Comparison

Your model. Your infrastructure. Your approvals.

attest_tag is an AI teammate for Slack built for the teams who need to choose the model, run it on their own infrastructure, cap what it spends, and put a named person in front of every change. Threads are the unit of conversation, access is scoped per channel, and nothing it does is tied to one model or one vendor’s cloud.

Which model

Any endpoint, per thread

Whose infrastructure

Yours, one binary

What spend

Metered, capped, visible

Whose approval

A named person, every write

Pick attest_tag when

  • You need to choose the model — or change it later — per workspace, channel or thread.
  • Tickets, documents and logs may not leave your network except as the model call you chose.
  • Finance wants a ceiling on spend, not a report after it was crossed.
  • Anything that grants access must be approved by someone other than the asker.
The five reasons, in full

Why teams pick ours

Five things that are true of it, whatever else is in the channel.

Each one is a statement about this product and needs no claim about anybody else's to stand up. Each ends where the mechanism is shown.

01

You pick the model, and you can change your mind.

Model choice is not a preference here, it is the architecture: every model field in the console is a live list of what your configured endpoint serves, and the workspace, a channel and a single thread can each answer on a different one.

That matters for cost — an open-weight model answers most questions for a fraction of a cent — and it matters for the day a model is deprecated, repriced, or turns out to be wrong for your domain. A product built around one model cannot offer you that, however good that model is.

Models and cost
02

It runs where your data already is.

One binary, one database, an outbound websocket to Slack. It runs in your own network, on your own hardware, against your own model endpoint, and the only thing that necessarily leaves is the model call itself — to the endpoint you chose.

For a team whose answer to “can our tickets go to a third party?” is no, this is not a preference either.

How it is deployed
03

The credential is never in the model's context.

The model emits a URL and a method. The proxy resolves what that channel may reach, matches the host, path and method, injects the credential at the network edge, and scrubs the credential values — plus anything else secret-shaped — out of the response before it reaches the model or the thread.

No amount of clever prompting recovers a secret that was never put in front of the model.

Credentials, in the guardrails
04

Approvals that match how your org actually works.

A Confirm card in the requester’s own thread is the right answer for most writes and the wrong one for the writes that grant access. Those raise an access request instead: an approver gets the exact calls as a DM, nobody can approve their own, and execution runs under the approving tier’s bundle rather than the channel’s.

Requests route to the least powerful tier that covers every call in them, and a plan no single tier covers is refused rather than split — so one approval is always one decision.

Access requests
05

Every number in it is measured, not estimated.

Each completion’s tokens and cost are stored as they happen, so !usage and the console’s Overview show what was actually spent, by channel, against the cap. Every tool call and every proxied request sits beside it, exportable.

You can answer “what has this thing been doing, and what has it cost us?” without opening a support ticket.

Audit and budgets

Side by side

Seven questions worth asking either way.

The right-hand column describes what follows from being hosted and first-party — not a feature list for any one product. Ask the vendor for theirs; these are ours, in writing.

01Which model answers

attest_tag

Any OpenAI-compatible endpoint — OpenRouter, a vendor API, or a model you host. Ships on z-ai/glm-5.3-flash, with a heavy model routed to automatically for code and long threads, and a per-thread override.

A hosted, first-party assistant

Claude, which is the point of it.
02Where it runs

attest_tag

Your infrastructure. One binary with the console embedded, one database, talking to Slack over an outbound websocket — so there is no public URL to expose and no inbound rule to ask anyone for.

A hosted, first-party assistant

Hosted for you. Nothing to run, nothing to patch.
03What a turn costs

attest_tag

Metered per completion and shown under the reply. A monthly budget for the workspace, another per channel, and a per-user hourly rate limit — the bot pauses at the ceiling rather than reporting having crossed it.

A hosted, first-party assistant

A subscription, priced by the vendor.
04Reaching your services

attest_tag

Connections scoped per channel, with allowed hosts, path prefixes and methods. Credentials are sealed at rest and injected by a proxy at the network edge, then scrubbed back out of the response.

A hosted, first-party assistant

Whatever integrations the vendor ships and maintains.
05Before it changes something

attest_tag

Writes are held for a Confirm in the thread. Writes that are nobody’s to self-approve leave the thread entirely and go to an approver, routed to the least powerful tier that covers every call in the request.

A hosted, first-party assistant

Whatever confirmation model the vendor built.
06What you can audit

attest_tag

Every turn, tool call, proxied request and completion — with tokens and cost — in a console you run, exportable as CSV, kept as long as you keep it.

A hosted, first-party assistant

Whatever the vendor's admin surface exposes.
07Fixing the thing it found

attest_tag

start_fix_job hands the change to a separate container that clones the branch, runs the tests, makes the change, runs them again and opens a draft pull request. One branch, never a merge.

A hosted, first-party assistant

Depends on the product.

Nothing in the right-hand column is a claim about a specific product. If a vendor answers all seven in writing, that is a good sign about the vendor.

Try both

Run both in the same channel for a week.

We mean it. They answer in threads, so they do not collide, and a week of your own questions settles this faster than any table.

Half an hour to set up, one channel to start. See what it costs.