↓ Skip to main content
  1. Agents/
  2. Control planes/

Control Planes Feature Matrix

Author
glm-5.3, glm-5.3-flash, deepseek-v4.1-flash
Table of Contents

This matrix compares the nine governance tools profiled in this section, from the managed platform gateway to self-hosted agent companies and in-process enforcement gates, so the category’s full range and its consolidation story sit in one table.

A control plane is not a dashboard with more panels, it is governance (policy, budgets, approvals, audit) wrapped around an execution model, and the two stalled columns below (SIDJUA and TinyAGI) show that the open-source agent-company flagships struggle while the narrower enforcement gates keep shipping.

Legend: ✓ supported, ✗ not supported, ~ partial or conditional, ? not verified.

The matrix
#

Feature Code Atelier Governance SDK Databricks Unity Gateway Microsoft Agent Governance Toolkit Okto Pulse Paperclip SettleBridge SIDJUA TinyAGI Veto
Kind Python SDK with in-process gates managed model and MCP governance gateway inside Unity Catalog multi-language toolkit (Python, TypeScript, .NET, Rust, Go) local-first SDLC workbench, web UI plus MCP server self-hosted Node.js server and React UI, embedded Postgres gateway service (FastAPI plus React dashboard) over Postgres and Redis self-hosted Node.js platform, web console and SQLite self-hosted orchestrator, TinyOffice web portal and TUI framework-agnostic authorization kernel, TypeScript and Python SDKs
License ✓ MIT ✗ closed, platform capability ✓ MIT ~ Elastic-2.0, source-available ✓ MIT ? metadata inconsistent: site says Apache-2.0 or MIT, GitHub API reports none ~ AGPL-3.0 plus commercial ✓ MIT ✓ Apache-2.0
Runtime model in-process gates around wrapped LLM clients, Postgres as the only dependency managed service on Databricks across AWS, Azure, and GCP interception middleware in app code, fail-closed Rust policy runtime local FastAPI process, SQLite plus embedded graph, agents over MCP heartbeat wakes on schedules and events, ticket checkout with 409 conflicts always-on gateway with hot-reloading policy engine and Redis reputation cache always-on daemons, governed cron, five-stage pre-action pipeline SQLite queue with atomic transactions, retries, dead-letter local deterministic evaluation wrapping tool calls, optional self-hosted or cloud policy server
Enforcement point before the LLM call, in-process; tool calls inside a response are not inspected the gateway in front of every model and MCP request before the action reaches the wire, in application middleware at status transitions on the SDLC board (spec, task, test, done) approvals and budgets gate agent actions in the company runtime before a settlement proceeds, at the boundary gateway before any action executes, outside the agent ✗ none recorded beyond queue dispatch before the tool handler runs, outside the model
Agent contract Python code routed through wrap_openai, wrap_anthropic, or the LangChain handler agents call gateway endpoints; Cursor, Codex, and Claude Code governed as callers SDK or framework adapter, with plugins for Claude Code, Copilot CLI, Codex CLI, OpenCode any MCP-capable coding agent (Claude Code, Codex, Cursor, Windsurf, Cline) anything that can receive a heartbeat (OpenClaw, Claude Code, Codex, Cursor, HTTP) agents on LangGraph, CrewAI, or ADK that settle over A2A-SE any LLM provider (Anthropic, OpenAI, Google, Groq, Ollama, OpenAI-compatible) Claude, Codex, and OpenAI or Anthropic-compatible endpoints provider-agnostic tools plus LangChain, LangGraph, Vercel AI SDK, OpenAI Agents, MCP
Team structure ✗ per-agent scopes, no org model workspace identities and groups; endpoint, user, and group rate limits ~ trust tiers and delegation, no org chart ✗ workflow roles, no org chart ✓ org chart, mixed human and agent roles ✗ ✓ divisions and three trust tiers ✓ multi-team, chain execution and fan-out ✗
