All articles

SOIT is now open source: a governed runtime for AI agents

SOIT Team

SOIT is now open source: a governed runtime for AI agents

Today we are open-sourcing SOIT, an agent runtime and governance platform for teams that need AI agents to touch real enterprise systems without losing control. The repository is public at github.com/soit-ai/soit, and the first formal release, v1.0.0, is out.

The problem is not building agents — it is trusting them. The demo takes a week; then someone asks what the agent is allowed to do and who decided that, where its credentials live, which hosts it can reach, what exactly it did last Tuesday, and what that run cost. Frameworks orchestrate calls and leave those controls to you. Hosted platforms answer some questions but you inherit their model choices and data boundary. We think the answer is a runtime where governance is a kernel concern, not a bolted-on afterthought.

The core idea: every agent run is a governed run. Chat turn, agent loop, or workflow run — everything flows through one runtime ledger, and the same controls apply everywhere. Tenant and workspace scoping on every resource with resource-level RBAC. Capabilities bound through per-version allowlists, so a tool from a plugin, an MCP server, or a built-in adapter passes the same checks. Credentials live in Vault and are injected at the gateway; business code never opens a raw HTTP client or LLM SDK. Outbound HTTP from tools is policy-controlled. Every execution records per-step tokens, latency, and cost, a full audit log, and a trace timeline you can replay. And the Dev role that builds agents cannot change egress policy, secrets, or installed plugins — that takes a workspace Owner or Admin.

SOIT Community ships the full platform around four pillars. Build: visual agent assembly with versioning, a DAG workflow editor, a knowledge pipeline into Milvus-backed retrieval, and MCP support including OAuth 2.1-protected servers. Execute: an outbox-based event-driven runtime with checkpoints, retries, fallback chains, and multi-model routing across OpenAI, Anthropic, DeepSeek, Qwen, and any OpenAI-compatible endpoint — including the one on your own GPU. Observe: a workspace control console with live run volume, cost burn, failure rates, OpenTelemetry tracing, and Prometheus metrics. Govern: everything above. It self-hosts with one Docker Compose command.

If your agents run in production, your agent platform is part of your attack surface. Every SOIT release is built by a tag-triggered pipeline that publishes digest-addressable images, SPDX SBOMs, and Sigstore-backed build provenance and SBOM attestations, alongside a deterministic source archive and SHA256SUMS. You can verify any artifact with gh attestation verify before it enters your environment.

A launch post should also say what you are not getting. SOIT is not a lightweight chatbot builder. Content safety and PII detection are not implemented — SOIT exposes a content-safety port so you can plug in a classifier you operate, and inspection outcomes become part of run evidence, but with no adapter configured, no inspection happens. We would rather tell you that than ship a checkbox.

SOIT is released under the Apache 2.0 license. Commercial use, self-hosting, internal deployments, and building products on top are all free. The core platform is and will remain open source; SSO, advanced audit reports, and high-availability deployment live in SOIT Enterprise.

The quickstart takes about ten minutes on a machine with Docker, and we have seeded good first issues for contributors. If your agents graduated from notebooks and hit the trust wall, we built this for you — come break it and tell us where it falls short.