“Which AI ran that?”
Someone used an agent on their laptop. Which one, which model, which settings? Nobody wrote it down.
ConvOps executors decide which AI runs each step of a workflow, and where: your own machine, your own runner, or an isolated run on Kubernetes. The process is taught once.
local · your runner · isolated on Kubernetes
Workflow step
The setting that decides which AI agent runs a step and where: on your machine, on your own runner, or in an isolated Kubernetes pod.
ConvOps is the operations layer for AI agents: an MCP server that holds your team's process as workflows, with approval gates, a shared memory and an audit trail. It runs no AI models.
updated
Agents already do real work. Most teams cannot say which agent, which model, whose key or which version did it.
“Which AI ran that?”
Someone used an agent on their laptop. Which one, which model, which settings? Nobody wrote it down.
“With whose keys?”
A personal API key, pasted into a config file months ago. It still works. Nobody knows where else it lives.
“On which version?”
The same prompt behaved differently last week. The agent updated itself and nothing recorded when.
A bug fix reaches the step that needs code. Follow it from the executor choice to the person who approves the result.
A bug fix reaches the step "Write the fix". The workflow already knows what this step must do. Now it needs someone to do it.
Fix the rounding in refunds. Add a test that fails today. Run the billing tests. Push to the task branch.
This step says isolated-sonnet. The task and the workspace have their own settings, but the step is closest, so the step wins.
from Step executor
The step is closest, so the step wins.
The executor fixes the engine, its version and the model. Its credential was handed over once, through a link. Nobody pastes it again.
One isolated run on Kubernetes, with its own volume and its own secret. A time limit starts with it. The secret stays masked in the log.
Tests pass. The agent commits and pushes to the task branch, then asks to advance. The run is recorded with its model, tokens and cost.
The next step is an approval. The pushed work waits for a human. Approve, and the workflow carries on. Not before.
Fix the rounding in refunds. Add a test that fails today. Run the billing tests. Push to the task branch.
Same process, same gates, same record. Only the place and the agent change.
The step runs in the AI client you already have open, on your own checkout. Nothing to install.
local
Your own infrastructure picks up the work and runs it your way. ConvOps keeps the process and the record.
custom
One Kubernetes pod per run, with its own volume, its own secret and a time limit. On our cloud or your cluster.
isolated
Bring your own models and credentials. Each executor holds one, handed over through a one-time link.
bring your own
Set a workspace default once. Override it on a task, or on a single step. Each step resolves on its own.
from Workspace default
Nothing set on the task or the step. The workspace default runs it.
One executor fixes everything a run depends on. The key arrives through a one-time link. Nobody pastes it anywhere.
Every isolated run records its tokens, cost and time. A run that hits its time limit picks up again on the same volume.
Agents run on their own. People keep the stop, the clock and the review.
One call names the engine, a version from the catalog, the model, the time limit and a credential reference. A value is refused. The intake source returns a one-time link instead.
executors_manage({
"action": "create",
"workspace": "engineering",
"slug": "isolated-sonnet",
"runner": "convops",
"config": {
"backend": "isolated",
"isolated": {
"agent": "claude-code",
"agent_version": "2.1.4",
"model": "sonnet",
"time_limit_s": 14400,
"credential": {
"kind": "api-key",
"secret": { "source": "intake" }
}
}
}
})
// response (abridged)
{
"slug": "isolated-sonnet",
"credential": {
"status": "awaiting value",
"one_time_link": "<sent to you, used once>"
}
}When a step is dispatched, the engine checks the step, then the task, then the workspace default. The first one set is the executor for that step only.
// step "Write the fix" executor: isolated-sonnet
// task 8c1e executor: nightly-runner
// workspace default executor: local
resolved executor for this step:
{
"executor": "isolated-sonnet",
"from": "step",
"agent": "claude-code",
"agent_version": "2.1.4",
"model": "sonnet",
"time_limit_s": 14400
}The isolated backend publishes a catalog of agents, versions and default models. An executor pins one version, so a run never changes under you.
executors_manage({ "action": "catalog" })
{
"agents": [
{ "agent": "claude-code", "versions": ["2.1.4", "2.1.3"], "default_model": "sonnet" },
{ "agent": "opencode", "versions": ["0.15.2"], "default_model": "anthropic/claude-sonnet-4-5" }
]
}A custom executor returns the dispatch envelope to your runner instead of starting a pod. Your runner does the work; the workflow, gates and record stay in ConvOps.
Claude Code and OpenCode today. The design is agent-neutral: an executor names an engine, a pinned version and a model, so other agents such as Codex and Kimi plug in the same way.
Three places. Locally, in the AI client you already have open. On your own runner, which picks up the work and runs it your way. Or as an isolated run: one Kubernetes pod per run, with its own volume, its own secret and a time limit.
Bring your own models and credentials. A credential is handed over through a one-time link, never pasted in chat. It is stored as a secret, given only to the run that needs it, and masked in every log and transcript.
Yes. A step can name its own executor, a task can name one for all its steps, and the workspace has a default. The closest setting wins: step, then task, then workspace.
Every executor carries a time limit, four hours by default. A run that hits it resumes on the same volume. Any run can also be stopped by a person at any point.
Yes. Isolated runs can run on your own Kubernetes, and enterprise customers can self-host all of ConvOps with a Helm chart. Nothing has to leave your cluster.