executors: Choose who does the work.

ConvOps executors decide which AI runs each step of a workflow, and where: your own machine, your own runner, or an isolated run on Kubernetes. The process is taught once.

local · your runner · isolated on Kubernetes

executorsexample workspace
routing1/4

Workflow step

Write the fixfresh pod, time limit 4h
next item
Your machinelocalClaude Code
idle
Your runneryour infrastructureOpenCode
idle
Isolated runKubernetes podClaude Code
idle
engine + modelversion pinnedkey given oncetime limit 4h
engines
Claude Code OpenCode Codex comingKimi coming
in short

What is an executor in ConvOps?

The setting that decides which AI agent runs a step and where: on your machine, on your own runner, or in an isolated Kubernetes pod.

ConvOps is the operations layer for AI agents: an MCP server that holds your team's process as workflows, with approval gates, a shared memory and an audit trail. It runs no AI models.

key facts · october 2026

  • An executor names the agent engine, its version, the model, the credentials and a time limit. The default time limit is four hours.
  • Claude Code and OpenCode run in isolated pods today.
  • The closest setting wins: the step's executor, then the task's, then the workspace default.
  • Any running run can be stopped from the runs view or through the API, and the record keeps what it used up to that point.
  • At Neomanex, 3 of the 17 configured executors start each dispatch as its own Kubernetes Job with its own volume and Secret (October 2026).

best for

  • Teams that need to know which AI, model and keys ran each step.
  • Mixing agents: one model for planning, another for implementation, an isolated pod for risky work.

not for

  • Hosting models. Executors run agent engines against the model provider and keys you configure.

updated

the problem

Which AI ran that?

Agents already do real work. Most teams cannot say which agent, which model, whose key or which version did it.

“Which AI ran that?”

Someone used an agent on their laptop. Which one, which model, which settings? Nobody wrote it down.

“With whose keys?”

A personal API key, pasted into a config file months ago. It still works. Nobody knows where else it lives.

“On which version?”

The same prompt behaved differently last week. The agent updated itself and nothing recorded when.

watch it work

One step, from routing to review.

A bug fix reaches the step that needs code. Follow it from the executor choice to the person who approves the result.

01the workflow

A step needs code.

A bug fix reaches the step "Write the fix". The workflow already knows what this step must do. Now it needs someone to do it.

workflowFix refund roundingexample
  1. Reproduce
  2. Write the fix
  3. Review the fix
  4. Release
step · Write the fixneeds an executor

Fix the rounding in refunds. Add a test that fails today. Run the billing tests. Push to the task branch.

who runs this step?
02the engine

The step names its executor.

This step says isolated-sonnet. The task and the workspace have their own settings, but the step is closest, so the step wins.

workflowFix refund roundingexample
  1. Reproduce
  2. Write the fixisolated-sonnet
  3. Review the fix
  4. Release
checked top to bottomfirst set wins
01Step executorWrite the fixisolated-sonnet
02Task executorFix refund roundingnightly-runner
03Workspace defaultengineeringlocal
runs on
checking layers

from Step executor 

The step is closest, so the step wins.

03the executor

Pinned, with a key handed over once.

The executor fixes the engine, its version and the model. Its credential was handed over once, through a link. Nobody pastes it again.

workflowFix refund roundingexample
  1. Reproduce
  2. Write the fixisolated-sonnet
  3. Review the fix
  4. Release
executor · isolated-sonnetisolated run
  • engine Claude Code
  • version 2.1.4pinned
  • model sonnet
  • credential•••••••• given oncemasked
  • time limit 4h
04isolated run

A pod starts, with a clock.

One isolated run on Kubernetes, with its own volume and its own secret. A time limit starts with it. The secret stays masked in the log.

workflowFix refund roundingexample
  1. Reproduce
  2. Write the fixisolated-sonnet
  3. Review the fix
  4. Release
isolated run · run-7f3arunning
›run started · executor isolated-sonnet
02agent claude-code 2.1.4 (pinned) · model sonnet
03time limit 4h · task volume mounted
04env ANTHROPIC_API_KEY=••••••••masked
05the agent

The work is pushed.

Tests pass. The agent commits and pushes to the task branch, then asks to advance. The run is recorded with its model, tokens and cost.

workflowFix refund roundingexample
  1. Reproduce
  2. Write the fixisolated-sonnet
  3. Review the fix
  4. Release
isolated run · run-7f3arunning
›run started · executor isolated-sonnet
02agent claude-code 2.1.4 (pinned) · model sonnet
03time limit 4h · task volume mounted
04env ANTHROPIC_API_KEY=••••••••masked
05tool workflow_step_get "Write the fix"
06edit src/billing/refund.ts (+14 -3)
07pnpm test billing · 48 passed
08pushed convops/task/8c1e
06you approve

A person reviews it.

The next step is an approval. The pushed work waits for a human. Approve, and the workflow carries on. Not before.

workflowFix refund roundingexample
  1. Reproduce
  2. Write the fixisolated-sonnet
  3. Review the fix
  4. Release
isolated run · run-7f3afinished
›run started · executor isolated-sonnet
02agent claude-code 2.1.4 (pinned) · model sonnet
03time limit 4h · task volume mounted
04env ANTHROPIC_API_KEY=••••••••masked
05tool workflow_step_get "Write the fix"
06edit src/billing/refund.ts (+14 -3)
07pnpm test billing · 48 passed
08pushed convops/task/8c1e
09advance · next step: Review the fix
›
waiting for a personReview the fix · convops/task/8c1eapprove
workflowFix refund roundingexample
  1. Reproduce
  2. Write the fix
  3. Review the fix
  4. Release
step · Write the fixneeds an executor

Fix the rounding in refunds. Add a test that fails today. Run the billing tests. Push to the task branch.

who runs this step?
three places to run

Your machine, your runner, or isolated.

