Skip to main content

Glossary

PreviewAvailable on: WindowsmacOSLinuxShips in the preview channel only. Not a stable release.

Canonical definitions, with the distinctions that matter kept sharp.

Terms are grouped by what they belong to. Where two terms are commonly conflated, the difference is stated rather than implied.

Four distinctions to get right first

IMPORTANT

A terminal is not an agent. A pane can run a plain shell forever with no model involved.

Installed is not authenticated. Harmony can detect a provider binary and still be unable to run a turn.

Queued is not delivered. A message can reach a harness and never start a turn.

Process alive is not working. An agent can hold a session open and advance nothing.

Product

TermDefinition
HarmonyThe product as a whole: desktop, TUI, CLI, daemon, and MCP server
Harmony DesktopThe Electron application — the full-surface client
Harmony TUIThe terminal-native agent surface, started with nala; its real model turns do not imply browser act authority
Harmony CLIScriptable, non-interactive commands against the same daemon
Harmony AgentThe first-party agent identity, as distinct from third-party providers. Its provider id is still nala-agent, and the Harmony TUI that hosts it still launches with nala, the product's original name
PiThe extensibility runtime bundled with the product

Runtime

TermDefinition
DaemonThe local process that owns durable state: sessions, orchestration, tasks, artifacts, A2A, channels. Survives app close
Session hostOwns provider processes and PTYs, plus launch reservations and principal registration
ClientAnything presenting the daemon's state — desktop, TUI, CLI. Closing a client does not stop work
Native Capability BusThe capability layer clients use to reach daemon functionality
PrincipalA registered identity a session runs as
Writer leaseThe mechanism deciding which participant may write a shared record

Workspace model

TermDefinition
WorkspaceA named context with its own pane tree, working directory, and status
SurfaceA tab within a workspace: terminal, browser, editor, diff, file tree, or a Harmony panel
PaneA leaf in the split tree. Max 20 per workspace
Terminal sessionA durable shell owned by the daemon, rendered in a pane

Agents and routes

TermDefinition
AgentA model-driven participant that can take work
Agent sessionA durable conversation with an agent
ProviderThe vendor behind an agent CLI (Claude, Codex, Cursor, …)
Account profileWhich of your identities with a provider is in use
ModelThe specific model requested
EffortReasoning depth, where the provider exposes it
Execution routeThe full path: harness, provider, account, model, effort, tool set, platform, billing class
Billing classWhose money is spent, under which plan
HarnessThe agent program being driven

Work

TermDefinition
TaskA durable unit of work with an identity and a state. Outlives panes and reboots
PlanA proposed sequence of steps toward a goal
Plan revisionA numbered version of a plan; revisions are kept
Orchestration runOne execution attempt of a plan
ArtifactA durable Markdown output attached to the work
WorktreeA separate git checkout so parallel agents do not collide. File isolation, not a security boundary
DelegationAn edge assigning a task to another agent

Messaging

TermDefinition
A2AAgent-to-agent messaging: send, ask, reply, inbox
ChannelA durable, Slack-like room for agents and humans
AttentionThe signal that something needs a human
ApprovalAn explicit consent gate before a consequential action

Delivery states

The real states Harmony reports, not a generic lifecycle:

StateMeans
received_and_startedThe agent is working on a turn. The only state where started is true
queued_behindAccepted into the harness queue, with N ahead
received_not_startedText delivered, no work signal yet
idleAt the prompt, queue empty
needs_enterStaged in the composer, needs another Enter
unknownCould not be determined from available evidence

See delivery lifecycle.

Persistence and memory

These terms describe an agent outliving its session. Each mechanism is independent — identity, provider session, checkpoint, and memory are four things, not one — and the labels match persistent agents and memory and feature status exactly.