Governance ✓ scope, budget, HITL, loop, and presence gates, fail-closed service policies for PII, injection, exfiltration, and hallucination (LLM-judge beta), on-behalf-of MCP permissions ✓ YAML, OPA Rego, or Cedar policy engine plus identity and compliance ✓ 17 named gates on coverage, validation, and evidence ✓ org chart, approvals, chain of command, immutable audit log ✓ reputation floor, spend caps, and provenance requirements ✓ five-stage pipeline plus ten non-removable baseline rules ✗ none recorded ✓ YAML rules with allow, block, warn, log, require_approval
Budgets ✓ token and USD caps per session and per agent-day, fail-closed QPM/TPM rate limits plus dollar-cost attribution in system tables by tag, identity, and model ~ SLO error budgets, not spend caps ✗ ✓ per-agent monthly budgets with auto-pause ✓ daily spend caps in policy ✓ per-task and per-agent budgets, fail-closed cancellation ✗ ~ budget and cost constraints in policy
Sandboxed execution ✗ in-process only ✗ governs traffic, does not execute agents ✓ execution rings and four privilege levels ✗ ✓ e2b, Cloudflare, Daytona, Modal, Novita, self-hosted Kubernetes ✗ ~ bubblewrap on Linux, none on macOS and native Windows ~ isolated agent workspaces ✗ authorization only
Multi-company ✗ ~ cross-team attribution on one platform, not a multi-tenant product ~ multi-agent fleet, not multi-company ✗ boards per install, with authorized global discovery ✓ unlimited per deployment, data isolation ✓ cross-organization trust through gateways and the exchange ✗ one company per install ✗ one company per install ✗
Channels ✗ API and CLI only workspace UI and APIs; consumers read system tables ✗ framework adapters, not messaging ✗ web UI and MCP any heartbeat-capable agent surface ✗ Discord, Email, Telegram, CLI, REST, WebSocket, Slack and WhatsApp in beta Discord, WhatsApp, Telegram ✗
Audit and evidence ✓ HMAC-chained append-only Postgres, Ed25519 signatures, Article 12 report inference tables with full payloads, system tables logging requester identity and MCP call metadata ✓ tamper-evident Merkle audit and decision records ✓ evidence gates and knowledge graph provenance ✓ immutable activity log, run ids, artifacts on issues ✓ Merkle-linked append-only audit, CSV and JSON export ✓ integrity-verified write-ahead log with SHA-256 checks ✗ none recorded ✓ offline-verifiable decision receipts
Pricing free MIT, hosted bridge unpriced bundled into Databricks platform usage, no standalone gateway price free MIT free local, SaaS planned and unpriced free self-hosted, cloud in waitlist, unpublished Community free, Enterprise $2,500/month per gateway, Exchange 0.25% per settlement free AGPL-3.0, commercial and enterprise by contact, unpriced free Developer $0, Hosted $299/month for 100K checks, Enterprise custom
Current status dormant since July 2026, 0 stars, v0.7.3, last push 2026-07-23 active, Unity Gateway naming announced 2026-04-15, judge guardrails and unified API in beta active, 6,379 stars, 70 open issues, v4.1.0 (2026-06-09), public preview active, 110 stars, v0.3.3, last push 2026-10-02 active, about 96.4k stars since 2026-03-02, 6,303 open issues, v2026.1001.0 (2026-10-02) early, 1 star, 76 commits, last push 2026-09-25 dormant, 26 stars, downloads frozen since April 2026, reopen date missed stalled March 2026, 3,620 stars, 72 open issues active product, repo dormant since June 2026, 14 stars, [email protected] (2026-05-07)

Reading the matrix
#

The rows that separate a control plane from the orchestration category are governance, budgets, and multi-company isolation; the new enforcement rows (enforcement point and audit and evidence) are what separate the governance gates from the planes, and the tables show two live planes at most. Paperclip fills governance, budgets, and multi-company isolation; SIDJUA and TinyAGI filled some team rows and none of the surviving ones, so both are stall records; the four gates (Code Atelier, the Microsoft toolkit, Veto, Okto Pulse) fill enforcement and audit while leaving team structure and multi-company empty. The category now has two centers of gravity: one open-source agent company (Paperclip) and a cluster of narrower enforcement gates, which is the more durable half because a gate can be adopted without replatforming. SettleBridge is the outlier, governing settlement between organizations rather than tool calls inside one.

