OpenBot — governed “AI coworkers” that can operate a computer

LinkedIn post by Sandhya Ahuja

Open-source, self-hostable template for turning agents into governed “AI coworkers”.

OpenBot is an open-source, self-hostable template for turning agents into governed “AI coworkers” that can actually operate a computer.

How it works

  • Each Bot gets its own container, Chromium profile, /workspace, and logins — agents do not share files or browser sessions.
  • Browser actions, file operations, shell commands, MCP calls, and component use all go through a central gateway that:
    1. Resolves the target
    2. Evaluates a CEL policy
    3. Records an audit entry
    4. Only then executes — or refuses — the action

Framework-agnostic

Because a Bot is simply an AG-UI endpoint, agents built with frameworks such as:

  • LangGraph
  • CrewAI
  • Mastra
  • Pydantic AI
  • Google ADK
  • or custom code

…can be connected without making OpenBot dependent on one agent framework.

Human-in-the-loop

Humans can watch the Bot’s live screen, take control for things like login or 2FA, and hand control back afterward.

Why this matters

The pattern: isolation per agent (container + profile + credentials) + central policy gateway (CEL) + full audit trail + human takeover for sensitive steps — addresses the two big enterprise blockers for computer-using agents: blast radius and accountability.