Enterprise agents, governed from first run.
SOIT helps teams run AI agents against real enterprise systems with permissions, secrets, egress, audit, cost, trace, and replay evidence built into the runtime.
No spam. We will only send SOIT product and early access updates. Star on GitHub
Every action becomes runtime evidence
Built on open infrastructure, runs on your cloud
These names are SOIT's own runtime stack, supported deployment platforms, and model integrations, not customer endorsements.
Empower your business with governed agent workflows
Generic AI tools are not enough for enterprise operations. SOIT keeps permissions, secrets, egress, audit, cost, trace, and replay in the runtime.
Secure Data Handling
Use secret references, egress policy, and audit trails instead of raw credentials in prompts.
Governed Runtime
Bind every run to workspace context, permission checks, tool boundaries, and evidence.
Real enterprise workflows, not isolated chatbot demos.
Support automation
Let agents triage tickets, retrieve policy, draft replies, and preserve review evidence.
Operations copilot
Route workflow steps through approved tools while keeping approvals and artifacts visible.
Knowledge actions
Connect retrieval and tool execution so citations, context, and outcomes remain inspectable.
Governed plugins
Register MCP tools and plugins with owners, scopes, audit trails, and release controls.
One console for every governed run.
Every action becomes runtime evidence
Runs
support-triage · last 24hNew run| Run | Agent | Policy | Steps | Cost | Status |
|---|---|---|---|---|---|
| #2847 | STsupport-triage | Pass | 12 | $0.42 | Running |
| #2846 | STsupport-triage | Pass | 9 | $0.31 | Complete |
| #2845 | OCops-copilot | Pass | 17 | $0.58 | Complete |
| #2844 | KAkb-actions | Review | 6 | $0.19 | Held |
| #2843 | BAbilling-agent | Pass | 11 | $0.37 | Complete |
| #2842 | OCops-copilot | Pass | 14 | $0.44 | Complete |
The console behind every governed run
Governance structures
Run Explorer
Governed runs
1,284
Policy pass rate
99.2%
Avg run cost
$0.38
Replay coverage
100%
Policy
Evaluate permissions, egress, and tool boundaries before execution.
Trace
Record model, retrieval, tool, workflow, and child run steps.
Cost
Attribute model and external resource usage to each governed run.
Replay
Retain evidence for inspection, regression, and release gates.
Connect the systems agents need, with governance in the middle.
Policy
Pass
Secrets
Refs only
Egress
Scoped
Pre-run policy
Permission, egress, and tool boundaries are evaluated before execution starts.
| support-triage | Live | v14 |
| ops-copilot | Live | v9 |
| kb-actions | Review | v3 |
| billing-agent | Live | v6 |
Govern
Apply workspace scope, RBAC, secret references, egress policy, and plugin governance.
100%
Secret references
Agents operate through references instead of raw credentials in prompts or logs.
Observe
Inspect run details, tool calls, citations, audits, costs, and replay data.
10:41:02 policy.allow ✓ signed
10:41:03 tool.crm.lookup ✓ signed
10:41:05 knowledge.cite v3 ✓ signed
10:41:08 audit.export.ready ✓ signed
Evidence retained
Audit, replay, and release-review data stay available for governance workflows.
OpenAI-compatible models
Keep model providers replaceable while retaining one governance layer.
Harden
Move toward Enterprise controls for SSO, SCIM, RBAC, audit exports, and HA.
4x
Evidence views
Trace, cost, audit, and replay stay attached to the same governed run.
| MCP tools | 17 |
| Plugins | 9 |
| Owners assigned | 100% |
| Scoped access | ✓ |
MCP tools
Expose approved tools through governed plugin ownership and scoped access.
SOIT is not another prompt surface. It is the control layer that makes agent execution inspectable before teams connect real systems.
SOIT.ai
Governed agent runtime for enterprise AI systems.
Choose the plan that's right for you
COMMUNITY
Free
open source, self-hosted
- Open-source core runtime
- Agent, workflow, knowledge, plugin/MCP
- Run ledger with trace and cost
- Basic RBAC
- Community support
Perfect for evaluating governed agents locally
ENTERPRISE
PopularCustom
private self-hosted
- Everything in Community
- SSO, SCIM, advanced RBAC
- Audit reports and compliance exports
- Signed images, backup, HA templates
- Enterprise support
For teams that need production governance controls
SOIT CLOUD
Waitlist
managed SaaS path
- Everything in Enterprise
- Managed upgrades and operations
- Tenant provisioning and quotas
- Billing and usage controls
- Support console
Managed operations when your team is ready
What is SOIT?
SOIT is a governed agent runtime that lets teams run AI agents against real enterprise systems with permissions, secrets, egress, audit, cost, trace, and replay evidence built into the runtime.
How can I get started with SOIT?
Start with the open-source SOIT Community edition: clone the repository, run the local stack, and walk through the governed support workflow demo described in the docs.
Which models and tools does SOIT support?
SOIT works with OpenAI-compatible model providers and exposes tools through governed plugins and MCP, alongside vector knowledge, Vault-backed secrets, and OpenTelemetry export.
Is SOIT suitable for production deployments?
Community contains the open-source core foundation. Production posture depends on your environment; Enterprise adds SSO, SCIM, advanced RBAC, compliance exports, and deployment controls.
What kind of support does SOIT provide?
Community users get docs, GitHub Discussions, and the community forum. Enterprise and Cloud paths include dedicated support channels.
Latest Articles

Your agent request touches twelve containers. Only one of them runs a model.
A walk through the SOIT quickstart topology, service by service: what each container is responsible for during a single run, and which guarantee disappears if you remove it.

I tried to cut our twelve-container stack down to four. Two of my three conclusions were wrong.
How far the SOIT quickstart topology can actually be trimmed for a demo, which service you fold in rather than delete, and the two things reading the code got wrong that only running it revealed.

Five questions to answer before you put MCP in production
MCP standardised how an agent gets tools. It says nothing about who may call one, where the credentials live, what the call can reach, what evidence it leaves, or whether you can replay it.

SOIT is now open source: a governed runtime for AI agents
SOIT is open source and v1.0.0 is released: an agent runtime where permissions, secrets, egress, audit, cost, trace, and replay are kernel concerns.

Introducing SOIT
Introducing SOIT, a governed agent runtime for enterprise AI systems.