Run AI agent fleets on-prem or colocated.
Directed, governed, observed — at every session.
Running on exuvia
Write a rule once. Every agent on every cell starts under it, and the policy that bound a session is a hash you can audit later.
See how directives workAgents on the same initiative brief each other. What one learns is waiting for the next — and for the human who picks it up.
Explore shared contextOne board for the whole fleet. Inject a turn, tail any stream, or attach and drive the terminal yourself — then hand it back.
See the consoleTUI harness, headless CLI, structured stream or a person at a keyboard — one lifecycle, one record. Better models in, better outcomes out.
Swap the executorPolicy is written centrally and materialized at session start, on every cell, under every harness. Layers resolve deterministically and the result is byte-reproducible.
Give teams one governed way to run Claude Code, Codex, a headless CLI or a human operator — with the same cell pinning, network controls, spend accounting and session record.
alice@ses_000042 $ cargo clippy -p identity -- -D warnings Checking identity v0.9.2 Finished · 0 warnings alice@ses_000042 $ ctrl-b d — released ● Clippy is clean. Re-running the suite…
Every agent's phase, cell, model and spend on one board, with the ones waiting on a human flagged. Attach to any session for a real terminal into the container; release and the agent carries on from exactly there.
Every session on an initiative reads what earlier ones learned and leaves a note for the next. Decisions, dead ends, the reason the v2 client won — carried across agents, across cells, across the person who resumes it on Monday.
Point several agents at an initiative and they split the plan, claim tasks, and pass what they learn through shared context — not through you. A review agent gates every merge against the same directive the others wrote under.
The files an agent touched, rendered in place — markdown, images, HTML in a sandboxed frame. A browser pane onto whatever the session is running, on the container's own port. A real terminal when you want it.
Control plane and nodes on your Kubernetes or bare metal. Air-gap capable; model endpoints of your choosing, including local weights.
Single-tenant hardware in a facility you approve. Reachable only over your tailnet. Capacity you can point at from any site.
Keep sensitive initiatives on-prem, burst the rest to colocated capacity. Same directives, same board, same audit trail.
Platform engineering · financial services
“We moved every coding agent off laptops and onto the fleet in a quarter. Directives mean the security review happens once, not per session.”Read the full story
What teams run on exuvia
Featured content
What it takes to run agents as a fleet rather than a pile: directives, shared context, executor independence, and evidence for every run.
Read the guideBearer tokens with read, dispatch and admin scopes; only hashes stored. SSO and SCIM on the enterprise tier.
Every checkpoint is content-addressed and signed by a device key. Verify with the bytes and a public key.
Ownership is epoch-fenced by the control plane. A stale writer is rejected, never silently merged.
Every dispatch, turn, claim, checkpoint and outcome is an event. Replay a session; replay a quarter.
Why a fleet should not care whether a session is driven by a model, a harness or a person — and what has to be true of the session for that to work.
Deterministic policy materialization, the bundle hash, and what it lets an auditor prove twelve months later.
The host clones and mounts; the agent never sees a token. A walk through the isolation model and its known gaps.
Run them on your hardware today, with directives and guardrails handled.