Skip to main content
Glama

Dispatch a Harness run

start_run
Destructive

Create or reuse a Harness session, configure model, reasoning, agent and permission presets, then submit the first path-referenced task and get a stable session link to track it.

Instructions

Create or reuse a native Harness session, select provider/model/reasoning, agent preset, and native permission preset, then submit the first task and return a stable session link. Task parameters are path-reference-only: provide the authorized workspace, reviewTargets, contextReadScope, excludedPaths, writeScope, and acceptance criteria. reviewTargets identify what to assess; they are not a read whitelist. contextReadScope declares where Harness may search and read supporting implementation, tests, configuration, and architecture material. Never embed source text, diffs, file dumps, encoded source, or repository archives. Harness reads named files from the authorized workspace itself. These fields are task instructions, not enforced per-path filesystem isolation. The selected Harness model may send content it reads to its configured model provider even though Relay itself uses a loopback address. Sharing webUrl is not completion: keep wait_run until a terminal status, then consume assistantText.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
taskNoTask parameters are path-reference-only: provide the authorized workspace, reviewTargets, contextReadScope, excludedPaths, writeScope, and acceptance criteria. reviewTargets identify what to assess; they are not a read whitelist. contextReadScope declares where Harness may search and read supporting implementation, tests, configuration, and architecture material. Never embed source text, diffs, file dumps, encoded source, or repository archives. Harness reads named files from the authorized workspace itself. These fields are task instructions, not enforced per-path filesystem isolation. The selected Harness model may send content it reads to its configured model provider even though Relay itself uses a loopback address.
modelNo
contentNoTask parameters are path-reference-only: provide the authorized workspace, reviewTargets, contextReadScope, excludedPaths, writeScope, and acceptance criteria. reviewTargets identify what to assess; they are not a read whitelist. contextReadScope declares where Harness may search and read supporting implementation, tests, configuration, and architecture material. Never embed source text, diffs, file dumps, encoded source, or repository archives. Harness reads named files from the authorized workspace itself. These fields are task instructions, not enforced per-path filesystem isolation. The selected Harness model may send content it reads to its configured model provider even though Relay itself uses a loopback address.
providerNo
sessionIdNo
workspaceYesAuthorized absolute Harness workspace root; Harness reads named in-scope files from here.
writeScopeNoPaths Harness may modify. Must be empty for read-only runs; this is an instruction declaration in addition to native permissions.
agentPresetNo
openBrowserNoKeep false unless the user explicitly asks to open the Harness page in the OS browser.
sessionModeNo
excludedPathsNoPaths excluded from contextual reading. This is an instruction declaration, not filesystem enforcement.
reviewTargetsNoSubjects to assess. This is not a read whitelist; supply together with contextReadScope.
idempotencyKeyNo
reasoningEffortNo
contextReadScopeNoWorkspace paths Harness may search and read for evidence. Use only the targets when the user explicitly requests a target-only review.
permissionPresetNo
authorizationBasisNoTruthful evidence that the user explicitly selected Harness or this named Harness model to inspect the stated workspace scope. The current explicit request is sufficient authorization for that selected provider to process in-scope reads; do not ask the user to repeat authorization solely because provider processing is external. This field does not broaden the workspace, scope, permissions, destination, or allowed external actions.
confirmedDangerousPermissionNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed1 schema field changedv0.2.17
    • changedInput schema / properties / authorizationBasis / description
      Previous value: -"Truthful evidence that the user explicitly selected Harness to inspect this workspace. Set only when the current conversation contains that instruction. This records evidence and does not expand permissions or guarantee approval."New value: +"Truthful evidence that the user explicitly selected Harness or this named Harness model to inspect the stated workspace scope. The current explicit request is sufficient authorization for that selected provider to process in-scope reads; do not ask the user to repeat authorization solely because provider processing is external. This field does not broaden the workspace, scope, permissions, destination, or allowed external actions."
  2. Changed9 schema fields changedv0.2.13
    • addedInput schema / properties / authorizationBasis
      Added value: +{
      +  "const": "explicit-user-request",
      +  "description": "Truthful evidence that the user explicitly selected Harness to inspect this workspace. Set only when the current conversation contains that instruction. This records evidence and does not expand permissions or guarantee approval.",
      +  "type": "string"
      +}
    • changedInput schema / properties / content / description
      Previous value: -"Task parameters are path-reference-only: provide the authorized workspace, file or directory locations, scope, and acceptance criteria. Never embed source text, diffs, file dumps, encoded source, or repository archives. Harness reads named files from the authorized workspace itself. This rule is identical for read-only and write-capable permissions."New value: +"Task parameters are path-reference-only: provide the authorized workspace, reviewTargets, contextReadScope, excludedPaths, writeScope, and acceptance criteria. reviewTargets identify what to assess; they are not a read whitelist. contextReadScope declares where Harness may search and read supporting implementation, tests, configuration, and architecture material. Never embed source text, diffs, file dumps, encoded source, or repository archives. Harness reads named files from the authorized workspace itself. These fields are task instructions, not enforced per-path filesystem isolation. The selected Harness model may send content it reads to its configured model provider even though Relay itself uses a loopback address."
    • changedInput schema / properties / content / items / oneOf
      Previous value: -[
      -  {
      -    "properties": {
      -      "text": {
      -        "description": "Task parameters are path-reference-only: provide the authorized workspace, file or directory locations, scope, and acceptance criteria. Never embed source text, diffs, file dumps, encoded source, or repository archives. Harness reads named files from the authorized workspace itself. This rule is identical for read-only and write-capable permissions.",
      -        "maxLength": 100000,
      -        "type": "string"
      -      },
      -      "type": {
      -        "const": "text",
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "type",
      -      "text"
      -    ],
      -    "type": "object"
      -  },
      -  {
      -    "properties": {
      -      "data": {
      -        "minLength": 1,
      -        "type": "string"
      -      },
      -      "mediaType": {
      -        "enum": [
      -          "image/png",
      -          "image/jpeg",
      -          "image/webp",
      -          "image/gif"
      -        ],
      -        "type": "string"
      -      },
      -      "name": {
      -        "type": "string"
      -      },
      -      "type": {
      -        "const": "image",
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "type",
      -      "mediaType",
      -      "data"
      -    ],
      -    "type": "object"
      -  }
      -]New value: +[
      +  {
      +    "properties": {
      +      "text": {
