<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>control-plane on tomrochette.com</title>
    <link>https://tomrochette.com/tags/control-plane/</link>
    <description>Recent content in control-plane on tomrochette.com</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <managingEditor>tom@tomrochette.com (Tom Rochette)</managingEditor>
    <webMaster>tom@tomrochette.com (Tom Rochette)</webMaster>
    <copyright>© 2026 Tom Rochette</copyright>
    <lastBuildDate>Sat, 03 Oct 2026 04:29:39 -0400</lastBuildDate><atom:link href="https://tomrochette.com/tags/control-plane/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>Databricks Unity Gateway</title>
      <link>https://tomrochette.com/agents/control-planes/databricks-unity-gateway/</link>
      <pubDate>Fri, 02 Oct 2026 00:00:00 +0000</pubDate>
      <author>tom@tomrochette.com (Tom Rochette)</author>
      <guid>https://tomrochette.com/agents/control-planes/databricks-unity-gateway/</guid>
      <category>research-note</category><category>agent-curated</category><category>fully-ai-generated</category><category>llm=glm-5.3-flash</category><category>control-plane</category><category>governance</category><category>mcp</category><category>enterprise</category>
      <description>&lt;p&gt;Databricks Unity Gateway is the governance layer, folded into Unity Catalog in April 2026, that routes every model and MCP service request from one control plane with permissions, guardrails, rate limits, budgets, and audit trails.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Its bet is that agent governance should inherit data governance: the same catalog that already decides who can query a table decides which agent may call which model, MCP server, or API, under whose permissions.&lt;/strong&gt;&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;What it is&#xA;    &lt;div id=&#34;what-it-is&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#what-it-is&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;A Databricks platform capability (AWS, Azure, and GCP docs), announced April 15, 2026, when AI Gateway became part of Unity Catalog and took its name.&#xA;Every request to a model or MCP server passes through the gateway: service policies (guardrails) run on requests and responses, rate limits apply at endpoint, user, or group level in QPM or TPM, and every call logs to Unity Catalog system tables with actual dollar costs.&#xA;MCP servers are first-class securables, with on-behalf-of execution so an MCP call runs with the requesting user&amp;rsquo;s exact permissions instead of a shared service account.&#xA;Guardrails cover PII detection and redaction, content safety, prompt-injection detection, data-exfiltration prevention, and hallucination checks, each backed by an editable prompt and model (rolling out in beta), and inference tables capture full request and response payloads for debugging and audit.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Status&#xA;    &lt;div id=&#34;status&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#status&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Active and strategic: this is a core Databricks product line, documented across all three clouds, with the April 2026 announcement naming coding agents (Cursor, Codex, Claude Code) as governed callers.&#xA;&lt;strong&gt;The gap to know is that coverage is uneven at the edges: rate limits do not apply to &lt;code&gt;ai_query&lt;/code&gt; batch inference workloads (usage tracking only), output guardrails do not apply to streaming or embeddings, and the platform is unavailable on AWS GovCloud and Azure Government.&lt;/strong&gt;&#xA;The LLM-judge guardrails and the OpenAI-compatible unified API were still beta in the April announcement.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Strengths&#xA;    &lt;div id=&#34;strengths&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#strengths&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;One policy surface for models and tools: the same permissions, audit, and tagging model your data already uses, applied to agent traffic.&lt;/li&gt;&#xA;&lt;li&gt;On-behalf-of execution is the right default, an agent inherits the human&amp;rsquo;s permissions rather than a god-mode service account.&lt;/li&gt;&#xA;&lt;li&gt;Cost attribution lands in system tables with real dollar figures, sliceable by endpoint tag, request tag, identity, or model, which FinOps can query like any other Delta table.&lt;/li&gt;&#xA;&lt;li&gt;Inference tables give engineering full payloads for debugging failures, and security gets who-called-what audit trails from the same log.&lt;/li&gt;&#xA;&lt;li&gt;Fallback chains route around quota exhaustion and outages without application changes.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Cautions&#xA;    &lt;div id=&#34;cautions&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#cautions&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;You buy the whole Databricks platform to get it: there is no standalone gateway, so a team not already on the lakehouse is paying for far more than governance.&lt;/li&gt;&#xA;&lt;li&gt;The known enforcement gaps matter in production: no rate limiting on batch inference, no output guardrails on streaming, and beta features rolling out region by region.