The execution boundary
The harness owns agent configuration, context, model invocation, the agent loop, tool dispatch, concurrent execution, cancellation, deadlines, limits, tool-call/result pairing, deterministic result ordering, and the extension lifecycle. The core kernel leaves session persistence to its host; the optional extensions crate provides JSONL transcript storage, and the Rust SDK offers persistent sessions. Fleet-scale scheduling, microVM lifecycle, networking, tenancy, and control-plane APIs remain outside this local execution stack.
Runtime pieces
The dependency direction is intentional: tools and extensions depend on the core contracts; the core does not depend on an individual provider, tool, terminal UI, or control plane.
In SDK sessions, subagents, workflows, and processes share session-owned lifetimes. Typed host operations and model tools use the same underlying services; see subagents and the tool reference for usage.
One turn
- The host builds a context from the session, instructions, mode, and active capabilities.
- The model emits text and, when needed, one or more tool calls.
- The dispatcher classifies calls, applies policy and approvals, then executes eligible calls concurrently.
- Results return to the model paired to the original call IDs and ordered by call position, even when execution completes out of order.
- Extensions observe or alter defined lifecycle seams without becoming part of the core loop.