Describe what your customer needs. The agent writes and tests the change in its own sandboxed VM. You review and press publish.
So do Cursor, Replit and v0 — and they are very good at it. IDfunction Agent assumes a team that answers for a customer system: shared workspaces, shared history, approval gates, one bill.
| Claude Code · Cursor · Codex | Replit · v0 · Bolt | IDfunction Agent | |
|---|---|---|---|
| Built for | Individual developers (Cursor Enterprise adds team features) | Individual developers & makers; v0 and Bolt support non-technical users and teams | The team responsible for a customer system |
| Sandbox | Developer’s laptop (local execution); Cursor has an emerging sandbox mode | Cloud sandboxes / live previews; Replit uses hardened containers, moving toward microVM-style isolation | KVM-isolated microVM per workspace |
| Audit trail | Local terminal / command history; Cursor Enterprise now includes audit logs | Replit Enterprise and Bolt Enterprise offer audit logs; v0 under team features | Canonical session log, exportable |
| Locked to | Tool-specific harness; Cursor supports multiple LLM providers | Platform harness; Bolt supports model / agent routing across providers | 3 harnesses, 4 providers, swappable mid-session |
| Parallel branches in one workspace | No (manual git branches possible) | Limited; Replit supports real-time collaboration | Yes — an isolated clone + sandbox per branch |
| Output | Code edits and suggestions, typically committed to a branch or PR | Code + live preview / working app; one-click deploy in several tools | Code + repo + CI + Docker image + deploy |
| Org model | Personal accounts standard; Cursor Team / Enterprise adds SSO, centralized billing, admin controls, and audit logs | Teams / Enterprise plans available — Replit, v0 Team (SSO), Bolt Teams / Enterprise (SSO, admin controls, centralized billing) | Org-first, role-scoped, SSO, aggregated billing |
| Non-developers can drive it | No | Yes | Yes, with admin gates |
All of these tools are good at what they were built for. Our bet is that the leverage in AI engineering has moved from the model to the harness — so the harness is what we build.
Published list prices for the tools above. IDfunction Agent bills the organisation, not the seat.
| Platform | Team / Pro plan | Enterprise / higher tier | Notes |
|---|---|---|---|
| Cursor | $40 per user / month | Custom | Teams plan includes SSO, centralized billing, analytics, team privacy mode. Enterprise adds pooled usage, SCIM, audit logs, priority support, invoice billing. |
| Bolt.new | $30 per member / month | Custom | Teams includes collaboration, admin controls, shared workspaces. Enterprise adds SSO, audit logs, compliance, dedicated support, custom SLAs. |
| v0 by Vercel (v0.app) | $30 per user / month | $100 per user / month (Business) or Custom | Team plan popular for collaboration + shared credits. Higher Business tier for heavier usage. |
| Replit | $100 per month (Pro) | Custom | Core is $20/mo. The old Teams plan was sunsetted; Pro is now the main paid tier with high agent credits. Enterprise is fully custom. |
| Claude (Anthropic) | $25–30 per user / month (Team Standard, min 5 seats) | ~$100–150 per user / month (Team Premium) or Custom | Premium tier gives better Claude Code / agent access. Enterprise is custom. |
List prices as published by each vendor and subject to change. Enterprise tiers are negotiated per contract.
Pick wrong today, swap tomorrow, keep the history.
A conversation in the workspace ends as configured PIAM software running in the customer’s environment. That handoff is the whole product.
Four steps from a sentence to a deployment.
A four-step wizard wires a GitHub repo, CI/CD, an optional droplet, and a microVM sandbox. Fork a template or attach an existing repo.
Pick a harness — Claude Code, DeepAgents, Codex — and say what the customer needs. The agent edits files inside the sandbox.
Three-state git tracks every file: Unsaved, Unpublished, Published. The agent commits — it cannot push without you.
One button: CI builds a Docker image, pushes to GHCR, and deploys. The customer environment goes live.
A typed, ordered transcript, normalised across every harness: each message, tool call, edit, shell command and approval, timestamped and replayable.
Git worktrees isolate branches but share one machine — fine for a developer, trouble for several agents at once. So every agent here works in a full cloneof the repo inside its own KVM-isolated microVM: own files, own dependencies, own session log. Run a refactor, a feature spike and a hotfix on the same repo at the same time, and merge when you’re ready.
Own VM, own disk, own dependency tree. Never again “wait, who installed that package?”
Each clone keeps its own canonical session log, so one line of work can be replayed or audited without untangling the others.
Teammates drive different clones of the same repo at the same time, and merge when they choose to.
Pin a customer-specific system prompt, restrict the tool allowlist, set approval gates and budgets. Settings resolve per-chat → per-workspace → per-team → defaults, and they outlive any single session.
Thinking, Executing, Waiting, Idle, Stopped, Error. Input is gated by state, so a busy agent never gets typed over.
Every file shows Unsaved, Unpublished or Published at a glance. No guessing what is about to ship.
Swap the model or the entire harness without losing the thread — the canonical session carries the conversation across.
Every tool call is named, scoped and timed. Reconnect-and-replay keeps a five-minute grace window if your tab drops.
Each clone is a fully sandboxed checkout — work in parallel without conflicts. The tree shows which clone this workspace is pinned to.
A PM describes a change — “update the lobby kiosk welcome text, re-enable weekend vendor access.” The agent makes the edits and commits. An admin reviews and publishes.
The business person never touched GitHub — but the work flowed through it.
All three run in production today.
An operator opens a deployed instance’s workspace, describes the change in plain language, and the agent applies it to the live config behind an approval gate. What used to be a ticket and a sprint takes minutes.
An orchestrator plus worker agents write into one canonical session with explicit ordering — coordinated work, one auditable transcript.
Run the same session against two models side by side. Replay production sessions as labelled test cases. Pick the better branch, merge or discard.
A local gateway that classifies every model request and right-sizes it on the fly. Flagship models for the hard work, cheaper models for the rest.
Blast radius is contained at the hypervisor. Approval gates sit on every dangerous move.
A MicroSandbox VM per workspace — no host filesystem access, isolated network, credentials injected at runtime.
Shell commands, deploys and destructive operations pause for a human decision.
Every secret encrypted. OIDC / SSO via Entra and Okta. Redis-backed rate limiting per user.
Agents build commits inside the sandbox. Only a human-pressed button pushes to remote, with the org’s stored token.
Every CRUD and API-key operation logged. Structured logs carry end-to-end correlation IDs.
Keep sensitive files, packages and services in your own environment — or run on our managed sandbox.
Our engineers ship PIAM customer projects through IDfunction Agent every day. Every feature on this page is here because a real delivery needed it.
We’re pre-launch on the client side, so there are no logos or testimonials yet. There’s us, using it daily.
We’re onboarding security and IT teams a few at a time. Join the waitlist and we’ll write to you when your slot opens.