cyberivy
OpenBotCopilotKitAI AgentsSelf-hosted AIAgent GovernanceAG-UIBrowser AutomationOpen Source AI

OpenBot gives self-hosted AI coworkers their own computers

October 8, 2026

Architekturdiagramm mit Nutzer, OpenBot-Server, Richtlinien-Gateway, getrennten Agenten-Computern und Prüfprotokoll

OpenBot is an open-source template for AI coworkers with isolated browsers, files, policies, and audit trails. The approach is controllable, but still at alpha stage.

What this is about

OpenBot by CopilotKit is a self-hostable template for organizations that want AI agents to do more than chat: they can act inside bounded work environments. Version 0.1.2 was released on October 7, 2026. The project is available under the MIT license and explicitly labels itself alpha software.

The important difference from a conventional chat window is that each configured AI coworker can receive its own container with a browser profile, files, and approved tools. People can watch it work, take control for sign-ins, and later inspect an audit trail showing what was allowed, denied, or failed.

What OpenBot actually does

OpenBot connects a web interface, PostgreSQL, isolated work computers, and any agent that speaks the open AG-UI protocol. Its example package includes thirteen configured roles, covering knowledge questions, ticket triage, meeting notes, and risk analysis. Teams can add their own roles through configuration files or the interface.

Browser, file, shell, and MCP actions pass through a central gateway. It evaluates policies and records decisions before an action runs. Rules can block a host, command, file, or scheduled routine. If no permission matches or a rule is broken, the system is designed to deny the action. According to the project documentation, credentials are stored encrypted and are not exposed in conversation transcripts.

The documented local setup requires Docker, Bun 1.3 or newer, a model account, and CopilotKit Intelligence. OpenBot does not include a model. A Docker image and startup script are available, but this is not a finished SaaS product: teams are expected to clone, customize, and operate the template themselves.

Why it matters

Agents with a browser, shell, and credentials can do much more than a text-only assistant. That increases usefulness, but also the possible impact of a bad instruction, a compromised website, or an overly broad permission. OpenBot makes policies, separate runtime environments, human takeover, and a readable audit trail visible product features.

Platform teams may also value the separation between the interface and agent logic. Through AG-UI, agents built with LangGraph, Mastra, CrewAI, Pydantic AI, Google ADK, or custom code can be connected. That reduces dependence on a single framework. Independently, the OWASP Agentic Security Initiative identifies identity, authorization, monitoring, and constrained tool access as central building blocks for safer agent systems.

In plain language

Imagine a workshop where every new employee gets a separate bench, a separate set of keys, and a list of machines they may use. A supervisor can watch, stop dangerous steps, and later read the workshop log. OpenBot applies that pattern to AI agents: a dedicated workspace, limited tools, and a traceable record.

A practical example

A support team configures an AI coworker to sort 40 new tickets each day. It may read the knowledge base, create drafts in the ticket system, and open public product pages. Sending a reply and accessing an unknown domain remain blocked.

For one ticket, the agent opens product documentation, creates a draft answer, and records its sources. When it reaches a two-factor sign-in, it requests human help. An employee briefly takes over the browser and then hands it back. At the end of the day, the team reviews the audit trail: 37 drafts were created, two actions were denied by a domain rule, and one sign-in was completed manually. These figures are an example, not a published OpenBot performance claim.

Scope and limits

  • Alpha software: The project itself warns about bugs and changes. Critical production use requires independent testing, backups, and a clear rollback path.
  • Operational overhead: Docker, a database, model access, policies, and CopilotKit Intelligence must be configured and maintained. Self-hosting does not remove security or privacy obligations.
  • No automatic safety: A gateway only helps when rules are narrow, credentials are constrained, and audit logs are actually reviewed. Prompt injection and compromised websites remain risks.
  • Dependencies: OpenBot is openly licensed, but its reference setup requires additional services and model access. Teams should review costs, licenses, and data paths first.

The sensible first test is therefore small: one local installation, one agent, one harmless browser task, and one explicitly denied action. Connect a real internal system only after isolation, logging, and human takeover work as expected.

SEO & GEO keywords

OpenBot, CopilotKit, self-hosted AI agents, AI coworkers, AG-UI, agent governance, browser automation, MCP, audit trail, container isolation, human in the loop, open-source AI

💡 In plain English

OpenBot is a self-hostable template for AI coworkers with their own browser and workspace. A policy layer decides what is allowed before each tool action and records the result in an audit trail.

Key Takeaways

  • →OpenBot gives each AI coworker a separate container with a browser, files, and tools.
  • →A central gateway evaluates policies and records actions before execution.
  • →AG-UI enables connections to multiple agent frameworks.
  • →The MIT-licensed project is a customizable template and still alpha software.
  • →The first test should be local, small, and disconnected from sensitive systems.

FAQ

Is OpenBot a finished cloud service?

No. It is a self-hostable template that teams must clone, configure, and operate.

Which AI model does OpenBot use?

OpenBot does not ship a model. Administrators provide their own model access, and the examples support multiple providers.

Can a person take control?

Yes. A person can take over the browser for sign-ins or sensitive steps and then return control to the agent.

Is OpenBot ready for production?

The project labels itself alpha. Independent security, functional, and recovery tests are necessary before production use.

Sources & Context