Launch HN: OneCLI (YC S26) – OSS sandboxed agent harness for teams

Hacker News
Published
1
0
Launch HN: OneCLI (YC S26) – OSS sandboxed agent harness for teams
Read the full story at Hacker NewsOriginal

Hi HN, Jonathan & Guy here from OneCLI, an agent harness built for teams, giving every employee a secured, sandboxed personal agent.

Here’s what you can do with it:

1. get a sandboxed agent, with all the OneCLI capabilities in place like connect your GitHub account, Gmail, Notion, or Dropbox simply from the chat.

2. deterministic human in the loop approval in the chat itself for things that you need 100% control like sending an email or deleting the Linear ticket.

3. manage team policy in one place, enforced across every agent in the workspace

4. enjoy global connections at the team level, like shared LLM keys or service accounts

Here’s a demo: https://www.youtube.com/watch?v=dlW-44ntpbE

We started working on this by accident, even though our careers were in the security space. We were working on a devtool called ChartDB, an open-source DB tool. When OpenClaw took off back in January, we started using it to orchestrate agents on top of ChartDB. We quickly understood there is a big issue around auth. Agents need credentials to do real work, but to give them those secrets would not be the best idea. They keep them in their memory and also write them down to local files and their sessions as plain text. And we knew that agents can easily be fooled into giving up those API keys/secrets. So we needed some way to control the agent and stop prompt injections from tricking it into using its services for an attacker's benefit.

We created OneCLI that started as a vault for AI Agents built in Rust.

We found out that most of our demand for OneCLI came from autonomous agents like Hermes, OpenClaw and NanoClaw for individuals and teams.

Users looked for useful agents that do things for the person who runs them with two missing parts: 1) managing secrets and permissions. 2) and for teams - multiplayer management.

We decided to pivot and provide the agent itself as a harness for teams, to give each employee an agent. We saw that teams had to deal with setting up their own harness again and again, and basically as we already had the vault as a gateway. We got the idea to provide the missing piece of the agent management out of the box and open source it (Apache-2.0, with a small enterprise exception).

We're open source first - the entire platform, not just a small portion of it like other agents, so companies can actually see the code, evaluate it, and trust it instead of taking our word for it. They run it isolated, in their own environment, fully under their control, at production quality, not a locked black box hosted somewhere else. That means the safety isn't just a promise, it's something they can verify themselves. Combined with real autonomy and least-privilege access, that's what makes it something a company can fully own and trust, not just adopt.

We also approach this from a company perspective rather than an individual one. Our solution manages agents on behalf of each employee, wrapped in deterministic guardrails that company admins configure through centralized policies.

For the agent engine itself we’re using jcode which is the core of the agent-loop. We found out that it improves the experience and makes the agent smarter and faster.

Here’s how it works:

It runs on infra you control. Fully open-source, self-host or cloud in minutes.

The agent never holds a real secret. It gets a placeholder. The real credential is injected at the gateway, per request, after the call is authorized. It never enters the agent's context, memory, or logs.

Enforcement outside the model. Prompts are suggestions. Policies defined by the org admin run at the network layer, outside the agent and the LLM. Block endpoints, rate limit per agent, require approval, scope per employee. The gateway decides. The agent can't bypass it.

Isolated VM per agent. Own memory, own keys, own permissions. Blast radius is one agent.

Speed of the Harness: Rust engine under the agent loop.

Full identity trail. Every agent is bound to an employee. Every call logged with who it acted for and which policy allowed it.

Some things people are doing with the platform include:

- Managing their company life cycle entirely from the sales calls, to the product side automatically open tickets to the engineering teams, that would kick the development agents to deliver and ship to production.

- Operational side, like automatically hygiene the CRM after calls, sourcing leads, book meetings and manage follow ups emails.

- Some of our customers also doing their entire grocery shopping using those agents and send them to take care of their chores like ordering things online.