&lt;/li&gt;&#xA;&lt;li&gt;The LLM-judge guardrails are prompts plus a model, so guardrail quality tracks model quality and each check adds latency and cost to the calls it inspects.&lt;/li&gt;&#xA;&lt;li&gt;Governance depth is Databricks-specific: policies do not follow your agents to another cloud or runtime.&lt;/li&gt;&#xA;&lt;li&gt;The renamed lineage (AI Gateway, then Unity Gateway) means older tutorials and configs describe a subset of the current product.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Pricing&#xA;    &lt;div id=&#34;pricing&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#pricing&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;No standalone price list: Unity Gateway is consumed as part of the Databricks platform, billed through its usual usage-based model rather than a separate gateway subscription.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Compared to&#xA;    &lt;div id=&#34;compared-to&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#compared-to&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/control-planes/veto/&#34; &gt;Veto&lt;/a&gt;: Veto intercepts individual tool calls before execution with policy and approvals at the agent-framework layer; Unity Gateway governs the model and MCP traffic from the platform layer instead.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/control-planes/microsoft-agent-governance-toolkit/&#34; &gt;Microsoft Agent Governance Toolkit&lt;/a&gt;: the toolkit ships deterministic runtime enforcement you deploy; Unity Gateway is a managed capability of a platform you already run.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/model-access/litellm/&#34; &gt;LiteLLM&lt;/a&gt;: LiteLLM is the self-hosted proxy for model routing and budgets without the catalog, identity, or MCP governance around it.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Bottom line&#xA;    &lt;div id=&#34;bottom-line&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#bottom-line&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;Recommended for teams already on Databricks whose agents now touch models, MCP servers, and governed data in the same request.&lt;/strong&gt;&#xA;Not for multi-cloud agent fleets, for batch-inference-heavy workloads that need enforced rate limits, or for anyone wanting gateway governance without a lakehouse.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Changes&#xA;    &lt;div id=&#34;changes&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#changes&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2026-10-02 - Created.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;See also&#xA;    &lt;div id=&#34;see-also&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#see-also&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/control-planes/control-planes-feature-matrix/&#34; &gt;Control Planes Feature Matrix&lt;/a&gt; - the category comparison this note joins&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/control-planes/veto/&#34; &gt;Veto&lt;/a&gt; - the tool-call interception layer at the agent framework level&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/control-planes/microsoft-agent-governance-toolkit/&#34; &gt;Microsoft Agent Governance Toolkit&lt;/a&gt; - the deployable runtime-governance counterpart&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/model-access/litellm/&#34; &gt;LiteLLM&lt;/a&gt; - the standalone model gateway without platform lock-in&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/protocols/mcp/&#34; &gt;Model Context Protocol (MCP)&lt;/a&gt; - the protocol whose servers this gateway governs&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;References&#xA;    &lt;div id=&#34;references&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#references&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.databricks.com/blog/ai-gateway-governance-layer-agentic-ai&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=www.databricks.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://www.databricks.com/blog/ai-gateway-governance-layer-agentic-ai&lt;/a&gt; - the April 15, 2026 announcement naming Unity Gateway: MCP governance, on-behalf-of execution, beta guardrails, fallbacks, and system-table cost attribution&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.databricks.com/aws/en/ai-gateway/&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=docs.databricks.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://docs.databricks.com/aws/en/ai-gateway/&lt;/a&gt; - the AWS documentation hub for AI governance with Unity Gateway&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.databricks.com/aws/en/ai-gateway/ai-governance&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=docs.databricks.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://docs.databricks.com/aws/en/ai-gateway/ai-governance&lt;/a&gt; - the setup guide: routing, service policies, and rate limits across model and MCP services&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.databricks.com/aws/en/ai-gateway/rate-limits&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=docs.databricks.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://docs.databricks.com/aws/en/ai-gateway/rate-limits&lt;/a&gt; - the endpoint, user, and group rate-limit mechanics in QPM and TPM&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/azure/databricks/ai-gateway/&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=learn.microsoft.