Self-Hosted AI Employee Workbench: One-Command Deploy, Digital Teams & Model Failover
MateClaw is an open-source, self-hosted AI workbench that deploys via a single Docker command, providing digital employees with roles, knowledge bases, and tool permissions, team collaboration via DAG task graphs, a traceable wiki-style knowledge base with page-level citations, model failover across 14+ providers, and enterprise-grade RBAC, audit logs, and approval workflows — all in a Java 21 Spring Boot stack.
Overview
MateClaw is an open-source AI employee workbench designed for self-hosted deployment. It addresses three common enterprise concerns: data privacy (no upload to external clouds), vendor lock-in (model provider failures), and uncontrolled tool sprawl. The platform packages digital employees, a traceable knowledge base, multi-channel access, model failover, and governance features into a single JAR or Docker image.
Project Metadata
Repository: https://github.com/mateaix/mateclaw Stars: 1.1k+
Language: Java 21
License: Apache-2.0
Tech stack: Spring Boot 3.5, Spring AI Alibaba, Vue 3
Current version: v2.2.0 (bi-weekly major releases)
Architecture: One Service, Five Entry Points
Deployment requires only one Docker command (desktop version bundles JRE 21 for double-click start). Once running, the same backend serves five interfaces:
Web Console : Admin UI for employees, models, skills, knowledge bases, permissions.
Desktop Client : Windows/Mac native apps with embedded runtime.
Web Widget : Single <script> embed for any website.
IM Channels : DingTalk, Feishu, WeCom, WeChat, Telegram, Discord, QQ, Slack (8 channels).
Plugin SDK : Java modules for third-party capability packs.
Digital Employees: Roles, Goals, Tools, Permissions
Each digital employee is configured with four attributes: role, long-term goal, background context, and tool permissions, plus a pixel avatar. Six templates ship out of the box: General Assistant, Product Assistant, Research Analyst, Customer Service, Data Analyst, Code Reviewer. Permissions are isolated per employee — tools granted to a customer-service agent never appear in a data analyst's toolbox, preventing accidental data leakage.
Knowledge Base: Traceable Wiki, Not Just Chunk Store
Unlike typical RAG pipelines that chunk documents into a vector store and return opaque citations, MateClaw's LLM Wiki ingests PDFs, Markdown, or web pages and converts them into structured wiki pages with automatic [[links]] between pages. Answers retain page-level references; clicking a citation opens a drawer showing the exact source text block. This lets users verify every AI claim against the original material.
The Transformations engine upgrades the knowledge base from retrieval to processing: users write templates that run map-reduce aggregations over raw materials to produce structured JSON, effectively turning the knowledge base into a data-processing pipeline.
Team Collaboration: DAG Task Graphs, Leases, Approvals, Rollback
Complex work is handled by persistent Team Runs. A goal is decomposed into a DAG on a Kanban board; members execute in parallel with automatic dependency handoff. Every step's output is attached to the same task ID. Engineering details include execution leases plus runtime heartbeats to prevent duplicate execution of long tasks, human approval gates insertable at any step, and one-click forced recovery for stuck tasks.
Skills evolve through a closed loop: the system reflects on conversations, mines cross-session repeated requests, and codifies improvements into the skill pack's LESSONS.md. Every evolution step is snapshotted and rollback-capable — making the strengthening process observable and reversible. As a bonus, the platform supports the ACP protocol, allowing coding agents like Claude Code and Codex to join the team as employees.
Model Layer: Failover Chain Across 14+ Providers
To avoid single-provider outages (key expiry, 401 errors, quota exhaustion), MateClaw chains providers in a configurable priority order. Requests try each provider sequentially (e.g., DashScope → OpenAI → Anthropic) until one succeeds or the chain exhausts. Failed providers enter a cooldown window to avoid wasting seconds on repeated timeouts. Supported providers include DashScope, DeepSeek, Kimi, Ollama, LM Studio, and others (14+ total), covering both domestic and international models. Local models are supported for air-gapped sensitive data. Priority is drag-and-drop sortable in settings; a health panel shows real-time green/red status per provider.
Governance: RBAC, Audit, Webhook Signing, Distributed Locks, Domestic DB Support
Enterprise readiness features ship out of the box: RBAC roles, JWT authentication, sensitive-operation approval flows, full audit logging. The admin console shows real-time per-employee activity and token consumption. Engineering-grade guarantees include HMAC-signed outbound webhooks, distributed locks to prevent duplicate scheduled jobs in multi-instance deployments, and database support for PostgreSQL, MySQL, and Kingbase (人大金仓) — signaling a focus on Chinese domestic-compliance requirements.
The runtime engine is pluggable: the native StateGraph engine runs ReAct and Plan-and-Execute loops, but can be swapped for the managed DeepSeek Harness external loop while sharing the same session and permission context.
Getting Started & Content Studio Demo
Docker deployment is a single command; default credentials are
admin/admin123</sub>. The desktop version bundles JRE 21 for zero-dependency startup. The team demonstrates the platform with a built-in Content Studio: from a one-sentence prompt it produces a publish-ready WeChat article (topic selection, research, drafting, image generation, layout, direct upload to WeChat draft box) or Xiaohongshu cards (three-plus 3:4 vertical images). An "AI-flavor removal" loop uses a deterministic trace score to drive detect-rewrite-recheck cycles, capped at three iterations.Limitations & Target Audience
The project openly acknowledges that OpenClaw and Hermes Agent have larger communities and are better suited for single-user, single-machine scenarios. MateClaw's 1.1k-star community means plugin ecosystem and troubleshooting resources are still early. With 169 open issues and a bi-weekly major release cadence, stability polishing likely lags behind feature velocity; the article recommends a test-environment run before production deployment. For individual developers not on the Java stack, OpenClaw remains lower friction.
MateClaw targets teams evaluating "putting AI assistants on our own servers." It bundles digital employees, knowledge base, approval/audit, IM channels, and model failover into one JAR, fitting naturally into existing Java ops workflows. The project's philosophy: capabilities can be chased, but trust must be accumulated — a line from its README that captures its positioning.
Signed-in readers can open the original source through BestHub's protected redirect.
This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactand we will review it promptly.
Geek Labs
Daily shares of interesting GitHub open-source projects. AI tools, automation gems, technical tutorials, open-source inspiration.
How this landed with the community
Was this worth your time?
0 Comments
Thoughtful readers leave field notes, pushback, and hard-won operational detail here.