TermDefinition
Persistent agentA durable Harmony identity — identity plus a frozen checkpoint — that can be reactivated later. The persistentAgents.enabled gate is off in current builds (the surface refuses with NALA_CAPABILITY_UNSUPPORTED). Not a provider login, not "this exact AI is preserved"
CheckpointA frozen, integrity-checked snapshot of workspace and session state taken at save time. Not the live process, and not its scrollback
IncarnationOne recorded run of the same persistent agent. Opening a validated Harmony session or starting a newly rehydrated worker appends a local incarnation; a verified Cloud return appends another, never a copy or a duplicate and never an overwrite. A Cloud import receipt alone is not proof of a running provider
Prepared activationThe activate API's bounded, checkpoint-bound plan, not by itself a running worker or a new incarnation. Desktop/TUI Open now consumes this plan through a daemon-owned supervised launch; a fallback offer starts no worker until the user explicitly chooses rehydration
RehydrateWith an explicit user choice, start a new supervised Harmony worker from the latest checkpoint and admitted, same-agent memories as bounded labeled loader data, never a fake user message. A prepared/declined offer starts none. Distinct from exact resume and provider /resume
Exact resumeContinue the same Harmony Agent Pi transcript only after Harmony validates a sealed file/path/hash/SDK-session/journal watermark and the real spawned worker opens it and returns a matching ready proof. Desktop/TUI Open uses it when proven; a failure offers, never silently switches to, rehydration. Third-party adapters remain rehydrate-only; a separate TUI worker is not same-pane attachment
Host-derived trustWhether a caller may store or recall is decided by the daemon from its own agent and session registry — never from a flag in a request, a hint on the wire, or the model's own say-so. Content an agent reads is data, not permission
Connection-bound agentA pipe socket bound to one agent after a daemon-verified first-party launch handshake (nonce, intent/session and live-process checks). A shared token alone leaves it unbound; a wire caller hint is not proof. Stock Node does not attest the socket's OS process
Agent-driven embedded browserRequires default-off browser.embeddedBackend.enabled, explicit embedded selection and an authenticated host invoker; distinct from the ordinary browser pane. Real Electron 44 offscreen/sandbox-on local fixture exercised act/upload/download, guest-death notice over the authenticated daemon pipe and tiled full-page pixels (38/38); no packaged or independent visual/OCR release proof
Provider-native context fragmentDefault-off root AGENTS.md/CLAUDE.md opt-in, bounded/hashed untrusted-user-authored loader data only for rehydration. The daemon derives a verified launch-intent workspace root or refuses ambiguity; no provider-native session/memory import, credential read or model obedience guarantee
Persistent-agent entitlement stateRead-only local-client projection of local_core, entitled, lapsed or unknown. No site grant reader is wired here; this status never gates local Core save/activate or erases on lapse
TUI persistent-agent commands/save and scoped /agents picker/review are default-off; /agents open now launches an exact resumed separate worker or explicitly asks before rehydration, never silently rebinds the active pane. /fleet, /agents fleet and Alt+A keep the live fleet; /browser operator RPC is live only when bound and enabled, and Resume still needs host verification
Persistent-agent Cloud identity blockOptional, default-OFF v2 stable agentId, filtered portable checkpoint and incarnation lineage. MAIN owner review, idempotent site-side incarnation import and site-HMAC-verified return can append a new local incarnation; memory defaults none and selected admitted-scoped only. A stored identity is not exact provider resume or an active Cloud worker
Cloud handoff continuitySame agent ID/checkpoint/lineage crosses only after Desktop owner review and independent Cloud+identity gates. No provider sessions/credentials, secret/local-only/sensitive/global/pending memory, job packets or full transcript cross; return appends after HMAC verification, never overwrites. Terminal `/cloud handoff
Cloud activity and identity cardOwner-scoped, read-only recent site workspace events and optional imported-incarnation receipt behind default-off Cloud/identity gates; unknown/absent is not a completed task or a resumed provider. The event cursor and DB index still need deployed-site qualification

Memory states

The states a save receipt reports for memory work, rendered verbatim. A staged candidate is not admitted memory:

StateMeans
not_startedExtraction has not started; on an extract-mode save, independent job enqueue was not confirmed and can be retried/reconciled
deferredNo completed memory result on this receipt: defer mode schedules no job now, while a successful extract enqueue has a separate durable job for later work
not_applicableThe checkpoint-only path; no memory work by design
unknownAn unrecognized state. Rendered as-is, never presented as success

There is deliberately no "queued" or "complete" memory state on a save receipt. Owner-scoped inspect reports job states (queued, leased, retry_wait, complete, abandoned) and redacted disposition counts separately. A completed job can admit zero memories. The extractor is structural, deterministic and uses no model call; retained external candidates remain review-required, while host-verified explicit user evidence may be admitted after policy checks.

Privacy and retention

TermDefinition
Forget memorynala.memory.forget tombstones one owned persistent-agent memory, excludes it from future daemon recall and advances a durable cache epoch. It cannot retract context already delivered to a model or erase backups
Archive agentHides an agent from active selectors while preserving its identity, checkpoints, incarnations and memory
Delete agentA separate workspace-bound confirmation token is required (not independent proof of a human click); confirmed deletion scrubs Harmony-owned checkpoints/incarnations and denies/scrubs the agent memory bank, leaving a minimal audit marker. A lapse does not delete, and provider-native session files are not removed
Export agentA bounded, redacted bundle of Harmony-owned identity, checkpoints and eligible memory with integrity hashes. Forgotten memory, credentials and provider-native session files are excluded; import/restore is not implemented

Browser-agent and job evidence

The Harmony browser agent page separates landed, default-off browser actions, packet/quarantine and ledger code from a real end-to-end application workflow, which is not available. A capability approval is not external confirmation.

