Bring agentic systems into production without losing control.

Heym helps AI, platform, and automation teams deploy, observe, and govern business-critical agents and workflows on their own infrastructure, with single sign-on, multi-instance execution, and a streamed audit trail. Heym Cloud is coming soon.

Self-hosted & VPCSource-availableSSO & audit logsYour data, your infra

Most teams can build an impressive agent prototype in a week. Production is where things stall: nobody can say exactly what the agent did, what it cost, or who approved the action it took. Heym runs agentic workflows and enterprise AI workflow automation as business-critical systems, with the control, visibility, and support that production demands.

  • Deployment on infrastructure you choose
  • End to end visibility into every execution
  • Human control over critical actions
  • Identity, scale, and audit under your platform team
  • Setup, integration, and production support

Deploy on infrastructure you control

Run Heym on-premises, in your VPC, or air-gapped. Self-hosted deployment means customer and revenue data never leaves your servers, and because Heym is source-available, security can audit every line before you ship. You bring your own models and credentials, so there is no lock-in to switch away from.

  • Self-hosted, your customer and revenue data never leaves your infrastructure
  • Source-available and fully auditable, hand security the actual code
  • Encrypted credentials at rest, keys and connections stay protected
  • Bring your own models (OpenAI, Ollama) and infrastructure with zero lock-in
  • Teams with shared, access-controlled credentials
  • Single sign-on against your own OpenID Connect provider, with password login switchable off
  • Horizontal scale built in: add worker instances against the same database and weight the split
  • Production Kubernetes assistance for high availability deployments

Run locally

Start Heym locally with the included run.sh script and own the full runtime from day one.

View on GitHub
Platform operations

Run it the way your platform team runs everything else

Single sign-on against your own identity provider, execution spread across as many instances as the work needs, and an audit line for every privileged action, streamed wherever your logs already go.

Single sign-on

Sign in with the identity provider you already run

An administrator pastes an issuer URL under Settings → SSO, and Heym reads the authorization, token, and key endpoints from your provider's own discovery document. No provider is hardcoded, so Keycloak, Okta, Entra ID, Auth0, and Google connect through the same fields. A connection test tells you the setup is right before anyone depends on it.

  • Any OpenID Connect provider, configured from a single issuer URL
  • Authorization code with PKCE, and the client secret stored encrypted
  • Accounts created on first sign-in, optionally limited to your own email domains
  • Password sign-in switched off instance-wide once SSO is verified
  • Named administrators keep password access, so a misconfigured provider cannot lock you out
Read the single sign-on setup guide
Multi-instance execution

Spread execution across as many instances as the work needs

Point a second instance at the same PostgreSQL database and it joins as a worker. Agent runs, cron, webhooks, and chat triggers are then shared between instances by a weight you set under Settings → Instances. The instances never talk to each other, so a worker needs no open port and no route back.

  • Weighted load balancing across every live instance, adjustable at any time without a restart
  • Weights renormalize on their own when an instance drops out, and again when it returns
  • Leader election moves cron, alert evaluation, and crash recovery within seconds of a failure
  • Every run in History names the instance that executed it, and history filters down to one
Read the load distribution guide
Log streaming & audit

Stream every privileged action off the box

Every sensitive action leaves a record: who did it, what they touched, and whether it worked. There is nothing to switch on and nothing extra to run, so the record keeping starts on your first day. Your team can watch it happen live inside Heym, or send it to wherever your company already keeps its logs, so the history is still there months later.

  • One line per action carrying actor, target, and outcome: success, failure, or denied
  • Live log streaming in the app for the operators you allow-list, filtered by container, level, and search
  • Failed logins, refused access, and replayed refresh tokens are recorded as exactly that
  • Secrets never reach a line: a credential update logs config_changed=true, never the config
  • Bulk work logs a count, so a 5,000-row import is one line rather than five thousand
  • Ship stdout to any log driver or collector for retention that survives a redeploy
Read the audit logging reference
Tracing & observability

Inspect every execution

Every workflow run produces a full trace: each node, each agent decision, each tool call, and each model call with token and cost visibility. When something fails, you see where and why instead of guessing. Read the AI agent observability guide for how teams debug agents in production.