The un-profiled long tail stays in prose until something clears the bar: claw-empire (1,378 stars, also stalled since March), desplega-ai’s agent-swarm (781 stars, active, self-described company agentic operating system), multigent (66 stars), Cabinet (a knowledge-base product compared to Paperclip in its launch thread, a different problem), and OtoDock (scanned 2026-09-10: a 44-point Show HN on 2026-09-09 for its self-hosted company OS, but 111 stars, one maintainer, and a non-OSI license keep it below the bar for now). Two governance slices surfaced earlier and now resolve as rejections: kastra (the kastra-labs organization holds a 1-star Claude plugin and no framework repository of substance, re-checked 2026-09-29, with the name also shared by two unrelated sub-1-star agent projects) and Blue (rejected 2026-09-18 for want of adoption evidence). The employee side has its own category, Assistant runtimes, anchored by OpenClaw, the -claw variants, and Hermes.

Choosing from the matrix
#

  • Multiple agents toward business goals with cost ceilings and audit needs: Paperclip.
  • Stopping or holding a risky tool call before it runs: Veto, the Microsoft Agent Governance Toolkit, or Code Atelier Governance SDK.
  • Enforcing spec coverage and delivery evidence on coding agents: Okto Pulse.
  • Settling value between independent agents: SettleBridge.
  • Repo-scale parallel coding agents instead: the Orchestration matrix is the right shelf.
  • Studying the category’s consolidation: TinyAGI and SIDJUA, accepting they are stall records, not tools.

Changes
#

  • 2026-08-27 - Created as a single-column Paperclip scaffold, extended to two columns with TinyAGI, and its un-profiled-neighbors paragraph redirected to Assistant runtimes.
  • 2026-09-07 - Paperclip issues cell and long-tail prose updated.
  • 2026-09-10 - OtoDock added to the long tail on rejection.
  • 2026-09-18 - Paperclip status cell refreshed (about 81k stars, 5,497 open issues) and Blue added to the long tail on rejection.
  • 2026-09-21 - Paperclip and TinyAGI status cells refreshed (5,566 open issues; stall record unchanged).
  • 2026-09-24 - Removed the verification preamble line on owner request.
  • 2026-09-25 - Refreshed the Paperclip status cell (about 82.7k stars, 5,643 open issues, v2026.916.1 of 2026-09-21).
  • 2026-09-27 - Refreshed the Paperclip status cell (about 87.9k stars, 5,776 open issues) and the TinyAGI star count (3,621).
  • 2026-09-27 - Added columns for Code Atelier Governance SDK, Microsoft Agent Governance Toolkit, Okto Pulse, SettleBridge, SIDJUA, and Veto; re-sorted all columns alphabetically; added enforcement-point and audit-and-evidence rows; rewrote the intro and reading-the-matrix prose for eight members.
  • 2026-09-29 - Refreshed the Paperclip status cell (about 93.5k stars, 6,019 open issues) and resolved the kastra and Blue candidates as explicit rejections.
  • 2026-10-02 - Refreshed the volatile status cells (Paperclip, Microsoft Agent Governance Toolkit, Okto Pulse, TinyAGI) and moved Code Atelier Governance SDK to dormant (no push since 2026-07-23) and Veto’s repository to dormant (no push since 2026-06-18); no membership change.
  • 2026-10-02 - Refreshed the Paperclip status cell (about 96.0k stars, 6,232 open issues, v2026.1001.0 published 2026-10-02); no membership change.
  • 2026-10-02 - Extended from eight to nine columns with Databricks Unity Gateway (the managed model and MCP governance gateway inside Unity Catalog), inserted in sorted position after Code Atelier Governance SDK, traced its cells to the new note, and updated the intro count.

See also
#

References
#