A distinct infrastructure category is forming between AI coding agents and the enterprises that want to deploy them. In a single week, OpenAI opened its Agents API in public beta, Coder shipped Claude Code support on its self-hosted Agent Relay, and independent developers published orchestration frameworks that all address the same gap: not the agent's capability, but the governance, context, and execution scaffolding around it. ANALYSIS The convergence suggests that "agent control plane" is becoming a recognized product category, not just an architectural pattern.
Why it matters
The bottleneck for enterprise adoption of AI coding agents has shifted from model quality to deployment infrastructure. Coder's Agent Relay integration with Claude Code was built because "adoption in regulated industries has been limited by deployment, not demand"1. OpenAI's Agents API addresses a parallel constraint: letting developers supply a task, model, tools, and compute environment in one API call while choosing whether execution happens in an OpenAI sandbox, on the developer's own infrastructure, or with partner environments such as Cloudflare, Modal, and Vercel3. ◆ Both moves treat the orchestration-and-governance layer, not the model itself, as the product surface that unlocks new customers.
The big picture
The emerging control-plane category spans at least three tiers of sophistication. At the platform level, Coder's Agent Relay is a self-hosted execution environment for cloud coding agents. It lets Claude Code agents run inside Coder workspaces on the customer's own infrastructure: "network-governed, sandboxed, and fully auditable". Anthropic handles billing and the agent loop; everything the agent touches lives on machines the customer controls. Coder launched Agent Relay on September 2 with Cursor as its first agent provider, and Anthropic's engineering team worked with Coder to bring Claude Code onto Agent Relay within days of that launch.
OpenAI's Agents API, which entered public beta on September 10, takes a different architectural stance. It adds context compaction for long sessions, tool search, parallel programmatic tool calls, and multi-agent support. OpenAI says the API has no extra fee during the beta, though token and tool usage still costs money. The Reddit post summarizing the launch frames the key design choice precisely: "The useful split is between orchestration and execution. Teams can reuse the Codex harness without putting every file, secret, or runtime inside OpenAI's sandbox".
Below these vendor platforms, individual practitioners are building their own control layers. One developer published AI Workflow Control Plane V2.2, a deterministic control layer for AI coding agents that separates task/risk routing, retrieval routing, context assembly, structural analysis, execution, and verification4. Its retrieval layer uses code-aware BM25 RRF for heterogeneous rank fusion and MMR for redundancy control. Retrieval ends in one of three states (sufficient, requires_exploration, or abstain), and weak evidence can prevent an agent from editing too early. Another developer built Sanctorum, an Electron desktop app where agents sit at desks on floors, with capabilities derived from seat-based permissions; every tool call pauses for user approval by default, and every delegation tree has a spending ceiling2.
Between the lines
One practitioner described the core frustration driving this category: "At that point I'm not sure if I'm using an agent or just supervising a very enthusiastic intern"5. The complaint targets not model intelligence but context delivery and boundary enforcement. ANALYSIS The pattern across these projects is that each one addresses the same underlying problem from a different angle: raw agent capability without structured governance shifts work from coding to supervision.
Coder and OpenAI are drawing the orchestration-versus-execution boundary in opposite directions. Coder keeps execution entirely on customer infrastructure while Anthropic retains the agent loop. OpenAI offers a spectrum from its own sandbox to developer-owned environments but hosts the orchestration harness itself. The independent projects split differently still: AI Workflow Control Plane V2.2 treats repository content as "untrusted evidence, not instructions" and fingerprints context packets using Git HEAD, index state, and changed-file hashes to detect stale context. Sanctorum enforces governance through spatial metaphor and spending ceilings.
What unites them is the premise that the control plane, not the model, is the trust boundary. Financial services and other regulated enterprises operate under security and compliance requirements that prevent autonomous agents from accessing source code, credentials, and internal services on infrastructure outside the organization's control. The control plane is where that constraint gets enforced.
What's next
Coder's Agent Relay already supports Cursor and Claude Code; the relay architecture is designed to onboard additional agent providers. OpenAI's Agents API remains in public beta with no announced end date. Josh Epstein, president at Coder, positioned Agent Relay as the path for Claude Code to reach "more organizations across industries". The production question, as the Agents API summary noted, "is how carefully they set those boundaries".