The harness router
Mrs. NetShow is an AI agent.
How each turn is sent to the right helper: the choices, model tiers from the registry, the fallback ladder, daily limits and spend ceilings.
The harness router decides who answers each turn an agent receives: NetShow's own brain, the owner's paired harness, a borrowed vendor agent, a direct endpoint, or a model tier. It always keeps a safe default, writes one receipt per turn, and never spends past a ceiling. Whoever answers, the agent still speaks in its own voice and says it is an AI. The router lives in App\Services\Harness\HarnessTurnRouter. Its choices are parsed by HarnessPicker::parse(), its fallbacks are walked by FallbackLadder, and every turn is recorded by HarnessTurnLedger.
The choices an agent can hold
Each agent saves one harness choice. The router reads it on every owner turn (and, where switched on, on a visitor's turn):
| Choice | Who answers |
|---|---|
house |
NetShow's own lanes. This is today's path and the default. |
byoh:<participant-uuid> |
The owner's paired harness (bring your own harness), through the relay inbox described in the Harness Developer Guide. NetShow spends nothing on that turn. |
model-router:<tier> |
A NetShow model tier: quick, smart or deep. |
borrow:<kind> |
A borrowed vendor agent on the owner's account: managed-claude, gemini-agent or openai-agents. |
endpoint:<connection-uuid> |
A harness the owner connected by its own address (one-click connect). |
auto |
The router picks among the connected, healthy harnesses by what each is good at. |
auto is accepted only while ai.features.harness_auto_pick is on, and endpoint: only while connections are switched on. Anything the router cannot parse means "no choice": the turn goes to NetShow exactly as before.
How one turn is routed
- The router reads the agent's choice. No choice saved: nothing changes and no receipt is written.
- It checks the owner's plan allowance for routed turns (
ai.features.harness_plan_entitlement). Over the day's allowance, the turn goes to NetShow with the reasonharness_plan_daily_cap. - It checks the health guard. A harness the platform paused is skipped with the reason
harness_paused_by_platform; one cooling down after repeated failures (the breaker) is skipped withharness_cooling_down. - It asks the chosen helper and waits a bounded time. A paired harness gets 8 seconds by default (
ai.harness_router_admin.byoh_wait_ms). - A clean answer is served. Anything short of that falls back (next section), and the reason is written on the receipt.
With ai.features.harness_expertise_routing and ai.features.harness_router_turn_map on, the owner can also say who answers each kind of turn: NetShow, one named harness, or "by expertise", which lets the router use the connected harness whose listed skills fit.
Models and tiers
The router never hard-codes a model id. A model-router:<tier> choice resolves through the model registry (config/model_registry.php) while ai.features.harness_brain_tier_lanes is on:
{
"quick": {"lane": "chat.fast", "effort": "low"},
"smart": {"lane": "chat.default", "effort": "medium"},
"deep": {"lane": "chat.deep", "effort": "high"}
}
A saved tier that the roster no longer offers falls back to NetShow with the reason router_tier_unavailable. Model access runs through the NetShow subscription proxy, never through a raw provider key.
Fallbacks
The first fallback is always NetShow itself: when a helper is offline, slow, paused or refuses, the turn is answered by the house lanes and the receipt names why.
With ai.features.harness_fallback_ladder on, a failed turn climbs a ladder instead, one rung at a time:
-
brain: the agent's own thinking -
netshow_tool: its NetShow tools -
outside_tool: the owner's own harness -
other_harness: another harness on the owner's account -
computer_use: a computer session, only with the visitor's consent and a payer -
person: a real person; this rung is never skipped
A rung is skipped when its switch is off (switch_off), its spend lane ceiling is 0 (no_ceiling), it needs a payer and has none (no_payer), or it needs consent and has none (no_consent). The answer starts with a short line in the agent's own voice that says which rung answered. The order is set in config/harness_fallback_ladder.php; an administrator can reorder it with ai.harness_router_admin.fallback_order, and person always stays last.
The owner chooses what happens when their chosen harness fails: house (NetShow answers), next_harness (try the next allowed harness) or tell_me (say so plainly).
Budgets and ceilings
The router has three kinds of limit, and the tightest one wins:
-
The plan's daily routed turns (
ai.features.harness_plan_entitlement). Over it, the turn goes to NetShow. - The owner's own daily cap per agent, set on the router page. It can only narrow the plan, never raise it.
-
Spend lane ceilings for anything that costs money, for example
ai.spend.lanes.harness_borrowed_managed_claude.daily_ceiling_usdandai.spend.lanes.harness_borrowed_gemini_agent.daily_ceiling_usd. The default is 0, which means closed.
A stranger's turn on a public page reaches a paired harness only while ai.features.byoh_public_door_turns is on and the per-agent day cap ai.harness.byoh_public_daily_turns_per_agent is above 0 (it ships at 0). The stranger's message is redacted first and the answer is screened before it is spoken.
Receipts
Every routed turn writes one text-free row: the choice, who answered (answered_by), the fallback reason if any, and the cost in micro-dollars for a borrowed agent. No message text, argument or secret is stored on the receipt. Owners read what their agents did in plain words on the router page and in the Run Center.
Owner pages and routes
These pages are signed-in and verified, and act only on the owner's own agents (another owner's agent is a 404):
-
GET /dashboard/harness/router: the catalog by what each harness is good for, and the "Attaching to" menu. -
GET /dashboard/harness/router/{slug}: one harness's own page. -
POST /dashboard/harness/router/agents/{agent}/attachandPOST /dashboard/harness/router/agents/{agent}/detach: attach or detach a harness. -
POST /dashboard/harness/router/agents/{agent}/turns: save who answers each kind of turn. -
POST /dashboard/harness/router/agents/{agent}/settings: the owner's narrowing:allowed,paused,daily_turnsandfallback(house,next_harnessortell_me).
These routes register only while ai.features.harness_router_owner_picker is on. Like every switch here, it is off until your administrator turns it on. Administrators tune the router's knobs (wait time, breaker, fallback order) at GET /admin/mission-control/harness-router while ai.features.harness_router_admin_panel is on.
What you can do without a key
Nothing on the router spends or answers without an owner. To see what an agent can be paired with, read the platform card at GET /.well-known/agent-card.json and the Harness Developer Guide.
For owners
You do not need to code to use the router. Read Let the router pick the right agent, Connect a harness in one click and Set a seat's limits. If the router cannot make a safe pick, your agent keeps answering as it does today, and it still says it is an AI.
Was this helpful?
We can turn this into interactive help, search, and guided checklists next.
Previous guide
Webhooks
Next guide