An AI execution layer for the enterprise. Agents get named owners, cited context from your own documents, isolated sandboxed runs, and an immutable audit log of every action. Deploy in CreateOS cloud, inside your VPC, or fully on-premise.
CreateOS Studio is the layer that sits between your enterprise and the AI agents running inside it.
Most enterprises already own agents: vendor copilots, internal builds, low-code experiments. What is missing is the layer that checks every action before it reaches your ERP or CRM, and proves afterwards what the agent did, on whose authority, and with which data.
Studio is that layer. It covers five steps: Define, Ground, Act, Govern and Operate.
DEFINE: agents specified like products, not prompts
Named ownership. Every agent has an owner, a goal and written instructions, and moves through a lifecycle from Draft to Active to Paused to Archived with rules on who can promote it.
Output contracts. Agents are held to the structure your downstream systems expect. Malformed output is flagged, not passed through.
Reusable skills. Your playbooks, style guides and SOPs become skills that any approved agent can attach.
Reproducible runs. Every run is pinned to a snapshot of its model, knowledge, skills, tools and limits. Ask what an agent was running on a given day and get an exact answer.
GROUND: context your agents can cite
Ingestion built in. Upload PDFs, Word documents and policies. Scanned files are read with OCR. Parsing, chunking, embedding and indexing run automatically, so there is no separate data engineering project.
Two shapes of knowledge. Vector search finds meaning. Graph search follows relationships, so agents understand how your entities connect.
Answers with receipts. Retrieved knowledge keeps its link back to the source document and page, so every output can cite where a fact came from.
Memory and permissions. Agents carry memory across runs, scoped per organization and per agent. Attaching knowledge to an agent is permission checked and audited.
ACT: real actions in real systems
Enterprise integrations. Agents connect to the tools you already run, including Notion, Slack, Salesforce and SAP SuccessFactors.
Frozen permissions. Each agent gets an explicit, locked list of allowed actions. If a tool vendor adds a capability tomorrow, your agent does not silently gain it.
Identity you choose. An agent can act as the individual user, or through a shared account that requires admin sign-off and is flagged in the audit log.
Human in the loop. Agents pause mid-task, ask a person to approve or supply input, and resume when answered.
Hard limits. Per-run caps on steps, tokens, time and tool calls. Revoking access revokes it at the provider, not just in our interface.
GOVERN: controls in the architecture, not in a policy document
Identity for people and agents. SSO, SAML, Google and OTP sign-in for people. Every agent is a separate identifiable principal.
Access at object level. Role-based access for teams, plus share lists on each agent, knowledge base and skill.
Model policy. Allowlists and autonomy tiers control which models an agent may use and how much agency it has.
Guardrails that fail closed. Runtime guardrails with circuit breakers, including Amazon Bedrock Guardrails and Google Model Armor. An agent without a working guardrail returns no answer.
Secrets stay yours. An encrypted vault, or your own, including AWS, HashiCorp, Azure and GCP.
Audit and isolation. The audit log is append-only and exportable. Tenant isolation is structural, not a setting.
OPERATE: run it, watch it, deploy it anywhere
One gateway, every model. A single managed gateway fronts every provider, including Amazon Bedrock. Switch or mix providers without re-platforming.
Sandboxed execution. Every run executes inside its own Firecracker micro-VM with its own kernel. Network access is outbound-only against a kernel-enforced allowlist, with no ingress by default.
Full observability. Per-run token usage, warnings and failure detail for every run.
Deploy on your terms. Containerized and Kubernetes-ready, with a documented API for everything. Run in CreateOS cloud, inside your VPC, or fully on-premise and region-locked.
KEEP THE AGENTS YOU ALREADY HAVE
Connect. Existing agents plug into the Studio gateway and tool layer and keep their own logic.
Govern. The same approval gates, permissions and audit log apply to every action they take.
Prove. Every run they make becomes a traceable record.
WHERE TEAMS USE IT
Manufacturing. Proposed writes are validated against live system state and approval rules before anything reaches the ERP.
Banking and financial services. Every case carries a full trace of cited sources, guardrail checks, approver and disposition.
Legal. Every fact is pinned to its source document and page, with the lawyer as the decision authority.
Marketing. Every outbound action sits behind a named human gate.
Healthcare. Administrative load drops while the clinician signs off on every decision.
Highlights
Governance inside the runtime, not in a policy document. Every agent is an identifiable principal with role-based access, object-level share lists, model allowlists and autonomy tiers. Runtime guardrails with circuit breakers, including Amazon Bedrock Guardrails and Google Model Armor, fail closed, so an agent without a working guardrail returns no answer. The audit log is append-only and exportable, which gives risk and model-validation teams a record instead of screenshots.
