Robots Atlas>ROBOTS ATLAS
Artificial Intelligence

OpenClaw Enterprise: an MIT-licensed control plane for AI agents

Sir Robot5 October 2026 · 3 min read
OpenClaw Enterprise: an MIT-licensed control plane for AI agents

On 29 September the OpenClaw Foundation released OpenClaw Enterprise, a free control plane for persistent AI agents. It is not a new model but a wrapper: multi-tenancy, security boundaries, lifecycle governance and auditing. Red Hat is folding it into OpenShift and Nvidia is adding the OpenShell runtime for agent isolation.

Key takeaways

  • OpenClaw Enterprise is free and available on GitHub
  • Multi-tenancy, security boundaries, lifecycle and auditing in one layer
  • Docker Compose for local work, Kubernetes for production deployments
  • Red Hat, a founding member, is integrating OCE into OpenShift
  • Nvidia is building the OpenShell runtime for agent isolation

Kubernetes for agents

Its authors describe OCE as Kubernetes for agents — a layer that does not replace the agent but wraps it. A company plugs in its own models, harnesses and sandboxes, and OCE decides who may run what and what ends up in the logs.

OCE starts locally on Docker Compose and runs in production on Kubernetes, entirely on the customer’s own infrastructure. Multi-tenancy lets a single installation serve several teams without blending their permissions.

OpenClaw itself works on a “trusted gateway, untrusted execution, deterministic policy” model, with a local gateway as the control point for sessions, tools, events and channels.

Agent
Agent requests a tool call
Trusted gateway
Local gateway intercepts the request
Does policy allow this operation?
YES
Sandbox executes the operationAllow
NO
Request deniedDeny
Audit
Written to the audit log

The diagram shows what OCE actually is: the agent never touches tools directly, and the decision to run something — plus the record of that decision — sits outside the model.

Who stands behind it

The project is stewarded by the OpenClaw Foundation, an independent nonprofit. Per the project repository on GitHub, OpenAI is a donor rather than an owner. The code ships under the MIT License.

OrganisationRole in the project
OpenClaw Foundationstewards the project, independent nonprofit
OpenAIdonor, not owner — runs an internal OCE pilot
Red Hatfounding member, integrating OCE into OpenShift
Nvidiabuilding OpenShell, a runtime that isolates agents
Amazonbacker
University of Michiganbacker

OpenAI is testing OCE in house. RJ Marsan of its technical staff called the Androidclaw agent’s ability to trace issues and publish fixes “kinda game changing”. Other backers include Amazon, Red Hat and the University of Michigan.

A free layer in a paid category

Agent control has so far been a commercial product. OCE enters that space as self-hosted code with no licence fee. Competition shifts from features to support, integrations and certifications. No date was given for the end of the internal pilot at OpenAI, nor any word on a hosted edition.

Why it matters

An agent without a control layer is a compliance problem inside a company, not a productivity one. OCE targets exactly that barrier: it separates what an agent can do from what it is allowed to run and what gets recorded. An open licence plus swappable models strips model vendors of the leverage that locking companies into a proprietary management layer would give them.

What next?

  • Red Hat is integrating OCE into OpenShift as a founding member of the project
  • Nvidia is building OpenShell, a runtime that isolates agents, as a separate component
  • OpenAI is running an internal OCE pilot with no announced end date

Sources

Share this article