Quick Verdict
Wanzhi is the current enterprise Agent platform from 01.AI, with a product identity distinct from its earlier personal-workspace version. The official site positions it as an operational hub for enterprise Agents, spanning Agent construction, enterprise data governance, model training, and deployment. Its workspace exposes prompts, model selection, knowledge bases, MCP, sandboxed tools, workflows, API publishing, and channels such as a Feishu bot.
This is a sales-led platform for organizations with a defined business process and an implementation budget, not a public free assistant for occasional individual use. Standard, Pro, and Max have no verifiable public prices. A quote must include implementation, model or compute consumption, storage, integrations, operations, and support. The vendor promotes private deployment and enterprise security, but those claims do not establish a DPA, retention schedule, subprocessor list, or no-training commitment. Buyers need those terms in writing.
Best For
- Enterprises building customer-service, knowledge, reporting, or internal-operations Agents with named process and data owners.
- Teams that want vendor-supported discovery, integration, deployment, and ongoing support rather than a self-service builder alone.
- Organizations willing to test identity, permissions, auditability, internal connectivity, and private deployment before production.
- Not ideal for individuals seeking a public free tier, buyers requiring list pricing, or teams without maintained source data and workflow ownership.
Key Features
- Agent building: Configures instructions, models, knowledge, and tools around a business task.
- Knowledge and data: Makes enterprise material available to retrieval and generation, subject to ingestion, freshness, and permission testing.
- MCP, sandbox, and tools: Adds MCP integrations and an isolated execution environment for code and file work.
- Workflow and multi-Agent operation: Supports decomposed and routed processes rather than a chat window alone.
- API and channel publishing: Exposes Agent capability to an organization’s systems and supported collaboration channels.
- Model and deployment lifecycle: The vendor advertises model training, deployment, and private-delivery options; exact models, hardware, upgrades, and responsibilities belong in the solution design.
Use Cases
Start with one frequent, measurable process, such as answering employee questions from an approved policy set or preparing a reviewable report from structured inputs. Document permitted sources, blocked systems, approval points, expected answers, and fallback behavior. Begin read-only. Do not connect production email, customer databases, finance systems, and write privileges during the first demonstration.
The pilot should measure grounded-answer accuracy, citation traceability, cross-user leakage, prompt injection, erroneous tool calls, concurrency, latency, per-task cost, and human escalation. API or Feishu delivery also needs identity propagation and object-level authorization tests. Verify what happens to histories and shared Agents when an employee loses access. A successful demo is not a production acceptance test.
Private Deployment and Security Due Diligence
Private deployment, secure sandboxes, permissions, and enterprise-grade controls are vendor claims until the selected architecture is documented and tested. A customer-hosted application may still call external models, OCR, telemetry, identity, update, or remote-support services. Require a data-flow diagram and outbound connection list covering key ownership, logs, encryption, backups, privileged access, patching, disaster recovery, and support access. Validate it with network observation and failure exercises.
Public material does not provide enough detail to confirm a customer-ready DPA; separate retention periods for prompts, files, vectors, output, logs, and backups; a complete subprocessor and model-provider list; data-location or transfer rules; customer-content training or product-improvement use; or deletion deadlines and evidence. Put the answers in the master agreement, DPA, security schedule, and SLA. Do not upload personal data, trade secrets, regulated records, or confidential client material to a trial environment without those controls.
Pricing
Wanzhi sells Standard, Pro, and Max through sales, with no public verifiable prices as of July 21, 2026. The table is a procurement checklist, not an official entitlement matrix.
| Plan | Public price | Confirm in the quote |
|---|---|---|
| Standard | Not published | Users, Agents, knowledge capacity, model/tool allowance, API, and support |
| Pro | Not published | Workflows, team governance, integrations, isolation, audit, and implementation |
| Max | Not published | Private topology, dedicated resources, SLA, customization, security, and operational responsibility |
Compare three-year total cost on one workload. Include software, implementation, model tokens or compute, vector and object storage, parsing, connectors, staging, upgrades, backup, disaster recovery, training, and support. Record overage, minimum commitment, renewal, acceptance failure, exit, and data-export terms in the signed order and attachments.
Pros
- Current identity is clearly centered on enterprise Agents rather than legacy consumer office functions.
- Agent configuration, knowledge, MCP, sandbox tools, API, and delivery channels form an implementation path.
- Vendor-assisted delivery may fit integrations that cannot be completed through self-service SaaS alone.
- Private-deployment options can be investigated for internal or dedicated environments.
- Chinese enterprise workflows and local implementation communication are central to the product.
Cons
- Standard, Pro, and Max lack public prices and a stable public entitlement comparison.
- Results depend heavily on data governance, workflow design, integration, testing, and ongoing operation.
- Private-deployment and security language does not replace architecture evidence or contractual liability.
- Public DPA, retention, subprocessor, training-use, and deletion detail is insufficient.
- Portability of models, knowledge, workflows, and audit data must be tested before procurement.
Alternatives
| Tool | Best for | Difference from Wanzhi |
|---|---|---|
| Dify | Technical teams starting from an open-source application platform | More self-hosting and ecosystem choice, with more customer engineering responsibility |
| FastGPT | Knowledge-base Q&A and controlled workflow prototypes | A narrower place to start for RAG-heavy projects |
| Coze | Business users building and distributing bots quickly | More self-service; compare deep enterprise delivery separately |
| LangGraph | Engineering teams needing code-level state and control | More programmable, but not a sales-delivered enterprise suite |
Build the same benchmark in Dify or LangGraph when the organization has strong engineers. That makes Wanzhi’s implementation speed, governance, and total cost measurable. For a document-centered pilot, FastGPT may keep the initial scope smaller.
FAQ
Is Wanzhi currently a personal productivity assistant?
No. In 2026, the official site presents an enterprise Agent platform covering Agent construction, data governance, model training, and deployment. This entry evaluates only that current enterprise product.
How much do Standard, Pro, and Max cost?
Public prices are not listed. Request comparable quotes using the same users, volume, deployment, implementation, and support assumptions, including model, compute, storage, and renewal costs.
Does private deployment guarantee that data stays inside the network?
No. Models, OCR, telemetry, identity, updates, or remote support can create external connections. Confirm boundaries through diagrams, endpoint lists, network tests, and contracts.
Does public information promise that customer content is never used for training?
Not clearly enough. Obtain written treatment for prompts, output, uploaded files, vectors, logs, model improvement, and human review for the selected plan.
Which procurement documents should a buyer request?
Request the master agreement, DPA, security schedule, SLA, subprocessor list, deployment and data-flow diagrams, retention/deletion table, incident notification, and exit and export terms.
What is a low-risk proof of concept?
Use authorized, minimized data in a read-only process. Prepare expected answers and adversarial tests, restrict tools and network access, and record quality, cost, latency, leakage, and escalation before adding production permissions.
Bottom Line
Wanzhi should be evaluated as an enterprise Agent, knowledge, tool, workflow, API, and private-delivery platform, not as its former consumer office assistant. Run one constrained read-only pilot and obtain comparable Standard, Pro, and Max quotes plus contractual data-processing answers. Expand only when business acceptance, security testing, and written obligations all pass.