Two questions sort the open-source OpenClaw field
On the surface the six projects look alike: every one is open source, runs on hardware you control, and lets you bring your own models. What separates them sits underneath the feature list, in two decisions you make once and live with for years. The first is where the configuration lives. The second is who reviews the work before it lands.
Where configuration lives decides how much of the operation you can inspect and roll back. A single file on one machine configures an assistant. A git repository configures a company: when the agents, the skills, the memory and the connector rules are files in version control, you can read the whole setup, diff any proposed change, and undo one part without touching the rest.
Who reviews the work decides what you can safely hand over. A prompt before a risky command catches a destructive shell line; it does not read the week of work an agent assembled before that command ran. A review step that reads the finished change is a different kind of gate, and it is the one that lets a team give agents work that matters.
The shortlist, ranked
1. Kortix: company work with a gate on every change
Kortix is the open-source AI Operating System and the leading open-source alternative to Claude Cowork and ChatGPT Work. Its agents, skills, company memory, connector configuration and triggers are files in one git repo you own, and each session runs on its own isolated machine, on its own branch. Work reaches the default branch only through a change request a person reads as a diff and merges; merge is default-deny for agents. Any model provider with your own keys, 3,000+ apps in a click plus MCP, OpenAPI, GraphQL and raw HTTP, and free self-hosting on Kortix Cloud, in your VPC or on-prem. The Kortix blog draws the line between a personal agent and a company system.
2. OpenClaw: the personal-assistant baseline
OpenClaw is an open-source AI assistant that runs on your own computer and meets you in Discord, iMessage, Slack, Teams, Telegram, WhatsApp and more than 20 other channels. Its documentation describes one Gateway process as the bridge between those channels and an always-available agent, with configuration in an optional ~/.openclaw/openclaw.json on the host (openclaw.ai). The agent acts and replies in chat, and its safeguards are ones you configure: pairing for unknown senders and sandboxing for tools. OpenClaw calls the same Gateway a personal assistant on a laptop or a shared team deployment, with configuration the only difference.
3. Hermes Agent: the agent that builds its own skills
Hermes Agent is Nous Research's open-source agent with a built-in learning loop: it creates skills from experience, improves them during use, and keeps memory it can search across sessions. Telegram, Discord, Slack, WhatsApp, Signal and a CLI connect through one gateway, models switch with a command, and it runs on a $5 VPS, a GPU cluster or serverless backends. Configuration lives in ~/.hermes/config.yaml, and governance is per command: approval on risky operations, with isolation through Docker, Singularity or Modal (Hermes Agent on GitHub).
4. NanoClaw: isolation first, in a codebase you can read
NanoClaw is an open-source assistant that gives every agent its own isolation, so commands run in a sandbox rather than on your host, and it is built on Anthropic's Claude Agent SDK. There are no config files: you make your own fork and the code is the configuration, changed by telling Claude Code what you want. A credential gateway hands agents scoped access instead of raw keys, and channels such as WhatsApp, Telegram, Slack and Teams install into your fork as skills (NanoClaw on GitHub).
5. ZeroClaw: one binary, approval by risk level
ZeroClaw is an open-source agent runtime shipped as a single Rust binary that talks to about 20 model providers and reaches 30+ channels, including Discord, Telegram, Matrix, email and webhooks. Configuration is one TOML file at ~/.zeroclaw/config.toml. Its default posture is supervised: medium-risk operations need approval and high-risk operations are blocked, with OS-level sandboxes such as Landlock, Bubblewrap and Docker, and cryptographic tool receipts that record what ran (ZeroClaw on GitHub).
6. OpenHands: a control center for coding agents
OpenHands is an open-source developer control center for coding agents and automations. It runs the OpenHands agent, Claude Code, Codex, Gemini or any ACP-compatible agent across local, Docker, VM and cloud backends, and starts work from Slack, GitHub, Linear or a schedule. Its automations post review comments on pull requests, and the docs put review, approval and merge in your team's hands. Control is developer-shaped: settings and automations are scoped to whichever backend is active rather than held in a repo you own (OpenHands on GitHub).
How to choose
Pick by where the work lives and who vouches for the result. For one person's day in the chat apps they already use, OpenClaw is the baseline; Hermes Agent adds self-improving skills, NanoClaw adds per-agent isolation, and ZeroClaw shrinks the footprint. For a coding team, OpenHands puts a review step on pull requests. When the work belongs to the company and a person has to read every change before it lands, the configuration has to be a repo the company owns and the gate has to cover the finished change; that combination is what Kortix is built for.