer.yaml]
skills: [skills/]
hooks:
  - on: pre_tool_call
    match: { tools: ["risk.override"] }
    on_timeout: escalate
evals: [evals/]
$ oz0 plugin install https://github.com/your-org/risk-tools --ref v1.4.0 --canary 10%

Example: a team adds its own risk model and a review hook. Edge locks the commit, runs the evals, and rolls it out to 10% of nodes first.

Built on Temporal, because agents fail.

Agent runs are long, expensive and break halfway. Temporal is the open-source engine made for exactly that kind of work, so we built on it instead of reinventing it.

It is MIT-licensed and written in Go, so it ships inside the server. Rather not run it yourself? Point Orchestrator Zero at your own cluster or at Temporal Cloud.

  • Embedded in the server
  • Your own cluster
  • Temporal Cloud
Durable execution
A crash, a deploy or a lost node never throws away a run. It continues after the last finished step.
Timers and signals
A run can wait days for a human approval and hold no machine while it waits.
Task queues
Each job lands on a node that has the right agent and capabilities.
Child workflows
Agents hand work to other agents on other machines, under one budget.
Worker Versioning
New agent versions roll out while runs are in flight, without breaking the ones already running.
Schedules
Recurring jobs keep firing, even while management is down.

Others cover part of it. Orchestrator Zero covers all seven.

Durable runs on machines you own, run as a fleet from a control plane you host, with no inbound ports, budgets that stop a run and tenants built in.

How Orchestrator Zero compares with other agent platforms
ProductAny machine you ownDurable runsFleet operationsSelf-hosted control planeNo inbound portsBudgets that stop a runTenants built in
Orchestrator Zero Yes Yes Yes Yes Yes Yes Yes
Windmill Yes Yes Tags; groups in Enterprise Yes Yes Metered, no cost stop 3 workspaces free
Temporal Agent HarnessExperimental Yes Yes Worker list, no machine join Yes Yes Tokens counted, no budget Namespaces, access is yours
Hatchet Yes Yes Labels, no version rollouts Yes Yes Not documented Yes
AgentField Yes Re-runs, resume is manual Yes Yes Calls into agents Caps for some harnesses Team boundaries
OpenClawPersonal and team assistant Yes Best-effort resume Yes Yes Yes Estimates, no cost cap One boundary per gateway
LangSmith DeploymentFormerly LangGraph Platform Enterprise plan Yes Deployments, no routing Enterprise plan Server takes requests Caps in cloud beta Yes
n8n Yes Manual retry No label routing Yes Yes Not documented Projects, paid plans
Kagent1.0 is in alpha Kubernetes only Lost if its node dies Kubernetes pools Yes Traffic routed in Tokens traced, no budget Auth in Enterprise
Managed cloudsAgentCore, Foundry, Gemini Enterprise Their cloud only No step-level resume No No Requests pushed in Token quotas only Per-user sessions

From each product's public documentation, 2 October 2026. Partial means part of the capability, or only in a paid tier. Not documented means we found nothing either way.

And beyond the table

Plugins in any language
MCP for tools, gRPC for hooks and harnesses, installed from any git repo.
Five gates on every agent
Contracts, policies, approvals, evals and quality gates.
Your code stays on your nodes
Servers and Temporal only coordinate. Agents and tools run on the machines you choose.
A neutral core
Claude first, any model through one gateway, nothing vendor-specific built in.

Meet Rev

Every job leaves a trail of light.

In Nordic folklore the northern lights are sparks from an arctic fox’s tail as it runs across the snow. In Finland they are still called revontulet: fox fires.

Rev is our fox. A small arctic fox with an aurora for a tail, it runs from machine to machine and lights up the sky with every job it finishes.

Name
Rev, from räv, Swedish for fox
Ears
Small and round, like a real arctic fox
Tail
Pure aurora
Home
Every machine you own

Free for private use.

Self-hosted on your own machines. Companies run it under an enterprise agreement.

Private

Free

For personal projects, homelabs and learning.

Enterprise

By agreement

For companies running agents in production. A commercial licence and direct support from the team that builds it.

The northern lights over northern Europe at night, seen from the International Space Station, with city lights below.

Bring every agent into orbit.

Start with one server and the machines you already have.