the harness of harnesses
Every tool you own, under an agent.Every agent, inside a shape you drew.
FireFunc harnesses the coding agents you already have — Claude Code, Codex, Cursor, Gemini — on machines you already own, under subscriptions you already pay for. You specify an agent in six decisions. Then you stop touching it.
your machines · your subscription · no token markup
the harness
enrich · check · match
one agent declared this trigger
5 held · 1 through
your network
- Jiraa ticket gained the label ready-for-dev
- heldbelow the confidence floor — released by a person
- Figmaread the frame live: spacing, fill, type
- builtthe screen on a machine we do not own
- ranthe test suite — 42 passed
- openeda pull request
- Jirawrote the link back on the ticket
where it ran
alis-mbp
claude code · your plan
Nothing merged. Auto-merge stays off until you turn it on.
FIG 01
Connected once, at the top
Every tool your company runs is authorised once at the organisation, lent to the workspaces that need it, and bound by the projects that use it. Nobody pastes a key into a project.
FIG 02
One condition wakes one agent
An agent is a specification, not a prompt: one trigger, the tools you ticked read or write, the skills it carries, bounds it cannot leave. Everything else is ignored, not queued.
FIG 03
The engine runs inside your line
Claude Code, Codex, Cursor and Gemini run where you installed them, on the plan you already pay for. Your repository, your working tree and the session transcript stay there. What crosses the line is the summary, a redacted step trail, and the pull request.
01the morning · 09:14
Nothing is on fire. Everything is waiting.
More arrived this morning than the room can read. A ticket that needs one file changed. An error nobody has opened. A review with three comments on it. None of it is hard, and none of it is moving — nobody here is slow, they are just unhelped.
At eleven the rules land. The same six tools send the same work, but now each thing meets an agent that declared it. One item matches nothing and is held, with the reason and the fix.
An illustration of one working day. Not customer data.
02a few clicks, once
Connect it once, at the top.
Six are connected and proven. The rest is the direction, not a dated promise.
03four answers
An agent is a specification, not a prompt.
Starts when. Works in. Delivers. How it runs. Four answers, asked in that order, and nothing activates until all four are given — which is the only reason the next one can be left alone.
Watch the fourth line of step three. A deliverable can be another agent’s trigger, so when this one finishes, the next one starts on its own, with no person in between.
1Starts whenset
One condition, named. Everything else is ignored, not queued.
2Works inset
One repository, and only the tools you ticked — reads and writes separately.
3Deliversset
What it must produce — and which agent takes it from there.
4How it runsset
Your engine, your machine, and the ceiling it may not cross.
Ticket → featureactive
on label ready-for-dev · orders-console · Claude Code on ci-box-01
wokeFPG-114 gained the label ready-for-dev
readthe ticket, and src/orders/table.tsx
changed3 files, 84 lines, on ci-box-01
openeda pull request
Review → revisionstarted by the agent above
on pull request · review requested · same repository, second machine
readingthree review comments on #482
A deliverable can be another agent’s trigger. That is the whole of the chain.
Four answers, one agent — and a deliverable that is another agent's trigger.
0407:02 · unattended
The condition you wrote is met. Nobody presses anything.
- Jiraget issue FPG-114 · acceptance criteria
- readsrc/orders/table.tsx
- readsrc/orders/use-orders.ts
- wrote3 files, 84 lines
- ranthe test suite — 42 passed
- openeda pull request
- Jiracommented, and moved it to In Review
your machine
alis-mbp · claude code
Your own subscription does the thinking. There is no inbound port — the runner dials out — and the work happens in a throwaway worktree off a clean branch.
A pull request, waiting for review
Nothing merged. Auto-merge is off until you turn it on.
The file, the diff and the transcript stay on the machine. A summary and a link come back.
05the best thing it does
An agent that will do anything is not autonomous. It is unattended.
- readthe spec
- Figmaget node 42:1130
- wrotea component
- readthe tokens file
- figma · use_figma
Denied by name — that tool was not granted
What you did not grant is never offered to the run at all, and the tools that would destroy something are denied by name rather than merely left off a list — because leaving a tool out is not the same as forbidding it.
And the run itself was held
Confidence at intake was below this agent’s minimum.
Open the item and choose Run it anyway, or lower the floor in the agent’s guardrails.
Every refusal says two things: the reason, and the fix.
06the same twenty seconds, twice
Many agents. Many repositories. At the same time.
Six pieces of work, three projects, three repositories, three machines your team registered — all moving together. Nothing is queued behind anything else, and adding a machine adds capacity without you rerouting a thing.
The lower board is the same six, taken one at a time. When the clock runs out, four of them have not started.
Both boards run the same twenty seconds, and the same six pieces of work.
0717:20 · the last switch is yours
By twenty past five, the queue is a reading list.
FPG-114 · pagination on the orders tableTicket → feature
- readJira FPG-114 · acceptance criteria
- readsrc/orders/table.tsx
- changed3 files, 84 lines
- openeda pull request, on alis-mbp
Send it back with a note, and the agent reads it
A correction is an instruction, not a complaint — it is picked up on the next run.
Nothing merges because an agent said so.
08Counted, not claimed
Every number here is read out of the code that defines it.
22
agent templates
each one a whole agent — trigger, grants, skills, deliverables
7
engines
four command-line agents and three cloud paths
6
tools live
GitHub, Jira, Linear, Sentry, Figma, Slack — proven end to end
64
permissions
four org roles, five workspace roles, resolved as a union
10
curated skills
files an agent carries into every single run
Connect one tool. Specify one agent. Then stop watching it.
Connect a tool with OAuth at your organisation. Lend it to a workspace. Start from one of the shipped templates or from nothing at all. Make six decisions. Install the runner on a machine you already own. From then on it is autonomous inside a shape you drew.
npm install -g @firefunc-agent/runner
firefunc-runner connect <token>
firefunc-runner install
Autonomous inside a shape you drew.
start
Autonomous inside a shape you drew.
Connect one tool. Install the runner on a machine you already trust. Specify one agent in six decisions. Then stop watching it — and if it holds back, it will tell you the reason and the fix.