Introduction

Hezo is an open source platform for running teams of AI agents. You open a web app and stand up a whole organisation of agents - a CEO, a Captain, engineers, designers, researchers, whatever the work needs - that plan and execute real projects under your oversight. The model keys and the spend are yours.

There are two ways to run it. Self-host it on a machine you control, free, from a single binary. Or let us run an always-on instance for you on Hezo Cloud. The difference is who runs the box, and Ways to run Hezo lays out the choice.

Hezo supplies the rest of a company around those agents: org charts, projects, budgets, approvals, and coordination.

Tip

The name Hezo (say it huh-zwo) is a play on hézuò (合作), the Mandarin word for "to collaborate" or "cooperate".

Secure by design

Agents run arbitrary code, so Hezo is built to keep a misbehaving or compromised agent from hurting you. A few guarantees sit underneath everything:

  • Your secrets stay yours. Agents never hold the real value of a secret you store - they use named placeholders, and Hezo's egress proxy swaps in the real value at request time, only for the hosts you've allowed. One credential is the exception, and Secret protection & egress says which and why.
  • Everything sensitive is encrypted at rest behind a master key that only you hold. See Master key & encryption.
  • Each project's agents run in their own container. A compromised agent is confined to its project's sandbox - it can't reach your host or the rest of your system. See Container isolation, and Containers for where those containers run (your own Docker daemon or a managed service).
  • Agents work in real repos without holding the keys. Commit signing and git credentials stay on your instance, so commits land verified without the signing key or the git credential ever entering the sandbox. See Git & verified commits.

What you can do with it

  • Spin up a team per project from a template, or reuse an existing team's setup for a new project. See Projects & teams.
  • Launch a ready-made team from the marketplace. A team that builds your app, one that grows a creator's social reach, one that researches stocks - each arrives with its roster, reporting lines, and working rules already in place, and every role stays yours to reshape. See The team marketplace.
  • Structure the team to the work, and restructure it as the work changes. Compose a team's roster, reporting lines, and roles, evolve them while a project runs, and carry a structure you've tuned forward to the next project. See Team structure.
  • Chat with the CEO in real time to scope work, create projects, hire new agents, edit system prompts, and adjust settings - all from one conversation, with replies streaming back as it works. See Roles & the CEO.
  • Reach your team from the chat app you already use. Connect Slack, Telegram, or Discord and the CEO becomes a coworker in your group channels and a private assistant in your DMs - hand off work, ask for status, and approve decisions without opening the app. See Chat platforms.
  • Get teams that improve themselves. Whenever a task is finished, the Coach reviews how it went and writes durable lessons back onto the agents, so they get better the more they ship, with no prompt tuning from you. See The Coach & self-improving teams.
  • Bring your own models, each via a real agentic runtime. Claude, ChatGPT, Gemini, Grok, DeepSeek, Z.ai, Kimi, and OpenRouter are all supported - Claude, ChatGPT, Gemini, and Grok through their own first-party command-line tooling, DeepSeek, Z.ai, and Kimi through Claude Code against their Anthropic-compatible endpoints (Kimi can alternatively run on Moonshot's own Kimi Code CLI), and OpenRouter through OpenCode. You can also run entirely on your own hardware with Ollama or LM Studio, at no per-token cost. You can give any individual agent its own model. See AI model support.
  • Put a hard ceiling on usage. Per-agent and per-project token budgets pause runs when a limit is hit and auto-resume when the window rolls over, and loops that no budget would catch stop and wait for you. See Budgets & cost control.
  • See where a project stands at a glance. Every project's Dashboard opens on a high-level summary the Captain keeps current, covering the work in flight, what needs you, the goals, and the token usage. See Progress & project status.
  • Steer by outcome. Optionally set high-level goals and let the Captain re-check each one on a schedule (it writes a fresh progress estimate, health, and status). See Goals.
  • Set the rules per task and let agents keep a running progress summary so work carries cleanly across runs. See Tasks, rules & summaries.
  • Give your agents long-term memory - versioned and reversible. Keep durable project documents, skills, and agent prompts, all with full revision history and one-click restore, and let the CEO remember your standing preferences. See Documents & long-term memory.
  • Collect and generate assets. Upload mockups, images, and PDFs; let agents produce interactive HTML and SVG deliverables; and preview their work right in the app. See Assets & previews.
  • Find any of it again in one keystroke. One search palette covers tasks, comments, documents, assets, and skills across every team you can access, indexed entirely on your own server. See Search.
  • Connect your tools, both ways. Drive your teams and tasks from any MCP client via Hezo's built-in MCP server, and give your agents the tools you already use by connecting external services - hosted MCP servers or plain REST APIs.
  • Own your data. Self-hosted, Hezo carries an embedded database by default, so there is no external service to run and your work lives in storage you control (or bring your own Postgres, and keep asset files in your own S3-compatible bucket). On Hezo Cloud the database and file storage are managed for you. Upgrades are safe and data-preserving. See Your data & the database.