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://learn.microsoft.com/en-us/azure/databricks/ai-gateway/&lt;/a&gt; - the Azure Databricks mirror confirming cross-cloud documentation&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://community.databricks.com/t5/generative-ai/ai-query-not-affected-by-ai-gateway-s-rate-limits/td-p/134257&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=community.databricks.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://community.databricks.com/t5/generative-ai/ai-query-not-affected-by-ai-gateway-s-rate-limits/td-p/134257&lt;/a&gt; - the vendor-forum confirmation that ai_query batch inference gets usage tracking only (the page 403s to curl, verified through the search excerpt)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://datapao.com/databricks-unity-ai-gateway/&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=datapao.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://datapao.com/databricks-unity-ai-gateway/&lt;/a&gt; - the third-party 2026 guide grounding the regional limits, the GovCloud absence, and the contextual service policies&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
      
    </item>
    
    <item>
      <title>OpenRig</title>
      <link>https://tomrochette.com/agents/orchestration/openrig/</link>
      <pubDate>Fri, 02 Oct 2026 00:00:00 +0000</pubDate>
      <author>tom@tomrochette.com (Tom Rochette)</author>
      <guid>https://tomrochette.com/agents/orchestration/openrig/</guid>
      <category>research-note</category><category>agent-curated</category><category>fully-ai-generated</category><category>llm=deepseek-v4.1-flash</category><category>llm=glm-5.3-flash</category><category>orchestration</category><category>control-plane</category><category>cross-harness</category><category>tmux</category><category>persistent-agents</category>
      <description>&lt;p&gt;OpenRig is an Apache-2.0, self-hosted control plane that turns ordinary Claude Code, Codex, and Pi terminal sessions into a persistent, named team defined in YAML.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;OpenRig&amp;rsquo;s bet is that the missing layer is topology, not another agent: it makes the team itself the configurable, restartable artifact and treats a cross-harness team (Claude Code and Codex together) as the default rather than a feature.&lt;/strong&gt;&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;What it is&#xA;    &lt;div id=&#34;what-it-is&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#what-it-is&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;A TypeScript daemon (a Hono HTTP server with SQLite) plus a &lt;code&gt;rig&lt;/code&gt; CLI, a terminal UI, and an MCP server, built on tmux by Mike Schwarz&amp;rsquo;s Esoteric Labs.&#xA;The unit is the rig: a &lt;code&gt;rig.yaml&lt;/code&gt; (RigSpec) declaring pods, seats, edges, continuity policies, and a &lt;code&gt;CULTURE.md&lt;/code&gt;, with reusable AgentSpec blueprints for individual agents.&#xA;The daemon boots each seat as an actual Claude Code or Codex tmux session with a stable address such as &lt;code&gt;dev-owner@first-project&lt;/code&gt;, so the conversation can change while the seat keeps its name, role, and accumulated context.&#xA;Seats coordinate over the terminal itself (&lt;code&gt;rig send&lt;/code&gt;, &lt;code&gt;rig broadcast&lt;/code&gt;, &lt;code&gt;rig chatroom&lt;/code&gt;, &lt;code&gt;rig capture&lt;/code&gt;, &lt;code&gt;rig transcript&lt;/code&gt;), pass owned work through &lt;code&gt;rig queue&lt;/code&gt; (one owner and one state per item), and follow declared workflows and watchdogs.&#xA;Working state lives on disk as projects, missions, and slices with specs, progress, and proof; &lt;code&gt;rig down --snapshot&lt;/code&gt; and &lt;code&gt;rig up &amp;lt;name&amp;gt;&lt;/code&gt; snapshot and restore the team by name with a per-seat outcome, &lt;code&gt;rig discover&lt;/code&gt; and &lt;code&gt;rig adopt&lt;/code&gt; can absorb existing tmux sessions, and a RigBundle is a portable archive with SHA-256 integrity.&#xA;It ships no model and holds no API keys: it drives the Claude Code and Codex logins you already have.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Status&#xA;    &lt;div id=&#34;status&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#status&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Active and early: about 4,470 stars and 305 forks as of 2026-10-03, created 2026-04-01, 24 contributors, 94 open issues and pull requests, and v0.6.4 published 2026-10-02, with npm &lt;code&gt;@openrig/cli&lt;/code&gt; at 0.6.4 after 54 versions since 2026-04-06.&#xA;&lt;strong&gt;The adoption signal is thin where it matters: GitHub traction is respectable, but the Hacker News footprint is a pair of Show HN threads at 8 and 6 points plus a 2-point repost, and the documentation index still names release 0.5.14 while npm ships 0.6.4.&lt;/strong&gt;&#xA;The project describes itself as built by its own network of agent teams since March 2026, a self-reported claim that independent field reports do not yet corroborate.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Strengths&#xA;    &lt;div id=&#34;strengths&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#strengths&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Cross-harness by default: Claude Code and Codex as peers in one rig, plus Pi and Oh My Pi through RPC runners, where much of the category pins to a single vendor.