A New Tool Lets Every Employee Have Their Own AI Assistant
OneCLI, an open-source project, launched out of stealth as a Y Combinator S26 batch company. It gives each employee a personal AI assistant that runs on the employee's own computer or server, with built-in security that manages passwords and enforces company rules on every action the assistant takes. (GitHub)
The way OneCLI is built is what sets it apart. Each AI assistant is a lasting program with its own isolated computer environment, its own file system, a chat page, memory, skills, a schedule, passwords it never actually sees, and its own Slack app. The assistants communicate through a gateway, which is like a middleman that connects to password managers like Bitwarden or 1Password to hand over credentials only when needed. Nothing is stored on the server. The gateway also checks every outgoing request against company policy, which is a very different approach from simply handing an AI assistant a permanent password and hoping nothing goes wrong.
OneCLI connects to the company's login system to create an assistant for each employee under that employee's name. That means anything the assistant does is tied to a specific person, not a shared account. This matters for keeping records of who did what, and it matters for any organization that has to follow rules requiring them to track individual user activity.
The software is designed for places where opening network ports to incoming traffic is not allowed. It only makes outgoing connections, so the assistant can run on a laptop, a home server, or a private cloud with no special network setup. For anyone who has struggled with complex network configuration to make a tool accessible remotely, this removes a whole category of frustration.
Approvals are built right into the chat interface, and they are mandatory, not just suggestions. If the assistant wants to do something significant like sending an email, deleting a task, or emptying a storage bucket, it has to stop and get explicit approval in the conversation before going ahead. The approval is not a notification the assistant can skip past; it is a locked door the action cannot pass through without a human key.
OneCLI includes a web dashboard for creating assistants, chatting with them, and changing their settings. The project is open-source, meaning anyone can view and contribute to the code, published on GitHub. Y Combinator listed OneCLI as part of its S26 batch in late July 2026. (LinkedIn)
The project did not start out as a platform for running AI assistants. OneCLI was originally built in Rust as a secure password vault for AI tools before changing direction to become a full assistant platform for teams. You can see this history in the current design's heavy focus on keeping passwords hidden and enforcing rules at that middleman gateway layer.
The design choices in OneCLI reflect problems that are becoming common for teams building with AI. Many AI tools treat passwords like settings files rather than something that should be handled carefully at the moment they are needed, which creates more security risk with every new connection added. OneCLI's approach of keeping passwords away from the assistant entirely, passing them through a gateway that also enforces rules, and tying every action to a real person's name addresses three problems that organizations run into when they move from experimenting with a single AI assistant to deploying them across a whole team.
In my view, the outbound-only design is smart for security but raises questions the project has not fully answered. Since the assistant only makes outgoing connections, the control software has to keep checking in to see if there is work to do, and it is unclear how well that performs when the network is slow or unreliable.
The mandatory approval model is a stronger safety guarantee than what many other AI tools offer, where the assistant can sometimes proceed if a human does not respond in time. Making approval a hard requirement for destructive actions trades some independence for safety, which aligns with how regulated industries expect sensitive actions to be authorized.
For teams already using Bitwarden or 1Password, the password integration is an easy starting point. For those using other systems, whether OneCLI can connect to those without creating a duplicate password store will determine whether it fits their setup.
The open-source release and YC backing give the project visibility at a moment when the real challenge for most organizations is moving from single-assistant demos to running multiple assistants across a whole team in production. The password vault origins, the middleman gateway approach, and the per-person login system together tackle a real set of problems in that gap. Whether the execution lives up to the design is what the coming months will reveal.


