Orlok
Self-hosted · Early access

Virtual colleagues for your offices

A self-hosted platform where your team works alongside virtual colleagues: they learn how your office works, act on your systems and never step outside the rules you set.

Max
Sysadmin colleague · IT office
You: The intranet is slow again. Can you check web-01?

Max: The nginx workers on web-01 are stuck, like last month. The office runbook says to restart the service, so I need your approval.

From the wiki:Intranet · web-01Runbook: restart nginx
Waiting for your approvalweb-01
systemctl restart nginx

Why Orlok

One more colleague at your servers

It reads, checks and steps in the way a person would.

Run it from wherever you are

From your computer or your phone: you get a notification when something needs you and approve it right in the chat.

Your data stays yours

It runs on your servers, your credentials are encrypted and colleagues use them without ever seeing them.

You choose the model

Anthropic, OpenAI or a local model with Ollama, even with no internet connection.

Built for the people who run the office

One installation, shaped around how your company works. A technician sets it up once; using it does not take one.

Self-hosters and sysadmins

Your hardware, your models, your rules.

  • Runs on your server with Docker Compose
  • Works fully offline with Ollama
  • Commands parsed and checked, never run blindly

IT teams of small and medium businesses

A helpdesk and sysadmin colleague that knows your infrastructure.

  • Office wiki kept current from documents and conversations
  • Interventions on servers over SSH and PowerShell, with approval
  • Step-by-step plans with live output

Companies with several offices

Separate offices and knowledge, one installation.

  • Each office has its own wiki and tools; everyone creates their own colleagues
  • People invited by email, with a role in each office
  • Append-only audit of every change and job

Everything a virtual colleague needs to be useful

Memory, real tools and clear rules, in one self-hosted platform.

Offices and virtual colleagues

  • Personal colleagues: each person creates their own, with a role and instructions
  • Administrators decide what each person may delegate, through colleague profiles
  • First-run setup: every installation starts empty

The office wiki as memory

  • Colleagues consult the wiki before answering and cite the pages they use
  • Things worth keeping proposed from your conversations, seen only by you
  • Knowledge graph, page status and a guided review of what is outdated

Real operations

  • Servers over SSH and PowerShell, from an isolated runner
  • Each person's own credentials, and approvals right in the chat
  • Multi-step plans and MCP tools per office, from a ready-made catalog

Your choice of models

  • Anthropic, OpenAI and OpenAI-compatible providers
  • Ollama and a built-in embedding model for fully local operation
  • Long conversations kept within each model's context window

Chat on desktop and mobile

  • Answers keep going when you close the page: pick them up on another device
  • Installable as an app on phones
  • English and Italian, ten light and dark themes

Notifications

  • Email and push when an approval is waiting for you
  • A message when a late intervention ends
  • Signed-in devices listed and revocable

A wiki that remembers how your office works

Virtual colleagues keep the office wiki themselves, and it stays a memory you can trust.

Nothing is silently lost

What no longer holds is marked as superseded, with its date, and comes last in search instead of disappearing. Colleagues change the exact text they mean, and a rewrite that would throw away most of a page is stopped unless the colleague says the cut is intended.

Facts kept apart, contradictions with proof

Colleagues are told never to merge statements with different numbers, addresses, versions or dates, and a rewrite that drops an address, a date or a command says which, so it can be put back. A contradiction raised on review must quote the page word for word, so nothing is invented.

Search made for IT

IP addresses, host names and codes are found exactly. Each office adds its own synonym groups, such as vpn, tunnel and site to site, next to a built-in IT vocabulary in Italian and English.

A map of what you know

Every page shows its related pages. The interactive map groups topics and points out surprising connections, bridge pages, isolated pages and topics that are barely linked.

Scans read on your server

PDF, Office and other documents are read on your server, and scans with OCR in Italian and English that ships with Orlok, with no network needed. Unreadable words are marked [illegible], never guessed. The colleague that files a document works through your model provider, or a local model with Ollama.

Bring your notes, not your passwords

Import from Joplin, Obsidian or Notion with links kept. What looks like a password, key or token is removed before it reaches the shared wiki.

Quick start

A database, the app and an isolated runner, started together with Docker Compose. You need a server with Docker.

  1. Set the secrets

    Copy the example settings, then fill in the public address and three generated keys.

    cp .env.production.example .env.production# ORLOK_PUBLIC_URL: the address people will useopenssl rand -base64 32   # ORLOK_SECRET_KEYopenssl rand -hex 24      # POSTGRES_PASSWORDopenssl rand -hex 32      # ORLOK_RUNNER_TOKEN
  2. Start Orlok

    Images are built on your server and database migrations run automatically.

    docker compose --env-file .env.production up -d --build
  3. Open the first-run setup

    Visit the address you configured (port 8080 by default): name the company and create the administrator, then add your first model provider.

Orlok is in early access: the installation package is shared on request. Ask for it

Secure by design, on your infrastructure

Virtual colleagues act on real systems, so every action follows your rules.

Your infrastructure

One installation per company, on your servers. Your wiki is indexed by a model that ships with Orlok, so your pages do not leave to become searchable: what goes out is what you ask the model provider you configure.

Offline when you need it

With Ollama and the built-in embedding model, Orlok works without any cloud service.

Encrypted credentials

Provider keys and credentials are encrypted with a key kept outside the database. Everyone stores their own accounts, and a colleague acts as the person it works for, never with more rights: it cannot see the account or pick another, so a refused command stays refused.

Modes and approvals

Commands are parsed, never matched as plain text. Administrators grant the modes people may use: in ask mode reads run right away and changes wait for approval. Dangerous commands stay blocked in every mode but yolo, which is granted on purpose. “Always allow” approves a kind of command, such as systemctl restart, for you alone, and can be taken back.

Isolated execution

Commands run in a separate runner container with no database access, a read-only filesystem and minimal privileges.

Full audit trail

Every change and job is written to an append-only log, with likely secrets masked in output.

Roadmap

What works today and what comes next.

Available now

  • Offices, personal virtual colleagues and email invitations
  • Office wiki with document import, knowledge graph, page status and guided review
  • Operations over SSH and PowerShell with approvals, plans and audit
  • MCP tool catalog: databases, AWS, Proxmox VE
  • Installable chat with email and push notifications

Next

  • Client module for Windows, Linux and macOS PCs, with user consent
  • Email, Telegram and Microsoft Teams channels
  • Passkeys and two-factor authentication
  • Ready-made colleague templates
  • Token and cost tracking with spending limits

Later

  • Company single sign-on (OIDC)
  • Monitoring webhooks and scheduled tasks
  • Company-wide wiki shared across offices
  • Sensitive data routed to local models only
  • Public releases with changelog and guided upgrades

Talk to us

Want to try Orlok in your company, or have a question? Write to us and we will get back to you.

We use your details only to reply to you.