Real actions in real systems, behind human gates. Agents act in Notion, Slack, Salesforce and SAP SuccessFactors through an explicit, locked list of allowed actions, so a vendor adding a capability does not extend your agent's reach. Choose whether an agent acts as the individual user or through a shared account that requires admin sign-off. Agents pause mid-task for approval and resume when answered, and per-run limits cap steps, tokens, time and tool calls.
Isolated execution, deployed on your terms. Every run executes inside its own Firecracker micro-VM with its own kernel, outbound-only network access against a kernel-enforced allowlist, and no ingress by default, so untrusted or AI-generated code cannot see the host or other tenants. Studio is containerized and Kubernetes-ready and deploys in CreateOS cloud, inside your VPC, or fully on-premise and region-locked.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
CreateOS Studio for a single organization, deployed in CreateOS cloud. Governed agent builder, knowledge base with citations, model gateway, sandboxed runs and audit log.
$70,000.00
Studio Enterprise
CreateOS Studio deployed inside your VPC or fully on-premise and region-locked, with SSO and SAML, per-agent identity, model allowlists, runtime guardrails, exportable audit log and enterprise support.
$100,000.00
Studio Enterprise Custom
Custom scope, volume and terms for large deployments, including dedicated onboarding and custom integration commitments. Available exclusively via private offer.
CreateOS Studio comes in three contract options, all priced in units. Studio Standard runs in CreateOS cloud for a single organization, with the governed agent builder, knowledge base, model gateway, sandboxed runs and audit log. Studio Enterprise deploys inside your VPC or on-premise and region-locked, adding SSO and SAML, per-agent identity, model allowlists, runtime guardrails, an exportable audit log and enterprise support. Studio Enterprise Custom covers large deployments with custom scope, volume and terms, plus dedicated onboarding and integration commitments. It is available only through a private offer, so you negotiate terms directly with the vendor.
Top-of-mind questions for buyers
What counts as one unit for billing across the Studio contract options?
Each option is priced in units, but the marketplace listing does not define what one unit maps to in concrete terms, such as a seat, agent, or workflow. Confirm the exact unit definition and how units are counted with the vendor before purchase.
How does the model gateway in Studio Standard route and bill my model usage?
The gateway sends each request to the available source for a model and uses one endpoint and one API key. You switch models by changing the model name, with no code changes. It supports deployment across multiple model providers and includes automatic failover if a source degrades.
What do I gain by moving from Studio Standard to Studio Enterprise?
Studio Standard runs in CreateOS cloud for one organization. Studio Enterprise deploys inside your VPC or on-premise and is region-locked. It adds SSO and SAML, per-agent identity, model allowlists, runtime guardrails, an exportable audit log, and enterprise support. Both include the governed agent builder, knowledge base, model gateway, and sandboxed runs.
createos.sh
Helpful?
Vendor refund policy
Subscriptions purchased through AWS Marketplace are non-refundable once the contract term begins, except where required by law. For questions about a charge or a subscription, contact business@nodeops.xyz and we will work with you and AWS Marketplace to resolve it.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Email support is included with every subscription, reachable at business@nodeops.xyz, with a target first response within one business day. Every deployment is assigned a named technical contact for onboarding, integration and model gateway configuration, covering CreateOS cloud, your VPC and on-premise installations. Faster response targets, dedicated onboarding and custom integration commitments are available under a private offer.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Lyzr Agent Studio makes building secure, reliable AI agents seamless - integrate them into your workflows, automate tasks, and customize them to fit your business goals. Lyzr Agent Studio is a powerful low-code platform for building, deploying, and managing secure AI agents tailored to your enterprise workflows. Lyzr integrates Safe AI and Responsible AI into its architecture, provides hybrid LLM+ML workflows for better accuracy, and ensures 100% data privacy with flexible deployment options.
Airia discovers shadow AI, enforces runtime guardrails across models and agents, and maps compliance evidence to EU AI Act, ISO 42001, and NIST AI RMF.
DataRobot's Agent Workforce Platform lets enterprises build, operate, and govern fleets of production AI agents on AWS - and in hybrid, sovereign, and air-gapped environments - with the same governance layer in every one. Model-, framework-, and orchestration-neutral, with forward-deployed DataRobot engineers who build your first mission-critical agents alongside your team.
Crewdle AI Studio is a secure, user-friendly platform designed to build, deploy, and manage AI models within your organization's infrastructure. It enables businesses to create multi-agent workflows, customize agents with specific skills, and integrate seamlessly with external systems, all while keeping sensitive data private and on-premises.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.