Enterprise
Run agents on private infrastructure, sign in through your identity provider, decide which agents, models and capabilities may run where, and keep a record of every decision.
Identity and access
Any OpenID Connect provider — Microsoft Entra ID, Okta, Keycloak, Auth0 — plus Google and GitHub.
Role-based access
Owner, admin, manager, developer and viewer, enforced by the API on every operation.
Two-factor authentication
Authenticator apps with recovery codes; audited administrator resets.
Scoped API tokens
One organization, capped at the owner’s role, stored only as a hash.
Governance
Organization, project, worker and task policies for agents, models, concurrency, Git and verification.
Approval gates
Require approval for production environments, pushes or plans.
Install policies, allowed trust levels, blocked permissions and approvals for risky ones.
Audit log
Append-only record of members, roles, settings, secrets (by name), approvals and installations.
Environment profiles
Per-environment variables and secrets, delivered only to the task that needs them and audited.
On Linux and macOS, restrict writes to the project and hide credential folders; optionally cut network.
Deployment
Docker Compose, Kubernetes with Helm and Terraform, or Node.js behind your proxy.
Private networks
Workers connect outbound only; the control plane can run entirely inside your network.
Bedrock, Vertex, Azure OpenAI, local models or any OpenAI-compatible gateway you run.
Signed webhooks, the REST API and orchestration plugins at task hooks.
Certifications
Self-hosted, managed cloud, or something in between.