AgenticOS Team Agent Workspace

Build and govern shared team agents on infrastructure you control, with centralized access, budgets, and approvals.

Stars
★ 61
Last updated
today
License
Apache-2.0
Primary language
Python

At a glance

How it runs
Self-hosted serviceWeb appDesktop app
Works with
Universal · cross-platformOpenAI API · Claude APICodex · Claude Code (Partial support)
Cost
Free software; you pay for model usage
Setup effort
Medium · a few setup steps
You'll need
Docker ComposePostgreSQL with pgvectorRedis or Valkeymodel provider access or local model runtimeShell / CLINetwork accessLocal filesystemMCP Server
Typical use
A finance team wants an agent to analyze a sales CSV, chart revenue by region, and share the findings with colleagues.
Not a fit if
  • Teams requiring native MFA, SAML, or SCIM
  • Organizations needing Kubernetes deployment or scale-out
  • Teams requiring budgets that cannot be exceeded by parallel runs
Source review
68/100 · Some gaps

What does this agent do, and when should you use it?

AgenticOS is an Apache-2.0, self-hosted platform where teams configure an agent's instructions, model, and tools in a browser, then publish it for colleagues. Agents run on Pydantic AI and pydantic-ai-harness and can be reached through web chat, Slack, Mattermost, Telegram, a website widget, hosted pages, the HTTP API, or WebSocket. They connect to company documents and apps, work with files, run Python or JavaScript, and produce answers, charts, documents, or interactive pages. FastAPI, Next.js, PostgreSQL with pgvector, Redis, and Prefect make up the platform; code execution runs in containers started by sandboxd. The platform deploys with Docker Compose on an organization's own host and supports 27 model providers as well as local runtimes such as Ollama and vLLM.

Builders configure an agent's instructions, model, and registered tools in the browser, then publish a version for colleagues. With the relevant capabilities and container sandbox enabled, an agent can read uploaded or synced files, run shell commands, Python, or JavaScript, and call connected business tools through MCP. It can retrieve documents from a knowledge base and answer with citations. Users start runs from web chat, configured messaging channels, a website widget, the API, or WebSocket; schedules and events can also trigger runs. The platform applies roles, budgets, and approval policies, records the agent version, tool calls, usage, and cost, and can publish results as interactive pages with stable links and version history.

  1. A finance team wants an agent to analyze a sales CSV, chart revenue by region, and share the findings with colleagues.
  2. Support staff need answers from an internal handbook and want to check the cited source documents.
  3. An engineering team wants an agent to inspect a repository, run commands, or prepare reports while retaining a record of each run.
  4. Researchers need a scheduled workflow or a run triggered by a new GitHub issue, with results published for colleagues.
  5. IT administrators need department-based sharing, organization and per-agent budgets, and human approval for sensitive tool calls.

How do you install or deploy this agent?

On macOS or Linux, have Docker Compose and access to a model provider. The quickstart script prompts for a model provider and key, login details, and an organization name, then starts a deployment with a working agent. Windows users can run it in WSL2 with Docker Desktop's WSL2 integration enabled.

How do you use this agent?

After installation, open http://localhost:3000 and sign in with the credentials chosen during setup. The document-assistant walkthrough shows how to upload a handbook, ask questions, and check cited sources. Developers can call a published agent's HTTP API as an authenticated member, or stream tokens over WebSocket.

What are this agent's strengths and limitations?

Pros
  • Supports 27 model providers and documents local model paths such as Ollama and vLLM, giving organizations choices for data boundaries.
  • Combines roles, department groups, per-agent and organization budgets, sensitive-tool approvals, and a verifiable hash-chained audit log.
  • Skills, context, and knowledge bases can be reused across agents; knowledge-base answers can include document citations.
  • Agents can be published to messaging channels, websites, the HTTP API, and WebSocket under one platform.
Limitations
  • Teams must operate the Docker Compose deployment and manage updates, backups, and recovery of the vault key.
  • Budgets can be exceeded by parallel runs, and the platform has no Kubernetes manifests or scale-out support.
  • There is no native MFA, SAML, or SCIM; authentication relies on an external identity provider.
  • Source permissions such as SharePoint ACLs are not mirrored per user, so connected credentials must be scoped carefully.

How does this agent compare with similar options?

The README compares AgenticOS with ChatGPT Enterprise, Copilot Studio, and n8n: it runs on company infrastructure, supports 27 model providers, and publishes agents for organizational use rather than individual assistant seats. Compared with n8n, it starts from the agent rather than a visual workflow canvas; the README says teams may use both. The docs also discuss the self-hosted builder Dify and coding agents such as Claude Code.

Key facts side by side with the most closely related agents.

Agent Source review Form / cost Stars Updated Language Full support on
AgenticOS Team Agent Workspace This agent 68 · Some gaps Self-hosted serviceFree + model costs ★ 61 today Python OpenAI API · Claude API
Self-hosted AI Starter Kit 50 · Major gaps Self-hosted serviceFree ★ 15k 2mo ago — —
Hector Agent Runtime 55 · Major gaps CLIFree + model costs ★ 60 5mo ago Go OpenAI API · Claude API
AutoCVE Security Audit Platform 44 · Major gaps Self-hosted serviceFree + model costs ★ 1.4k 1mo ago Python —

How does FollowAgents rate this agent?

