Skip to content
Rush Commerce
AI & Automation3 min read

OpenClaw Enterprise: a free agent control plane, pilot only

OpenClaw Enterprise is an MIT-licensed, self-hosted control plane for persistent AI agents from OpenAI, Red Hat and Nvidia. It is free, and it is pre-1.0.

The OpenClaw Foundation just open-sourced OpenClaw Enterprise, a self-hosted control plane for persistent AI agents, built with OpenAI, Red Hat and Nvidia. It is MIT-licensed and the foundation says it will always be free. That is the headline. The fine print is the part that matters: the foundation itself recommends it for internal pilot workloads, and 1.0 is not out yet.

What actually happened

Per the OpenClaw blog, the September 29 release is a vendor-neutral platform for running long-lived agents on your own infrastructure. The feature list is the governance list: multi-tenancy with hard security boundaries, fine-grained permissions, workload isolation, sandboxing, audit logging, and review of agent actions by a language model. The harness, the model and the sandbox are all meant to be swappable.

The code started inside OpenAI and was donated to the foundation. Red Hat is a co-developer and is piloting it internally. Nvidia contributed its open agent safety platform work; VentureBeat reports that includes the OpenShell runtime for agent isolation. The GitHub repo ships a control plane (OCC) with an HTTP API, a browser console, IAM and audit logging, deployable locally with Docker or Podman plus k3d, or onto Kubernetes with Helm. The foundation says it released early on purpose so users can shape it before a 1.0 planned for later this year.

"Free" covers the software. You still pay for compute, models, storage and the people who run it.

Why a self-hosted agent control plane matters for your business

A month ago, OpenClaw 2.0's own docs said shared sessions were not a security boundary. Our advice was one gateway per role. OpenClaw Enterprise is the project's answer to that gap: tenancy, permissions and isolation as real platform features, not convention. That is the right direction.

It also moves the agent-governance layer to something you own. The alternative is the vendor dashboard: your agent inventory, permissions and audit trail live in someone else's product, on their pricing page. An MIT control plane on your own cluster keeps that record in-house even if you change model vendors next quarter.

But read "pilot" literally. Pre-1.0 means APIs and schemas will move. Do not put customer data or payment credentials behind it yet. Stand it up next to one internal agent, point it at read-only integrations, and check two things: can you answer "which agent did what, with which credential" from the audit log alone, and does a swapped model or sandbox actually work? If yes, you have a migration path when 1.0 lands.

And a control plane only governs agents you register with it. Agents that run outside it stay invisible to it.

Key takeaways

  • OpenClaw Enterprise launched September 29, 2026: an MIT-licensed, self-hosted control plane for persistent agents
  • Features: multi-tenancy, fine-grained permissions, workload isolation, sandboxing, audit logging, LLM review of agent actions
  • Built inside OpenAI, donated to the OpenClaw Foundation; Red Hat co-develops, Nvidia contributed agent safety components
  • The foundation recommends it for internal pilot workloads only; 1.0 is planned for later in 2026
  • The software is free; compute, models, storage and operations are not
  • Pilot it on one internal, read-only agent and test the audit trail before trusting it with customer data

Want agents you can audit without a vendor dashboard? We build agent systems on infrastructure you own, with scoped credentials and a log that answers "who did what" in one query. See how we build them, or tell us which agent you want to pilot first.

Sources: OpenClaw blog, OpenClaw Enterprise on GitHub, VentureBeat.

  • #openclaw
  • #ai-agents
  • #agent-governance
  • #self-hosted
  • #open-source
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.