glossary · Running it

Agent executor

definition

An agent executor is a named configuration that decides which AI agent runs a piece of work and where it runs, such as in your own client, on your own runner, or in an isolated environment, so work can be handed off without a person at the keyboard.

in one line: Which agent runs the work, and where.

in context

Where does an agent executor fit?

The step says what. The executor says who. Step, then task, then workspace. The closest setting wins.

Your machinethe client you have open
Your runnergets the envelope
Isolated runone pod per run
Three places a step can run.
two ways to say it

What is an agent executor, in plain words?

Same idea at two depths: the plain version, then what the engine actually does.

Once nobody is at the keyboard, someone has to have written down which agent, which model, and where.

The same workflow can run attended today and unattended later.

for engineers

Local, custom runner, or an isolated Kubernetes run with its own volume, secret and time limit.

Credentials arrive through a one-time link and are masked in logs. Each run records tokens and cost.

the longer answer

Why does an agent executor matter?

When AI work runs in a person's chat, the question of who runs it answers itself. Once work runs on a schedule or is handed off, it needs an answer written down: which agent, which version, which model, with which credentials, on which machine, for how long. An executor is that answer, given a name so a process can refer to it instead of repeating the details.

Executors separate the process from the runtime. The workflow says what must happen at each step; the executor says who does it. That lets the same workflow run attended today and unattended later, or let a cheap model handle routine steps while a stronger one handles the hard step, without rewriting the process.

The reliability questions live here too. A good executor setup has a time limit per run, a way to stop a run, a record of what each run cost, and credentials handed to the run that needs them and to nothing else.

in convops

How does an agent executor work in ConvOps?

In ConvOps, an executor can point to three places. Local means the step runs in the AI client you already have open. A custom runner means ConvOps returns a dispatch envelope to your own infrastructure, which does the work its way while the workflow, gates and record stay in ConvOps. An isolated run means one Kubernetes pod per run, with its own volume, its own secret and a time limit (four hours by default), on ConvOps cloud or your own cluster. Claude Code and OpenCode are supported in isolated runs today. A step can name an executor, a task can name one, and the workspace has a default; the closest setting wins. Credentials are handed over through a one-time link, never pasted in chat, and are masked in logs. Each run records its model, tokens and cost.

questions

What do people ask about an agent executor?

What is the difference between an agent and an executor?

The agent is the worker, such as Claude Code. The executor is the named setup that runs it: which agent, which model, which credentials, which machine, which time limit. Workflows refer to the executor, so the runtime can change without rewriting the process.

Which executors does ConvOps support?

Local, which runs in the client you have open; a custom runner, which receives a dispatch envelope on your own infrastructure; and an isolated run, one Kubernetes pod per run on ConvOps cloud or your own cluster, with Claude Code and OpenCode supported today.

How are credentials handed to an executor?

In ConvOps, through a one-time link, never pasted in chat, and they are masked in logs. An isolated run gets its own secret.