Runtimes and agents
How AI Workbench runs the agent tools you already use, where their models come from, and how a team of agents works together.
AI Workbench does not bring its own AI. It runs the agent tools you already use, called runtimes, and gives them a shared way of working: a project, a team, a task board, plans, memory and an inbox. This page explains how the pieces fit.
Runtimes
A runtime is an agent tool that the workbench starts and talks to. Each agent is its own process, running one runtime, and the workbench speaks to all of them the same way (over the Agent Client Protocol), so a team can mix them.
The runtimes the workbench can drive:
- GitHub Copilot CLI
- Claude Code
- OpenAI Codex
- Google Antigravity
- OpenCode
- Kilo Code
- Grok Build (xAI)
- Cline
- Mojo Up native bridge: built in, an agent for any OpenAI-compatible model, local or hosted. No Copilot licence needed.
- Custom ACP: any agent command that speaks the Agent Client Protocol.
Turn runtimes on or off, and sign them in, under Settings → Models → Runtimes. One runtime is your default: new team members, specialists and the Chat agent use it unless they choose another. You pick it in Settings → Setup.
Each runtime signs in its own way: with your subscription (see Your subscriptions), with an API key, or through a model provider.
Where models come from
A runtime that uses its vendor's own service talks to that vendor directly: a signed-in Claude Code talks to Anthropic, for example. Runtimes that can use another model reach it through the workbench's model gateway, which fronts:
- Local models: the bundled llama.cpp runner (CPU, CUDA or ROCm), Ollama, LM Studio, Foundry Local, MLX on Apple silicon, vLLM, Unsloth Desktop or any llama.cpp server. A local model is optional; nothing you send it leaves the computer.
- Hosted providers: Anthropic, OpenRouter, Azure OpenAI and AI Foundry, Amazon Bedrock, Google Gemini API, xAI, Groq, Together AI, DeepInfra, Fireworks AI, DeepSeek, Mistral AI, Kilo Gateway, or any OpenAI-compatible endpoint.
The gateway applies your budgets, fallbacks and data-loss prevention, records usage and cost per agent and model, and repairs the requests that almost-OpenAI-compatible servers get wrong. Agents get a stand-in key, never your real one.
Agents, specialists and teams
An agent is one running runtime with a role. A specialist is a saved definition of one: a role, a runtime, a model, its skills and where it runs. A team is a set of specialists that work together:
- A manager plans the work, hands out tasks, reviews what comes back and merges it.
- Developers and other specialists do the work, each on their own task.
- A review-and-revise loop asks you when it stalls.
A common pattern is a stronger model that plans and reviews, with cheaper or local models doing the work. The ready-made Start with a pair and Feature squad teams are a starting point; change any of it in Teams.
A team member can run on this computer, or on another machine: a WSL distro, a dev container, an SSH host, a node, or, in a team, another person's workbench or node.
Each agent works on its own branch
Every agent works in its own git worktree: a separate checkout of the repository on a branch of its own, so agents edit without treading on each other. Their work meets on an integration branch, which you merge or open as a pull request. Nothing reaches main without you.
In Chat you choose where an agent runs: This checkout (the repository folder itself), Own worktree (a separate copy on its own branch) or Last worktree. Chat work in its own worktree merges back after ten quiet minutes or when you keep it; change that under Settings → Behaviour.
How much an agent may do on its own
Each agent has a permission mode: Supervised, Auto-accept edits, Auto (the default) or Full access. When an agent wants to do something its mode does not allow, it asks, and the request waits in your inbox, on your phone, or in the node's console. A policy can cap the mode and require some actions to always ask.
Every action, whether you, an agent, a routine or a remote device asked for it, goes through one control layer that records who asked for what in the audit log.