FollowAgents source review · FARS-2.1
Some gaps
68/ 100 5-point scale 3.4 / 5
Trust 17/29
Reliability 8/14
Adaptability 15/18
Convention 14/18
Effectiveness 10/13
Verifiability 4/8
Why each dimension lost points
Trust17 / 29 · 2.9/5

The README describes roles, resource sharing, budgets, human approval for sensitive tools, sandboxes, a credential vault, and audit records, supporting least privilege and confirmation at 2; the security notes list hardening steps, backups, and limitations but do not provide complete evidence for the controls, so neither receives full marks. The README describes optional models, parsers, tools, and some data flows, earning 2 for transparency; it also says logs lack automatic PII redaction and notes an external MCP service, so sensitive-data handling earns 2. SECURITY.md recommends dependency audits in CI but the supplied evidence shows neither results nor dependency-lock evidence, earning 1 for dependency security. Scheduled tasks, webhooks, chat channels, and tools can cause external effects; configuration and approval controls are described, but withdrawal and recovery controls are limited, so external effects and rollback each earn 2. Version history supports rollback at 2. A security reporting email is provided, but publisher identity is unverified, so source attribution earns 1.

Reliability8 / 14 · 2.9/5

The CI workflow describes multiple test suites, migrations, coverage gates, and timeouts, supporting dependency availability and failure messaging at 2 each. However, the workflow says AI review is no longer triggered on pull requests, and the README's enterprise SSO claims conflict with SECURITY.md, which says only Google OAuth is available and SAML/OIDC are not; self-consistency earns 1.

Adaptability15 / 18 · 4.2/5

The materials identify enterprises, teams, security staff, developers, and several work scenarios clearly, earning 3. Capabilities depend on the model, enabled tools, and configuration, and trigger types are listed, but the supplied material does not fully define boundaries or trigger conditions; these earn 2 each. Docker Compose, self-hosting, Postgres, multiple model providers, and local models support varied environments, earning 3 for environment fit.

Convention14 / 18 · 3.9/5

The README is well organized and provides a quick start, product tour, integrations, tutorials, and FAQ, earning 3 for information architecture and examples. Installation notes cover Docker Compose, resource needs, WSL2, a check-only command, and manual-install guidance, but detailed steps are linked externally, earning 2. Product terminology and multilingual documentation show some consistency, but the supplied evidence cannot establish repository-wide naming stability, earning 2. SECURITY.md lists limitations including MFA, SSO, and log redaction, earning 2. The complete license text matches Apache-2.0 metadata, earning 3. Release and version-restoration references are present, but the supplied material has no changelog; maintenance responsibility is named in the README, but identity is unverified. Versioning and maintenance each earn 2.

Effectiveness10 / 13 · 3.8/5

The materials describe run records, source citations, shareable artifacts, and dashboards, supporting ordinary-use output usability at 2. Combining agent building, governance, integrations, and run auditing offers clear marginal value, earning 3. Deployment requires operators, models, infrastructure, external services, and ongoing maintenance; costs are described but not quantified comparatively, so cost-benefit earns 2.

Verifiability4 / 8 · 2.5/5

Feature and control claims have some support across the README, security notes, CI workflow, and test descriptions, earning 2 for traceability. The supplied materials do not systematically corroborate product claims, and the SSO statements conflict, so cross-source corroboration earns 1. The README distinguishes demo data from benchmarks and notes that some integrations require configuration, but many capabilities remain documentation claims in the supplied evidence; fact-inference separation earns 2.

Risks and how to mitigate them
  • The README claims OIDC single sign-on for Entra ID, Okta, Keycloak, and others, while SECURITY.md says there is no SAML/OIDC beyond Google OAuth; verify the actual support before deployment.
  • SECURITY.md says logs have no automatic PII redaction and recommends configuring rate limits, key rotation, HTTPS, and database backups; operators must implement these measures.
  • MCP registry entries are publisher metadata and integrations require separate setup and permission review; the materials also say Outlook connects through an external MCP service.
Evidence confidence: Low Reviewed Oct 09, 2026 Reviewed revision b62bb4e26feb New commits since this review; the score may not cover them
See the full review method →

FAQ

Does the software itself cost money?
It is Apache-2.0 software for commercial use and private deployment. You still pay for the infrastructure you run and any model providers or external services you choose.
Can it run with local models only?
Yes. Configure Ollama, LiteLLM, or an OpenAI-compatible server such as vLLM or LM Studio, and use local embedding models and document parsers. Review each configured model, parser, and tool for its data flow.
How do budgets and approvals work?
Monthly organization and per-agent budgets are checked before each model request. Sensitive tools can require human approval, and every run is recorded. Parallel runs can still overshoot budgets.
Does it inherit per-user permissions from sources such as SharePoint?
No. The README says source-system permissions are not mirrored per user, so scope the credentials used for each connection to the intended access.
What does a small-team deployment require?
The docs say a single-host Docker Compose deployment runs on 4 vCPU and 8 GB RAM, with two API workers suggested for a team of ten. Someone must own operations, backups, and connected external services.
View on GitHub ↗ Install ↓

Related agents