covey and Paperclip
Two ways to run AI agents as a workforce.
Last checked: 29 September 2026. Paperclip releases roughly weekly; if something here is out of date, tell us and we will correct it.
Paperclip and covey start from the same idea: AI agents should be managed like staff, with a role, a manager, a task list, a budget and someone who can stop them. Both are open source and self-hosted. Both let several companies share one installation, wake agents on schedules and events so an idle agent costs nothing, require approvals for sensitive actions, cap spend, and keep a record of what happened.
Paperclip is the larger project by far. It has a big community, supports many more agent runtimes (Claude Code, Codex, Cursor, Gemini, OpenCode, OpenClaw and others), offers ready-made connections to cloud sandbox providers, and gets you to a first result with a single npx command. If that is what you need, Paperclip is a good choice.
The two differ in what they treat as the default, and in where the boundary sits when an agent does something it should not.
Where the agent runs
| Topic | Paperclip | covey |
|---|---|---|
| Default | A process on the host machine. Per-task isolated worktrees are an experimental setting, off by default.[1][2] | Every agent in its own container with a persistent home directory, started through a runner, also on a single machine. |
| Sandboxes | Via provider plugins (E2B, Daytona, Modal, Cloudflare, Novita, Kubernetes and others).[3] | Built in. Remote runners on your own hosts. |
| Internet access from the sandbox | “The provider and the operator set the policy for general internet access. Paperclip does not enforce this policy inside the sandbox.” The Kubernetes plugin can set per-run egress rules.[4] | An egress proxy with an allowlist, part of the platform and on by default with the docker sandbox provider. Sandboxes on remote runners are not covered yet. |
Credentials
| Topic | Paperclip | covey |
|---|---|---|
| Model and runtime keys | Environment variables such as ANTHROPIC_API_KEY, or managed connections.[5][2] | Stored centrally, brokered per run. |
| Target-system access | Connections are brokered and deny-by-default by design; the heartbeat pipeline includes secret injection into the run.[6][1] | No long-lived secret enters the sandbox. Access is issued per run, short-lived and scoped. |
People and permissions
| Topic | Paperclip | covey |
|---|---|---|
| First start | local_trusted: loopback only, no login. Authenticated mode is an option.[7] | Login from the first start. |
| Human roles | owner, admin, operator, viewer.[8] | Organisation admin, agent owner, security/compliance, auditor (read-only), controlling (cost). |
| Stated priority | “Do not build enterprise-grade RBAC first.”[9] | Separation of duties is a design principle: security sets rules an agent owner cannot soften. |
| Default for agent-editable skills | “skill permissions are opt-in restrictions, not opt-in capabilities.”[9] | Restrictive defaults ship with the install: replies to customers need approval, HR systems are off limits, delete is denied. |
Also different
- Memory
- covey keeps an agent's memory as linked wiki pages with a pgvector index, readable and correctable by hand. Paperclip lists “Memory / Knowledge” on its roadmap as planned.[10]
- Target systems
- covey ships plugins for Jira, Confluence, GitLab, GitHub, Zammad, Zendesk, Salesforce, Teams, SharePoint, Nextcloud, Kubernetes, email, a headless browser and MCP. Paperclip's connections focus on GitHub, Google Workspace, Slack and other SaaS tools; Jira, Linear and Asana are on its roadmap.[10]
- Packaging
- covey is one Go binary with the web interface and migrations compiled in, plus Postgres. Paperclip is a Node.js application (Node 24.11+) with embedded or external Postgres.[2]
- Licence
- Paperclip is MIT. covey is AGPL-3.0; its plugin SDK is MIT.
Where Paperclip is ahead
- Community and momentum.
- The number of agent runtimes and cloud sandbox providers it supports.
- Time to first result.
- Planning features: revisioned plans with approval per revision, watchdogs, evals.
- Chat channels (Slack, Discord, Telegram, Teams, iMessage; experimental).
Which one fits
Paperclip
Choose Paperclip if you want the widest choice of agents and sandbox providers, a fast local start, or a permissive licence.
covey
Choose covey if the people who have to sign off (IT, security, audit) need the limits to hold outside the agent: a workplace per agent, brokered access, an egress allowlist, and a recording of every run that someone who was not there can read.
Sources
Checked on September 29, 2026. Statements about Paperclip come from its own public sources: documentation, repository, release notes or website. Anything marked as a vendor claim appears only on marketing or pricing pages.
- [1]Paperclip v2026.916.0 release notes
- [2]Paperclip README
- [3]Paperclip repository, packages/plugins/sandbox-providers
- [4]SANDBOX-REQUIREMENTS.md
- [5]paperclip.ing: Bring your own agent
- [6]doc/connections/SECURITY-THREAT-MODEL.md
- [7]doc/DEPLOYMENT-MODES.md
- [8]paperclip.ing: Org chart
- [9]doc/PRODUCT.md
- [10]ROADMAP.md
Other comparisons
OpenAI dots
dots are always-on agents that run in OpenAI's cloud on GPT-6 Astra. covey runs an organisation's agents on its own servers, with Claude Code or Codex as the engine.
Checked on September 29, 2026Governance layerMicrosoft Agent 365
Agent 365 registers and governs agents in Microsoft's cloud. covey is a self-hosted platform where agents do their work.
Checked on September 29, 2026Framework and platformCrewAI
CrewAI is a Python framework for programming agents, plus a platform to deploy them. covey runs agents you describe in configuration.
Checked on September 29, 2026SaaS workforceRelevance AI
Relevance AI builds and runs agent teams in its own cloud, without code. covey runs agents on your hosts, each in its own container.
Checked on September 29, 2026