{"id":111185,"title":"OneCLI - Give every employee a secured, sandboxed pro assistant agent","tagline":"Self-hosted agent harness for teams: sandboxed, policy-controlled, and never touching a real credential. Works from web and Slack.","body":"Hi everyone 👋, we're Jonathan and Guy, founders of OneCLI.**\\\n\\\n🏆 TL;DR**\n\nOneCLI is an open source agent harness for teams. Each employee gets their own sandboxed pro assistant agent, connected to their GitHub, Gmail, Notion, Dropbox, or CRM right from the chat/Slack, while the whole workspace runs under one policy your admins control. \\\n\\\nAgents never hold real secrets: the credential is injected at the network layer, per request, after the call is authorized. You can't steal what isn't there.\n\n**Launch Video**\\\n\u003chttps://youtu.be/LUAMdqbl_Rw\u003e\n\n🚧 **The Problem**\n\nLately, autonomous agents have arrived and shown up everywhere. Tools like OpenClaw and Hermes have become extremely popular and been adopted by open source communities, mostly by individuals. Companies, however, have been left behind: they need integration with their identity providers to enable easy provisioning of agents on behalf of an employee's identity, with least-privilege access.\n\nThose tools have fundamental flaws. Security fundamentals, like secret handling and organization-level control, are missing by default. So companies must choose between weak agents or making them powerful but risky.\n\n✅ **What OneCLI Does**\n\nOneCLI gives teams the whole harness, open source and self-hosted, so agents can be powerful and safe at once:\n\n* **Sandboxed agent per employee:** each agent runs isolated with its own memory, skills, and permissions.\n* **Secrets injected at the network layer:** the agent gets a placeholder, the gateway swaps in the real credential per request, after the call is authorized. Credentials never enter the agent's context, memory, or logs.\n* **Policy enforced outside the model:** admins define org-wide policy. Block endpoints and scope access per agent.\n* **Human-in-the-loop where it counts:** sensitive actions (send the email, delete the Linear ticket, empty the S3 bucket) wait for deterministic approval in the chat.\n* **Full identity trail:** every agent is bound to an employee, every call logged with who it acted for and which policy allowed it.\n\n🚀 **Team**\n\nWe've spent our careers in security. Jonathan built zero trust network access at Axis Security (acquired by HPE). The core ZTNA idea is that you never trust the client and enforce access outside it, at the network layer. Guy was the first employee at Argon (AppSec company acquired by Aqua Security), protecting client codebases. Agents need exactly the treatment ZTNA gives humans, so we built it.\n\n🙏 **Our Ask**\n\n* Do you want to provide each of your employees with a secure OpenClaw isolated in a sandbox? Shoot me an email: [jonathan@onecli.sh](mailto:jonathan@onecli.sh)\n* Star/try the repo:[ https://github.com/onecli/onecli](https://github.com/onecli/onecli). Self-host in minutes, free.","slug":"SvJ-onecli-give-every-employee-a-secured-sandboxed-pro-assistant-agent","created_at":"2026-08-20T14:00:00.677Z","updated_at":"2026-09-19T06:38:05.654Z","total_vote_count":29,"url":"https://www.ycombinator.com/launches/SvJ-onecli-give-every-employee-a-secured-sandboxed-pro-assistant-agent","share_image_url":"//bookface-static.ycombinator.com/assets/ycdc/yc-og-image-c440a0ad1dacfb86eeeb343717479cc54d256614449b4ef719977a0a451f8bc8.png","company":{"id":33320,"name":"OneCLI","slug":"onecli","url":"https://onecli.sh","logo":"https://bookface-images.s3.amazonaws.com/small_logos/0405005492b7122ac5f4784e260fc64d7bd99053.png","batch":"Summer 2026","industry":"B2B","tags":["AIOps","Artificial Intelligence","B2B","Workflow Automation","Open Source"],"search_path":"https://bookface.ycombinator.com/company/33320"}}