Skip to main content

Feature status

PreviewAvailable on: WindowsmacOSLinuxShips in the preview channel only. Not a stable release.

What ships, what is preview, what is designed but unproven, and what is planned. The honest version.

Harmony is in active development and ships from a preview channel. This page records the state of each major subsystem so no page elsewhere has to imply it.

How to read the labels

LabelMeaning
StableShipping, supported, safe to rely on
BetaShipping and still changing
PreviewShips in the preview channel only; not a stable release
ExperimentalPresent in the build, unproven end to end; may change or be removed
PlannedNot available in this release
DeprecatedPresent, scheduled for removal
Platform-limitedAvailable on some platforms only

The whole product is currently distributed as an unsigned developer preview. Nothing below should be read as a stability guarantee.

Subsystem status

SubsystemStatusNotes
Terminal multiplexer (panes, splits, workspaces)PreviewThe oldest and most exercised surface
Daemon-backed durable sessionsPreviewSessions survive app close and reboot
Scrollback persistencePreview—
Desktop UI shellPreview—
Harmony TUI AgentPreviewRuns real model turns; see the note below
CLI (harmony …)PreviewBroad subcommand surface
MCP serverPreviewLarge tool surface published to MCP hosts
Provider launch (status bar)PreviewRepeatedly repaired recently; verify on your machine
A2A messagingPreviewDurable send/ask/reply/inbox
ChannelsPreviewSame-machine cross-workspace mentions route within one daemon; peer-machine mention delivery over LAN Link is not shipped (define-only)
Tasks and artifactsPreviewDaemon is the durable writer
WorktreesPreview—
Orchestration / Crew ModeExperimentalModes differ in how much is proven
Company mode (agent teams)ExperimentalTemplate-driven team provisioning
Voice dictation (Whisper)PreviewNeeds Python 3.10+ on PATH
Read Aloud (Kokoro TTS)PreviewOn-device after first model download
LAN Link (peer machines)ExperimentalRemote messages render as text only, never executed
Browser surfacePreviewEmbedded Chromium plus a driven session; distinct from the gated agent backend below
Agent-driven embedded browser backendExperimental, off in current buildsRequires browser.embeddedBackend.enabled (default false) to be explicitly enabled, embedded selection and an authenticated host invoker. Real Electron 44 offscreen/sandbox-on local fixture passed 38 checks incl. act/upload/download, authenticated guest-crash notice and tiled full-page pixels; not an assembled/onscreen app, atomic visual capture or independent OCR
Agent-driven standalone browser backendExperimental, off in current buildsExplicit harmonyBrowser: 'standalone' selection; default mode is off. Popup denial, screenshot, teardown receipts and download quarantine are composed. A real sandboxed-Chromium 20-encounter local fixture dogfood passed, not real applications or full-app qualification
Agent browser open/observe/actExperimental, off in current buildsClosed tools need an owned lease, latest element ref/generation, fresh DOM/screenshot and approval. The gated daemon packet resolver reads the exact active approved JobPacket: ordinary text facts and human answers only after revision approval. A select without a typed option asks; absent facts still refuse and create durable questions, not invented values. Redacted browser lifecycle spans append to the existing activity ledger; live UI read wiring remains open. See browser agent
Agent browser submitExperimental, disarmed by defaultModel-facing browser_submit refuses with submitArmed: false. Desktop now renders a masked pre-submit diff/approval screen for a pending request, but production still has no trusted current-form reader, host intent resolver or armed gate. Flipping the latch or seeing a modal cannot submit; a click/ticket is not external confirmation; login/MFA/CAPTCHA needs human takeover
Approved job packet and browser uploadExperimental, off in current buildsDesktop packet review, sender-validated MAIN and daemon active-packet binding are implemented; the executor refuses unapproved/revoked/foreign PDF. Release hold: the Pi worker selects its tool catalogue at initialization before browser_open permits packet approval, so browser_upload is not correctly advertised/revoked per turn. No model-selected path or qualified end-user flow
Browser download quarantineExperimental, off in current buildsStandalone CDP and embedded host hooks quarantine bounded downloads as untrusted hash refs, never execute/import. Embedded local Electron fixture exercised download/capture, not a packaged or live-site file-safety proof
