Runners: agents inside your own network
A runner runs your organization's AI agents inside your own network: your cloud account or your own data center. You still build and manage agents in the SourceLace app, but their runs happen on the runner. Your data, the AI calls, everyone's source sign-ins and the results never leave your network; only each run's status, steps and counts go back to SourceLace.
Runners are switched on per organization by your SourceLace contact. When they are on, admins see a Runners page in the app.
What stays where
| On the runner, in your network | On SourceLace |
|---|---|
| Every run: what the agent read, its summary, the files it made, drafts and changes waiting for approval | The agent itself: its name, instructions, sources, actions and schedule |
| Each person's sign-ins to your sources | Who owns each agent, and where it runs |
| Your organization's own AI key, and every call to the AI model | Each run's status, times, one line per step (tool, source, object, row count, outcome) and counts |
| Secret options of your sources, such as client secrets, and the OAuth apps registered for the runner | The audit trail of what each runner asked for and reported |
A run's report to SourceLace has no place for a summary, rows, record values, drafts or files, and SourceLace refuses any report that tries to send one.
Setting one up
Your IT team installs the runner; their guide is SourceLace's runner installation guide, which your SourceLace contact sends them. In short:
- An admin opens Runners in the app, presses Add runner, names it (such as "Frankfurt VPC") and copies the token. It is shown once.
- IT starts the SourceLace server image in runner mode inside your network, with its own Postgres database, a master key, the token, and the runner page's own https address (such as
https://runner.corvanta.internal). A Docker Compose example and Helm values come with SourceLace. - The runner connects out to SourceLace over HTTPS and asks for work every 15 seconds. You open no inbound port; its page is only for people inside your network.
- An admin signs in to the runner's page and, under Settings, enters your organization's own AI key (Anthropic or OpenAI) and any secret source options.
Signing in to the runner
Open the runner's page inside your network and press sign in. Your browser goes to SourceLace, where you sign in as usual, and comes straight back. SourceLace tells the runner only your email address, your organization and your role. Only members of the runner's organization can sign in, and never to a revoked runner. A sign-in on the runner lasts 12 hours.
Your sources on the runner
Agents act as their owner, with the owner's own sign-ins, exactly as on SourceLace. Those sign-ins are kept on the runner, so each person connects their sources once on the runner's page, under Your sources. The runner shows the sources your organization's agents on that runner use.
Where a source signs in through an OAuth app your organization registers itself (such as ServiceNow, Workday, Oracle Fusion, Snowflake or Salesforce), register it with the runner's own callback address, such as https://runner.corvanta.internal/connect/callback, and an admin enters its secret on the runner's Settings page. SourceLace never receives those secrets.
Running an agent on a runner
In the agent editor, choose the runner under Where it runs. An admin can also require that every agent runs on one of your runners. Such an agent starts on a schedule or with Run now; calendar and event triggers are not available on runners yet, because checking them needs the owner's sign-ins, which are on the runner.
When a run is done, its run page on SourceLace shows Ran in your network and an Open result link to the runner's page, where the summary, the steps and the files are.
Approvals on the runner
Changes an agent proposes wait under Approvals on the runner's page. The agent's owner or an admin approves or rejects each one there. An approved change is made at once, as the agent's owner, with the owner's sign-in held on the runner. Once a run has nothing left to approve, SourceLace hears that it is done.
How long results are kept
Runs, their files and decided approvals are deleted from the runner after your organization's retention period, which an admin sets on the runner's Settings page (30 days unless you change it).
Is the runner healthy?
The Runners page shows each runner's status, when it last asked for work, its version and its health: how long it has been running, how many runs it holds, the type of its last error, and free disk and memory. The runner sends only these counts, never messages or data.
- Healthy: it asks for work as usual.
- Quiet: it has not asked for work in the last 90 seconds. It may be stopped, or unable to reach SourceLace.
- Out of date: it works, but runs an older version than SourceLace. Ask IT to update its image.
- Revoked: its token no longer works.
When a runner with agents assigned to it stays quiet for 10 minutes, admins see a notice at the top of the app until it is back, and the audit trail records it once. An admin can shorten the 10 minutes (to as little as 2) on the Limits page. Runs due on a quiet runner wait for it, and their run history says so.
When something is wrong
On the runner's own Settings page, an admin can:
- Check connectivity: whether the runner reaches SourceLace (through your proxy, if
HTTPS_PROXYis set), its own database, and each of your sources. Sources are only checked for whether their address answers: no sign-in is used and nothing is read. Every problem comes with what to do, such as asking your network team to open a firewall rule. - Download support bundle: a zip to send SourceLace support, with the runner's version, its settings with every secret left out, the types of recent errors and how many of each, and the connectivity check. It holds no tokens, keys, passwords, AI keys, data or run results, and nothing about people beyond counts.
Stopping a runner
Pausing or stopping an agent, your organization's stop switch, and revoking the runner on the Runners page all reach the runner within seconds: a run in progress stops at its next step. A revoked runner gets no more work and nobody can sign in to it.
See also AI agents and Security and privacy.