Feature status
What ships, what is preview, what is designed but unproven, and what is planned. The honest version.
Harmony is in active development and ships from a preview channel. This page records the state of each major subsystem so no page elsewhere has to imply it.
How to read the labels
| Label | Meaning |
|---|---|
| Stable | Shipping, supported, safe to rely on |
| Beta | Shipping and still changing |
| Preview | Ships in the preview channel only; not a stable release |
| Experimental | Present in the build, unproven end to end; may change or be removed |
| Planned | Not available in this release |
| Deprecated | Present, scheduled for removal |
| Platform-limited | Available on some platforms only |
The whole product is currently distributed as an unsigned developer preview. Nothing below should be read as a stability guarantee.
Subsystem status
| Subsystem | Status | Notes |
|---|---|---|
| Terminal multiplexer (panes, splits, workspaces) | Preview | The oldest and most exercised surface |
| Daemon-backed durable sessions | Preview | Sessions survive app close and reboot |
| Scrollback persistence | Preview | — |
| Desktop UI shell | Preview | — |
| Harmony TUI Agent | Preview | Runs real model turns; see the note below |
CLI (harmony …) | Preview | Broad subcommand surface |
| MCP server | Preview | Large tool surface published to MCP hosts |
| Provider launch (status bar) | Preview | Repeatedly repaired recently; verify on your machine |
| A2A messaging | Preview | Durable send/ask/reply/inbox |
| Channels | Preview | Same-machine cross-workspace mentions route within one daemon; peer-machine mention delivery over LAN Link is not shipped (define-only) |
| Tasks and artifacts | Preview | Daemon is the durable writer |
| Worktrees | Preview | — |
| Orchestration / Crew Mode | Experimental | Modes differ in how much is proven |
| Company mode (agent teams) | Experimental | Template-driven team provisioning |
| Voice dictation (Whisper) | Preview | Needs Python 3.10+ on PATH |
| Read Aloud (Kokoro TTS) | Preview | On-device after first model download |
| LAN Link (peer machines) | Experimental | Remote messages render as text only, never executed |
| Browser surface | Preview | Embedded Chromium plus a driven session; distinct from the gated agent backend below |
| Agent-driven embedded browser backend | Experimental, off in current builds | Requires browser.embeddedBackend.enabled (default false) to be explicitly enabled, embedded selection and an authenticated host invoker. Real Electron 44 offscreen/sandbox-on local fixture passed 38 checks incl. act/upload/download, authenticated guest-crash notice and tiled full-page pixels; not an assembled/onscreen app, atomic visual capture or independent OCR |
| Agent-driven standalone browser backend | Experimental, off in current builds | Explicit harmonyBrowser: 'standalone' selection; default mode is off. Popup denial, screenshot, teardown receipts and download quarantine are composed. A real sandboxed-Chromium 20-encounter local fixture dogfood passed, not real applications or full-app qualification |
| Agent browser open/observe/act | Experimental, off in current builds | Closed tools need an owned lease, latest element ref/generation, fresh DOM/screenshot and approval. The gated daemon packet resolver reads the exact active approved JobPacket: ordinary text facts and human answers only after revision approval. A select without a typed option asks; absent facts still refuse and create durable questions, not invented values. Redacted browser lifecycle spans append to the existing activity ledger; live UI read wiring remains open. See browser agent |
| Agent browser submit | Experimental, disarmed by default | Model-facing browser_submit refuses with submitArmed: false. Desktop now renders a masked pre-submit diff/approval screen for a pending request, but production still has no trusted current-form reader, host intent resolver or armed gate. Flipping the latch or seeing a modal cannot submit; a click/ticket is not external confirmation; login/MFA/CAPTCHA needs human takeover |
| Approved job packet and browser upload | Experimental, off in current builds | Desktop packet review, sender-validated MAIN and daemon active-packet binding are implemented; the executor refuses unapproved/revoked/foreign PDF. Release hold: the Pi worker selects its tool catalogue at initialization before browser_open permits packet approval, so browser_upload is not correctly advertised/revoked per turn. No model-selected path or qualified end-user flow |
| Browser download quarantine | Experimental, off in current builds | Standalone CDP and embedded host hooks quarantine bounded downloads as untrusted hash refs, never execute/import. Embedded local Electron fixture exercised download/capture, not a packaged or live-site file-safety proof |
Application ledger and harmony jobs | Experimental, off in current builds | Separate jobs.applicationLedger.enabled: false; schema v9 dedup/recovery and missing-fact blocked → prepared only after packet approval. A 20-encounter local fixture produced 13 verified-page results, four blocks, one unknown, two duplicates and restarted from receipts. Production host confirmation artifact reader is not wired, so normal RPC cannot claim external submission |
| Editor / diff / file tree | Preview | — |
| Auto-update | Preview | Verifies size and SHA-256 before applying |
