Listing Thumbnail

    CreateOS Studio - Build, govern, and audit enterprise AI agents

     Info
    Sold by: CreateOS 
    An AI execution layer for the enterprise. Agents get named owners, cited context from your own documents, isolated sandboxed runs, and an immutable audit log of every action. Deploy in CreateOS cloud, inside your VPC, or fully on-premise.

    Overview

    CreateOS Studio is the layer that sits between your enterprise and the AI agents running inside it.

    Most enterprises already own agents: vendor copilots, internal builds, low-code experiments. What is missing is the layer that checks every action before it reaches your ERP or CRM, and proves afterwards what the agent did, on whose authority, and with which data.

    Studio is that layer. It covers five steps: Define, Ground, Act, Govern and Operate.

    DEFINE: agents specified like products, not prompts

    • Named ownership. Every agent has an owner, a goal and written instructions, and moves through a lifecycle from Draft to Active to Paused to Archived with rules on who can promote it.
    • Output contracts. Agents are held to the structure your downstream systems expect. Malformed output is flagged, not passed through.
    • Reusable skills. Your playbooks, style guides and SOPs become skills that any approved agent can attach.
    • Reproducible runs. Every run is pinned to a snapshot of its model, knowledge, skills, tools and limits. Ask what an agent was running on a given day and get an exact answer.

    GROUND: context your agents can cite

    • Ingestion built in. Upload PDFs, Word documents and policies. Scanned files are read with OCR. Parsing, chunking, embedding and indexing run automatically, so there is no separate data engineering project.
    • Two shapes of knowledge. Vector search finds meaning. Graph search follows relationships, so agents understand how your entities connect.
    • Answers with receipts. Retrieved knowledge keeps its link back to the source document and page, so every output can cite where a fact came from.
    • Memory and permissions. Agents carry memory across runs, scoped per organization and per agent. Attaching knowledge to an agent is permission checked and audited.

    ACT: real actions in real systems

    • Enterprise integrations. Agents connect to the tools you already run, including Notion, Slack, Salesforce and SAP SuccessFactors.
    • Frozen permissions. Each agent gets an explicit, locked list of allowed actions. If a tool vendor adds a capability tomorrow, your agent does not silently gain it.
    • Identity you choose. An agent can act as the individual user, or through a shared account that requires admin sign-off and is flagged in the audit log.
    • Human in the loop. Agents pause mid-task, ask a person to approve or supply input, and resume when answered.
    • Hard limits. Per-run caps on steps, tokens, time and tool calls. Revoking access revokes it at the provider, not just in our interface.

    GOVERN: controls in the architecture, not in a policy document

    • Identity for people and agents. SSO, SAML, Google and OTP sign-in for people. Every agent is a separate identifiable principal.
    • Access at object level. Role-based access for teams, plus share lists on each agent, knowledge base and skill.
    • Model policy. Allowlists and autonomy tiers control which models an agent may use and how much agency it has.
    • Guardrails that fail closed. Runtime guardrails with circuit breakers, including Amazon Bedrock Guardrails and Google Model Armor. An agent without a working guardrail returns no answer.
    • Secrets stay yours. An encrypted vault, or your own, including AWS, HashiCorp, Azure and GCP.
    • Audit and isolation. The audit log is append-only and exportable. Tenant isolation is structural, not a setting.

    OPERATE: run it, watch it, deploy it anywhere

    • One gateway, every model. A single managed gateway fronts every provider, including Amazon Bedrock. Switch or mix providers without re-platforming.
    • Sandboxed execution. Every run executes inside its own Firecracker micro-VM with its own kernel. Network access is outbound-only against a kernel-enforced allowlist, with no ingress by default.
    • Full observability. Per-run token usage, warnings and failure detail for every run.
    • Deploy on your terms. Containerized and Kubernetes-ready, with a documented API for everything. Run in CreateOS cloud, inside your VPC, or fully on-premise and region-locked.

    KEEP THE AGENTS YOU ALREADY HAVE

    • Connect. Existing agents plug into the Studio gateway and tool layer and keep their own logic.
    • Govern. The same approval gates, permissions and audit log apply to every action they take.
    • Prove. Every run they make becomes a traceable record.

