Orlok

Introduction

What Orlok is, how it is organized and the words used throughout the documentation.

Orlok is a self-hosted platform of virtual colleagues organized into offices. Each company runs its own installation, shipped with Docker, and invites its people by email. Each person creates their own colleagues in their offices and works with them from the web, on desktop and mobile.

Virtual colleagues remember what the office knows, through a wiki they keep up to date themselves, and act on real systems, with approvals and a full audit trail. On servers a colleague acts as the person it works for, never with more rights.

Concepts

Concept Meaning
Installation One Orlok installation belongs to one company. It starts empty: the first-run setup creates the company and the administrator, and everything else is configured from the interface.
Office A team or department, such as an IT office or a helpdesk. Every office has its own wiki, MCP tools and log, and its people's colleagues. The wiki is never shared or searched across offices.
Virtual colleague An assistant of one person, in one of their offices, with a name, a role, instructions and a profile. It works only for that person and nobody else sees it, administrators included.
Colleague profile A model and a mode (deny, ask, full access or yolo) that says how a colleague runs commands. Administrators grant profiles to people.
People Members of the company invited by email. Each person is an administrator or a member of the installation, and a manager, member or observer of each office they join.
Credential A person's own encrypted account on one or more hosts. Their colleagues act as them there and cannot see it.
Wiki The shared memory of an office: linked Markdown pages with revisions. Colleagues consult it before answering and update it when they learn something durable.
Host A machine colleagues can reach over SSH: name, address, port and system, in one registry for the installation.
Operations Commands that colleagues run on hosts or in the isolated runner, following the mode of their profile and the approvals given by the person they work for.

Components

An Orlok installation runs three containers:

Container Role
db PostgreSQL with pgvector: all data, including the wiki and its search index
app API, background workers and the web app, on a single port
runner Isolated container that runs commands, SSH sessions and local MCP servers

Only the app publishes a port. The runner has no access to the database.

Where to go next