TermDefinition
Agent browserVerified-session, approval-checked browser tools, default mode off; distinct from an ordinary browser surface. Standalone needs explicit selection; embedded also needs a separate default-off latch and qualified host invoker
Browser surface leaseDaemon-owned, time-limited receipt tying the actual target to a launch/session/principal/workspace/task (and verified embedded pane), not a page-chosen tab. Transitions are durably journaled; physical closure says confirmed only after backend ACK and otherwise awaits repair
Untrusted page observationBounded DOM and element refs framed as untrusted-page data with provenance/hash, never an instruction or grant to act. Standalone and real-Electron fixture embedded CDP screenshots pair to a DOM hash; visual-text agreement is still unassessed. Harness quotes/hashes page/download/clipboard fragments in an inspector projection, not yet Pi's provider-wire constructor
Observation generation tokenShort-lived token tied to one lease/surface/DOM observation; each act/upload needs its latest opaque element ref, fresh DOM, paired screenshot and separate approval. A stale token, changed page, forged ref or missing evidence refuses; a token alone is not authority
User fact packetHost-verified scope/origin-bound allowlist for type/select valueId; the model sends no raw field/selector/JS. A gated daemon resolver reads only the active approved JobPacket: ordinary text facts and answered revisions after approval, not arbitrary or model-invented facts. Missing values still refuse NALA_RUNTIME_TOOL_MISSING_FACT, do no browser effect and require a human answer/new packet approval; backend selection alone is not permission
FactRequestA restart-durable, owner/application/field/origin-bound missing-fact question with A2A notice; queued is not delivered. Human TUI/Desktop answers create a draft JobPacket revision with who/when provenance; MAIN-reviewed approval, not the answer alone, permits fresh-observation retry. Unanswered stays blocked
Human browser takeoverPositive login/credential/passkey/MFA/CAPTCHA heuristics block agent browser calls and hand the live lease to a human; negative detection proves nothing and never justifies bypass. /browser handoff uses a bound operator RPC; Resume requires independent host-verified local-user proof, not a typed command. Without a runtime pause callback only browser tools pause
Submit gatebrowser_submit refuses with default submitArmed: false. Desktop has a redacted pre-submit review of a pending gate request, but production still lacks the trusted current-form/intent reader and armed gate, so a flag edit or modal alone cannot submit. An armed local fixture still needs host intent, fresh diff/approval and deny/kill policy; a ticket/click is not an external receipt
Approved job packetContent-addressed facts/provenance and reviewed PDF. Desktop/MAIN/daemon can approve/revoke and bind an active packet; executor refuses unapproved/revoked/foreign files. Release hold: worker's browser_upload catalogue is static at initialization before the packet becomes active, so per-turn advertisement/revocation is not solved. Page text cannot approve or invent a fact
Download quarantinePer-session host-controlled allowlist for PDF/text/CSV downloads; size/MIME/hash checked, bytes never executed or promoted to memory. The model sees only untrusted-download hash refs, not paths or trusted content
Application ledgerImplemented under jobs.applicationLedger.enabled: false (schema v9, nala.jobs.*, read-only harmony jobs): canonical HTTPS job identity, dedup, state/evidence and restart receipts, not a browser submit engine or general memory
Verified submissionsubmitted_verified requires host-matched owner-scoped confirmation observation after an authorized attempt. Production jobs RPC lacks the host approval/confirmation artifact verifier, so it cannot normally mint this verdict; observed page confirmation is not independent employer acceptance
Outcome unknownA durable ambiguous attempt (outcome_unknown), not a successful application and never automatically retried; human reconciliation or fresh verified confirmation is required
Browser lifecycle spanClosed redacted navigate/settle/act/upload/download/handoff/deny event in the existing activity ledger, with bounded scoped read projection. Not an external success receipt; live UI reader still unwired

Extensibility

TermDefinition
SkillA packaged capability an agent can invoke
CommandA slash command in the TUI or desktop composer
PromptReusable instruction text
ExtensionCode extending the application
PluginA packaged extension
HookA handler fired on a lifecycle event
MCPModel Context Protocol — Harmony publishes tools to MCP hosts
ACPAgent Client Protocol — Harmony can drive external ACP harnesses

SECURITY

Extensions, skills, and plugins are not sandboxed by default. Treat third-party extension code as code you are choosing to run.

Modes

TermDefinition
Safe / YOLO / AskExecution modes governing how much an agent may do unprompted
A2A modeOff, Connect, or Orchestrate — how much agents may coordinate
Crew ModeOwnership-scale delegation, separate from the YOLO authority setting. Experimental; see feature status