Key takeaways
- Open-Inspect runs asynchronous coding sessions, automations, and parallel child sessions for a trusted organization.
- OpenCode remains the default harness; Claude Agent SDK is now a second option for Anthropic models.
- Workspace roles and audit logs exist, but users do not receive individual repository access boundaries.
- Cloudflare and container control planes have different operational limits; self-hosting still requires infrastructure and model spending.
FAQ
What is Background Agents?
Also called Open-Inspect, it is an MIT-licensed background coding system inspired by Ramp's internal Inspect. Teams deploy and operate their own instance.
Does it only use OpenCode and Modal?
No. Claude Agent SDK is a second harness, and the deployment guide lists Modal, Daytona, Vercel Sandbox, OpenComputer, and E2B backends.
Is it suitable for unrelated customers in one deployment?
The documented security model is one trusted organization. Workspace roles regulate features, but source-control access is shared and sessions are workspace resources.
What does it cost?
The MIT software has no license fee. Operators pay for hosting, sandbox resources, models, and maintenance; the managed-deployment site does not publish a fixed price.
Executive Summary
Background Agents, also called Open-Inspect, is an open-source background coding system in Cole Murray's GitHub repository. Inspired by Ramp Inspect, it combines asynchronous sessions, a development environment, multiplayer prompting, and pull-request creation. It is designed for an internal trusted team. [1]
Since the June review, the project has added a Claude Agent harness, workspace roles, and authorization audit logs. The earlier description of an OpenCode-only system without audit controls is outdated. Those additions do not change the documented single-workspace repository trust model. [2][3]
| Attribute | Checked September 15, 2026 |
|---|---|
| Software license | MIT [4] |
| Primary workflow | Background coding sessions with web and bot interfaces [1] |
| Harnesses | OpenCode; Claude Agent SDK for Anthropic models [5] |
| Operator responsibility | Deployment, credentials, sandbox provider, and model access [6] |
See Cloud Coding Agent Platforms for the broader category.
Product Overview
Users can launch work through the web UI, Slack, GitHub, Linear, or webhooks. Sessions can contain multiple repositories, support collaborative prompting, and spawn child sessions in separate sandboxes. The project documents snapshots, prebuilt images, and proactive warming to reduce startup work; this review did not measure launch latency. [1]
Automations support schedules, inbound webhooks, Sentry alerts, Slack messages, and opt-in GitHub events. Scheduled multi-repository runs fan out into one session per repository; Linear event automations remain listed as planned, which is separate from the available Linear bot. [7]
Managed skills provide reusable instructions and supporting files assigned to repositories or environments, with session-specific revisions. Their documentation explicitly treats them as trusted instructions, not a permission boundary. [8]
Architecture and Deployment
| Layer | Current documented choices |
|---|---|
| Standard control plane | Cloudflare Workers, Durable Objects, KV, and D1 |
| Web application | Vercel or Cloudflare through OpenNext |
| Sandbox backend | Modal, Daytona, Vercel Sandbox, OpenComputer, or E2B |
These are deployment options from the current setup guide, not a claim that all providers have identical lifecycle or recovery behavior. [6]
A container alternative runs the control plane as one Node process with SQLite and S3-compatible storage, including an AWS deployment path. It is not a drop-in route to feature parity: the container guide lists the GitHub autofix queue and Slack/Linear bots as unavailable there. Its Litestream replica covers the global database, not complete session recovery; the operator needs a whole-volume backup for deployment state. The documented design also assumes one host accesses the data volume. [9]
Harness and model choice
OpenCode is the default and supports the model catalog, including OpenAI. Claude Agent supports Anthropic models through either an API key or connected account. A session fixes its harness at creation, children inherit it, and bots currently create OpenCode sessions. The project's account integration is documented behavior; model availability, quotas, and permitted account use remain provider-specific. [5][1]
Security Boundaries
