Personal sandboxed agents
Provision an AI agent for each employee, with each agent running in its own isolated environment.
OneCLI is an open-source platform for giving employees personal AI agents that can work across company tools. It provides isolated sandboxes, gateway-enforced policies, scoped credentials, approvals, and audit logs for team use.
OneCLI is an open-source platform for running AI agents as a team. It provisions a personal agent for each employee and lets people interact with that agent from the web, Slack, or the terminal. Agents can work across connected business tools while OneCLI controls how requests reach those services.
The platform separates agents from the credentials they use. Credentials remain in an encrypted vault and are attached by the gateway for individual requests, so keys are not exposed to the agent, model, prompts, environment variables, or logs. Each agent runs in an isolated sandbox, while policies can govern network requests and sensitive actions.
OneCLI is intended for business workflows where employees need AI assistance with operational data or tools but organizations need review and traceability. Examples shown on the product site include Salesforce updates, approved metric queries in Snowflake, and investigations that start from Datadog alerts and open code patches as pull requests.
Provision an AI agent for each employee, with each agent running in its own isolated environment.
Store credentials in an encrypted vault and attach scoped, expiring access at the gateway for each request; agents and models do not see the underlying keys.
Block endpoints, rate-limit agents, scope access by employee, and require human approval for sensitive operations. Controls apply to MCP calls, CLI commands, shell requests, and HTTP traffic from agent-written code.
Configure which changes require approval, pause an agent before execution, and retain an audit trail of requests and actions by employee.
Let employees use the same agent identity, permissions, and audit trail from the web, Slack, or the terminal.
Connect services such as Salesforce, HubSpot, Zoho CRM, Snowflake, Supabase, MongoDB, Slack, Gmail, Outlook, Notion, Linear, Google Drive, Datadog, Sentry, and GitHub. OneCLI also supports agent frameworks and pipelines that make HTTP calls, including OpenClaw, NanoClaw, IronClaw, Dify, n8n, and OpenHands.
A RevOps agent can read meeting information, match records, prepare bulk Salesforce updates, and pause for approval before writes are applied.
A BI agent can answer plain-language questions in Slack by selecting approved metric definitions, running a query in Snowflake, and returning the result.
An SRE or developer agent can begin with a Datadog alert, trace an error to a commit, write a patch, and open a pull request for review.
Teams can schedule repeated tasks, such as reassigning Salesforce accounts from a handoff list in Notion, while approval rules determine whether the agent may make the final changes.
Organizations can give employees individual agents without distributing shared API keys, and can disable an agent during offboarding while preserving its audit history.
Employees can chat with their agent in the web app, Slack, or the terminal. The agent keeps the same identity, permissions, and audit trail across those entry points.
No. Credentials are stored in an encrypted vault and attached at the gateway boundary for individual requests. They are not exposed in environment variables, prompts, or logs.
Administrators can block endpoints, set per-agent rate limits, scope credentials, and require human approval for sensitive operations. These rules are enforced outside the agent and model at the network layer.
No. The FAQ describes it as framework-agnostic and lists OpenClaw, NanoClaw, IronClaw, Dify, n8n, OpenHands, and custom HTTP-based pipelines as compatible options.
The source describes the core code as Apache-2.0 licensed and says it can be self-hosted with a one-line install. The pricing page lists self-hosted deployment as an Enterprise feature; OneCLI Cloud is available as the managed alternative.
トラフィックデータは参考情報としてご利用ください。
www.edgee.ai
Edgee is an agent gateway for coding teams that reduces token usage, routes requests across models, and provides usage visibility. Its Compression V2 works as a drop-in CLI layer for Claude Code, Codex, OpenCode, Cursor, and other supported agents.
www.docker.com
Docker MCP Enterprise Gateway governs how MCP-compatible clients access approved servers and tools. It applies identity-aware policy, supplies credentials from an approved secret store, and records tool-call decisions for enterprise teams.
theagentrouter.ai
Agent Router is an open-source Go project for managing unified access to generative AI services through Envoy Gateway. It is intended for teams that want a gateway-based control point for AI service traffic and related agent or MCP workloads.
treg.to
treg.to is an API gateway and MCP server for calling tools and data providers through one endpoint and credential. It helps agents and developers use cataloged SEO, enrichment, advertising, social, scraping, and other data tools without managing separate provider keys for every metered call.
www.cohesor.com
Cohesor is an AI gateway and control plane for routing model requests, compressing agent context, governing spend, and brokering MCP tool calls. It is designed for teams running internal or customer-facing AI agents.
obot.ai
Obot is an open-source enterprise AI control plane and MCP gateway for deploying, governing, and auditing AI agents, MCP servers, and Skills. It helps organizations centralize access policies, discovery, authentication, and activity records across AI tooling.