Bring your own

Your harnesses, in one IDE

Bisa ships no coding agent and no model client. It drives the harnesses on your machine — signed in as you, on your plans — gives each the platform's tools, and says honestly what it can and cannot do with each one. It installs nothing and signs in to nothing for you: where a harness is missing, it shows the official line to copy.

What Bisa does with each harness
HarnessWorkflow steps and conversationsIn a terminal tabThe guardAccount usage
Claude Codedriven, with the platform's toolsreports its state, resumed with --continuejudged before it runsyes
Codex CLIdriven, with the platform's toolsreports its state, resumed with resume --lastobservedyes
OpenCodedriven, with the platform's toolsread from its own event stream, resumed with --continueobservedwith a Claude sign-in
GitHub Copilot CLIdriven over ACP, with the platform's toolsreports its state, resumed with --continuejudged before it runsnot offered by the harness
Grok Builddriven over ACP, with the platform's toolsa plain terminal, resumed with --continuejudged when Bisa drives it; not seen in a terminalnot offered by the harness
pidriven, in conversationreports its state, resumed with --continueobservednot offered by the harness
Oh My Pidriven, in conversationreports its state, resumed with --continueobservedyes
Any ACP agentdriven, with the platform's tools—judged before it runs—
An A2A agenta remote agent, driven—observed—
Your own JSON harnessdriven, in conversationits own resume, when you give oneobserved—
Goose · Cursor Agentover ACP, as any ACP agentdetected and opened, resumed with their own flagjudged over ACP—

Judged before it runs: the harness asks before a tool runs, and the Tool & Commands Guard answers. Observed: the harness runs under its own sandbox and approval prompt; what it did is reported and redacted, but not vetoed. In conversation: the harness takes no MCP server, so a workflow's agent step is placed on a harness that does.

Claude Code

The deepest integration. A workflow step or a conversation runs a Claude Code session with the platform's MCP server; every read, write and command comes back to the guard before it runs, and a secret's placeholder is restored only at that moment. In a terminal tab its hooks report each turn, tool and question to the roster, and the guard answers its PreToolUse. Skills arrive where it reads them; the effort is its own --effort; the footer shows what its account has left.

Codex CLI

Driven with the platform's tools and an effort fitted to its levels. In a terminal its hooks report turns, tools and permissions; it asks nobody before a tool runs, so the guard observes it rather than vetoing. Its account's windows and plan come from the CLI itself.

OpenCode

Driven with the platform's tools; in a terminal Bisa reads OpenCode's own event stream — turns, tools, permissions, questions, cost and sub-agents — and injects nothing. Observed by the guard.

GitHub Copilot CLI

Driven over the Agent Client Protocol: the model and then the effort are set the protocol's way, and every tool is asked before it runs. Bisa never starts it with a word that allows tools unasked. In a terminal, hooks written for that one launch report its state and let the guard answer before each tool.

Grok Build

Driven over the Agent Client Protocol with the platform's tools, the model and the effort set as the session offers them, every tool asked before it runs. Its terminal takes no hook for one launch and Bisa writes nothing into your configuration, so a Grok tab is a plain terminal: unreported and unguarded.

pi and Oh My Pi

Driven in conversation, and reporting their turns and tools from a terminal through a generated extension. Neither takes an MCP server, so a workflow's agent step goes to a harness that does. Oh My Pi's account usage shows in the footer.

Any ACP agent — Goose, Cursor Agent and more

Anything that speaks the Agent Client Protocol is a harness: it is handed the platform's MCP server, asks before each tool, and is set to a model when its session offers one. Goose and Cursor Agent are also detected in a terminal and resumed with their own flags.

A2A agents, and your own

A remote agent that speaks A2A can be an agent's harness, and Bisa's own agents can be exposed over A2A. A harness Bisa does not know is a descriptor of your own: a program and its arguments, speaking line-delimited JSON.

Agents, harnesses and models, in the guide