Joch
Open-source agent control plane

Harness your agent fleet.

Joch is the vendor-neutral control plane for securing, governing, and operating AI agents across every model, framework, tool, and runtime.

Apache-2.0OWASP AOSOpenTelemetry · OCSFCycloneDX · SPDX
joch — operator shell

// The questions vendor SDKs leave to the operator

What agents exist across my company, and who owns them?
What models, tools, MCP servers, and memory does each agent depend on?
What did each agent do yesterday — and what did it cost?
Can I move an agent from OpenAI to Claude — and what would break?
Can I block all agents from calling email.send without approval?
Can I deploy the same agent locally, in Docker, and in Kubernetes?
Can I compare two agent versions before promoting to production?
Which MCP servers are pinned, and which were quarantined this week?

If you operate ten, a hundred, or a thousand agents — you need a control plane.

// Bring any agent. Run it anywhere.

Vendor-neutral by design.

Joch sits above your SDKs and providers. Switch frameworks or models without rewriting governance.

SDKs & frameworks

OpenAI Agents SDK
Claude Agent SDK
Google ADK
Microsoft Agent Framework
LangGraph
CrewAI
Custom Python / TS

Model providers

OpenAI
Anthropic
Google
Microsoft Foundry
Ollama
vLLM
llama.cpp

Runtimes

Local
Docker
Kubernetes
Managed runtimes

// Use cases

What operators do with Joch.

Fleet Inventory

Discover, register, and catalog every agent across SDKs and teams in one place.

MCP Governance

Pin, scan, sandbox, and quarantine MCP servers across the entire fleet.

Cross-Provider Migration

Move a live conversation between providers with a deterministic checkpoint and capability check.

Cost Control

Cap, attribute, and alert on agent costs across teams and providers — without changing agent code.

Release Gates

Block agent promotions on failing evals, AgBOM regressions, or missing approvals.

Approvals

Route human approvals for risky tool calls without blocking the agent loop.

// Pricing

Open-core. Honest pricing.

Pay for control-plane operations, never for inference. The OSS core is sufficient for production fleets.

Open Source

FreeApache-2.0

Full control plane, gateways, AOS exporters, CLI, console — self-hostable end to end.

  • Full control plane + Console + Operator
  • Tool & MCP gateway
  • AOS-conformant AgBOM and traces
  • Framework & provider adapters
  • Community support
  • Helm chart, container images, Homebrew
Get started

Cloud Starter

Freefor small teams

Hosted control plane to remove the hosting friction. Limits on agents, executions, and retention.

  • Hosted multi-tenant control plane
  • Hosted Console
  • Managed AgBOM & trace storage
  • Customer-runtime tunnel
  • Community-vetted MCP catalog
  • Best-effort response
Get started
Recommended

Cloud Team

Per agent+ execution overage

The typical landing tier for engineering organizations.

  • Everything in Starter
  • SSO / SCIM, RBAC
  • Premium connectors
  • Multi-region trace & AgBOM (90d)
  • Slack / email approval routing
  • Audit export to SIEM
  • Business-hours support · 99.9% SLA
Get started

Cloud Enterprise

Customcapacity-based

For regulated industries and large fleets where dedicated hosting matters.

  • Everything in Team
  • Advanced policy packs
  • Signed MCP / tool marketplace
  • Dedicated control plane in your cloud
  • FedRAMP / SOC 2 / ISO 27001
  • Advanced eval packs · custom integrations
  • 24×7 with named TAM · 99.95% SLA
Contact sales

Need self-hosted Enterprise?

Joch Enterprise ships every Cloud feature in an airgap-friendly distribution with hardened images, FedRAMP packaging, and a dedicated CVE channel.

Talk to us

// No unmanaged agents.

Govern every agent. Audit every action.

Install Joch in front of your fleet. Discover, govern, trace, approve, deploy, roll back.