What OpenWork for teams governs, and how open-source Kortix answers a security review
OpenWork for teams adds Den, a control plane over a desktop app where agents work on local files. A security review asks how those agents are governed. Kortix is the open-source AI Operating System: every session runs on its own isolated machine, and session work reaches main only through a change request a person reviews.
One repo scopes what every agent may touch
The agents block in kortix.yaml sets governance only: which agents may launch, and what each one may touch.
agents: kortix: file: agents/kortix.md connectors: all secrets: all kortix_permissions: all skills: all release-bot: file: agents/release-bot.md connectors: [github] kortix_permissions: [project.gitops.push] secrets: [GITHUB_AGENT_TOKEN]The release-bot agent reaches only GitHub, only the push capability, and one secret.
Team control, side by side
Kortix governs the sessions themselves; OpenWork manages desktop installs and seat access.
Open source
- KortixOur recommendationYesYes
- PartlyYes for the app and core; the control plane is subscription-based
Where agents run
- KortixOur recommendationOne isolated sandbox per session, on its own branch
- Each member's own computer; a hosted cloud computer is an optional add-on
Permissions
- KortixOur recommendationPer-resource permissions for people and agents
- Published skills, plugins and model access per member or team
Human approval
- KortixOur recommendationMerge is default-deny for agents; Allow, Ask or Block on each call
- Desktop and access policies set in the control plane
Identity
- KortixOur recommendationSAML 2.0 single sign-on and SCIM 2.0
- SAML SSO on Team, SCIM on Enterprise
Audit
- KortixOur recommendationEvery action is recorded; reading the log depends on the plan
- An audit trail and usage analytics on Enterprise
OpenWork rows come from openworklabs.com/enterprise and the OpenWork repository at github.com/different-ai/openwork. Kortix rows come from the Kortix docs. Checked October 2026.
What OpenWork for teams is
OpenWork is a free, open-source desktop app for macOS, Windows and Linux where AI agents work on local files. It is built on OpenCode and reaches any model through your own keys, a ChatGPT sign-in or a local model. Teams add OpenWork Den, the control plane that manages OpenWork across a team or a company. Den provisions inference, manages members, teams and access, sets desktop policies, and publishes skills and plugins through marketplaces. The agents keep working where the app runs, on each person's computer, and OpenWork Enterprise adds a managed private instance or a self-hosted control plane, SSO and SCIM, an audit trail exportable to a SIEM, and usage and spend analytics.
Desktop-first control plane, server-first platform
OpenWork's local-first design is the strength of the desktop app, and it shapes how a team is governed. The controls center on what reaches each person's computer: which skills, plugins and model access a seat receives, which app versions the team allows, and which member may use which model. A hosted cloud computer lets work run off a laptop as an optional add-on.
Kortix starts at the platform. One isolated sandbox per session. Each session has its own isolated machine and branch. Thousands of agents run in parallel on one config, each on its own cloud computer. Run it on Kortix Cloud, in your VPC, or on your own on-prem network. Self-host is free. Any model provider with your own keys. The governance sits in the platform rather than in the desktop app, so a rule applies to a session no matter which person, agent or trigger started it.
What a security review asks, and how Kortix answers
A team that rolls agents out across a company gets asked four questions: what an agent may touch, who approves what it does, what identity, audit and secrets look like, and where the configuration lives. Kortix answers each with a mechanism a reviewer can read.
Permissions for people and agents
The first question is what an agent may touch. Per-resource permissions for people and agents. Roles, groups, and an audit trail. That is the access model a reviewer checks, and it is documented in full (Read the docs).
Approval on every call and every merge
The second question is who approves what an agent does. Actions are always_run, require_approval, block, shown as Allow, Ask, Block. Approval holds the call; the agent's turn pauses and resumes. Approval gates you set. Off until you set them. At the other end of a session, session work reaches main through a change request. Merge is default-deny for agents (Read the docs).
Identity, audit and secrets
The third question covers who an agent is, what it did, and what it holds. SAML 2.0 single sign-on and SCIM 2.0. Every action is recorded. Reading, exporting and streaming the audit log depend on the plan. Secrets are encrypted at rest with a key per project. Connector credentials are brokered server-side and never enter the machine, and a scoped connector reaches 3,000+ apps in a click, plus MCP, OpenAPI, Postman, GraphQL and raw HTTP (Kortix).
One repo for the whole configuration
The fourth question is where the configuration lives. Kortix is the open-source AI Operating System: your agents, their skills, your company memory, and every connector in one git repo you own. An agent can edit its own configuration on its session branch and propose the change. A person approves it. The code is public at Kortix on GitHub, so a reviewer reads what the team runs (Read the docs).
Frequently asked questions
Can a team run OpenWork's control plane on its own infrastructure?
Yes. OpenWork documents a self-hosted control plane, and a managed private instance is the alternative for a team that does not run it. The desktop app itself stays on each person's computer (OpenWork Enterprise).
Which models can each product run?
OpenWork works with more than 50 providers through your own keys or local models. Kortix takes any model provider with your own keys. Or the ChatGPT plan you already pay for. Or sign in with your OpenCode Console account for OpenCode Zen and Go.
What does a Kortix rollout cost?
Free includes 200 credits each month for sandbox compute and 1 project. The team plan is $40 per seat per month and includes 2,500 pooled credits per seat. Enterprise adds SAML SSO, SCIM directory sync, advanced RBAC, audit logs, an SLA and a DPA, and Cloud, VPC or on-prem deployment (Kortix pricing, checked October 2026).
How does Kortix keep an agent from merging its own work?
Session work reaches main through a change request. Merge is default-deny for agents, and a session can never merge a change request it opened itself.
Run your agent rollout from one repo you own.
Every session is isolated, tool calls can be set to Allow, Ask or Block, and work lands through a change request.
Open source · Any model, your keys · Self-host, VPC, or on-prem