

An open-source platform giving every employee a sandboxed AI agent that reaches company tools through a credential gateway and never holds a real secret.

An open-source platform giving every employee a sandboxed AI agent that reaches company tools through a credential gateway and never holds a real secret.
OneCLI is a Y Combinator-backed, open-source platform that provisions a secured, sandboxed AI assistant agent for each employee in an organisation. Every agent runs inside its own isolated VM and reaches company tools through the OneCLI gateway, which injects scoped credentials per request — the agent itself never holds a password, API key or real secret. Guardrails are enforced outside the model rather than by prompting: administrators define hard limits on destructive actions (deleting a repository, sending a payment, wiping a customer record), rate-based circuit breakers that pause an agent behaving faster or more repetitively than a human, and approval gates that stop sensitive steps until a person says go. Each agent inherits only the access its owner already has, so a support agent cannot wander into billing or payroll. Employees interact with their agent from Slack, the OneCLI CLI or the SDK, and the whole platform can be self-hosted on the Enterprise plan.

An open-source platform giving every employee a sandboxed AI agent that reaches company tools through a credential gateway and never holds a real secret.
OneCLI works by combining Per-Request Credential Injection: The OneCLI gateway injects scoped credentials for each call so agents never hold a real secret, and keys never leave the vault., Isolated VM Per Employee: Every employee's agent runs in its own virtual machine, keeping one person's agent workload and data separated from everyone else's., Hard Policy Limits Outside the Model: Destructive actions such as deleting a repository, sending a payment or wiping a customer record are blocked by external enforcement rather than by asking the model to behave., Runaway Agent Circuit Breaker: An agent that starts repeating itself or acting far faster than a person would is automatically slowed or paused before it can cause damage., Human Approval Gates: Sensitive steps — like emailing a customer — pause with the work already prepared and wait for a team member's explicit go-ahead. to help users with Company-Wide Assistant Rollout: Give every employee an autonomous agent without handing out shared credentials or standing API keys., Regulated Workflow Automation: Automate finance or customer operations where certain actions must be provably impossible for an agent to take., Slack-Native Task Delegation: Ask an agent in Slack to complete a multi-step job across internal tools and get pinged only when a human decision is needed., Least-Privilege Agent Access: Scope each department's agent to that department's systems so support, engineering and billing stay in their own lanes., Security Review of Agent Activity: Use audit-log retention and resource-level scoping to reconstruct exactly what an agent touched and when..
Key features include Per-Request Credential Injection: The OneCLI gateway injects scoped credentials for each call so agents never hold a real secret, and keys never leave the vault., Isolated VM Per Employee: Every employee's agent runs in its own virtual machine, keeping one person's agent workload and data separated from everyone else's., Hard Policy Limits Outside the Model: Destructive actions such as deleting a repository, sending a payment or wiping a customer record are blocked by external enforcement rather than by asking the model to behave., Runaway Agent Circuit Breaker: An agent that starts repeating itself or acting far faster than a person would is automatically slowed or paused before it can cause damage., Human Approval Gates: Sensitive steps — like emailing a customer — pause with the work already prepared and wait for a team member's explicit go-ahead..
OneCLI is useful for anyone interested in Company-Wide Assistant Rollout: Give every employee an autonomous agent without handing out shared credentials or standing API keys., Regulated Workflow Automation: Automate finance or customer operations where certain actions must be provably impossible for an agent to take., Slack-Native Task Delegation: Ask an agent in Slack to complete a multi-step job across internal tools and get pinged only when a human decision is needed., Least-Privilege Agent Access: Scope each department's agent to that department's systems so support, engineering and billing stay in their own lanes., Security Review of Agent Activity: Use audit-log retention and resource-level scoping to reconstruct exactly what an agent touched and when..
OneCLI offers a free tier with paid plans for advanced features.
Visit https://www.onecli.sh/ to sign up and explore OneCLI.
Browse by use case: Automation & Productivity
Compare OneCLI: vs Apache Maka · vs Construct Computer · vs ShogunAI · vs fx