AI Agents
Give your staff somewhere sanctioned to use AI
Self-hosted, governed chat and retrieval for your whole organization. Role-based access control, group scoping, SSO, and no data leaving your boundary.
Your staff are already using AI. The question is not whether to allow it — that decision was made for you months ago, one browser tab at a time. The question is whether it happens somewhere you can see.
Open WebUI is a self-hosted interface that puts chat and document retrieval inside your own infrastructure. It supports role-based access control, user groups, and LDAP, Active Directory and SSO integration, and it runs fully offline. For most organizations it is the fastest route from shadow AI to governed AI.
One point of accuracy, because it affects your legal review: Open WebUI is source-available rather than OSI open source from v0.6.6 onward. Its own documentation says the licence is not OSI-approved. Plan your review around that rather than around an assumption.
What we deploy
A deployment your assessor can read
The interface is the easy part. The controls around it are what make it defensible.
Inside your boundary
Deployed on infrastructure you control — on-premise, private cloud, or an Azure enclave. No prompt, document or completion transits a third-party service unless you explicitly route it there.
Role-based access and group scoping
Not everyone should reach every model or every document collection. We map groups to your existing directory and scope retrieval so a user cannot surface content they could not open directly.
SSO and directory integration
LDAP, Active Directory and SSO, so access follows joiners, movers and leavers automatically. An AI tool with its own parallel user list becomes an offboarding gap within a quarter.
Model routing you choose
Point it at self-hosted open-weight models, a commercial API, or both with rules about which data may reach which. The routing policy is a control, and we document it as one.
Retention and logging decided up front
What gets kept, for how long, and who can read it. In a HIPAA context this is the difference between a defensible deployment and an unlogged PHI processor nobody inventoried.
A sanctioned path that is genuinely better
Governance only works if the approved tool is good enough that people prefer it. A locked-down deployment nobody wants to use does not reduce shadow AI; it relocates it.
Questions
Frequently asked
Is Open WebUI open source?
Not precisely, and the distinction matters for procurement. Code through v0.6.5 was BSD-3-Clause. From v0.6.6, released April 2025, the project uses a custom licence that its own documentation states is not OSI-approved. You can still read, self-host and modify it — but do not let a legal review proceed on the assumption that it carries an OSI-approved licence.
Are there conditions on rebranding it?
Yes, and this one catches people at scale. The v0.6.6+ licence adds a branding-retention clause: you may not alter, remove or obscure the Open WebUI branding unless the deployment has 50 or fewer users in a rolling 30-day period, you are a substantive contributor with written permission, or you hold an enterprise licence. A white-labelled pilot can therefore be compliant at 40 users and non-compliant at 60. We raise this before you build a rollout plan around it, not after.
Does this replace our Microsoft or Google AI tooling?
Usually not — it sits alongside. Most organizations end up with a commercial assistant for general productivity and a self-hosted deployment for anything touching regulated data. The valuable artifact is the routing policy that says which is which, and having it written down before someone pastes a patient record into the wrong window.
How does this help with an audit?
It converts an unknown into an inventory. Before: an unknown number of staff using an unknown set of tools with unknown data. After: a named system, in a documented location, with access control mapped to your directory, a retention policy, and logs. That is a control an assessor can test rather than a policy statement they have to take on faith.
What does it cost to run?
The software itself is free to self-host. Your real costs are infrastructure, the inference you route to, and operating it. If you run open-weight models on your own hardware, marginal cost per query approaches zero and your spend becomes capital rather than per-seat — which for a large staff is often the argument that wins.
Interested in this agent?
Let's scope it against your compliance requirements and agree what it returns.