MEHO started with a real datacenter operated by VMware Cloud Foundation on bare metal, which became the product's requirements.
Published
Signal category
Products & Services
Quote
“We did not start with a product. We started with a real datacenter — VMware Cloud Foundation on bare metal — operated every day with AI agents.”
— MEHO team
Company
MEHO
Governance layer for AI agents acting on infrastructure.
- Industry
- Software Development
- Company size
- 1 employees
AI agents are now good enough to do infrastructure work — drain a node, rotate a credential, restart a service, delete a namespace — not just describe it. But the tooling hasn't caught up. Today, giving an agent real access usually means giving it a long-lived, over-privileged credential — because nothing better exists between the agent and the API. No policy layer. No audit trail. No proof of what ran, when, or as whom. MEHO is that missing layer. An open-source governance backplane that sits between any MCP client (Claude Code, Cursor, Cline, your own agent) and the infrastructure it operates on. MEHO runs no model — bring your own agent; MEHO governs what it's allowed to do: — Every operation is policy-gated against the caller's role and per-target grants before it executes. — Credentials are short-lived and issued just-in-time — the agent authenticates with an OIDC token; MEHO exchanges it for a backend credential per operation. The agent never holds a secret. — Every action lands as an immutable, principal-attributed audit row and is published to a real-time activity feed other agents and humans can watch. — Results are reduced server-side — the agent gets a compact, relevant view, never a 4 MB raw API dump. Under the hood: 25+ connectors spanning VMware VCF, vSphere, NSX, Kubernetes, Proxmox, Vault, Keycloak, Prometheus, and more — with deep operator fluency on the VMware/VCF side. Built in public by the team at evoila RDC. Shipping weekly. Open source · Apache 2.0 · github.com/evoila/meho
Founded 2025