11 AOÛ 2026
GOUVERNANCE

Databricks open-sources "Omnigent", a "meta-harness" that governs Claude Code, Codex and Cursor at platform level — the same bet AppManager has made from the start, but on business actions, not code

On 13 June, Databricks/Mosaic released Omnigent as open source (Apache 2.0 licence): a single control layer placed above the coding agents people already use — Claude Code, Codex, Cursor, Pi, in-house agents. An OS sandbox that locks down system access, secrets injected only through an egress proxy on approved requests, cost budgets and conditional permissions: no tuning in the prompt, control at the level of the platform itself.

Omnigent is not one more agent, it is a layer that sits above the ones that already exist, with two concrete promises documented in the GitHub repo and in the post by Matei Zaharia (Databricks co-founder), Kasey Uhlenhuth and Corey Zumar: first, never hand a secret directly to the agent — credentials only pass through an egress proxy, on requests already approved; second, contextual policies able to track dynamic state, for example "after an agent downloads a new npm package, require human approval before any git push". On top of that come explicit cost budgets — pause the agent and ask for confirmation every 100 dollars spent — and an OS sandbox that locks down system access and intercepts network traffic.

What stands out is not the feature list — it is who is publishing it. Databricks/Mosaic is not a compliance vendor looking for a market: it is one of the most serious AI-infrastructure players in the industry, and its conclusion is that governing coding agents in production requires platform-level control, not trust that the prompt or the model will behave on their own. At AppH we have applied exactly the same principle from day one, but on different ground: it is never an agent that decides a business action — sending a quote, replying to a customer e-mail, triggering an automation — is harmless enough to skip an approval. The structure of the product enforces it, not a setting that could one day be loosened.

For AppH

  • A top-tier AI-infra player — not a small niche vendor — reaches the same conclusion we did: governing agents in production requires platform-level control, not just a good prompt. It confirms the bet we made from the start, not that we are catching up with a trend after an incident.
  • The principle Omnigent applies to code (npm, git push) is structurally the same one AppManager applies to business actions (quotes, e-mail, automations): never direct execution by the agent, always a human approval point before a real action goes out.

Against / the honest limit

  • This is not a product-to-product comparison: Omnigent governs development agents (Claude Code, Codex, Cursor) on technical infrastructure — npm packages, commits, OS access. AppH governs agents that act on an SMB's operations — CRM, invoicing, stock. Two different domains; pitting them against each other directly would be dishonest.
  • We have not tested Omnigent ourselves — everything we know comes from the official blog post and the GitHub README, not from an independent security audit. It is impossible to verify from the outside whether the sandbox really keeps its promises in real conditions.

The easy headline would be "even Databricks proves us right" — but the real lesson is not that an AI-infra player validates our approach, it is that the question of agent control is no longer asked at prompt level anywhere in the industry, from code to business management. Omnigent does it for code because that is where Databricks operates; AppH does it for SMB business operations because that is where we operate. What they share is not the product, it is the principle: an agent should never be the sole judge of what is "harmless enough" to act on without a human looking first. That holds for a git push just as it does for a quote sent to a customer.

Reviewed by a human at AppH
← Previous article (older)Next article (newer) →

← Back to news

Want us to walk you through how this applies to a real case?

Talk to AppH

Get new posts by email

One email when we publish new analysis — never spam, unsubscribe in one click.