&lt;/li&gt;&#xA;&lt;li&gt;Persistent seats with snapshot and restore by name, reporting each seat as resumed, rebuilt, fresh, waiting on a decision or attention, or failed, which answers the which-tab-was-the-reviewer problem directly.&lt;/li&gt;&#xA;&lt;li&gt;Terminal-native coordination with no second API: agents message each other by typing into tmux panes, so anything a human can do in a session an agent can do.&lt;/li&gt;&#xA;&lt;li&gt;An agent-first CLI and MCP server (&lt;code&gt;rig_up&lt;/code&gt;, &lt;code&gt;rig_ps&lt;/code&gt;, &lt;code&gt;rig_send&lt;/code&gt;, &lt;code&gt;rig_chatroom_send&lt;/code&gt;) that lets the team manage its own topology.&lt;/li&gt;&#xA;&lt;li&gt;Local and self-hosted with no cloud dependency and no token markup, running on the subscriptions you already pay for.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Cautions&#xA;    &lt;div id=&#34;cautions&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#cautions&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;The human is still the reviewer: a Show HN commenter notes that unsupervised agents degrade quickly, and the design routes work and attention rather than removing the review step, which the author describes as operating with a hand near the wheel.&lt;/li&gt;&#xA;&lt;li&gt;No agent isolation: seats share the host network and filesystem through tmux, and the author confirmed in-thread that isolating agents is not solved yet, so it assumes a single trusted machine.&lt;/li&gt;&#xA;&lt;li&gt;Setup is invasive: it writes provider trust settings and executable hooks, edits &lt;code&gt;~/.tmux.conf&lt;/code&gt;, &lt;code&gt;~/.claude.json&lt;/code&gt;, &lt;code&gt;~/.codex/config.toml&lt;/code&gt;, &lt;code&gt;.claude/settings.local.json&lt;/code&gt;, and &lt;code&gt;.mcp.json&lt;/code&gt;, and pre-trusts the workspace, with no complete preservation or rollback guarantee, so back up before first use.&lt;/li&gt;&#xA;&lt;li&gt;Platform limits: macOS or Linux with Node 22 or 24 and tmux; native Windows is unsupported and WSL2 is untested.&lt;/li&gt;&#xA;&lt;li&gt;Early and churning: 0.6.x with 39 releases in six months, documentation that lags the package, and a popularity story that leans on the author&amp;rsquo;s own accounts.&lt;/li&gt;&#xA;&lt;li&gt;The permission model needs care: agents can run &lt;code&gt;rig&lt;/code&gt; commands without repeated prompts if you accept the setup offer, and &lt;code&gt;--dangerously-interact&lt;/code&gt; lets one seat answer another&amp;rsquo;s permission prompt (off by default, recorded with a reason), which is the trust boundary a long-running fleet puts pressure on.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Pricing&#xA;    &lt;div id=&#34;pricing&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#pricing&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;Free and open source under Apache-2.0.&#xA;No hosted tier, no token markup, and no OpenRig API keys; agents run on the Claude Code and Codex subscriptions you already have, so model usage is billed by those providers.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Compared to&#xA;    &lt;div id=&#34;compared-to&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#compared-to&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/orchestration/omnara/&#34; &gt;Omnara&lt;/a&gt;: the other control plane that owns agent execution and state, with machine pools and dashboard, phone, CLI, API, and Slack supervision; choose Omnara for hosted execution and mobile reach, OpenRig for cross-harness teams of actual Claude Code and Codex sessions on your own machine.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/orchestration/conductor/&#34; &gt;Conductor&lt;/a&gt;: the polished closed macOS GUI for parallel sessions; choose Conductor for a shallow, well-reviewed Mac workflow, OpenRig for a self-hosted daemon that defines, boots, and restores a named team.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/orchestration/squad/&#34; &gt;Squad&lt;/a&gt;: a persistent agent team as versioned repo files inside GitHub Copilot CLI; choose Squad to stay inside Copilot, OpenRig for harness-independent, tmux-backed seats with a durable cross-session queue.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Bottom line&#xA;    &lt;div id=&#34;bottom-line&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#bottom-line&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;Recommended for terminal-native engineers who already run several Claude Code and Codex sessions and want to define, boot, and restore the team as infrastructure.&lt;/strong&gt;&#xA;Not for anyone who needs agent sandboxing, a Windows desktop, or a managed cloud with a support contract.&lt;/p&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;Changes&#xA;    &lt;div id=&#34;changes&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#changes&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;2026-10-02 - Created.&lt;/li&gt;&#xA;&lt;li&gt;2026-10-02 - Re-verified the note against the GitHub API, npm, and openrig.dev hours after creation: v0.6.4, 24 contributors, 39 releases, npm 0.6.4 across 54 versions since 2026-04-06, the 0.5.14 docs lag, and both HN thread point counts all confirmed, and the MCP server, discover and adopt, RigBundle integrity, and permission-override claims all checked against the live site.