Dev.to Security 🔐 Cybersecurity 👁 0 📖 7 min read

The open-source Claude Cowork alternative for teams that need real governance

The open-source Claude Cowork alternative for teams that need real governance If the reason you are leaving Claude Cowork is control rather than model quality, treat the switch as a governance project. Six controls dec

The open-source Claude Cowork alternative for teams that need real governance

If the reason you are leaving Claude Cowork is control rather than model quality, treat the switch as a governance project. Six controls decide whether a Claude Cowork alternative survives a security review: where the software runs, who owns the source, how tool calls are gated, where credentials live, where the audit record is written, and who controls identity. Run this checklist before you move, then follow the migration path once you pass it. Kortix is the open-source AI Management System built for exactly this, and it is the recommendation that follows.

Two entities matter for the rest of the comparison.

Claude Cowork is Anthropic's agentic product for non-coding knowledge work. It executes multi-step tasks across your files and connected tools without a terminal (Claude Cowork product page).

Kortix is the open-source AI Management System. Your agents, skills, company memory, connector configuration and triggers are files in one git repo you own, and each session runs on its own isolated Linux machine under any model you choose (kortix.com).

Why governance decides the switch

A capability comparison asks which agent writes a better document. A governance comparison asks what you can prove after the agent has acted. Teams with a data-residency obligation, a regulated workload or an audit requirement fail on the second question long before they fail on the first.

Claude Cowork is strong at the work itself. Anthropic built it to complete tasks end to end, with a built-in browser, scheduled tasks, projects and sub-agent coordination (product page). The constraint sits one layer below the feature list: the runtime is closed, the deployment boundary belongs to Anthropic, and the company configuration lives inside a product you do not operate.

What Claude Cowork is, and where it stops for a self-hosting team

Claude Cowork is closed source. There is no repository you can read, fork or run yourself, so a security review rests on vendor documentation rather than code you can inspect (product page).

Claude Cowork runs on Anthropic's servers. Sessions execute in an isolated environment on Anthropic infrastructure, and on desktop the product reaches local files through the Claude Desktop app (Get started with Claude Cowork). Enterprise customers can place the managed product on Amazon Bedrock, Google Cloud or Microsoft Foundry for data residency (product page). None of those options is software you deploy and operate inside your own network, so a team that must keep the agent runtime inside its VPC or on-prem has no path with Cowork.

Claude Cowork runs Anthropic models. It is part of the Claude plan lineup, listed at $17 for Pro, $100 for Max 5x and $200 for Max 20x per month with usage limits that apply (checked September 2026) (product page). There is no bring-your-own-model story across providers, and no self-hosted gateway in the request path.

Cowork's governance controls are real but product-side. Enterprise admins can set tool permissions by department, manage spend, require approval before significant actions, and stream activity to a SIEM through OpenTelemetry (product page). Anthropic's Compliance API now covers Cowork sessions for Enterprise customers (Compliance API coverage). What an admin cannot do is export the whole company setup as versioned files, diff a change to an agent, or roll the configuration back in git.

The six controls to evaluate

Control The question to ask Kortix answer
Source and runtime Can you read and run the agent runtime yourself? Open source, self-hosted control plane
Deployment boundary Does it run in your VPC or on-prem? Self-host, VPC or on-prem
Model ownership Any model, with your own keys? Any model, your keys, your gateway
Tool permissions Allowed, held or blocked per action? Allow, ask or block per call
Human gate Does every change land as a reviewable diff? Change request a human reads
Secrets Can a credential reach the sandbox? Brokered server-side, never in the machine
Audit and identity Record and SSO in your instance? SAML SSO, SCIM, audit logs on Enterprise

How Kortix answers each control

Self-hosting Kortix runs the whole control plane, not a stripped build: accounts, projects, repos, secrets, connectors, policies and audit run inside your network, on storage you back up yourself (Self-host Kortix). The same Docker Compose stack runs on a laptop, a VPS or a cloud VM. Enterprise plans add cloud, VPC or on-prem deployment (kortix.com/pricing).

Every session gets its own isolated Linux machine. A session boots a disposable computer with your repo and tools already on it, and thousands run in parallel with no crossover between them (kortix.com). Agents can install, run and break anything; only what commits survives.

