> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agentium.in/llms.txt
> Use this file to discover all available pages before exploring further.

# Review selected workspace files

> An end-to-end read-only harness that finds a release task from two local documents.

Create a small workspace, load two explicitly selected UTF-8 files as source context, and ask a model to identify the remaining release task. The application removes the temporary workspace after execution.

[Download the complete project](/downloads/harness-workspace.zip), extract it, then run `npm install` and `npm run check`. Use `npm start` to execute the recipe with the requirements below.

## Set up the project

Use Node.js `^22.18.0` or `^24.11.0`. In an empty directory:

```bash theme={null}
npm init -y
npm pkg set type=module
npm install @agentium/core@4.0.0 @agentium/harness@4.0.0 openai zod
npm install --save-dev typescript tsx @types/node
export OPENAI_API_KEY="your-key"
```

Running this recipe contacts OpenAI. Set `OPENAI_MODEL` to a compatible model your account can use; see [model choices](/reference/example-models).

## Run the reviewer

Save this as `harness-workspace.ts`:

```typescript harness-workspace.ts theme={null}
import { mkdtemp, rm, writeFile } from "node:fs/promises";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { pathToFileURL } from "node:url";
import { openai, type ModelProvider } from "@agentium/core";
import { agentDriver, HarnessRuntime, research } from "@agentium/harness";

export async function reviewWorkspace(model: ModelProvider) {
  // This demonstration owns a temporary workspace containing two selected files.
  const root = await mkdtemp(join(tmpdir(), "agentium-review-"));
  const identity = { tenantId: "demo", userId: "reviewer" };
  const sessionId = "workspace-review";
  const runtime = new HarnessRuntime({
    definition: research({
      id: "workspace-reviewer",
      files: { id: "release-notes", root, files: ["README.md", "CHECKLIST.md"] },
    }),
    driver: agentDriver({
      name: "release-reviewer", model,
      instructions: "Compare the supplied files. Report unresolved release tasks with source filenames. Do not claim to run checks.",
    }),
    requirements: ["filesystem:read"],
    grants: { toolIds: [], modelRoles: ["main"] },
    budgets: { maxModelCalls: 2, maxToolCalls: 0, maxTokens: 6000 },
  });
  try {
    await writeFile(join(root, "README.md"), "# Atlas\nRelease 4.0 requires docs and migration verification.\n");
    await writeFile(join(root, "CHECKLIST.md"), "# Release\n- [x] Package published\n- [ ] Verify migration example\n");
    const result = await runtime.run("What remains before we announce the release?", { identity, sessionId });
    if (result.status !== "completed") throw new Error(`Review ended: ${result.status} (${result.reason?.code})`);
    console.log(result.text);
    return result;
  } finally {
    try {
      const diagnostics = await runtime.resources.closeSession(identity, sessionId);
      if (diagnostics.length) throw new Error(`Session cleanup failed: ${diagnostics.join(", ")}`);
    } finally {
      await rm(root, { recursive: true, force: true });
    }
  }
}

if (process.argv[1] && import.meta.url === pathToFileURL(process.argv[1]).href) {
  await reviewWorkspace(openai(process.env.OPENAI_MODEL ?? "gpt-6.1-sol"));
}
```

```bash theme={null}
npx tsx harness-workspace.ts
```

Expect an answer identifying **Verify migration example** as outstanding, with references to `README.md` and `CHECKLIST.md`. The model has no shell or write tools and does not run the migration check itself.

## Point it at your project

Replace the temporary-directory setup with an absolute project path and your explicit file list. Remove the demo's `writeFile` and `rm` calls when the host does not own that directory. Keep `requirements: ["filesystem:read"]`: it authorizes binding the file context ability.

`fileContext` reads only selected files under the canonical root and enforces retrieval bounds. Source files remain data, not trusted instructions. This grant is not OS isolation; the host process still has its normal filesystem permissions.

## Add execution deliberately

To actually run a test or build, add an application-owned tool and grant its exact name. Choose a [sandbox backend](/sandbox/overview) for the code's trust level and define timeouts, output bounds, and ownership. A file snapshot does not capture running processes or external side effects.

The file source is fetched at run time. Changes, missing files, invalid UTF-8, or exceeded context bounds can fail the run; inspect its status and reason instead of treating an empty answer as success.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.