HN
Today

Launch HN: OneCLI (YC S26) – OSS sandboxed agent harness for teams

OneCLI introduces an open-source, sandboxed agent harness designed for teams, providing every employee with a secured personal AI agent. It addresses the critical challenges of secrets management, permissions, and multi-user administration for autonomous agents in a corporate setting. This technical solution tackles complex issues of scaling and securing AI agents within an enterprise context, making it highly relevant for the Hacker News audience.

18
Score
4
Comments
#4
Highest Rank
14h
on Front Page
First Seen
Aug 19, 5:00 PM
Last Seen
Aug 20, 10:00 AM
Rank Over Time
45111923282921202424262424

The Lowdown

OneCLI, launched by Y Combinator alumni Jonathan and Guy, introduces an open-source sandboxed agent harness tailored for teams, aiming to provide every employee with a secure, personal AI agent. Originating from a need to secure AI agents handling sensitive credentials, OneCLI evolved into a comprehensive platform that addresses the critical challenges of secrets management, permissions, and multi-user administration for autonomous agents in a corporate environment.

  • Secure Agent Deployment: Provides each employee with an isolated, sandboxed AI agent, ensuring credentials never directly touch the agent's memory or context.
  • Centralized Policy & Management: Offers a unified system to manage team policies, enforce guardrails, and control agent actions deterministically, including human-in-the-loop approvals for critical tasks.
  • Credential Injection at Gateway: Utilizes a Rust-based gateway to inject real credentials only at the point of access, post-authorization, preventing agents from ever holding sensitive secrets.
  • Open-Source First: The entire platform is open-source (Apache-2.0 with an enterprise exception), allowing companies to self-host, audit the code, and ensure full control and trust over their agent deployments.
  • Team-Oriented Architecture: Designed from a company perspective, integrating with identity providers and offering global connections for shared resources like LLM keys, managing agents on behalf of employees.
  • Robust Security Features: Features isolated VMs per agent, enforcement outside the LLM, a full identity trail for accountability, and a security-focused architecture derived from the founders' zero-trust security backgrounds.
  • Practical Applications: Enables automation across various business functions, from managing sales lifecycles and operational hygiene to more mundane tasks like grocery shopping, demonstrating its versatility.

OneCLI positions itself as an essential infrastructure layer for organizations looking to safely and efficiently integrate autonomous AI agents into their workflows, offering a secure, auditable, and scalable solution for enterprise-grade AI agent management.