Managed Agents / Contract
What you can rely on
The short version of the managed runtime contract: where your code and data run, how keys are handled, and what happens when something fails.
The same harness, operated for you
Managed Agents is the hosted composition of the open-source Acyclic harness. It adds managed capacity, deployment, recovery operations and organization controls. It does not introduce a separate agent loop, and nothing about forking, recursion or durable execution is reserved for the hosted version.
You connect with the normal harness API, admit tasks and observe their handles. The CLI is sugar over that API, so anything it does your own code can do.
Placement and data boundaries
The agent loop, tools, memory, files and models can live in different places. A private-network tool can stay in your environment while independent tasks run on hosted sandboxes, or the sandboxes themselves can run in your cloud account.
Placement requirements state which resources and trust domains a task can reach. A connection never authorizes data movement on its own. Tenant isolation and grant enforcement are done by the host and cannot be replaced by customer plugins.
Keys and secrets
- Provider keys and other secrets are supplied as scoped references through host configuration, never pasted into prompts.
- Secrets stay in host-managed bindings, outside model context and outside serialized task state.
- Usage is attributed per task from the provider's own receipts, so what you see per session matches what your provider bills.
Continuation and recovery
Resumable components continue from recorded boundaries after host loss. Work that only exists live in a process is not made durable just by being hosted; it needs a supported checkpoint or an explicit restart, and the host tells you which.
Cancellation is a request, observation can reconnect, and ambiguous side effects are surfaced for reconciliation rather than silently retried. The host reports expired references, incompatible code versions and unsupported recovery instead of restarting from scratch.
What is published once measured
Capacity limits, prices and service guarantees are not published until they are measured. While we onboard teams, swarms run on real provider receipts with no managed-service charge, and the rate card is set with the first teams on it.