The runtime

Different agents.
Shared work.

ToolsEnabled Fleet is an MCP server for the Codex and Claude Code CLIs: agent fleet management and mediation, loaded by each official client. It adds coordination inside your sandbox, while each client continues to use its own conversation and sign-in.

Work in progress · Beta
01

A shared work record.

Submit, claim, checkpoint, and complete tasks across clients and sessions. The ledger holds task records and standing rules, with entries labelled by the client that filed them.

task.submit / task.checkpoint / ledger.read
02

Memory that carries over.

Keep shared notes and values between sessions. Index local files and search them lexically, with no model required for search.

memory.set / memory.get / search.query
03

Coordinated file edits.

Mediated edits are checked against the bytes an agent observed. Unaffected reads can be rebased after another edit; stale observations cause a refusal. Native file tools can bypass this coordination.

host.read_file / host.patch_file
04

A bounded team of agents.

Start Claude Code and Codex workers, let them delegate, and receive their reports through the tree. Child tool access and provider tiers stay within their ancestors’ runtime allowances.

agent.spawn / agent.resume / agent.set_role
05

Policy feedback you can act on.

Read OpenShell’s advisor state and observed denials. Get an explanation, then a scoped network-access proposal. You review access changes through OpenShell on the host.

openshell.denials / openshell.propose
06

A view from your terminal.

Inspect the agent tree, work record, asks, and settings without a hosted dashboard. Answer a question from a worker and carry on in your shell.

toolsenabled tree / ledger / settings

Agent trees

Delegate the work.
Keep the structure.

The current tree allows up to four direct workers per agent and three levels below you. Reports return to the manager that started the worker.

These are cooperative runtime rules inside one shared sandbox. They are not isolation between workers. For unattended or larger teams, use provider API keys under the applicable provider terms.

  • Claude Code worker
  • Codex worker
  • Refused: wider than its parent

Current validation

Implemented.
Still being evaluated.

On beta 3’s exact archive: full Linux installs under three umasks, a two-hour Linux soak with a real beta 2 to beta 3 upgrade in every round, the frozen hand test twice (42 passed, 0 failed each time), a host rehearsal of the two-command install, a two-hour Windows soak through WSL 2 (32 rounds, 0 failures), and an independent security review of the lifecycle changes; see the release notes. Autonomous task performance is not established by these checks.