HolmesGPT vs Cleric: AI SRE Compared (2026)
HolmesGPT is an open-source, read-only investigation agent. Cleric is a commercial agent that holds the pager and opens fix PRs. How the two differ, with pricing.
Key Takeaways
- HolmesGPT and Cleric solve the same problem from opposite starting points: HolmesGPT is a free, open-source investigation agent you run yourself, and Cleric is a commercial hosted agent priced per credit that also opens fix pull requests. HolmesGPT is Apache-2.0 and a CNCF Sandbox project; Cleric publishes per-credit pricing.
- HolmesGPT is read-only by design. Its README states it "has read-only access and respects RBAC permissions. It is safe to run in production environments."
- Cleric starts read-only but can escalate. Its site says "Read-only by default" and "Read access by default, write access when you're ready," and it "opens PR" for a fix once approved.
- Both work beyond Kubernetes. HolmesGPT "Works with any stack," naming Kubernetes, VMs, cloud providers, databases, and SaaS platforms. Cleric is a hosted product with SOC 2 Type II compliance.
- Cleric's pricing is public and usage-based. Tiers run from Starter at "$100 / month" for "100 credits" to Pro at "$2,000 / month" for "2,000 credits," where an issue investigation costs "10 credits" at "$1" per credit.
- The real choice is operating model, not feature checklists. Self-hosted and free versus hosted and metered, read-only versus opt-in write, and how much of the run you want to own.
HolmesGPT is an open-source, read-only AI agent for investigating incidents, and Cleric is a commercial hosted AI SRE that investigates alerts and can open fix pull requests once granted write access. The two are often compared because both automate the first pass of an incident, but they differ on licensing, cost model, and how far each is allowed to act.
What is HolmesGPT?
HolmesGPT is an open-source investigation agent from Robusta that reads observability data and runs read-only checks to find the root cause of an incident. Its GitHub README describes it as an "SRE Agent" and a "CNCF Sandbox Project," distributed under the Apache 2.0 License. The safety posture is a headline feature: "By design, HolmesGPT has read-only access and respects RBAC permissions. It is safe to run in production environments."
It is not Kubernetes-only. The README states it "Works with any stack," listing Kubernetes, VMs, cloud providers, databases, and SaaS platforms, and works "with any infrastructure," from bare metal to containers. It connects to observability backends through "Deep integrations" the README lists as "Prometheus, Grafana, Datadog, Kubernetes, and many more," plus any REST API, and supports multiple model providers including "OpenAI, Anthropic, Azure, Bedrock, Gemini." Because it is open source, you run it on your own infrastructure and pay only for the LLM tokens it consumes.
What is Cleric?
Cleric is a commercial, hosted AI SRE that takes alerts, investigates them, and can propose fixes. Its site positions it around prevention and on-call relief: "Agents that check every production change, then fix regressions before customers notice," and "Give the pager to Cleric." Its access model is staged: "Read-only by default" and "Read access by default, write access when you're ready." When it acts, it does so through review, with the site showing steps like "Cleric opens PR #484 for your approval." Cleric is operated by "Agentik, Inc. dba Cleric" and states it is "SOC 2 Type II compliant, with regular manual penetration testing," with data "encrypted everywhere and never used for training."
How do HolmesGPT and Cleric compare?
The clearest way to compare them is by operating model, not feature count. One is a library you run; the other is a service you subscribe to.
| Dimension | HolmesGPT | Cleric |
|---|---|---|
| License / model | Open source, Apache 2.0, CNCF Sandbox | Commercial, hosted (Agentik, Inc. dba Cleric) |
| Cost | Free software; you pay LLM token costs | Per-credit, "$100 / month" to "$2,000 / month" plus Enterprise |
| Access posture | "read-only access and respects RBAC permissions" | "Read-only by default," write access opt-in |
| Acts on systems | Investigates only | Investigates, then "opens PR" for approval |
| Where it runs | Your infrastructure | Hosted; "SOC 2 Type II compliant" |
| Scope | "Works with any stack" | Production monitoring, change verification, on-call |
The table makes the trade explicit. HolmesGPT gives you an auditable, read-only investigator with no per-incident cost and no data leaving your control, at the price of running and maintaining it yourself. Cleric gives you a managed agent that also drafts fixes and holds the pager, at a metered cost and with your telemetry flowing through a hosted service that states it does not train on your data.
How much does Cleric cost?
Cleric publishes usage-based pricing, which is unusual in this category and useful for planning. Its pricing page lists Starter at "$100 / month" for "100 credits / month," Team at "$600 / month" for "600 credits / month," Pro at "$2,000 / month" for "2,000 credits / month," and Enterprise at "Custom." The unit economics are stated plainly: "Credits cost $1 on monthly plans," an issue investigation is "10 credits" (so "$10"), and chats are "1 credit / min." Unused credits "roll over for one month, up to twice your monthly allocation," and there is a trial of "500 evaluation credits · No time limit."
HolmesGPT has no license cost because it is open source; its running cost is the LLM tokens each investigation consumes plus the infrastructure you host it on. That is the fundamental difference in the cost model: Cleric prices the outcome (an investigated issue), HolmesGPT prices the inputs (tokens and compute).
Which should an SRE team choose?
It depends on how much of the run you want to own and whether you want the agent to act, not just advise. A team that needs an auditable, read-only investigator inside its own perimeter, with no per-incident cost and full control of the model and data path, fits HolmesGPT. A team that wants a managed agent to hold the pager, verify production changes, and draft fixes, and that prefers a predictable per-credit bill over operating the tooling, fits Cleric.
A third option is a self-hosted agent that stays read-only for investigation but can propose a fix as a human-merged pull request, keeping both the control of open source and the option to act. Aurora is built that way: a single investigation agent by default with an opt-in multi-agent orchestrator, powerful tools behind an explicit allowlist, sandboxed Kubernetes execution when enabled, and a structural chokepoint that blocks mutating writes when no human is present so remediation only ever lands as a pull request a human merges. For the wider field, see open-source AI SRE: Aurora vs HolmesGPT vs K8sGPT, the HolmesGPT alternative for multi-cloud, and the root cause analysis guide for SREs.
The summary
HolmesGPT and Cleric answer the same need from opposite ends. HolmesGPT is free, open source, and read-only by design, and you run it yourself and pay for tokens. Cleric is hosted, priced per credit from $100 to $2,000 a month, read-only by default but able to open a fix pull request once you grant write access. The decision is about operating model and how much authority you want the agent to have, not a feature scorecard.
Try Aurora
- Start free: aurora-ai.net (hosted, no infrastructure to run)
- GitHub: github.com/Arvo-AI/aurora
- Book a demo: cal.com/arvo-ai/demo
- See it on an incident: Aurora root cause analysis
Sourcing note. HolmesGPT's description, Apache 2.0 license, CNCF Sandbox status, read-only and RBAC wording, and supported-stack wording are quoted from its GitHub README, verified 28 September 2026. Cleric's positioning, read-only and write-access wording, PR-approval flow, SOC 2 Type II statement, and all pricing (tiers, credits, per-credit cost, issue-investigation cost, rollover, trial) are quoted from cleric.ai and its pricing page, verified the same day. Pricing changes; re-check the pricing page before relying on a figure. Aurora's controls are described from its open-source repository.