Review · Stage 2 framework findings · 2026-07-02

Porter's Five Forces Review - OpenAI-Ona Threat Refresh

This page renders the complete non-canonical Porter working packet for the focused first-party platform-layer refresh. Approval writes only the framework intermediate at research/competitive-analysis-porter-five-forces.md; parent synthesis remains gated until all selected framework intermediates are approved.

Parent command$competitive-analysis
Working packetresearch/_working/preliminary-porter-five-forces-research.md
Canonical target after approvalresearch/competitive-analysis-porter-five-forces.md
Run manifestresearch/_working/competitive-analysis-run.yaml

Table of Contents

Market Boundary

The relevant market is no longer only AI coding agent orchestration in the narrow desktop/TUI sense. The OpenAI-Ona trigger pushes the boundary toward hosted and cross-device coding-agent execution platforms: products that can run coding agents away from the user's immediate terminal, expose review or steering surfaces on web/mobile, and apply account, sandbox, billing, or policy controls around autonomous code changes.

IncludedOpenAI Codex + Ona, Anthropic Claude Code, GitHub Copilot, and Cursor.
Excluded from focused refreshIndie/OSS agent workbenches and CDE infrastructure vendors, except as substitute or supplier-pressure context.

Force Assessment

ForcePressureEvidenceConfidenceImplication
RivalryHighOpenAI, Anthropic, GitHub, and Cursor now compete across hosted-agent, mobile/web steering, sandboxing, and governance jobs.HighIncrease first-party encroachment severity in synthesis.
New EntrantsHighVisible wrapper entry remains low-cost, while durable platform entry is harder because first-party vendors own distribution, identity, hosted execution, and billing.Medium-HighSustainable entry requires a narrow non-vendor wedge.
SubstitutesHighBundled first-party tools, DIY VPS/tmux/Tailscale, GitHub Mobile remote control, Claude Remote Control/channels/routines, Cursor cloud agents, and OSS dashboards are credible alternatives.HighRemote phone control alone is insufficient.
Buyer PowerModerate-HighThe ICP is technical, price-sensitive, and comfortable stitching tools together; bundled first-party subscriptions raise the proof bar.Medium-HighUsers will demand clear proof beyond bundled/free alternatives.
Supplier / Platform PowerHighVendors control agents, clients, hosted sandboxes, mobile surfaces, account systems, API terms, enterprise policies, and billing rails.HighVendor lock-in and API dependence are core structural risks.

Force Pressure Chart

Scoring translates pressure labels to review-only numeric values: High = 3, Moderate-High = 2.5.

Structural Opportunities

  1. Neutral operations layer outside vendor accounts. GitHub supports Claude and Codex inside GitHub, but that neutrality is bounded by GitHub rails.
  2. Persistent BYO-client continuity. The opening is persistent execution with the user's preferred agents and clients.
  3. Predictable orchestration pricing. Usage/credit models create cost uncertainty that a separate orchestration layer can avoid if model usage remains BYOK or clearly separated.
  4. Policy and approval layer across agents. Cross-agent review can matter if it proves risk classification, audit, and mobile decisions across heterogeneous agents.
  5. Personal/small-team operations. Incumbents are moving toward enterprise governance, leaving room below procurement and admin-heavy workflows.

Structural Risks

  1. First-party bundling compresses willingness to pay. A separate account and subscription must be justified.
  2. Distribution platforms can absorb the aggregator role. GitHub already acts as a hub for Copilot, Claude, Codex, and custom agents.
  3. Supplier terms can break neutral orchestration. Agent CLIs, APIs, sessions, credentials, and policy surfaces remain vendor-controlled.
  4. DIY remains credible for the exact ICP. Senior engineers can stitch together tmux, VPS, Tailscale, vendor mobile surfaces, and OSS dashboards.
  5. Security incidents raise the burden of proof. Autonomous agents can become credential and command-execution risk surfaces.

Evidence Matrix

ClaimSourceTypeConfidence
Claude Code spans terminal, IDE, desktop, browser, iOS, Remote Control, channels, routines, background agents, and custom agent tooling.Anthropic Claude Code overviewOfficial docsHigh
GitHub Copilot cloud agent runs in an ephemeral GitHub Actions-powered environment.GitHub cloud agent docsOfficial docsHigh
GitHub remote control works from GitHub.com or GitHub Mobile but requires the local machine online.GitHub remote-control docsOfficial docsHigh
GitHub supports third-party coding agents including Anthropic Claude and OpenAI Codex.GitHub third-party agents docsOfficial docsHigh
GitHub cloud/local sandboxes provide isolated execution and policy controls.GitHub sandbox docsOfficial docsHigh
Cursor bundles cloud agents and usage-based billing with paid plans.Cursor pricingOfficial pricingHigh
Codex mobile validates remote steering and phone-based approvals.TechRadar; Business InsiderNews/product coverageMedium-High
OpenAI-Ona is reported as strengthening Codex cloud capabilities.Economic TimesNews/market coverageMedium
Codex agentic usage is growing and includes concurrent-agent behavior.arXiv Codex usage studyResearch paperMedium

Assumptions and Confidence

AssumptionConfidenceWhat would change it
OpenAI will fold Ona cloud-execution strengths into Codex rather than keep Ona neutral.MediumOfficial OpenAI/Ona roadmap preserving neutral, model-agnostic Ona.
GitHub third-party-agent distribution will keep expanding from preview.Medium-HighGitHub narrowing or discontinuing third-party agent support.
Solo founders and senior engineers will still pay for neutral orchestration.MediumMVP telemetry showing users prefer bundled vendor controls.
Supplier/platform power is the highest structural risk.HighStable public standards for coding-agent sessions and approvals.

Source Coverage Gaps

Approval Gates

Approve the Porter Five Forces working packet?

Confirm the write boundary?

Compile Responses

Use this after answering approval gates or selecting section feedback. Partial YAML is allowed for feedback; complete approval requires every required gate answered without unresolved negative feedback.

No YAML compiled yet.