Open Managed Agent RuntimeDeveloper PreviewApache-2.0

The open runtime for managed agents

Run any harness on any model. Govern every call from outside the agent, where the agent cannot edit the rules. Keep a signed record of everything it did.

The problem

Agents are a new kind of workload.

They run untrusted code against production systems, for hours, and they have to survive a restart. The unit is not a request — it is a session.

warnstop
Cost

Nobody can say which agent spent what.

Agents spend in bursts, across providers, on credentials issued to individuals, so the bill arrives aggregated and late.

AGENTrefVAULT
Control

Per-tool permissions can't express the limits that matter.

They cannot say “stop once this session has spent $25”, and cannot tell rm -rf ./build from rm -rf /.

modelsmallfrontierharnessClaudeCodex
Choice

Models and harnesses are commoditizing. Switching them is not.

Each agent is built against one harness and one model, so next month's better or cheaper option means a rebuild, not an edit.

Open at every layer

Any harness. Any model. Governance you control.

Most platforms bind you to one framework, one harness, one model and their idea of safe. Orca is an open, declarative runtime that governs agents from outside the harness, where they cannot bypass it.

Any harness

Run the harness you already use, and swap it with a config change.

  • Claude Agent SDKNow
  • Claude CodePreview
  • CodexNow
  • PiNow
  • Bring your own harnessPreview

Any model

Route to any provider, and switch models without touching agent code.

  • AnthropicNow
  • OpenAINow
  • Azure OpenAINow
  • BedrockNow
  • VertexNow
  • OpenAI-compatibleNow

Governance

Guardrails that only tighten, credentials held at the gateway, a signed record.

  • Guardrails (allow/ask/deny)Now
  • Credential vaultNow
  • Session tokens (TTL)Now
  • MCP egress controlNow
  • Signed tapeNow
  • Session budgetsNow
Architecture

Declare an agent. The engine runs it.

The loop, the isolation, the credentials, and the record of everything it did — one runtime, driven through the API, the CLI or the SDKs.

Agent Engine architecture: clients reach the Registry, which works with a Harness Server that runs the agent loop.
  • SDK, CLI and UI clients reach the Registry.
  • The Registry works with the Harness Server. It never runs agent code itself.
  • The Harness Server executes built-in tools in a Sandbox.
  • The Harness Server and the Sandbox both reach the AI Gateway, which holds the credentials.
  • The AI Gateway calls MCP tool servers and LLM providers on their behalf.
  • Transcripts and audit logs land in the Event Store, backed by Kafka, Postgres or Pulsar.
Where Orca fits

Build and test with your tools. Run and govern the agents with Orca.

Most of the agent lifecycle already has good tooling. What has been missing — and mostly closed — is the runtime in the middle: the thing that actually runs an agent, and governs it while it runs.

The agent development lifecycle, with the runtime at its centre: Orca runs and governs the agents; you build, test and monitor with your own tools.
  • Build, test and monitor happen in the tools you already use.
  • Run and govern are provided by Orca.
  • The Orca Agent Engine sits at the centre as the runtime.
  • Orca exports to your evaluation and observability platforms; it does not ask you to migrate to it.
How it fits together

Run it. Govern what leaves. Keep the record.

Agent Engine runs the session. AI Gateway governs what leaves it. Eval & Observability exports what happened.

Run

Agent Engine

The declarative runtime for any harness and any model.

Learn more
Govern

AI Gateway

Guardrails that hold, and a record you can verify.

Learn more
Record

Eval & Observability

Session logs as OpenTelemetry traces, in your own stack.

Learn more