| Agent memory (trust, scope, sensitive-content screen) | Experimental | Existing local fabric; scoped admission and sensitive screening. See persistent agents and memory |
| Persistent-agent identity, checkpoint save and activation | Experimental, off in current builds | persistentAgents.enabled: false; disabled calls refuse. First-party Harmony Agent sealed-session exact resume is worker-validated and Desktop/TUI Open launches through the supervised path; validation failure offers a hash-pinned, new-session rehydration choice, never a silent switch. Third-party adapters cannot exact-resume. TUI Open starts a separate worker, not same-pane attachment; no live-provider/package proof |
| Save-time persistent-agent memory extraction | Experimental, off in current builds | Opted-in save enqueues a separate retryable deterministic structural job after checkpoint commit; deferred on the save receipt is not memory completion |
| Persistent-agent forget, archive, delete and export | Experimental, off in current builds | Scoped forget tombstones memory; delete needs separate confirmation; export is redacted and bounded. Neither deletes provider-native sessions |
| Persistent-agent caller authority | Experimental, off in current builds | Per-connection pipe identity plus verified first-party launch-handshake binder implemented; unbound calls fail closed, shared token alone is not an agent principal |
| Provider-native context on reopen | Experimental, off in current builds | Optional root AGENTS.md/CLAUDE.md is bounded, hashed, labeled data in a new rehydrated worker only; daemon derives the root from a verified launch intent or one unambiguous same-workspace root, otherwise refuses. No provider-store import/export, credential scraping or exact third-party resume |
| Persistent-agent entitlement projection | Experimental, off in current builds | Read-only local_core/entitled/lapsed/unknown parity across local clients; no authenticated site grant reader is wired and it never gates local Core save/activate |
| TUI persistent-agent and browser controls | Experimental, off in current builds | /save and scoped /agents picker/review use the gated service; /agents open launches a separate worker or asks before rehydration. `/browser status |
| Persistent-agent Cloud identity handoff and return | Experimental, off in current builds | Optional v2 agentId/filtered checkpoint/lineage; MAIN owner review, owner-scoped site incarnation import and HMAC-verified return code append a new local incarnation. Memory policy defaults none, selected admitted-scoped only; secrets, local-only/sensitive data and job packets never sync. No live provider/VM or packaged round-trip proof |
| Terminal Cloud status and handoff | Experimental, off in current builds | /cloud status and CLI harmony cloud status --json show observed site workspace state; agent task claim remains neutral without fresh evidence. Terminal handoff/return only previews and routes to Desktop owner review/Bring Home; no TUI/CLI identity transfer or HMAC verification |
| Cloud persistent-agent exact provider-session continuity | Planned | A Cloud-side incarnation or identity card is not evidence of exact provider transcript resume or active Cloud agent execution |
| Website account and Harmony Cloud | Preview | Sign-in, billing, hosted workspaces on this site |
| Cloud Command Center live activity and identity card | Experimental, off in current builds | Authenticated workspace detail gains owner-scoped, read-only cursor-based live activity and an optional imported-identity receipt card behind existing Cloud and identity gates. Unknown/empty are explicit; no new remote controls, deployed index migration, live DB/provider or full site build proven |
| Website as installable web app (PWA) | Preview | Optional; same account in a browser. Caches only a public offline document — never private jobs. Guide |
| Native iOS / Android apps | Planned | In development. Not an App Store or Play Store download. Account/workspace foundation exists in source; Account UI is not the shipping phone product |
| Code signing | Planned | No Authenticode or Developer ID signing yet |
| macOS packaging | Preview | arm64 and x64 DMG targets; live availability comes from the release manifest |
| Linux packaging | Preview | AppImage and DEB targets when the channel lists them. RPM is not v1 |
Persistent-agent gates
These persistent-agent rows describe code on the app feature branch, not
features enabled in current builds. persistentAgents.enabled defaults to
false; the separate memory fabric does not turn on save, Open, extraction or
delete. activate can return a prepared, checkpoint-bound plan; Desktop/TUI
Open now consumes it through the real supervised Harmony worker launch.
Only that first-party runtime declares exact resume after a sealed-ref and
worker-ready proof. On failure, the user must choose rehydration into a new
session; a plan/offer alone is not an attached incarnation. The UI/worker
fixture is not a complete packaged-provider journey.
The daemon can bind a per-connection identity to a first-party agent after a
verified launch handshake. An unbound client still has no agent authority:
a shared token or callerAgentId hint cannot make it one, and the handshake
does not prove the socket's OS process on stock Node. Optional root project
instructions enter only a labeled, bounded Harmony loader capsule from a
daemon-verified root on explicit opt-in; no provider-native store is changed.