Workspace roles are not repository ACLs. Owner, Administrator, Member, and Viewer control product actions. Sessions remain workspace resources, and the shared source-control installation determines the repository set. A user's personal repository access is not checked for each session. This is unsuitable as-is for unrelated tenants or teams needing confidential sessions within one installation. [3]
Suspension denies new operations and invalidates browser sessions, but live connections can take up to five minutes to close. It does not automatically stop a running sandbox. Operational offboarding must account for work already executing. [3]
The Claude harness guide is unusually explicit about a second boundary: commands and repository hooks launched by the agent inherit its environment and can read the model credential. The wrapper reduces accidental propagation; it does not prevent deliberate exfiltration by code running in that sandbox. Disabling an account in Open-Inspect also does not revoke an already-issued token at Anthropic. [5]
The September 1 changelog adds a workspace audit log for authorization decisions. This is useful evidence of improved controls, not an independent compliance or isolation certification. [2]
Pricing and Licensing
| Component | Cost model |
|---|---|
| Open-source software | MIT permits commercial use subject to its notice conditions [4] |
| Hosting and execution | Your selected cloud, sandbox, and model services [6] |
| Managed deployment | Offered through an inquiry form; no public fixed rate found on the site [10] |
Single-tenant design is a security and deployment constraint, not a ban on commercial use. The previous estimated hourly and monthly totals were not tied to a reproducible workload and have been removed. Size costs using actual concurrency, sandbox resources, model consumption, and operational support.
What Developers Say
On September 15, 2026, GitHub user Blue101black reported that a Linear-delegated task opened its PR as the shared bot despite the web UI identifying the human prompt author. The report's proposed root cause is explicitly AI-generated; this review treats the observed attribution mismatch as the user's experience and does not adopt that diagnosis as independently verified. Issue #1912 remained open when checked. [11]
This illustrates why commit authorship, session attribution, and the account that creates a PR should be tested separately. It is one report rather than a measure of overall reliability. The landing page's speed and adoption slogans are likewise not independent benchmarks. [10]
Where Tembo Fits
Disclosure: Ry Walker is Tembo’s co-founder and CEO. Tembo is discussed here as an alternative. [12]
Tembo is a direct alternative when the decision is how to operate background coding agents for a team. It documents orchestration of Claude Code, Codex, Cursor, and other harnesses, with shared session visibility and reviewable pull requests. [13] It offers both managed cloud and self-hosted deployment; self-hosting still leaves backups and recovery with the operator. [14]
Open-Inspect offers an MIT codebase to inspect and customize around a trusted workspace. Tembo is the commercial platform option to evaluate when managed operations and a common team workflow matter more than owning the orchestration implementation. Compare your required integrations, access model, and recovery responsibilities in a pilot, rather than assuming either approach is automatically more secure. [4][3]
Assessment
Best fit: a trusted engineering organization willing to own deployment and recovery, or a team studying an inspectable background-agent architecture. Harness and provider choices have broadened, and the documented operational boundaries are concrete enough to design a realistic pilot.
Poor fit: a multi-tenant hosted product without additional authorization work, or a team seeking turnkey operations. Validate your selected backend, bot identity, restore procedure, and unattended-run controls before expanding access.
This review checked current repository documentation, licensing, changelog entries, and a first-hand issue on September 15, 2026. It did not deploy the system, benchmark cost or speed, or audit sandbox escape resistance. See the research methodology.
Sources
- [1] Background Agents GitHub repository
- [2] Open-Inspect changelog
- [3] Open-Inspect authentication and authorization
- [4] Open-Inspect MIT license
- [5] Claude Agent harness and credential lifecycle
- [6] Open-Inspect deployment guide
- [7] Open-Inspect automation triggers and repository scope
- [8] Open-Inspect managed skills
- [9] Container control plane and recovery limitations
- [10] Background Agents website and managed deployment
- [11] Issue #1912: Linear/Slack PR identity report, September 15, 2026
- [12] Tembo founding team
- [13] Tembo cloud agents and review workflow
- [14] Tembo cloud and self-hosted deployment