Control plane, not agent
OpenClaw describes OCE as “Kubernetes for agents”: infrastructure to deploy and manage agents across an organization, not a model or a prescription for how any one agent should think.
The platform includes multi-organization and user management, fine-grained permissions, workload isolation, sandboxes and auditing. Language models can also be used to check agent actions. Its components are replaceable, so companies can choose among models, agent runtimes and sandbox implementations instead of adopting one fixed stack.
OCE can run on a company’s own servers. OpenClaw supports Docker Compose for local development and Kubernetes for internal deployments. The repository also includes OpenClaw Control Plane (OCC), a component for deploying agents and managing their lifecycle. Local installations can use Kubernetes, while production environments can run in existing Kubernetes clusters.
The MIT license permits commercial use, and OpenClaw says the platform will remain free for organizations. Free software does not mean free operations: companies still pay for compute, models, storage and infrastructure management.
OpenAI’s internal test
OpenClaw says OpenAI is running always-on OpenClaw agents with access to its code repositories and plugins. R. Jay Marsan, a member of OpenAI’s technical team, described an internal agent called Androidclaw that works with company context, Git, GitHub and logging systems.
Marsan said Androidclaw can investigate failed builds, find related code changes, trace product problems to incidents and sometimes prepare and apply fixes. He said the agent has spread widely within the company, and that its ability to find causes and publish fixes has changed how teams handle problems.
That example shows why companies want agents—and why managing their permissions is difficult. A bot that summarizes a document may need only read access. An agent investigating production failures or fixing builds could need access to repositories, logs, cloud infrastructure, continuous integration systems, credentials and deployment tools. OCE is aimed at governing that broader access.
Red Hat and Nvidia are working on adjacent parts of the security problem. In 2026, Red Hat is exploring how to run OpenClaw and other agents safely on shared enterprise infrastructure. OpenShift projects separate agents from sensitive credentials using dedicated namespaces, restricted access and credential proxies, while treating the agent process itself as untrusted.
Red Hat, a founding member of the OpenClaw Foundation, says it plans to account for the project’s requirements in its broader AI platform. Those include multi-user agent deployments, identity-based tool filtering and isolation with OpenShell in Kubernetes environments.
Nvidia’s open-source OpenShell runtime puts autonomous agents in isolated environments, denies access by default and keeps audit logs. Its broader Open Agent Safety Platform adds independent monitoring intended to contain agents that act outside permitted rules. OCE sits above mechanisms like these, providing an organizational layer for deploying and governing agents across a company.
Three different bets on control
OCE is not the same kind of product as NanoClaw. NanoClaw is a lightweight alternative to OpenClaw itself, built for personal agents that are easier to study, modify and host. Each agent runs in its own container with a separate workspace and memory, and explicitly connected resources. It supports Slack, Discord, Telegram, email and scheduled tasks.
That makes NanoClaw closer to the runtime layer beneath OCE than to a competing control plane. Its emphasis is simplicity and operating-system-level isolation; OCE’s is centralized management of many agents, users and workloads. In principle, a lightweight runtime such as NanoClaw could sit under an enterprise control plane, but published materials do not describe a specific OCE integration.
RunLayer is a closer comparison. It centrally manages policies, agent identities, runtime security, monitoring and auditing, and supports Claude Code, Cursor, ChatGPT, Codex and enterprise MCP servers. It also offers an MCP gateway and a cloud environment for running agents, and detects unauthorized “shadow AI” tools inside organizations.
RunLayer connects to enterprise identity systems through SSO and SCIM and supports deployment on customer infrastructure. It is a commercial enterprise platform, built to cover a broader AI environment that includes third-party applications, reusable skills and MCP servers. OCE is open-source infrastructure focused on deploying and managing always-on agents. It does not currently offer the same breadth of shadow-AI discovery, return-on-investment analysis or enterprise MCP catalog management.
RunLayer raised $30 million in a Series A round in June 2026 from Felicis and Khosla Ventures, bringing its total funding to $42 million. It names Instacart, Gusto, Opendoor and dbt Labs among its customers. OpenClaw is betting instead on a vendor-neutral control plane that could serve competing runtimes, models and security products.
OpenAI’s Dots and ChatGPT Space are further up the stack. Dots are always-on AI colleagues that can continue tasks after a user closes a chat. Each gets a cloud computer and browser, connects to thousands of apps through OpenAI’s plugin ecosystem, and can communicate through ChatGPT, Slack and Microsoft Teams. ChatGPT Space is a shared workspace where employees, ChatGPT, Codex and Dots can access pages, files, presentations, spreadsheets and project context.
Those products give employees a way to assign work to agents and collaborate with them; OpenAI supplies much of the runtime and infrastructure. OCE is for IT or platform teams managing agents on company-controlled infrastructure. OpenAI plans specialized Dots with corporate accounts, credentials and job responsibilities, and is testing them in procurement, invoice processing, customer support and contract work. Those machine identities need lifecycle management, access controls and audits—the territory OCE and RunLayer address.
I think the interesting distinction is not simply open source versus commercial software. It is who controls the agent’s working environment: OpenAI’s products bundle the employee interface with OpenAI’s cloud and models, while OCE is designed to let companies choose their own components and host the control plane themselves. The products could complement each other, and OpenAI is already testing OCE internally.
Enterprise in name, early in practice
OCE is not yet presented as production-ready enterprise infrastructure. The Foundation recommends it for internal testing, saying developers and organizations should help shape the platform before its planned version 1.0 release later this year. OpenClaw also plans to publish a reference architecture explaining how workload boundaries, sandboxes, model-based checks and permissions fit together.
What I’d want to know is how those controls hold up when agents need real access to sensitive systems—and how much operational work customers must do to make them reliable. The announcement lays out the pieces, but the detailed security architecture is still to come.
That gap matters because always-on agents are already being tried in sensitive workflows, while the systems for governing them are less mature than those used for human accounts, cloud workloads and conventional applications. The emerging market spans lightweight isolated runtimes, commercial platforms that govern multiple AI tools, and open control planes for fleets of agents. If OpenClaw’s bet works, the decisive infrastructure may be the layer companies trust to let agents act—not the model that gives them their smartest answer.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X