AI
Harnesses
A harness makes an AI coding agent build a project, or maintain a server, the way an expert in that stack would - without you writing the rules yourself.
A stack harness is a package of rules, settings, safe permissions,
format hooks and slash commands. Synapse looks at a project folder (or a server), works
out what it is, and offers to apply the matching harness. It writes files like
AGENTS.md and .claude/settings.json into the project, merged
with anything already there, and every agent that reads AGENTS.md - Claude
Code, Codex, Cursor, Gemini CLI, OpenCode and others - follows the same rules.
Harnesses need the Stack harnesses service. Switch it on in Services.
Applying a harness
- Open the Harnesses view (or Session tools, for a connected host) for a project folder or server.
- Synapse detects the stack from files, dependencies and, for servers, the operating system and installed commands, and suggests the best match.
- Review the preview: every file it will write or merge, every permission rule it adds, every hook and any MCP server, listed exactly.
- Apply. Files you already have keep your content - the harness only adds its own marked block or its own files.
- Run the checks (a one-click button per check) to see the harness's definition of done pass or fail for the project as it stands today.
Applying again after editing the project is a no-op; applying a newer version of the same harness updates its blocks and files in place. Remove takes out only what the harness added - your own edits, and anything you added yourself, are left alone.
Nothing is written until you approve the preview, and setup steps (like installing a dev dependency) only run when you click them - never automatically.
Project harnesses
Applied to a project folder. Detection looks at files and dependencies in that folder.
Laravel + MariaDB
Laravel 13 on MariaDB with any official frontend: Inertia + React, Inertia + Vue, Livewire
(with Flux) or plain Blade. One harness covers all four - AGENTS.md has
shared backend rules (Pest, Pint, Larastan, MariaDB-safe migrations) plus a section for
whichever frontend your project actually uses. It sits alongside Laravel's own official AI
package, Laravel Boost, rather than
replacing it.
- Adds:
AGENTS.md/CLAUDE.md/GEMINI.md, permissions that allow tests and formatters but ask beforemigrate/db:seedand denymigrate:fresh/db:wipe, an edit hook that runs Pint (and your JS/TS/Vue formatter), and/feature,/migration,/laravel-reviewand/checkscommands. - Checks: build,
php artisan test, Pint, PHPStan (Larastan), types and frontend lint - the list adapts to the frontend, so Livewire and Blade apps skip the TypeScript check.
WordPress
For a whole WordPress install, a theme (block, classic or child) or a plugin, including block plugins. Extends with hooks instead of editing core, and treats live sites and their databases with care.
- Adds:
AGENTS.mdand friends, WordPress-Extra coding standards (phpcs.xml.dist), PHPStan with the WordPress extension, a hook that blocks database wipes and core edits and asks before risky WP-CLI commands, and/plugin-feature,/block,/theme-changeand/wp-security-reviewcommands. - Checks: PHP syntax, WordPress Coding Standards (phpcs), PHPStan, and a blocks build/lint when the project has one.
Next.js + TypeScript + Postgres
Next.js 16 (App Router, Server Components, Server Actions, Turbopack) with Postgres through Drizzle or Prisma, whichever the project already uses. Treats Server Actions as public endpoints that need their own authorisation and validation, and keeps data access in a server-only layer.
- Adds:
AGENTS.mdand friends (built next to the block Next.js 16.3+ writes intoAGENTS.mditself), permissions that denyprisma migrate reset,drizzle-kit push/dropand reading.env*, a format hook,/feature//migration//reviewcommands, and the officialnext-devtools-mcpserver. - Checks:
npm run typecheck,lint,test,build.
Plain PHP + MariaDB
For PHP projects without a framework: Composer with PSR-4 autoloading, a front controller and small router, PDO, plain-PHP templates. Aimed at typical shared hosting and at older codebases that need careful, well-tested changes.
- Adds:
AGENTS.mdand friends, forward-only SQL migrations (bin/migrate.php), a lint-changed-files script, PHPUnit/PHPStan (level 8)/PHP-CS-Fixer configs, and/feature,/migration,/security-auditand/legacy-changecommands. - Checks: lint changed files, PHPUnit, PHPStan, PHP-CS-Fixer.
- Has extra rules for legacy folders: it never mass-reformats old code, and PHPStan only scans legacy folders (so their functions are known) rather than reporting every existing error in them.
Server harnesses
A server harness is for maintaining a live server, not writing application code. It's
applied to an ops workspace folder on the host (~/ops by
default, changeable per host), and agents run with that folder as their working
directory. Detection reads the operating system and which commands and paths exist on the
host itself.
cPanel & WHM
For AlmaLinux, CloudLinux or Rocky servers running cPanel & WHM, as root/WHM or as a single cPanel account (including inside CloudLinux's CageFS).
- Adds: runbooks (
/health-check,/disk-cleanup,/ssl-check,/mail-queue,/account-report,/security-audit,/update-plan,/backup-check...), read-only report scripts, a journal hook, andJOURNAL.md/backups/in the ops folder. - Safe by default: read-only diagnostics (WHM API and uapi read functions,
uptime,df, log reads...) are pre-approved; anything that changes the server asks first; account termination, firewall flushes, stopping cPHulk or sshd, and reading secrets are always denied.
Linux server
For a live Linux server without a control panel - Ubuntu/Debian (apt, ufw, AppArmor) or the RHEL family (dnf, firewalld, SELinux) in one harness. Hosts running cPanel, Plesk, DirectAdmin, HestiaCP, VestaCP or ISPConfig are excluded, since they have their own harness or panel tools.
- Adds: 13 read-only report scripts (health, load, disk, updates, services, TLS, SSH, firewall, backups...), a lock-out check that confirms you'll still be able to log in after a change, a config-validate-then-reload workflow, and runbooks such as
/health-check,/update-planand/ssh-audit. - Checks: every installed config validator passes, the lock-out guard passes, no failed services or full disks, and today's changes have a journal entry with a rollback note.
Docker host
For Linux hosts running containerised services with Docker Engine and Compose, including hosts fronted by Traefik, Caddy or nginx-proxy. Complements the Linux server harness (apply both on a Docker host) rather than replacing it.
- Adds: read-only reports for container health, stack validity, disk usage, logging config and a security review; a volume backup script that only acts with
--run; runbooks like/docker-health-check,/docker-disk-cleanupand/update-stack. - Never: the harness denies
volume rm/prune,system prune --volumes, and any command that would delete a volume - and never adds a user to thedockergroup, since that's root-equivalent.
How safety works
Every harness's .claude/settings.json splits commands into three lists:
allow (safe, read-only or routine commands that run without asking),
ask (changes that need a human in the loop), and deny
(destructive commands that never run, regardless of what the agent proposes). The
Harnesses preview shows you the exact rules before you apply. These rules reduce risk but
are not a sandbox - they match command text, so always run agents as the least privileged
user that can do the job.