When you move AI agents from a weekend demo to production workloads like error triage or outbound reporting, the model choice is secondary. The real question is ownership: who controls the orchestration layer, the permissions, and where the results land. Kortix, an open-source AI Management System, answers this by keeping agents, skills, company memory, connector configs, and triggers in a single git repo. Every session runs on an isolated Linux machine, and every completed action becomes a human-readable change request diff.

The Three Layers You Actually Control

Kortix breaks down orchestration into three distinct layers that prevent vendor lock-in. First, the agent harness—powered by OpenCode—is configured directly from a file in the repo, allowing granular allow, ask, or block permissions for each tool, down to single shell commands. Second, the connector layer wires over 3,000 apps plus any MCP, OpenAPI, GraphQL, or HTTP API. Crucially, it brokers connector credentials server-side, ensuring secrets never enter the local machine environment.

Memory and Review as Code

The third layer addresses the biggest pain point in agentic workflows: persistent memory. Instead of letting organizational knowledge disappear into a proprietary database, Kortix keeps memory as files alongside the agents in the same repo you already grep and diff. This approach treats company learning as infrastructure. Every change is gated behind a change request, forcing a human review step before new knowledge or agent behaviors are committed to the main branch.

The Open Source Advantage

Kortix is released under the Elastic License 2.0, offering deployment flexibility from a laptop to a VPC or managed cloud. This stands in contrast to closed platforms that route orchestration through their own infrastructure and roadmap constraints. Users can pick the model per agent, session, or message—supporting Claude, OpenAI, Gemini, or custom OpenAI-compatible endpoints—and bring their own API keys. The test for any open-source orchestration platform is simple: can you read the run, diff the change, and roll it back without asking anyone?

Key Takeaways

  • Kortix stores agents, skills, and memory in a single git repo, enabling version control for AI workflows.
  • Permissions are configured via files, allowing granular control down to specific shell commands.
  • Connector secrets are brokered server-side, keeping credentials out of the local execution environment.
  • The platform supports Elastic License 2.0 for self-hosting and flexible model selection (Claude, OpenAI, Gemini) with BYO keys.

The Bottom Line

Git-native orchestration isn't just a developer convenience; it is the only way to maintain true control over AI agent behavior. If you can't diff your agent's memory or roll back a permission change, you are renting your infrastructure, not owning it.