About the team: Both founders come from cybersecurity backgrounds. Jonathan spent years at Axis Security building zero trust network access. The core idea is that you never trust the client. You decide exactly what a person can reach, and you enforce it outside of them, at the network layer, so it doesn't matter what the client tries to do. That's how every serious company gives access to humans today. Guy was the 1st employee in Argon security doing AppSec.

We would love to hear your thoughts on the move, happy to get issues open to improve and get your agent to be powerful and secure - designed for teams, not just individuals.


Comments URL: https://news.ycombinator.com/item?id=49363710

Points: 3

# Comments: 0

Related Markets

All Markets
View full chart →
View Full Chart
View full chart →
View Full Chart

Market data may be delayed. Not financial advice.

Reader Reactions
The Story At A Glance
  • • OneCLI provides a sandboxed agent harness that uses a Rust-based vault to manage AI credentials.

  • • The system enforces security at the network layer to prevent prompt injection and unauthorized access.

  • • It allows organizations to deploy autonomous agents with centralized policy control and human-in-the-loop approvals.
Context
The founders transitioned from building database tools to creating a security gateway for autonomous agents. They identified that agents often leak sensitive API keys and require a way to manage permissions within a team structure.

Christian Perspective
The emphasis on deterministic control and human-in-the-loop approval aligns with the necessity of human stewardship over technology. It recognizes that autonomous systems lack a moral compass and must be bound by external authority. This mirrors the biblical principle that power must be subject to oversight to prevent corruption.

Implications
As AI agents begin to handle personal chores and professional workflows, the risk of digital deception increases. This technology provides a necessary defense against the chaos that unmanaged automation could bring to the family and the workplace. It reinforces the need for clear boundaries and accountability in an increasingly automated world.

Broader Trends
The move toward sandboxed, controlled AI reflects a growing tension between total digital autonomy and the need for centralized security. This mirrors the broader societal struggle between the chaos of unregulated systems and the necessity of structured, hierarchical order. It shows a shift toward managing the "blast radius" of technological errors.

Takeaway
Maintain strict human oversight over all automated processes to ensure they serve the interests of the family and the nation. Use tools that prioritize local, self-hosted control to avoid dependence on globalist, black-box cloud providers. Prioritize technologies that reinforce individual accountability and clear lines of authority.

What is your reaction to this story?

Reader Reactions

Want to join the conversation about this story?

Join our community at Gab.com

Alto is powered by

Gab AI

The one AI they can't control. Our exclusive AI model trained to uphold Christian values and traditional principles in every interaction.

Support Alto & Gab

Alto is funded entirely by readers like you. Your donation helps us continue delivering curated news from a right-wing Christian Nationalist perspective, powered by Gab AI.

Gab Shop

Support free speech with official merchandise

View All Products

Install Alto on Your Phone

Add Alto to your home screen for quick access to breaking news — no app store required.

iPhone & iPad

Using Safari Browser

1

Open alto.gab.com in Safari

alto.gab.com
2

Tap the Share button

at the bottom of Safari
3

Tap "More"

More
4

Scroll and tap "Add to Home Screen"

Add to Home Screen

Tap "Add" to confirm

Alto will appear on your home screen like any other app!

Android

Using Chrome Browser

1

Open alto.gab.com in Chrome

alto.gab.com
2

Tap the menu button

three dots in top right
3

Tap "Add to Home screen"

Add to Home screen

Tap "Add" to confirm

Alto will appear on your home screen like any other app!
gab

Speak Freely

Join millions on the original and only true free speech social network.

What Makes Gab Different

We're not just another social network. We're a platform built on principles that matter.

Freedom of Speech & Reach

All First Amendment protected speech is welcome. No algorithmic throttling or shadow banning.

Family-Friendly Platform

We maintain a clean environment. Explicit adult content is strictly prohibited.

Western Nations Only

Third-world IPs are blocked. No scammers, no spam farms. Built for Western civilization.

Funded By Users

Our users are our investors and customers. You're not the product being sold.

Battle Tested

A decade of standing strong. Banned from app stores, banks—and still here.

American Owned & Operated

We reject foreign censorship demands. Built by Americans, for free people.