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;See also&#xA;    &lt;div id=&#34;see-also&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#see-also&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/orchestration/orchestration-feature-matrix/&#34; &gt;Orchestration Feature Matrix&lt;/a&gt; - the category comparison this note joins&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/orchestration/omnara/&#34; &gt;Omnara&lt;/a&gt; - the closest control-plane rival&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/orchestration/conductor/&#34; &gt;Conductor&lt;/a&gt; - the closed Mac GUI incumbent&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/orchestration/squad/&#34; &gt;Squad&lt;/a&gt; - the Copilot CLI team harness&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://tomrochette.com/agents/the-agentic-development-environment-landscape/&#34; &gt;The Agentic Development Environment Landscape&lt;/a&gt; - the tracker this category extends&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&#xA;&lt;h2 class=&#34;relative group&#34;&gt;References&#xA;    &lt;div id=&#34;references&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;&#xA;    &#xA;    &lt;span&#xA;        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none&#34;&gt;&#xA;        &lt;a class=&#34;text-primary-300 dark:text-neutral-700 !no-underline&#34; href=&#34;#references&#34; aria-label=&#34;Anchor&#34;&gt;#&lt;/a&gt;&#xA;    &lt;/span&gt;&#xA;    &#xA;&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://openrig.dev/&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=openrig.dev&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://openrig.dev/&lt;/a&gt; - definition, self-hosted positioning, install path, and the Claude Code, Codex, and Pi framing&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://openrig.dev/docs/getting-started&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=openrig.dev&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://openrig.dev/docs/getting-started&lt;/a&gt; - prerequisites, starters, seat and pod concepts, and the human-and-agent user model&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://openrig.dev/what-is&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=openrig.dev&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://openrig.dev/what-is&lt;/a&gt; - architecture, primitives, and the software-factory framing&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/mvschwarz/openrig&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=github.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://github.com/mvschwarz/openrig&lt;/a&gt; - repository, Apache-2.0 license, stars, and the what-it-changes-on-your-machine table&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://www.npmjs.com/package/@openrig/cli&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=www.npmjs.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://www.npmjs.com/package/@openrig/cli&lt;/a&gt; - package version 0.6.4 and the release history&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://openrig.dev/blog/orchestrator&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=openrig.dev&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://openrig.dev/blog/orchestrator&lt;/a&gt; - launch demo, the two-orchestrator high-availability pair, and the September 2026 permission-override update&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://openrig.dev/blog/cross-harness-agents&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=openrig.dev&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://openrig.dev/blog/cross-harness-agents&lt;/a&gt; - the cross-harness thesis and the terminal-as-transport mechanism&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://esoteric.run/blog/why-i-built-openrig&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=esoteric.run&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://esoteric.run/blog/why-i-built-openrig&lt;/a&gt; - the author&amp;rsquo;s design rationale and the restore-everything motivation&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://openrig.dev/compare/claude-managed-agents&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=openrig.dev&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://openrig.dev/compare/claude-managed-agents&lt;/a&gt; - the managed-cloud counterpart and the local-versus-hosted split&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://news.ycombinator.com/item?id=47772935&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=news.ycombinator.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://news.ycombinator.com/item?id=47772935&lt;/a&gt; - the Show HN launch thread and the supervision concern&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://news.ycombinator.com/item?id=48241066&#34;  target=&#34;_blank&#34; rel=&#34;noreferrer&#34;&gt;&lt;img class=&#34;external-link-favicon&#34; src=&#34;https://www.google.com/s2/favicons?domain=news.ycombinator.com&amp;sz=128&#34; alt=&#34;&#34; width=&#34;16&#34; height=&#34;16&#34; loading=&#34;lazy&#34;&gt;https://news.ycombinator.com/item?id=48241066&lt;/a&gt; - the control-plane thread and the agent-isolation question&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;</description>
      
    </item>
    
  </channel>
</rss>
