← Back to Blog

How to Run an AI Directory & Identity Agent with OE Runtime

Search, audit, and manage users in Active Directory or LDAP with natural language. OE Runtime connects directly to your directory server, checks account health, and surfaces stale or misconfigured accounts — no IT ticket required.

📂
Step 1
Search Users
Search Active Directory for accounts created or modified in the last 30 days with status, department, and last login.
Step 2
Check Account Health
Identify disabled accounts with active memberships, stale logins, and incomplete user profiles.
Step 3
Report
Produce a directory health summary with flagged accounts and recommended remediation actions.

What You Need


Create the Project Folder

Create a folder called directory-identity/ and add these two files:

directory-identity/
├── SKILL.md         # the portable skill (agentskills.io)
├── agent.yaml       # wires SKILL.md to your connector
└── oe-config.json  # LLM key + connector credentials

The Skill Files

Create SKILL.md inside a directory-identity/ directory. This is the portable skill — it follows the agentskills.io format and runs unchanged on Claude, Cursor, Windsurf, or OE Runtime:

---
name: directory-identity
description: Search and manage users in LDAP or Active Directory
license: Apache-2.0
metadata:
  author: Open Enthrium
  version: "1.0"
---

You are a directory services agent. Search for users, list groups,
retrieve account details, and manage entries in LDAP or Active Directory.
Always confirm before making any changes.
Complete all steps fully before writing your report.

## Step 1: Search Users
Search Active Directory for all user accounts created or modified in the last 30 days.
Retrieve: display name, email, department, account status (enabled/disabled), and last login date.

## Step 2: Check Account Health
From the retrieved accounts:
- Identify any accounts that are disabled but still have group memberships
- Identify accounts with no login in the last 30 days
- Flag accounts with missing email or department fields

## Step 3: Report
Produce a directory health summary:
- Total accounts found
- Number of enabled vs disabled accounts
- Accounts flagged for review (disabled with memberships, stale logins, incomplete profiles)
- Recommended actions for each flagged account

Create agent.yaml in the same directory to wire the skill to your connector:

name: Directory Agent
description: Search and manage users in LDAP or Active Directory
connectors:
  - connection_name: Active Directory
    connection_type: ldap
skills:
  - path: ./
    trigger_type: auto

The Config File

Create oe-config.json in the same directory:

{
  "llm": {
    "provider": "openai",
    "model": "gpt-4o",
    "apiKey": "YOUR_OPENAI_API_KEY"
  },
  "server": {
    "enabled": false,
    "port": 3333,
    "apiKey": "your-secret-api-key"
  },
  "connectors": [
    {
      "connection_name": "Active Directory",
      "connection_type": "ldap",
      "url": "ldap://192.168.1.10:389",
      "bindDN": "cn=admin,dc=example,dc=com",
      "bindPassword": "YOUR_LDAP_PASSWORD",
      "baseDN": "dc=example,dc=com"
    }
  ]
}

Replace the url, bindDN, bindPassword, and baseDN with your Active Directory or LDAP server details. Use a read-only service account for safety when running audit queries.

Download OE Runtime

OE Runtime — Direct Downloads

Run the Agent

From the parent folder containing your skill directory:

MethodBest forDownload
1 npx recommended No install needed — always runs the latest version —
2 Windows .exe Download once, run offline on Windows ⊞ Windows (.exe)
3 macOS binary Download once, run offline on Mac  macOS
4 Linux binary Server deployments, cron jobs, Docker 🐧 Linux
5 API Server integration Call from any app, webhook, or automation pipeline 📮 Postman Collection

1 npx recommended

npx -y @openenthrium/oe-runtime@latest ./directory-identity

2 Windows

oe-runtime-win.exe ./directory-identity

3 macOS

chmod +x oe-runtime-macos
./oe-runtime-macos ./directory-identity

First run blocked? System Settings → Privacy & Security → Allow Anyway.

4 Linux

chmod +x oe-runtime-linux
./oe-runtime-linux ./directory-identity

5 API Server integration

Add a "server" block to oe-config.json, then start with --serve:

{
  "llm": { ... },
  "server": { "enabled": true, "port": 3333, "apiKey": "your-secret-key" },
  "connectors": [ ... ]
}
npx -y @openenthrium/oe-runtime@latest --serve --config oe-config.json

Run with inline YAML:

curl -X POST http://localhost:3333/run \
  -H "Content-Type: application/json" \
  -H "X-API-Key: your-secret-key" \
  -d '{"yaml": "...", "params": {}}'

Or run from a file on the server:

curl -X POST http://localhost:3333/run-file \
  -H "Content-Type: application/json" \
  -H "X-API-Key: your-secret-key" \
  -d '{"file": "/path/to/agent.yaml", "params": {}}'

Use Cases

Build your own agents with OE Runtime

Download OE Runtime and run any AI agent locally or as a server — no cloud required.

Get OE Runtime →
Series OE Runtime Agent Guides — 21 Connectors
Series overview →