Comparison
Your model. Your infrastructure. Your approvals.
attest_tag is an AI teammate for Slack built for the teams who need to choose the model, run it on their own infrastructure, cap what it spends, and put a named person in front of every change. Threads are the unit of conversation, access is scoped per channel, and nothing it does is tied to one model or one vendor’s cloud.
Which model
Any endpoint, per thread
Whose infrastructure
Yours, one binary
What spend
Metered, capped, visible
Whose approval
A named person, every write
Pick attest_tag when
- You need to choose the model — or change it later — per workspace, channel or thread.
- Tickets, documents and logs may not leave your network except as the model call you chose.
- Finance wants a ceiling on spend, not a report after it was crossed.
- Anything that grants access must be approved by someone other than the asker.
Why teams pick ours
Five things that are true of it, whatever else is in the channel.
Each one is a statement about this product and needs no claim about anybody else's to stand up. Each ends where the mechanism is shown.
You pick the model, and you can change your mind.
Model choice is not a preference here, it is the architecture: every model field in the console is a live list of what your configured endpoint serves, and the workspace, a channel and a single thread can each answer on a different one.
That matters for cost — an open-weight model answers most questions for a fraction of a cent — and it matters for the day a model is deprecated, repriced, or turns out to be wrong for your domain. A product built around one model cannot offer you that, however good that model is.
It runs where your data already is.
One binary, one database, an outbound websocket to Slack. It runs in your own network, on your own hardware, against your own model endpoint, and the only thing that necessarily leaves is the model call itself — to the endpoint you chose.
For a team whose answer to “can our tickets go to a third party?” is no, this is not a preference either.
The credential is never in the model's context.
The model emits a URL and a method. The proxy resolves what that channel may reach, matches the host, path and method, injects the credential at the network edge, and scrubs the credential values — plus anything else secret-shaped — out of the response before it reaches the model or the thread.
No amount of clever prompting recovers a secret that was never put in front of the model.
Approvals that match how your org actually works.
A Confirm card in the requester’s own thread is the right answer for most writes and the wrong one for the writes that grant access. Those raise an access request instead: an approver gets the exact calls as a DM, nobody can approve their own, and execution runs under the approving tier’s bundle rather than the channel’s.
Requests route to the least powerful tier that covers every call in them, and a plan no single tier covers is refused rather than split — so one approval is always one decision.
Every number in it is measured, not estimated.
Each completion’s tokens and cost are stored as they happen, so !usage and the console’s Overview show what was actually spent, by channel, against the cap. Every tool call and every proxied request sits beside it, exportable.
You can answer “what has this thing been doing, and what has it cost us?” without opening a support ticket.
Side by side
Seven questions worth asking either way.
The right-hand column describes what follows from being hosted and first-party — not a feature list for any one product. Ask the vendor for theirs; these are ours, in writing.
attest_tag
z-ai/glm-5.3-flash, with a heavy model routed to automatically for code and long threads, and a per-thread override.A hosted, first-party assistant
attest_tag
A hosted, first-party assistant
attest_tag
A hosted, first-party assistant
attest_tag
A hosted, first-party assistant
attest_tag
A hosted, first-party assistant
attest_tag
A hosted, first-party assistant
attest_tag
start_fix_job hands the change to a separate container that clones the branch, runs the tests, makes the change, runs them again and opens a draft pull request. One branch, never a merge.A hosted, first-party assistant
Nothing in the right-hand column is a claim about a specific product. If a vendor answers all seven in writing, that is a good sign about the vendor.
Try both
Run both in the same channel for a week.
We mean it. They answer in threads, so they do not collide, and a week of your own questions settles this faster than any table.
Half an hour to set up, one channel to start. See what it costs.