One fleet, many kinds of work.
Orchestrator Zero fits wherever agents need machines, networks and data on your side of the firewall. These are the four areas where that matters most, with the agents teams build for each.
Networking
Agents on every network you run.
A node in every site reaches the switches, routers and firewalls the cloud cannot. Audit configs, chase outages and roll out changes.
- config-auditorCompares running configurations with your source of truth and opens a ticket for every drift.
- outage-triagePulls counters, logs and neighbour tables from the devices around a failing link and writes up what it found.
- change-runnerApplies a reviewed change site by site and checks reachability after each one, stopping at the first failure.
Security
Security agents that stay inside the perimeter.
Triage alerts on the hosts they came from, collect evidence where it lives and isolate a machine only after someone approves.
- alert-triageEnriches an alert with process trees, logins and connections from the host that raised it, and rates it.
- evidence-collectorCollects logs and artefacts on the affected machines and hashes them before anything moves.
- containmentIsolates a host or disables an account, and undoes it when the case closes.
IT operations
Runbooks that finish what they start.
Runbooks as durable jobs: check every affected machine, wait for a person when needed and pick up where you left off after a restart.
- incident-responderGathers logs, metrics and recent changes from every affected machine and proposes a fix.
- patch-runnerPatches machines in waves, checks health after each wave and stops at the first one that fails.
- disk-janitorFinds what is filling a disk and cleans up what the policy allows.
Software engineering
Coding agents on your own hardware.
Review pull requests, fix flaky tests and run migrations on your own build machines, with a budget per job and the code kept at home.
- pr-reviewerReviews every pull request against your guidelines and leaves comments where they matter.
- test-fixerReproduces a flaky test, finds the cause and opens a fix with the evidence.
- migratorUpgrades a dependency across many repositories, one child job per repository.
The same platform under every one.
Join your machines
Servers, laptops, GPU boxes and devices in every site, with one command each.
Install agents from Git
Agents, tools and skills come as plugins, rolled out to the nodes that need them.
Start jobs
From the CLI, your apps or a schedule. Follow them live and see what each one cost.
- Durable runs
- A crash, a deploy or a lost node never throws a run away.
- Nodes that only dial out
- No inbound ports, no VPN, any network.
- A yes before anything risky
- Approvals on the tools you mark.
- Every token metered
- Cost per call, budgets per job and tenant.
- Plugins from Git
- Agents, tools and skills in any language.
- Yours to host
- Management, edge and Temporal on your servers.
Where it is going
Built to scale out, with an identity for everything in it.
Every node already has its own certificate, dials out only and is one more worker on a task queue. That is the footing for what comes next in each area.
- NetworkingA node on every router and switch.The switch next to a fault tells the router, the router tries the backup line, and the agents on both agree on what broke, without a data centre in the loop.
- SecurityHosts that defend each other.Attackers often go for the link to the SOC first. The nodes on a segment keep their policies, act on them locally and hand over the evidence when the line returns.
- IT operationsSites that keep running offline.The local edge keeps the jobs, plugins and certificates its nodes need. Checks, patches and fixes go on while the line is down, and every step syncs back afterwards.
- Software engineeringEvery agent run its own identity.A run that fixes one repository gets a short-lived credential for that repository alone, and it expires when the run ends.
Your kind of work is not here?
If an agent needs a machine you own, it fits. Tell us what you want to run.