Application ledger and harmony jobsExperimental, off in current buildsSeparate jobs.applicationLedger.enabled: false; schema v9 dedup/recovery and missing-fact blocked → prepared only after packet approval. A 20-encounter local fixture produced 13 verified-page results, four blocks, one unknown, two duplicates and restarted from receipts. Production host confirmation artifact reader is not wired, so normal RPC cannot claim external submission
Editor / diff / file treePreview—
Auto-updatePreviewVerifies size and SHA-256 before applying
Agent memory (trust, scope, sensitive-content screen)ExperimentalExisting local fabric; scoped admission and sensitive screening. See persistent agents and memory
Persistent-agent identity, checkpoint save and activationExperimental, off in current buildspersistentAgents.enabled: false; disabled calls refuse. First-party Harmony Agent sealed-session exact resume is worker-validated and Desktop/TUI Open launches through the supervised path; validation failure offers a hash-pinned, new-session rehydration choice, never a silent switch. Third-party adapters cannot exact-resume. TUI Open starts a separate worker, not same-pane attachment; no live-provider/package proof
Save-time persistent-agent memory extractionExperimental, off in current buildsOpted-in save enqueues a separate retryable deterministic structural job after checkpoint commit; deferred on the save receipt is not memory completion
Persistent-agent forget, archive, delete and exportExperimental, off in current buildsScoped forget tombstones memory; delete needs separate confirmation; export is redacted and bounded. Neither deletes provider-native sessions
Persistent-agent caller authorityExperimental, off in current buildsPer-connection pipe identity plus verified first-party launch-handshake binder implemented; unbound calls fail closed, shared token alone is not an agent principal
Provider-native context on reopenExperimental, off in current buildsOptional root AGENTS.md/CLAUDE.md is bounded, hashed, labeled data in a new rehydrated worker only; daemon derives the root from a verified launch intent or one unambiguous same-workspace root, otherwise refuses. No provider-store import/export, credential scraping or exact third-party resume
Persistent-agent entitlement projectionExperimental, off in current buildsRead-only local_core/entitled/lapsed/unknown parity across local clients; no authenticated site grant reader is wired and it never gates local Core save/activate
TUI persistent-agent and browser controlsExperimental, off in current builds/save and scoped /agents picker/review use the gated service; /agents open launches a separate worker or asks before rehydration. `/browser status
Persistent-agent Cloud identity handoff and returnExperimental, off in current buildsOptional v2 agentId/filtered checkpoint/lineage; MAIN owner review, owner-scoped site incarnation import and HMAC-verified return code append a new local incarnation. Memory policy defaults none, selected admitted-scoped only; secrets, local-only/sensitive data and job packets never sync. No live provider/VM or packaged round-trip proof
Terminal Cloud status and handoffExperimental, off in current builds/cloud status and CLI harmony cloud status --json show observed site workspace state; agent task claim remains neutral without fresh evidence. Terminal handoff/return only previews and routes to Desktop owner review/Bring Home; no TUI/CLI identity transfer or HMAC verification
Cloud persistent-agent exact provider-session continuityPlannedA Cloud-side incarnation or identity card is not evidence of exact provider transcript resume or active Cloud agent execution
Website account and Harmony CloudPreviewSign-in, billing, hosted workspaces on this site
Cloud Command Center live activity and identity cardExperimental, off in current buildsAuthenticated workspace detail gains owner-scoped, read-only cursor-based live activity and an optional imported-identity receipt card behind existing Cloud and identity gates. Unknown/empty are explicit; no new remote controls, deployed index migration, live DB/provider or full site build proven
Website as installable web app (PWA)PreviewOptional; same account in a browser. Caches only a public offline document — never private jobs. Guide
Native iOS / Android appsPlannedIn development. Not an App Store or Play Store download. Account/workspace foundation exists in source; Account UI is not the shipping phone product
Code signingPlannedNo Authenticode or Developer ID signing yet
macOS packagingPreviewarm64 and x64 DMG targets; live availability comes from the release manifest
Linux packagingPreviewAppImage and DEB targets when the channel lists them. RPM is not v1