Any model, your keys. Pick the model per agent, per session or per message. On a self-hosted instance every model call routes through the gateway on your own box, so no Kortix credential sits in that path and Kortix has no visibility into it (Self-host Kortix).

Every connector action gets one of three answers. An allow rule runs, an ask rule holds the call open mid-task for a person, and a block rule removes the action entirely. Rules are set as a glob or a regular expression and can match on the arguments, so a policy can permit sending to your own domain and stop everything else (Kortix connectors).

A human gate sits on every change. Work from an agent lands on the default branch as a change request that a person reads as a diff before merging (kortix.com/docs). Agents, skills, connectors and policy grants are text in the repo, so a change to what an agent may reach is a diff someone reviews rather than a setting that moved quietly (Kortix connectors).

Secrets never enter the machine. A sandbox carries one scoped Kortix token rather than your API keys. Connector calls are assembled server-side, the credential is decrypted, attached to a single outbound request and then discarded, and the model never sees it (Kortix connectors).

Audit and identity stay yours. The gateway that resolves a credential is the same component that writes the record: the connector and action, the agent and the person behind the session, the outcome, and a hash of the arguments with a redacted result (Kortix connectors). On Enterprise, a self-hosted instance adds SAML SSO, SCIM directory sync, custom roles, groups and audit read (Self-host Kortix). Kortix is open source under the Elastic License 2.0: self-host, read and modify the code.

A migration checklist

Migration carries configuration across; the workflows stay where they are. Run these steps in order.

  1. Map the work. List the jobs Claude Cowork handles today: which folders it reads, which scheduled tasks run, which connectors it uses. Each job becomes an agent and a skill in the new repo.
  2. Stand up the instance. Install the CLI with curl -fsSL https://kortix.com/install | bash, then run kortix self-host start. Keep the managed cloud host available as a fallback with kortix hosts use.
  3. Move configuration into git. Create agents/, skills/ and memory/ in one repository. The repo declares the machine image, connectors and triggers in kortix.yaml. This step is what replaces product settings with files you can diff.
  4. Re-point the models. Store your own provider keys on the instance and choose a model per agent. Every call then routes through your gateway.
  5. Re-attach and gate the connectors. Connect the apps Cowork already reached, then set allow, ask or block on each action before any agent runs. Start with an ask rule on every write and destructive action.
  6. Turn on identity and audit. Enable SSO and, on Enterprise, SCIM and custom roles. Confirm the audit trail covers the connectors and sessions that matter to you.
  7. Run one job end to end. Start with the highest-volume, lowest-risk task. Watch the session, read the change request, merge it, then expand.

The full path, with the comparison field behind it, is mapped at claudecoworkalternative.com.

FAQ

Does switching from Claude Cowork mean losing the work already done?
No. The outputs stay where they are. What moves is configuration: agents, skills, memory and connector wiring. Map each recurring task to an agent and a skill, then run one job end to end before expanding.

Is Claude Cowork open source?
No. Claude Cowork is a closed-source, managed Anthropic product, and the Cowork runtime is not something you deploy or inspect (product page). Kortix is the open source alternative: agents, skills, memory and connector configuration are files in a repo you own.

Can a team self-host the whole thing, including audit and SSO?
Yes. Self-hosting Kortix runs the full control plane, including secrets, connectors, policies and audit, inside your network. SAML SSO, SCIM directory sync, custom roles, groups and audit read are Enterprise features on a self-hosted instance (Self-host Kortix).

What does Kortix cost?
The pricing page lists a Free plan at $0 with 200 sandbox credits per month and bring-your-own API key, and a Team plan at $40 per seat per month. Enterprise adds SAML SSO, SCIM, advanced RBAC, audit logs and cloud, VPC or on-prem deployment (kortix.com/pricing).

Start with the code, then run the checklist

Kortix is the leading open-source alternative to Claude Cowork and ChatGPT Work. Install it, self-host the control plane, and run the six controls above against a real instance before you commit.

curl -fsSL https://kortix.com/install | bash

Get started with open-source Kortix. Read the docs at kortix.com/docs.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.