Product · harnessserver

HarnessServer

HarnessServer runs in the Agent host environment, staging compiled Skills, SOPs, and Rules into Workspaces by role, and serving REST and MCP endpoints for runtime context on demand. In standalone deployment, REST and MCP-SSE run on the same HTTP port; conversation WebSockets are optional in standalone mode. It does not ingest enterprise knowledge directly; managerial memory is disabled by default and restricted to authorized Agents. Before global promotion, HarnessServer can replay candidate against baseline and write the conclusion as promotion-review evidence (when connected to LarkScout). It can operate standalone on local content or connect to LarkScout for upstream synchronization and search.

HarnessServer (Content Delivery for Agents) architecture diagram for enterprise digital workforce infrastructure
HarnessServer logo

HarnessServer

Content Delivery for AgentsContext delivery and capability distribution component for Agent host environments

Stage Skills, SOPs, and context into Workspaces by role—preloaded or on-demand, configurable per Agent.

Pre-Staged
Main config and Skills ready in advance
Role-Based
coordinator / worker distribution
REST + MCP
Colocated on same port in standalone mode

Typical pains

  1. Each Workspace requires manual, error-prone configuration of prompts and tools
  2. Newly onboarded Agents waste cycles exploring the environment before becoming productive
  3. New Agent rollouts lack a standardized, repeatable onboarding pipeline

Core value

Which agents each skill is deployed to

Once a skill is approved, HarnessServer deploys it to the matching agents. The content detail panel in AULO shows which agents it is deployed to, and at which version.

Content detail: deployed agents and versions

Role-based MCP exposure control

HarnessServer lets administrators configure tool visibility by role with unconfigured roles hidden by default (default-deny), generating versioned revisions with rollback support.

MCP exposure: configure visible tools by role with default-deny for unconfigured roles, each change versioned for rollback

SkillScan deployment safety gate and static analysis

Enabled by default in fresh install configurations and configurable to disable, inactive when turned off; runs static scans before Skill deployment to identify dangerous patterns and taint flows down to source lines, allowing safety gates to block risky installs.

Pre-deployment static scan for Skills with SkillScan enabled: dangerous patterns and taint paths pinned to file lines, enabling safety gates to block installation

Capabilities

Context supply

Dual-Side On-Demand InjectionExecution-tier Workers pull context indices on task start or refresh; orchestration-tier Coordinators pull actionable SOPs by name without pre-injecting full SOP texts into main configs
Pre-Staged WorkspacesUpon delivery/approval, Workspaces are pre-staged with main configs, deployed Skills, and visible context indices; detailed SOPs are pulled on demand by name
Context File GenerationGenerates framework-native CLAUDE.md / AGENTS.md / NODAL.md; main configs may inline a shared section so the file stays byte-stable for vendor prompt cache context files
Per-Agent Content AssemblyRules can be always loaded into the main config, optional (listed in the catalog, full text fetched by name), or left out of the catalog (still fetchable by name); SOPs can be optional or left out. Always-loaded content has a size cap, and overflow drops to a catalog line with a warning; always-loaded changes apply on next start, on-demand content on next fetch
Bitemporal Managerial MemoryWhen enabled, stores valid time and transaction time and supports point-in-time queries; off by default; only Agents with memory_access may query it, not unauthorized Workers

Does / does not

Does
  • Dual-side on-demand context injection: Workers pull task context indices; Coordinators fetch SOPs by name
  • Role-based workspace pre-provisioning: approved Skills deploy automatically (including upgrades); SOP / Rule sync by permission
  • SkillScan pre-deploy static analysis: enabled by default for new installs and configurable to disable, providing Python AST danger-pattern and dependency static scanning
  • Context snapshot and Content Version provenance: versions stamped on traces for context-change audit
  • Content-version evaluation runtime: candidate and baseline versions replay the same task batch in pairs; conclusions are recorded per content version and written to promotion-review evidence
  • Framework context file generation: CLAUDE.md / AGENTS.md / NODAL.md
  • Standalone and LarkScout integration: REST + MCP on its own, or connected to the LarkScout knowledge base
  • Per-Agent content assembly: Rules can be always loaded, optional, or left out of the catalog (still fetchable by name), and SOPs optional or left out; expected vs. actual tiers can be checked
Does not
  • Does not ingest raw documents or compile knowledge (upstream Claim compilation is LarkScout)
  • Does not provide an unauthenticated global shared memory pool (bitemporal managerial memory is isolated and authorized-Agents-only)
  • Does not manage OS-level process sandboxes (container and syscall controls belong to NodalOS)
  • Does not produce a platform-wide score or Agent ranking (evaluation conclusions and performance aggregates appear only in AULO panels and are never written into Agent-visible files)

By role

Technology leaders

Standardizes Agent onboarding, shifting Workspaces from manual scripting to role-based pre-staging and on-demand retrieval

Compliance & risk

Managerial memory is disabled by default and strictly isolated to authorized Agents

Business leaders

Bridges the final mile between knowledge compilation and execution, eliminating Agent onboarding guesswork

Integrations

LarkScout upstream knowledge sync and search (enabled with endpoint and credentials)NodalOS Workspace managementFramework-native Agent context filesServes conversation channels to AULO in standalone mode; conversations bypass this service when NodalOS is connected

Related products

Next steps

SYSTEM READYproduct/harnessserver