Persistent-agent gates

These persistent-agent rows describe code on the app feature branch, not features enabled in current builds. persistentAgents.enabled defaults to false; the separate memory fabric does not turn on save, Open, extraction or delete. activate can return a prepared, checkpoint-bound plan; Desktop/TUI Open now consumes it through the real supervised Harmony worker launch. Only that first-party runtime declares exact resume after a sealed-ref and worker-ready proof. On failure, the user must choose rehydration into a new session; a plan/offer alone is not an attached incarnation. The UI/worker fixture is not a complete packaged-provider journey.

The daemon can bind a per-connection identity to a first-party agent after a verified launch handshake. An unbound client still has no agent authority: a shared token or callerAgentId hint cannot make it one, and the handshake does not prove the socket's OS process on stock Node. Optional root project instructions enter only a labeled, bounded Harmony loader capsule from a daemon-verified root on explicit opt-in; no provider-native store is changed. The read-only entitlement state never gates local Core, and without a site grant reader cannot claim a verified remote grant. The agent-driven embedded browser still needs a separate default-off latch, explicit selection and a qualified host invoker; the visible browser surface proves none of them.

Browser agent and application limits

The closed tool set includes browser_open/browser_observe, browser_click/browser_type/browser_select/browser_scroll/browser_wait and gated browser_submit; default browser mode is off. An act needs an owned lease, newest element ref/generation, fresh DOM/screenshot and approval. A missing value returns NALA_RUNTIME_TOOL_MISSING_FACT, with no browser effect; a gated daemon source resolves only previously MAIN-approved packet revisions. Durable FactRequests/A2A notices and TUI/Desktop answers create draft packet revisions, not permission to type; MAIN approval restores a blocked application to prepared. Unanswered questions stay blocked. Page content is untrusted data. The Harness compiler quotes/hashes page/download/ clipboard fragments in its volatile inspector projection; Pi provider-wire serialization and model obedience are not established by that snapshot. Redacted browser lifecycle spans are durable in the existing activity ledger, with a bounded read projection not yet wired to the live UI.

submitArmed defaults false; Desktop has a field-diff review screen but production still lacks the host form/intent reader and armed gate. A flag edit alone cannot submit. Positive login/MFA/passkey/CAPTCHA signals hand control to a human; negative detection is no safety proof and never justifies bypass. Packet review and active binding exist, but browser_upload's worker catalogue is fixed too early for correct per-turn advertising/revocation. The separate, default-off ledger retains outcome_unknown without auto-retry and production has no host confirmation artifact reader for submitted_verified. A 20-case real-Chromium local fixture run is not real applications or employer acceptance. Real Electron offscreen fixture pixels/crash-notices now passed, but no assembled/onscreen release. See Harmony browser agent.

A note on the TUI

Earlier internal documentation described the TUI as never running a model turn. That was accurate when written and is no longer accurate. The current implementation creates a structured session, submits the prompt, and polls session events until the turn completes, with a substantial test suite behind it.

It is labelled Preview rather than Stable because it ships only in the preview channel and is changing quickly — not because it is a stub. On the app feature branch, /save and the interactive scoped /agents picker/review are default-off persistent-agent operations; /fleet, /agents fleet and Alt+A keep the live fleet. /agents open uses the supervised Open path; rehydration requires a separate choice, while the original TUI pane remains bound to its session. /browser operator RPC actions share the live lease and ApprovalService; Resume still needs host verification. /cloud status displays site workspace state and leaves unproven agent-task status neutral; /cloud handoff|return routes to Desktop review rather than transferring or verifying from the terminal. CLI harmony persistent-agents, harmony jobs and harmony cloud status --json do not enable a disabled service.

Known limitations

  • The Windows build is unsigned; SmartScreen will warn.
  • Platform artifacts vary by release channel; the live download page is authoritative and never offers an artifact omitted by the manifest.
  • Channel mentions route across workspaces on the same machine. Delivery to a peer machine over LAN Link is not implemented (define-only); a queued mention nudge is not a delivered receipt, which requires recipient acknowledgement.
  • Persistent-agent save/Open/extraction/privacy and both agent-browser backends remain off by default. Exact resume is validated only for Harmony's own Harmony runtime; Desktop/TUI Open now launches a separate supervised worker, with rehydration explicitly offered when exact fails. No provider-backed, same-pane TUI or packaged journey is proven. Native context is opt-in data, not a provider-store import; local Core does not depend on entitlement.
  • Browser act, packet review, download quarantine, missing-fact questions and the application ledger have landed in source, not as an enabled job workflow. Upload's static worker catalogue is not correctly refreshed per turn; submit remains disarmed without a production host intent/form reader; the ledger's production confirmation verifier is not wired. Fixture Electron/Chromium results do not qualify a full app or real applications.
  • An optional v2 Cloud identity handoff has MAIN owner review, site-side incarnation import and a signed return verifier behind independent OFF gates. Terminal commands route to Desktop rather than authorizing transfer; website live activity/identity is read only. No live Cloud provider/VM, deployed migration or packaged end-to-end persistent-agent continuity was proven. Website workspace presence alone is not agent execution.
  • Some orchestration modes are designed ahead of being proven end to end; treat anything labelled Experimental as unproven on your machine until you see it work.
  • The web app is not desktop feature parity. GitHub installation, push receipts, and first-party Harmony Cloud agents are not documented here as shipping phone features.