  • Per-run traces across nodes, agents, and tool calls
  • Token and cost visibility for every model call
  • Failure points surfaced with inputs and outputs
  • Native OpenTelemetry export to the stack you already run
  • An audit line for every privileged action, streamed with your container logs
Human governance

Human approval before critical actions

Agents draft, people decide. Add human-in-the-loop checkpoints before emails go out, records change, or money moves. Reviewers see the full context, approve or reject, and the workflow continues or stops. Nothing critical happens unattended unless you decide it should.

  • Approval steps before irreversible actions
  • Reviews with full execution context
  • Pause and resume runs under human control
  • Every approval recorded in the run trace
Integrations

Connects to the systems you already run

Native nodes cover GitHub, Jira, Slack, Telegram, email, Google Sheets, BigQuery, and more. HTTP and webhook nodes reach any internal API, and MCP support connects Heym to the growing ecosystem of tool servers. When you need a connector that does not exist yet, we build, package, and deliver it as a plugin for your deployment.

  • First-party nodes for code, data, and messaging systems
  • HTTP, webhook, and cron nodes for anything custom
  • MCP support for the growing ecosystem of tool servers
  • Custom nodes and plugins developed on demand for your systems

Where enterprise teams start

Three patterns that turn agentic systems into dependable operations.

Production Pilot

Start with a Heym Production Pilot

Bring one valuable workflow into production in four to six weeks. We help your team deploy Heym, connect one or two core systems, add approval checkpoints, and establish tracing and cost visibility. The engagement starts with agreed success metrics and ends with a production rollout plan and a commercial licensing proposal.

  • One real business process, deployed on your infrastructure or Heym Cloud when it opens
  • One or two core integrations connected
  • Human approval checkpoints where they matter
  • Tracing and cost visibility from day one
  • Technical onboarding for your team
  • Success metrics agreed before we start
Licensing & support

Commercial licensing and production support

Enterprise customers pay for reduced production responsibility, not just software. Engagements can include commercial licensing, deployment and onboarding, migration support, custom integrations, managed upgrades, architecture reviews, and agreed response times for production issues.

  • Commercial license for internal and customer-facing use
  • Deployment, onboarding, and training for your team
  • Migration support from existing automation tools
  • Custom integrations built for your systems
  • Managed upgrades and priority engineering support
  • Security and architecture reviews
  • Agreed response times for production issues
Soon

Heym Cloud

Managed Heym cloud hosting for teams that want the speed of Heym without owning the infrastructure.

We'll reach out when Heym Cloud opens up. No spam.

Evaluation questions

What security and platform teams ask

The questions that come up in every procurement review, answered with the mechanism behind each one.

Talk to sales

Book an enterprise demo

Tell us about your team and the workflow you want in production. We will tailor a walkthrough to your stack, or reach us at enterprise@heym.run.

We'll reply within one business day. No spam, ever.

AI workflows don't fail because of prompts. They fail because of orchestration.

One canvas for agents, RAG, human-in-the-loop, MCP, traces, evals, and alerts, self-hosted and observable.

apiRequesttriggercheckEventif / elserouteEventswitchinsertRecorddataupdateRecorddataauthErrorerrornotifySlackintegration
Self-host
in minutes
1 canvas
agents · RAG · HITL · MCP
Every run
traced end to end
Related reading

Go deeper on production AI systems

Practical guides for tracing, OpenTelemetry, RAG, and multi-agent orchestration.

Heym
incident analysis · production AI
Observed across 100s of AI rollouts

AI workflows don't fail because of prompts.
They fail because of orchestration.

symptom · glue code01
5 tools
Scripts, vector DB, approval bot, tracing, browser runner — none of them talk.
symptom · visibility02
~0%
Observable behavior across the stack. Debugging is guesswork.
with heym · one runtime
1 canvas
Agents, RAG, HITL, MCP, traces & evals. Self-hosted. Observable.
AI-Native RuntimeProduction-Grade
github.com/heymrun/heym