# What is Harness-as-a-Service (HaaS)? (/blog/what-is-harness-as-a-service)

![Illustration: A small friendly robot with a round camera-eye head sits in a simple cart harness pulled by nothing, the harness neatly holding a toolbox, a notebook, a coin jar and a key ring on hooks.](/blog/what-is-harness-as-a-service/hero.webp)

Harness-as-a-Service is a hosted harness that any agent signs into. The harness is everything around the model: the tools it can call, the auth behind them, the memory it keeps, the budget it may spend and the record of what it did. The model reasons. The harness decides what the agent can reach, on whose behalf, and with what limits.

**The model reasons, the harness decides reach**

Before, each agent carries its own harness, and the copies drift:

* Claude Code on a laptop: a Slack token that can post to the public channel, last week's decision in memory
* Codex in CI: a Slack token that cannot post there, nothing in memory
* A bot you built: its own tokens, and its own budget and log, or none

After, every agent signs into one hosted harness at `api.corespeed.io/mcp`, owned by the org:

* Connectors: tokens in custody, such as `slack__post_message`
* Approvals: Allow, Ask or Deny for writes
* Memory: shared or private, such as `memory__search_memory`
* Budgets: credits, a cap per key
* Activity: one ledger, one trail

## What is a harness? \[#what-is-a-harness]

An agent is a model in a loop with tools. The loop and the tools are the harness: the code that presents a tool list, carries credentials, executes a call, feeds the result back, remembers across sessions, counts cost and writes a log. Claude Code is a harness. Codex is a harness. A bot built on an SDK is a harness you wrote.

Every one of those harnesses needs the same parts. Each needs a token for Slack, a token for GitHub, a way to refresh them, a memory store, a budget and a log. When a team runs several agents, each harness grows its own copy, and the copies drift. One agent can post to the public channel; another cannot. One has last week's decision in memory; another has nothing.

## Why did the leverage move to the harness? \[#why-did-the-leverage-move-to-the-harness]

Models are available to everyone through an API. Two teams calling the same model get the same reasoning. What differs is what the agent can reach, what it knows at the start of a session, what it is allowed to spend, and whether anyone can reconstruct what happened. Those are harness properties.

That makes the harness the place where an agent becomes safe to run for a team. A model with no tools can do nothing. A model with every token in its process can do anything, and the first prompt injection decides what. The harness in between is where scope, custody and limits live.

## What does a hosted harness include? \[#what-does-a-hosted-harness-include]

CoreSpeed describes the long-term idea as an operating system for agents. The analogy maps cleanly.

| Operating system           | Hosted harness                                | In CoreSpeed                                                                |
| -------------------------- | --------------------------------------------- | --------------------------------------------------------------------------- |
| Drivers                    | Connectors: the apps an agent can act through | `notion__create_page`, `slack__post_message`, `github__create_pull_request` |
| Permissions                | Approvals: which writes a person decides      | Smart Approval, a plain-English policy, three verdicts                      |
| Filesystem                 | Memory: state that outlives a session         | `memory__remember`, `memory__search_memory`, shared or private              |
| Quotas                     | Budgets: what an agent may spend              | Credits, an org wallet threshold, a monthly cap per key                     |
| System log                 | Activity: who did what, with which outcome    | Dashboard → Activity, joined to one ledger                                  |
| Users and service accounts | Principals: members and agents                | Browser sign-in, `sk-cs-` member keys, `sk-csa-` agent keys                 |

The unit of ownership is the organization. Connections, memory, budgets, policy and the trail live in the org, and every agent a member runs reaches them through one sign-in. Built-in capabilities ride along: media generation and understanding, live web search and page reading, public social data, and the org's own MCP servers as `org__` tools. [Introducing CoreSpeed](/blog/introducing-corespeed) tells the story from the founders' side.

## How does an agent sign into a hosted harness? \[#how-does-an-agent-sign-into-a-hosted-harness]

Over MCP. CoreSpeed is one remote MCP server, `https://api.corespeed.io/mcp`, over Streamable HTTP. A client with a browser signs in with OAuth; a headless client sends an API key. For Claude Code, the setup is one command:

```bash
claude mcp add corespeed https://api.corespeed.io/mcp --transport http --scope user
```

Or give the agent the line `set up https://corespeed.io/SKILL.md` in chat. It fetches the skill, adds the server at user scope, signs you in, keeps the skill and asks which apps to connect. After that, `tools/list` returns what this caller may call, and every call carries the org's spend caps, lands in one ledger and is recorded in the trail. The [MCP server docs](/docs/mcp) cover Codex, Cursor, Copilot in VS Code, OpenClaw, Hermes, claude.ai and ChatGPT.

## What does a hosted harness not do? \[#what-does-a-hosted-harness-not-do]

It does not run your agent. CoreSpeed equips the agent you already run, on your laptop, in CI, or as a job you operate elsewhere. The loop stays yours; the harness provides what the loop reaches.

It sees only the calls routed through it. A local MCP server, a shell command or a direct HTTP call from your own code never passes the gate, the meter or the trail. And memory enforces nothing: it is context, while policy lives in approvals and budgets.

## FAQ \[#faq]

**Is Harness-as-a-Service the same as an agent framework?**

A framework is code you run to build the loop. A hosted harness is a service the loop signs into for tools, auth, memory, budgets and audit. You can use both.

**Do I have to replace Claude Code or Codex?**

No. Each member keeps their client. The client registers one MCP server and signs in.

**Does CoreSpeed host or schedule my agent?**

No. You run the agent. CoreSpeed provides what it reaches and records what it does.

**What does it cost to start?**

A first browser sign-in creates your organization on its first tool call, with 3,000 free credits that expire 90 days after the grant and no card required. Memory operations and `tools/list` are free per call. Rates are on [pricing](/pricing).