Eight components or eighty lines: two ways to keep an agent's secrets
A reader asked how our agent sandbox and secrets scheme compare to OneCLI, an open-source platform for running AI agents as a team. Fair question, and the answer is more interesting than “ours is better”, because on one axis theirs is, and checking the comparison turned up a sentence on our own product page that was not true.
What OneCLI is
A team control plane. One sandboxed agent per employee, provisioned from your identity provider, under a team policy, with shared connections, memory, scheduling, and a Slack identity each. It runs on your infrastructure. The runner is outbound-only with no inbound ports, which is the same idea our tunnel client uses to live behind NAT.