II Agent Harness

Secure. Deploy. Measure.

Bring Claude Code, Codex, OpenCode, or your own harness.
Keep your infrastructure. Add the building blocks around it.

Explore the integration

Roadmap · Integration packages are planned.

A checkmarked access lock, retained deployment versions, and a connected run trace.
Secure accessVersion & deployMeasure the run

Real access boundaries.
Before the agent runs.

Give agents the credentials and resources their job needs. Check the setup for indirect access paths and verify who can launch it. Your providers enforce the boundaries.

Example validation and authorization

Permissions / Deployment checksCheck record 08
Check first. Start only when authorized.
Protected operationGate result
Viewer DeploymentApply a new agent version Denied
Operator DeploymentFresh required checks passed Allowed
Required check UnansweredRequired checks must pass Blocked
Agent A Agent BInvoke B’s configured setup Denied
An unanswered required check does not count as a pass. Access checks happen before the operation starts.

You provide Provider access rules, verified identities, and credential delivery. A prompt is not an access boundary.

Permission integration

Version the whole setup.
Deploy it on your terms.

Keep the harness, container, repository, permissions, and environment together in a versioned setup. Deploy a known revision again without rewriting what earlier runs used.

Example versioned deployment

Deployments / Research agentVersion history
Configuration change

Research agent

v16 → v17
Changes from deployment 16 to deployment 17
ConfigurationBeforeAfter
Workloaddigest a81c…digest f09b…
Compute2 CPU / 4 GiB4 CPU / 8 GiB
TargetLocal infrastructureLocal infrastructure
Setup 16Existing deployment
Setup 17New deployment
Next setupFuture deployment

A setup edit does not update the resources of an existing deployment.

Local and Google Cloud first. AWS, Azure, and GitHub are planned targets.

You provide Your harness, compute, provider access, and workload lifecycle. You start, track, recover, and tear down the work.

Deployment integration

Understand the run.
Evaluate the work.

Link inputs, outputs, usage, and retained artifacts to the setup that produced them. Debug a run, compare changes, or evaluate the same outputs again without rewriting the original execution.

Example telemetry UI

II Agent HarnessLocal workspace

Traces / Run 042

Repository fix

Completed

Initiated by YouInvoked Agent B

Trace 4 spans

  1. Agent B2.4s
    1. Inspect repositoryModel · 600ms
      Starts at 0ms
    2. Read sourceTool · 200ms
      Starts at 600ms
    3. Prepare patchModel · 1.6s
      Starts at 800ms

Invocation details

Input
“Fix the failing test.”
Output
Candidate patch captured.
Evaluation pending.

Invocation: AuthorizedCheck record 08

Input tokens
800
Output tokens
200
Estimated cost
$0.004

Setup 17 · Deployment 16 · Custom harness 2.4.1

Example execution. Completion and evaluation are separate; one execution can have several grading attempts.

You provide Storage, retention, an evaluator, and task-specific grading inputs. SWE-bench and Harbor integrations are on the roadmap.

Telemetry integration

Reusable building blocks.
Your local control panel.

Use the local console to configure setups, review access findings, and inspect linked deployment, execution, and evaluation records. Extend the integrations for your own environment.

Example management UI

II Agent HarnessLocal workspace

Dashboards / Workspace

Workspace overview

Last 7 days
Invocations
1,284
From telemetry
Allowed requests
96%
From permission decisions
Evaluation pass rate
89%
Imported grades
80 / 90 passed

Agent definition

Name / ID
Research agent / Agent B
Role
Configured invoker
Invocation authorization
Trusted identity required
Definition guide

Configuration

Deployment
Local infrastructure · v17
Capture
Redacted input + output
Export
Configured destination
Integration guide
Invocation record

Repository fix Run 042

View trace
Example records. Evaluation outcomes, deployment results, and lifecycle reports remain distinct.

You provide Your local environment and workload updates. Closing the panel does not stop the agent.

Local console integration

Bring your harness.
Keep your infrastructure.

Keep your models, identities, credentials, compute, and telemetry storage. We’re building the reusable infrastructure around them. Use the pieces you need; extend the rest.

Read the integration guide