Same process, same gates, same record. Only the place and the agent change.

Your machine

The step runs in the AI client you already have open, on your own checkout. Nothing to install.

local

Your runner

Your own infrastructure picks up the work and runs it your way. ConvOps keeps the process and the record.

custom

Isolated run

One Kubernetes pod per run, with its own volume, its own secret and a time limit. On our cloud or your cluster.

isolated

Your models, your keys

Bring your own models and credentials. Each executor holds one, handed over through a one-time link.

bring your own

precedence

The closest setting wins.

Set a workspace default once. Override it on a task, or on a single step. Each step resolves on its own.

checked top to bottomfirst set wins
01Step executorset on one workflow stepnot set
02Task executorset on the tasknot set
03Workspace defaultworkspace settingsisolated-sonnet
runs on
checking layers

from Workspace default 

Nothing set on the task or the step. The workspace default runs it.

the executor, configured

Engine, version, model, key, clock.

One executor fixes everything a run depends on. The key arrives through a one-time link. Nobody pastes it anywhere.

executors · new executorexample
engine
nameisolated-sonnet
agentclaude-code
where it runs
version
time limit
4hdefault
model
credential
No value field. Keys are never pasted here.
start commandoptional · agent default
a run's life

Start, work, push. Or resume.

Every isolated run records its tokens, cost and time. A run that hits its time limit picks up again on the same volume.

runFix refund roundingscheduled
queuedpod startingworkingpushing
pushed
tokens0k
cost$0.00
duration0m 0s
runUpgrade payments SDKscheduled
queuedpod startingworkingresumedpushing
pushed
tokens0k
cost$0.00
duration0h 0m
the stop

Stop any run.

Agents run on their own. People keep the stop, the clock and the review.

runRewrite pricing pagescheduled
queuedpod startingworkingpushing
stopped
tokens0k
cost$0.00
duration0m 0s
  • Stop any run, at any point.From the app or from your AI client. The run ends and the record says it was stopped.
  • A clock on every executor.Four hours by default, set per executor. A run that hits it resumes on the same volume.
  • Pushed work waits for you.Put an approval after the step. A person reviews what the run pushed before anything moves on.
the difference

Laptops and keys vs executors.

  • Agents run on laptops with personal API keys.
  • Nobody can say which model or version did the work.
  • Keys get pasted into chats and config files.
  • A stuck agent runs until someone notices.
  • Every machine is set up a little differently.
  • Switching AI means rebuilding the setup.

Create an executor

One call names the engine, a version from the catalog, the model, the time limit and a credential reference. A value is refused. The intake source returns a one-time link instead.

payload
executors_manage({
  "action": "create",
  "workspace": "engineering",
  "slug": "isolated-sonnet",
  "runner": "convops",
  "config": {
    "backend": "isolated",
    "isolated": {
      "agent": "claude-code",
      "agent_version": "2.1.4",
      "model": "sonnet",
      "time_limit_s": 14400,
      "credential": {
        "kind": "api-key",
        "secret": { "source": "intake" }
      }
    }
  }
})

// response (abridged)
{
  "slug": "isolated-sonnet",
  "credential": {
    "status": "awaiting value",
    "one_time_link": "<sent to you, used once>"
  }
}
example · executors_manage create, isolated backend

Resolution: closest wins

When a step is dispatched, the engine checks the step, then the task, then the workspace default. The first one set is the executor for that step only.

payload
// step "Write the fix"  executor: isolated-sonnet
// task  8c1e           executor: nightly-runner
// workspace default    executor: local

resolved executor for this step:
{
  "executor": "isolated-sonnet",
  "from": "step",
  "agent": "claude-code",
  "agent_version": "2.1.4",
  "model": "sonnet",
  "time_limit_s": 14400
}
example · how one step resolves

Pinned versions

The isolated backend publishes a catalog of agents, versions and default models. An executor pins one version, so a run never changes under you.

payload
executors_manage({ "action": "catalog" })

{
  "agents": [
    { "agent": "claude-code", "versions": ["2.1.4", "2.1.3"], "default_model": "sonnet" },
    { "agent": "opencode",    "versions": ["0.15.2"],         "default_model": "anthropic/claude-sonnet-4-5" }
  ]
}
example · catalog (abridged)

Your own runner

A custom executor returns the dispatch envelope to your runner instead of starting a pod. Your runner does the work; the workflow, gates and record stay in ConvOps.

questions

What buyers ask.

Which AI agents can an executor run?

Claude Code and OpenCode today. The design is agent-neutral: an executor names an engine, a pinned version and a model, so other agents such as Codex and Kimi plug in the same way.

Where does the work actually run?

Three places. Locally, in the AI client you already have open. On your own runner, which picks up the work and runs it your way. Or as an isolated run: one Kubernetes pod per run, with its own volume, its own secret and a time limit.

How do you handle our API keys?

Bring your own models and credentials. A credential is handed over through a one-time link, never pasted in chat. It is stored as a secret, given only to the run that needs it, and masked in every log and transcript.

Can different steps use different executors?

Yes. A step can name its own executor, a task can name one for all its steps, and the workspace has a default. The closest setting wins: step, then task, then workspace.

What stops a run from going on forever?

Every executor carries a time limit, four hours by default. A run that hits it resumes on the same volume. Any run can also be stopped by a person at any point.

Can it all run inside our own cluster?

Yes. Isolated runs can run on your own Kubernetes, and enterprise customers can self-host all of ConvOps with a Helm chart. Nothing has to leave your cluster.