    WHERE TEAMS USE IT

    • Manufacturing. Proposed writes are validated against live system state and approval rules before anything reaches the ERP.
    • Banking and financial services. Every case carries a full trace of cited sources, guardrail checks, approver and disposition.
    • Legal. Every fact is pinned to its source document and page, with the lawyer as the decision authority.
    • Marketing. Every outbound action sits behind a named human gate.
    • Healthcare. Administrative load drops while the clinician signs off on every decision.

    Highlights

    • Governance inside the runtime, not in a policy document. Every agent is an identifiable principal with role-based access, object-level share lists, model allowlists and autonomy tiers. Runtime guardrails with circuit breakers, including Amazon Bedrock Guardrails and Google Model Armor, fail closed, so an agent without a working guardrail returns no answer. The audit log is append-only and exportable, which gives risk and model-validation teams a record instead of screenshots.
    • Real actions in real systems, behind human gates. Agents act in Notion, Slack, Salesforce and SAP SuccessFactors through an explicit, locked list of allowed actions, so a vendor adding a capability does not extend your agent's reach. Choose whether an agent acts as the individual user or through a shared account that requires admin sign-off. Agents pause mid-task for approval and resume when answered, and per-run limits cap steps, tokens, time and tool calls.
    • Isolated execution, deployed on your terms. Every run executes inside its own Firecracker micro-VM with its own kernel, outbound-only network access against a kernel-enforced allowlist, and no ingress by default, so untrusted or AI-generated code cannot see the host or other tenants. Studio is containerized and Kubernetes-ready and deploys in CreateOS cloud, inside your VPC, or fully on-premise and region-locked.

    Details

    Sold by

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    CreateOS Studio - Build, govern, and audit enterprise AI agents

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (3)

     Info
    Dimension
    Description
    Cost/12 months
    Studio Standard
    CreateOS Studio for a single organization, deployed in CreateOS cloud. Governed agent builder, knowledge base with citations, model gateway, sandboxed runs and audit log.
    $70,000.00
    Studio Enterprise
    CreateOS Studio deployed inside your VPC or fully on-premise and region-locked, with SSO and SAML, per-agent identity, model allowlists, runtime guardrails, exportable audit log and enterprise support.
    $100,000.00
    Studio Enterprise Custom
    Custom scope, volume and terms for large deployments, including dedicated onboarding and custom integration commitments. Available exclusively via private offer.
    $100,000.00

    AI Insights

     Info

    Dimensions summary

    CreateOS Studio comes in three contract options, all priced in units. Studio Standard runs in CreateOS cloud for a single organization, with the governed agent builder, knowledge base, model gateway, sandboxed runs and audit log. Studio Enterprise deploys inside your VPC or on-premise and region-locked, adding SSO and SAML, per-agent identity, model allowlists, runtime guardrails, an exportable audit log and enterprise support. Studio Enterprise Custom covers large deployments with custom scope, volume and terms, plus dedicated onboarding and integration commitments. It is available only through a private offer, so you negotiate terms directly with the vendor.

    Top-of-mind questions for buyers

    Each option is priced in units, but the marketplace listing does not define what one unit maps to in concrete terms, such as a seat, agent, or workflow. Confirm the exact unit definition and how units are counted with the vendor before purchase.
    The gateway sends each request to the available source for a model and uses one endpoint and one API key. You switch models by changing the model name, with no code changes. It supports deployment across multiple model providers and includes automatic failover if a source degrades.
    Studio Standard runs in CreateOS cloud for one organization. Studio Enterprise deploys inside your VPC or on-premise and is region-locked. It adds SSO and SAML, per-agent identity, model allowlists, runtime guardrails, an exportable audit log, and enterprise support. Both include the governed agent builder, knowledge base, model gateway, and sandboxed runs.
    createos.sh
    Helpful?

    Vendor refund policy

    Subscriptions purchased through AWS Marketplace are non-refundable once the contract term begins, except where required by law. For questions about a charge or a subscription, contact business@nodeops.xyz  and we will work with you and AWS Marketplace to resolve it.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Email support is included with every subscription, reachable at business@nodeops.xyz , with a target first response within one business day. Every deployment is assigned a named technical contact for onboarding, integration and model gateway configuration, covering CreateOS cloud, your VPC and on-premise installations. Faster response targets, dedicated onboarding and custom integration commitments are available under a private offer.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.