Skip to main content
Glama
openhoard

openhoard

Official
by openhoard

"Open the Acme Q3 deck." ยท "What CSVs was I working on yesterday?" ยท "Share the forecast with Acme, read-only, until Oct 31." ยท "Who can see payroll, and why?"

OpenHoard replaces the folder tree with an AI-managed, governed file layer. Every file is indexed, tagged, summarized and access-controlled, so people and their AI agents find things by meaning, not by path. Every action is checked by policy and written to a tamper-evident audit log.

Status: pre-alpha, designed in the open. The vision below is where we're headed; see the roadmap for what exists today.

The headlines

๐Ÿ‰ Your files, finally findable

Ask in plain English. Permission-aware search across SharePoint, cloud buckets and Git, with zero AI tokens spent per search.

๐Ÿ”’ Every file has a guardian

Access follows tags, not folders. Former employees lose access automatically. External links expire by default.

๐Ÿง  The filesystem that remembers

"What was I working on yesterday?" "What changed in the Acme contract?" OpenHoard keeps the history, so you don't have to.

๐Ÿท๏ธ No more Final_v2_FINAL.docx

AI names, tags, deduplicates and spots the real final version, and warns you before you send an old one.

๐Ÿค– Bring any AI. Keep control.

Works with Claude, ChatGPT, Copilot or local models over MCP. You decide, per tag, what AI is allowed to read.

๐Ÿ›ก๏ธ Built for auditors, not just users

Hash-chained audit log, 30-day undo on everything, HIPAA / SOC 2 / legal-hold packs on the roadmap.

๐Ÿ“ฆ No migration required

Index SharePoint and OneDrive in place today. Move shared work into S3 or Azure Blob when you're ready.

๐Ÿšš SFTP is over

Send customers a link. They drag in 1 GB+ files from any browser, with no account and no client, and the files land tagged in the right project.

๐Ÿงฉ Open core, open edges

Apache-2.0. Connectors, enrichers, policy packs and skills are plugins anyone can build.

Related MCP server: Glean Remote MCP Server

Why your company needs this (the slide for your boss)

The folder tree was designed for filing cabinets. It's failing modern teams:

  • 54% of US office workers say they waste time searching for files in disorganized systems (Elastic / Wakefield Research via TechRepublic).

  • 77% of organizations had at least one Microsoft 365 governance incident in the past year (ShareGate survey via WindowsForum).

  • 38% had former employees or guests keep access they should have lost, and 26% had sensitive content reach the wrong people (same survey).

  • AI assistants now read everything a user can access, so oversharing that used to be hidden is now one prompt away.

OpenHoard's pitch in one line: keep your storage, lose the chaos. Findable files, provable access control, and AI you can actually trust with company data.

  • Deploys like any managed app: SSO (Entra ID, Google, Okta), SCIM, silent sign-in, MDM packages (planned).

  • Least privilege by design: SharePoint access via Sites.Selected; AI clients on an allowlist; plugins sandboxed with declared capabilities.

  • One policy layer across SharePoint, buckets and Git, readable as "who can see this and why".

  • Security-first AI: prompt injection is in the threat model from day one. Text in a file can never authorize an action.

  • No lock-in: open source, self-hostable, one-click export of files, tags and audit history.

Presenting OpenHoard to your IT team? Use the IT overview deck (PDF): architecture, data flow, storage, tags, security and status in 15 slides with speaker notes.

How it works

            โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ Trusted core (small, audited) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
            โ”‚ identity ยท permissions/policy ยท index/search ยท summaries ยท    โ”‚
            โ”‚ audit ยท plugin sandbox                                        โ”‚
            โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ฒโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                                            โ”‚ versioned contracts + capability manifests
   connectors ยท enrichers ยท policy/vocabulary packs ยท skills ยท client integrations

The core makes every trust decision. Plugins extend what OpenHoard can reach and understand; they can never decide who gets access. Deep dives: architecture ยท threat model ยท roadmap.

Repository layout

Path

What lives there

core/

The trusted core: identity, policy, catalog (index + search), summarize, audit, sandbox

connectors/

Storage and source connectors (S3, Azure Blob, SharePoint, Git hosts, โ€ฆ)

enrichers/

Extractors and taggers for specific file types

packs/

Policy and tag-vocabulary packs (legal, healthcare, manufacturing, โ€ฆ)

skills/

Agent skills built on the core MCP tools

clients/

Web app, desktop client, Office/Teams integrations

packages/schemas

Versioned JSON Schemas for plugin manifests and other contracts

apps/server, apps/cli

The gateway (HTTP, soon MCP) and the openhoard CLI (npm; PyPI twin in packages/cli-py)

assets/

Logo and brand assets

Try it

Run the server locally. Node 24 and pnpm are all you need; no Docker, no database to install:

pnpm install && pnpm dev   # http://127.0.0.1:7420/healthz

The CLI validates plugin manifests against the published schema, the first contract every plugin must meet.

npx openhoard manifest validate connectors/example/openhoard.plugin.json
pipx run openhoard manifest validate connectors/example/openhoard.plugin.json

Join the hoard

We're building this in the open and want the community to own the edges. Start with CONTRIBUTING.md. Connectors, enrichers, packs and skills are the best places to begin. Found a security issue? See SECURITY.md.

License

Apache-2.0 ยท "OpenHoard" and the dragon-eye logo are trademarks of the OpenHoard project.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI assistants and developer tools to securely access and interact with an organization's enterprise knowledge, documents, and people through natural language while respecting existing access permissions.
    166
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables Claude to search, retrieve, and analyze indexed files with sensitivity classifications and automatic redaction of sensitive information.
    MIT