The open agent control plane

Own what acts on your behalf.

Find every AI agent. Give each one an owner. Control what it can call, spend and touch.

Any cloud · Any framework · Any model · Your network

Agent sprawl

AI is everywhere. Control isn’t.

Agents now run in every cloud, SaaS app and laptop, each with its own console, keys and bill.

Four questionsTodayWith Opencontroller

What do we have?

A spreadsheet someone updated in March.

Every agent, on every cloud, in one live inventory.

1,284 agents · 0 without an owner

What can it do?

Whatever its API key allows.

Only what its identity and policy allow.

Refund ≤ $2,500 · cases:read

What is it costing?

Four invoices. No owners.

Every dollar, by agent, version and team.

$48,210.37 this month · claims ops 31%

Who can stop it?

Whoever finds the right console.

Its owner, in one click. Or a policy, automatically.

Paused 14:03:51 · by P. Raman

If any answer takes more than a minute, that’s agent sprawl.

See all four answered

The platform

Ten blocks. One control plane.

Find, ship, run and improve every agent the same way, whoever built it and wherever it runs.

10 blocks · 70+ modules · one policy model

Follow one agentClaims intake, from shadow to production, through all ten

Find

Know every agent you have.

Block 01

01Discover

Find the agents nobody told you about.

Read-only scans across clouds, clusters and developer laptops turn shadow agents into one live inventory.

Discovery 0929-0914 · read-only · 145 shadow agents found, 2 shown

Ship

Release agents like software.

Blocks 02 – 05

02Register

Give every agent an owner.

One record per agent: owner, purpose, versions, tools, MCP servers and risk tier. Nothing runs unnamed.

03Identity

Retire the shared API key.

Each agent gets its own workload identity, acts on behalf of real people, and signs in through the IdP you already run.

04Evals

Test before you trust.

Multi-turn, red-team and regression evals gate every release, and the evidence ships with the version.

05Deploy

Ship with a way back.

Ordered environments, approvals, canaries, one-step rollback and quarantine. Your CI keeps building.

Run

Control happens in the path.

Blocks 06 – 09

A dashboard can’t stop an agent. Opencontroller sits between your agents and everything they call.

Agent Gateway · claims-intakeLive
  1. Appclaims-portal41 / 600 per minAllow
  2. Userdan.okafor · claims-opsGroup claims-opsAllow
  3. Agentfraud-screen · A2AScopedAllow
  4. Servicemarketing-botInternal serviceAllow
  5. Partnerbroker-portalOutside orgDeny
  6. AnyoneanonymousSign-in requiredDeny

06Agent Gateway

Decide who gets to call each agent.

Public, internal or private. Every caller, human, app or agent, is authenticated, authorized and rate-limited. Try the switch.

07LLM Gateway

Put every model call on a budget.

Virtual keys, team budgets, rate limits, routing, fallback and caching across model providers.

08Guardrails

Stop the bad call before it lands.

Prompt injection, PII, secrets, groundedness and per-tool limits, checked in the path both ways.

09Observability

Know why it did that.

OpenTelemetry traces with cost, quality and owner on every span, exported to the tools you already run.

Want to watch it stop one of your agents?

Book a demo

Improve

Get better with every release.

Block 10

10Refine

Turn every failure into a test.

Failures cluster, fixes are proposed and proven on held-out evals, and each resolved issue joins the suite.

v15.1 goes back through the release gate

Refine · 1 cluster · 3-line change · the fix that lifts v15 over the groundedness gate

Control without migration

Keep your stack. Add control.

Your clouds, frameworks, models, CI/CD, identity and observability stay where they are. Change an endpoint, not your application.

Your network · your cloud account

Destinations you allow
  • Hosted models OpenAI-compatible
  • Models you host On-prem
  • SaaS tools MCP
  • Enterprise APIs REST
In the path

Opencontroller

Enforcement · in the request path

  • Agent Gateway
  • LLM Gateway
  • Guardrails

Control plane · system of record

  • Registry
  • Identity
  • Policy
  • Releases
  • Evidence

Your systems, unchanged

  • Identity provider OIDC · SAML · SCIM
  • CI/CD Webhooks · CLI
  • Secrets manager Stays in place
  • Observability · SIEM OpenTelemetry
Your runtimes
  • AWS
  • Azure
  • Google Cloud
  • Kubernetes
  • Your data center
  • Vendor platforms
  • Developer laptops Basecode
Your VPC · the control plane and gateways run in your cloud account, inside your network boundary
  • Open by design
  • OpenAI-compatible
  • MCP
  • A2A
  • OpenTelemetry
  • OIDC
  • SAML
  • SCIM
  • REST
  • Webhooks
  • CLI

Sovereign by architecture

Runs inside your walls.

Deploy in your VPC, on-prem or air-gapped. Control-plane data, credentials and telemetry never need to reach Lyzr.

  • SOC 2 Type II
  • ISO 27001
  • ISO 42001
  • HIPAA
  • GDPR
Lyzr trust center

Egress ledger · 3 destinations you authorized · nothing sent to Lyzr

FAQ

Asked on every first call.

Do we have to move our agents?

No. Agents stay on the runtimes they run on today. Opencontroller registers them, observes them, and enforces policy wherever their traffic passes through its gateways.

Does it work with agents we didn’t build with Lyzr?

Yes. It is cloud-, framework- and model-agnostic, with adapters for Amazon Bedrock AgentCore, Gemini Enterprise Agent Platform and Microsoft Foundry, and open standards for everything else.

How much control do we get over third-party agents?

It depends on the path. Every agent gets a registry record. With telemetry, you can observe it. Route its traffic through the gateways and you can authenticate, budget, guard and stop it.

Where does our data go?

Only where you allow. Customer-managed deployments don’t require control-plane data, credentials or telemetry to reach Lyzr, and model and tool calls go only to destinations you authorize.

We already run an AI gateway. Why add this?

A model gateway covers one block of ten. Opencontroller adds inventory, identity, evals, releases, agent access and refinement, all on one policy model.

Can it see coding agents on developer laptops?

Yes, with Basecode. It brings supported coding agents such as Claude Code, Codex and Copilot under the same policy and spend controls, from the laptop to the runtime.

How long does setup take?

Less than a week for a first environment. Discovery is read-only, so it starts without changing anything you run.

What happens if we leave?

You keep everything. Your agents, pipelines and data never moved, so leaving means pointing endpoints back.

Ready for open water?

Bring the agent you worry about most. Leave knowing how to find it, scope it and stop it.

Book a demo

Set up in less than a week