      +        "description": "Task parameters are path-reference-only: provide the authorized workspace, reviewTargets, contextReadScope, excludedPaths, writeScope, and acceptance criteria. reviewTargets identify what to assess; they are not a read whitelist. contextReadScope declares where Harness may search and read supporting implementation, tests, configuration, and architecture material. Never embed source text, diffs, file dumps, encoded source, or repository archives. Harness reads named files from the authorized workspace itself. These fields are task instructions, not enforced per-path filesystem isolation. The selected Harness model may send content it reads to its configured model provider even though Relay itself uses a loopback address.",
      +        "maxLength": 100000,
      +        "type": "string"
      +      },
      +      "type": {
      +        "const": "text",
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "type",
      +      "text"
      +    ],
      +    "type": "object"
      +  },
      +  {
      +    "properties": {
      +      "data": {
      +        "minLength": 1,
      +        "type": "string"
      +      },
      +      "mediaType": {
      +        "enum": [
      +          "image/png",
      +          "image/jpeg",
      +          "image/webp",
      +          "image/gif"
      +        ],
      +        "type": "string"
      +      },
      +      "name": {
      +        "type": "string"
      +      },
      +      "type": {
      +        "const": "image",
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "type",
      +      "mediaType",
      +      "data"
      +    ],
      +    "type": "object"
      +  }
      +]
    • addedInput schema / properties / contextReadScope
      Added value: +{
      +  "description": "Workspace paths Harness may search and read for evidence. Use only the targets when the user explicitly requests a target-only review.",
      +  "items": {
      +    "description": "Workspace-relative path, or an absolute path contained by the authorized workspace.",
      +    "minLength": 1,
      +    "type": "string"
      +  },
      +  "minItems": 1,
      +  "type": "array"
      +}
    • addedInput schema / properties / excludedPaths
      Added value: +{
      +  "description": "Paths excluded from contextual reading. This is an instruction declaration, not filesystem enforcement.",
      +  "items": {
      +    "description": "Workspace-relative path, or an absolute path contained by the authorized workspace.",
      +    "minLength": 1,
      +    "type": "string"
      +  },
      +  "type": "array"
      +}
    • addedInput schema / properties / openBrowser / description
      Added value: +"Keep false unless the user explicitly asks to open the Harness page in the OS browser."
    • addedInput schema / properties / reviewTargets
      Added value: +{
      +  "description": "Subjects to assess. This is not a read whitelist; supply together with contextReadScope.",
      +  "items": {
      +    "description": "Workspace-relative path, or an absolute path contained by the authorized workspace.",
      +    "minLength": 1,
      +    "type": "string"
      +  },
      +  "minItems": 1,
      +  "type": "array"
      +}
    • changedInput schema / properties / task / description
      Previous value: -"Task parameters are path-reference-only: provide the authorized workspace, file or directory locations, scope, and acceptance criteria. Never embed source text, diffs, file dumps, encoded source, or repository archives. Harness reads named files from the authorized workspace itself. This rule is identical for read-only and write-capable permissions."New value: +"Task parameters are path-reference-only: provide the authorized workspace, reviewTargets, contextReadScope, excludedPaths, writeScope, and acceptance criteria. reviewTargets identify what to assess; they are not a read whitelist. contextReadScope declares where Harness may search and read supporting implementation, tests, configuration, and architecture material. Never embed source text, diffs, file dumps, encoded source, or repository archives. Harness reads named files from the authorized workspace itself. These fields are task instructions, not enforced per-path filesystem isolation. The selected Harness model may send content it reads to its configured model provider even though Relay itself uses a loopback address."
    • addedInput schema / properties / writeScope
      Added value: +{
      +  "description": "Paths Harness may modify. Must be empty for read-only runs; this is an instruction declaration in addition to native permissions.",
      +  "items": {
      +    "description": "Workspace-relative path, or an absolute path contained by the authorized workspace.",
      +    "minLength": 1,
      +    "type": "string"
      +  },
      +  "type": "array"
      +}
  3. Changed4 schema fields changedv0.2.9
    • addedInput schema / properties / content / description
      Added value: +"Task parameters are path-reference-only: provide the authorized workspace, file or directory locations, scope, and acceptance criteria. Never embed source text, diffs, file dumps, encoded source, or repository archives. Harness reads named files from the authorized workspace itself. This rule is identical for read-only and write-capable permissions."
    • changedInput schema / properties / content / items / oneOf
      Previous value: -[
      -  {
      -    "properties": {
      -      "text": {
      -        "maxLength": 100000,
      -        "type": "string"
      -      },
      -      "type": {
      -        "const": "text",
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "type",
      -      "text"
      -    ],
      -    "type": "object"
      -  },
      -  {
      -    "properties": {
      -      "data": {
      -        "minLength": 1,
      -        "type": "string"
      -      },
      -      "mediaType": {
      -        "enum": [
      -          "image/png",
      -          "image/jpeg",
      -          "image/webp",
      -          "image/gif"
      -        ],
      -        "type": "string"
      -      },
      -      "name": {
      -        "type": "string"
      -      },
      -      "type": {
      -        "const": "image",
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "type",
      -      "mediaType",
      -      "data"
      -    ],
      -    "type": "object"
      -  }
      -]New value: +[
      +  {
      +    "properties": {
      +      "text": {
      +        "description": "Task parameters are path-reference-only: provide the authorized workspace, file or directory locations, scope, and acceptance criteria. Never embed source text, diffs, file dumps, encoded source, or repository archives. Harness reads named files from the authorized workspace itself. This rule is identical for read-only and write-capable permissions.",
      +        "maxLength": 100000,
      +        "type": "string"
      +      },
      +      "type": {
      +        "const": "text",
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "type",
      +      "text"
      +    ],
      +    "type": "object"
      +  },
      +  {
      +    "properties": {
      +      "data": {
      +        "minLength": 1,
      +        "type": "string"
      +      },
      +      "mediaType": {
      +        "enum": [
      +          "image/png",
      +          "image/jpeg",
      +          "image/webp",
      +          "image/gif"
      +        ],
      +        "type": "string"
      +      },
      +      "name": {
      +        "type": "string"
      +      },
      +      "type": {
      +        "const": "image",
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "type",
      +      "mediaType",
      +      "data"
      +    ],
      +    "type": "object"
      +  }
      +]
    • addedInput schema / properties / task / description
      Added value: +"Task parameters are path-reference-only: provide the authorized workspace, file or directory locations, scope, and acceptance criteria. Never embed source text, diffs, file dumps, encoded source, or repository archives. Harness reads named files from the authorized workspace itself. This rule is identical for read-only and write-capable permissions."
    • addedInput schema / properties / workspace / description
      Added value: +"Authorized absolute Harness workspace root; Harness reads named in-scope files from here."
  4. First observedv0.2.6

