0x00 OO_INIT APPROVED OPS AUDIT:ON SECRETS:REFS
Private workspace for AI agents / staging active

OpenOrange Private AI workspace

Run agents, collaborate in Code, inspect every request, understand model and service usage, and keep access, privacy, and control in the same place.

OpenOrange product sequence

// one connected product
Workspace
Agents
Code
Usage
Control
Services
OpenOrange - Workspace

$ openorange open private workspace

Give each team one private place for users, agents, apps, chat, models, services, requests, and billing.

01 OpenOrange - Workspace
02 OpenOrange - Agents
03 OpenOrange - Code
04 OpenOrange - Usage
05 OpenOrange - Control
06 OpenOrange - Services
// product proof

One product, from daily work to the full picture.

The current workspace, active OpenOrange Code work, and incoming runtime integrations read as one coherent product while keeping current and incoming capabilities clear.

01 available workspace

Work in OpenOrange

Run agents, collaborate in chat, inspect requests, and understand model and service usage from one team workspace.

$ workspace
02 in review

Build in OpenOrange Code

Share coding projects and history while isolated sessions handle execution, forks, queues, handoff, models, and GitHub workflows.

$ openorange code
03 integrations underway

Bring the right agent

Use OpenClaw now, then add Hermes, IronClaw, and specialized runtimes as their integrations land.

$ runtime adapters
surface state proof
workspace private by team Users, agents, apps, chat, models, services, billing, and requests share one clear instance boundary.
agent chat context + approvals Chat exposes runtime identity, streaming, queues, context usage, tool decisions, and session cost in the same conversation.
code projects + sessions OpenOrange Code is in review with shared projects, isolated sessions, durable queues, forks, writer handoff, model choice, and per-user attribution.
runtimes open, not locked OpenClaw runs today; Hermes and IronClaw are coming through explicit runtime integrations rather than product forks.
usage models + services Requests, tokens, cache, spend, search, mail, connectors, reliability, and limits remain attributable.
control policy + privacy Access grants, model limits, tool decisions, redaction state, contextual approvals, and audit history stay attached to the work.

OpenOrange system position

// system spec

Everything your team needs to run agents well.

OpenOrange stays simple: a private workspace, multiple runtimes, collaborative Code, connected services, clear usage, and controls that stay close to the work.

01

Private workspace

One dedicated OpenOrange instance for each team.

Users, agents, apps, flows, API keys, chat, Brain, models, services, billing, and requests live together without collapsing runtime data into a central SaaS account.

[users][agents][chat][requests]
02

Agent runtimes

Choose the runtime that fits the work.

OpenClaw is integrated today. Hermes and IronClaw are on the way, with runtime cards and adapters keeping identity, chat, channels, health, and usage consistent across them.

[openclaw][hermes][ironclaw][custom]
03

OpenOrange Code

Collaborative coding agents inside the same private workspace.

Teams share projects, models, configurations, sessions, history, prompt queues, forks, and writer handoffs. Each session still runs in an isolated OCI container with its own toolchain.

[projects][sessions][sandboxes][github]
04

Usage and observability

See what every person, agent, model, and service consumes.

Model spend, tokens, cache, requests, search, mail, connectors, latency, reliability, and limits stay attributable instead of disappearing into provider dashboards.

[models][services][cost][health]
05

Access, privacy, and control

Controls appear where people need them, not as a separate product.

Manage user grants, model policy, limits, tool decisions, redaction, local secret references, contextual approvals, and attributable audit history from the private instance.

[access][policy][privacy][audit]
06

Apps and services

Useful capabilities around every agent runtime.

Connect apps, flows, browser access, search, mail, and other services while keeping provider state, activity, latency, reliability, and accounting visible.

[apps][search][mail][connectors]
// FAQ

FAQ

Frequently asked questions

OpenOrange is a private workspace where a team runs AI agents, collaborates in chat and Code, controls access and models, and understands requests, services, and spend.

A private instance brings users, agents, projects, chat, access, requests, usage, and billing views together. Agent runtimes keep their own execution state, memories, media, and local data.

Secrets, sessions, memories, media, caches, runtime databases, overlays, and raw logs stay on the instance or runtime host. OpenOrange works with scoped credentials, references, redacted observations, and attributable request metadata.

OpenClaw is integrated today. Hermes and IronClaw integrations are on the way, and the runtime boundary is explicit so specialized or custom agents can join the same workspace without pretending every runtime behaves identically.

Raw payloads do not need to become control-plane data. Request traces can preserve actor, route, model, token, cost, cache, redaction state, and audit context while sensitive contents stay local or redacted.

No. Ordinary work stays direct. Instance policy can allow, ask, or deny sensitive capabilities, so approval appears only when it adds value while attributable audit history remains available.

A private instance includes its own workspace, users, agents, chat, apps, flows, API keys, Brain, model access, services, request history, usage, billing views, privacy controls, and account settings.

Token values, provider keys, registry credentials, and channel credentials stay in local secret files or secret backends. OpenOrange stores secret references and audit context, not copied secret values.

The instance dashboard attributes model activity by actor, agent, route, model, request, tokens, cache behavior, price version, and tariff. Staging now extends the same operational view to service activity such as search, mail, connectors, and web access.

Request a private OpenOrange pilot

Request a private OpenOrange pilot.

Tell us what you run today, what needs to become visible, and what must stay controlled. A human reviews every brief; this form does not create an instance automatically.

intake:human private pilot reply required

Your team, current agents, preferred runtimes, coding workflow, service usage, model spend, privacy needs, or deployment scope.

Best reply channel?

Where should we reply?

human review first