The read-only entitlement state never gates local Core, and without a site
grant reader cannot claim a verified remote grant. The agent-driven
embedded browser still needs a separate default-off latch, explicit selection
and a qualified host invoker; the visible browser surface proves none of them.
Browser agent and application limits
The closed tool set includes browser_open/browser_observe,
browser_click/browser_type/browser_select/browser_scroll/browser_wait
and gated browser_submit; default browser mode is off. An act needs an
owned lease, newest element ref/generation, fresh DOM/screenshot and approval.
A missing value returns NALA_RUNTIME_TOOL_MISSING_FACT, with no browser
effect; a gated daemon source resolves only previously MAIN-approved packet
revisions. Durable FactRequests/A2A notices and TUI/Desktop answers create
draft packet revisions, not permission to type; MAIN approval restores a
blocked application to prepared. Unanswered questions stay blocked. Page
content is untrusted data. The Harness compiler quotes/hashes page/download/
clipboard fragments in its volatile inspector projection; Pi provider-wire
serialization and model obedience are not established by that snapshot.
Redacted browser lifecycle spans are durable in the existing activity ledger,
with a bounded read projection not yet wired to the live UI.
submitArmed defaults false; Desktop has a field-diff review screen but
production still lacks the host form/intent reader and armed gate. A flag edit
alone cannot submit. Positive login/MFA/passkey/CAPTCHA signals hand control to
a human; negative detection is no safety proof and never justifies bypass.
Packet review and active binding exist, but browser_upload's worker catalogue
is fixed too early for correct per-turn advertising/revocation. The separate,
default-off ledger retains outcome_unknown without auto-retry and production
has no host confirmation artifact reader for submitted_verified. A 20-case
real-Chromium local fixture run is not real applications or employer
acceptance. Real Electron offscreen fixture pixels/crash-notices now passed,
but no assembled/onscreen release. See
Harmony browser agent.
A note on the TUI
Earlier internal documentation described the TUI as never running a model turn. That was accurate when written and is no longer accurate. The current implementation creates a structured session, submits the prompt, and polls session events until the turn completes, with a substantial test suite behind it.
It is labelled Preview rather than Stable because it ships only in the
preview channel and is changing quickly — not because it is a stub. On the app
feature branch, /save and the interactive scoped /agents picker/review are
default-off persistent-agent operations; /fleet, /agents fleet and
Alt+A keep the live fleet. /agents open uses the supervised Open path;
rehydration requires a separate choice, while the original TUI pane remains
bound to its session. /browser operator RPC actions share the live lease and
ApprovalService; Resume still needs host verification. /cloud status displays
site workspace state and leaves unproven agent-task status neutral;
/cloud handoff|return routes to Desktop review rather than transferring or
verifying from the terminal. CLI harmony persistent-agents, harmony jobs and
harmony cloud status --json do not enable a disabled service.
Known limitations
- The Windows build is unsigned; SmartScreen will warn.
- Platform artifacts vary by release channel; the live download page is authoritative and never offers an artifact omitted by the manifest.
- Channel mentions route across workspaces on the same machine. Delivery to a peer machine over LAN Link is not implemented (define-only); a queued mention nudge is not a delivered receipt, which requires recipient acknowledgement.
- Persistent-agent save/Open/extraction/privacy and both agent-browser backends remain off by default. Exact resume is validated only for Harmony's own Harmony runtime; Desktop/TUI Open now launches a separate supervised worker, with rehydration explicitly offered when exact fails. No provider-backed, same-pane TUI or packaged journey is proven. Native context is opt-in data, not a provider-store import; local Core does not depend on entitlement.
- Browser act, packet review, download quarantine, missing-fact questions and the application ledger have landed in source, not as an enabled job workflow. Upload's static worker catalogue is not correctly refreshed per turn; submit remains disarmed without a production host intent/form reader; the ledger's production confirmation verifier is not wired. Fixture Electron/Chromium results do not qualify a full app or real applications.
- An optional v2 Cloud identity handoff has MAIN owner review, site-side incarnation import and a signed return verifier behind independent OFF gates. Terminal commands route to Desktop rather than authorizing transfer; website live activity/identity is read only. No live Cloud provider/VM, deployed migration or packaged end-to-end persistent-agent continuity was proven. Website workspace presence alone is not agent execution.
- Some orchestration modes are designed ahead of being proven end to end; treat anything labelled Experimental as unproven on your machine until you see it work.
- The web app is not desktop feature parity. GitHub installation, push receipts, and first-party Harmony Cloud agents are not documented here as shipping phone features.