TDQS

A4.2/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond annotations, the definition discloses what would otherwise be invisible: task paths are instructions rather than enforced file-system isolation, Harness reads files from the workspace itself, and the selected model may send read content to its external provider despite Relay's loopback address. It also warns that webUrl sharing is not completion and flags the authorizationBasis requirement, which is strong behavioral disclosure.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description front-loads the main purpose and then packs critical constraints into a dense but mostly purposeful paragraph. A few ideas reappear, such as path-reference-only and non-enforcement, and bullet formatting would improve scanability, but no major irrelevant content is present.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For an 18-parameter, potentially destructive tool with no output schema, the description covers lifecycle, security, egress, and permission semantics well. It omits concrete valid values for provider/model/reasoning/agentPreset and does not describe the returned run payload beyond a stable session link, so an agent may need list_capabilities or wait_run docs to fully proceed.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

With only 50% schema coverage, the description adds essential semantics for the highest-risk inputs: task must be path-reference-only, reviewTargets are not a read whitelist, contextReadScope defines where Harness may search, and writeScope must be empty for read-only runs. It does not explain every parameter such as provider, model, reasoningEffort, or agentPreset, leaving some vocabulary to inference.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific action—create or reuse a Harness session, submit the first task, and return a session link—so an agent understands what start_run accomplishes. It does not explicitly contrast start_run with close siblings such as start_review or reply_run, though the 'first task' wording implies the distinction.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives clear invocation context: creating vs reusing a session, needing a workspace and task instructions, and calling wait_run afterward instead of treating the returned webUrl as completion. It doesn't explicitly name alternatives like start_review or reply_run or state when not to use them, so it falls short of full routing guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.