Concepts
Agents, models and environments
Three separate things combine when an agent does work: the harness that drives it, the model that reasons, and the environment where it runs. Floating Keys treats each one as a distinct choice with its own readiness and limits.
Harness, model, environment#
- Floating Keys and CoreAdmit, record, review
- HarnessCodex, Claude Code — drives the work
- ModelReasons; called by the harness
- EnvironmentYour computer, a working copy, an enrolled device, or a planned isolated worker
- Harness
- The agent program that plans, edits and calls tools — for example Codex or Claude Code. It has its own sessions, settings and sign-in.
- Model
- The language model the harness calls. The same harness can use different models, and model access can have its own policy.
- Environment
- Where the process actually runs: your computer, a separate working copy of a repository, an enrolled device, or — in the plan — an isolated hosted worker.
A harness being installed, signed in, compatible and ready to run are four separate facts. Floating Keys reports each one instead of assuming readiness from a program’s name, and those observations can go stale.
Coding agent support today#
This table describes the governed workflow — runs admitted, tracked and reviewed through Core. Having a preset or detecting a program is not the same as governed support.
| Agent | Governed runs | Imported history | Native session resume |
|---|---|---|---|
| Codex | LocalTask, checks and result review verified on a local machine | PartialRead-only copies; see Memory | PlannedNot offered by the governed flow |
| Claude Code | PartialAdapter implemented; signed-in execution still being verified | PartialRead-only copies | PlannedNot supported by this adapter |
| Cursor | PlannedNo governed execution | PartialBest-effort local import | PlannedNot supported |
| Other agent CLIs | PlannedNo governed adapter yet | Planned | Planned |
The local command-line route runner can also launch several agent CLIs from configuration presets. That path runs each task in a separate working copy and records the result, but it is a simpler local tool, not the governed run workflow above.
What local policy does — and does not — do#
Projects can declare which commands and paths an agent should use. By default, policy observes: it records violations without stopping the run. In enforce mode, a run that broke the rules is failed after its changes are captured.
An optional local model gateway can check each model call against policy before forwarding it, keeping provider keys inside the gateway. It only governs traffic sent through it; it is not a firewall, so a harness that can reach a provider directly can bypass it.
Status reflects September 2026. Planned items are design targets, not commitments to a date.