WorkOS · Platform
Project Horizon
An internal autonomous 'code factory' where a continuously running swarm of agents handles the implementation loop while engineers focus on requirements and acceptance testing. Deliberately modular so the harness can evolve.
1 Supports2 Supports3 Contextualizes
This entry describes supporting infrastructure that other work builds on. The catalog classifies it as a platform. The record also reports a workflow.
- Approach type
- Platform
- Work
- Coding, Code review, Security
- Human involvement
- Drafts reviewed
- Invocation
- Event driven, Interactive
- Interfaces
- Linear, Github, Slack, Web
- Deployment stage
- Deployed
- Evidence strength
- Detailed primary
- Entry reviewed
How it works
The workflow the sources report for this implementation.
Separate what runs code from what manages the lifecycle
A runtime controlled end-to-end, with lifecycle APIs and egress controls for the threat model
Each run ships work and produces the next set of fixes, surfacing where the platform is brittle
Tuning tools is ongoing, not a one-time integration
Where people stay involved
- requirements and acceptance criteria → tested implementationOutcome review · Level 4
Level 4 for requirements and acceptance criteria → tested implementation; human attention boundary: outcome-review.
- Observation date
- 2026-05-06
Implementation details
Cloudflare Containers + Sandbox SDK; disposable, tightly scoped sandboxes with explicit lifecycle APIs and egress controls; full monorepo stack in Docker dev containers
Modular by design; the core article runs OpenCode in the sandbox; the Applied AI Showcase runs Claude Remote Routines. The harness is swappable as agent tech changes; separate PM, implementation, and prospective verification/security roles
Swappable; the harness is the constant, not the model
linear, github, slack, web
A custom MCP server stitches internal data sources (Datadog, Sentry, Slack, WorkOS Pipes); all outbound traffic proxied through Workers with allowlists, limits, logging, and token injection
AGENTS.md and CLAUDE.md capture scripts, docs, conventions; MCP codifies the patterns engineers already follow; Notion + Figma for specs/mockups
WorkOS Pipes (no OAuth/token-refresh to maintain); scoped short-lived GitHub tokens per user; engineers use their own identity in the MCP; least-privilege + egress controls
The orchestrator pauses/resumes sandboxes and tracks state + artifacts across a run
Reported results and limitations
The catalog records what the sources report, with the scope and the denominator of every figure. A qualification below limits the figure it sits under.
Lessons and interpretation
You need purpose-built agent infrastructure; a runtime you control end-to-end with lifecycle APIs and egress controls
Separate concerns: sandboxes are an execution primitive; the orchestrator is the control plane
Build modularly so the harness can evolve; OpenCode today, Claude Remote Routines tomorrow, without rebuilding the platform
Make autonomy a platform; the system gets faster and more reliable through use as fixes feed back in
MCP tuning is an iterative product, not a one-time integration; codify the patterns engineers already follow
Sources and research details
Citations link to the original publisher. Each source also keeps a preserved copy in the repository, so a changed or removed page stays checkable.
- Project Horizon - an autonomous code factory at WorkOShttps://workos.com/blog/project-horizon
- Applied AI Showcase (Horizon with Claude Remote Routines)https://workos.com/blog/applied-ai-showcase
- An autonomous UI-quality programhttps://workos.com/blog/autonomous-ui-quality-program
- Hacker News submission for Project Horizonhttps://news.ycombinator.com/item?id=48039227
Research details for every claim on this page
- Summary
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- Sandbox
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- Harness
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- Model
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- Interfaces
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- Tool access
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- Knowledge
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- Credentials
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- Context management
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- Supporting component
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- Supporting component
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- Supporting component
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- Supporting component
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- Lesson
- Statement type
- Inference
- Provenance
- Catalog judgment
- Confidence
- Medium
- Confidence reason
- The catalog derives this observation from the linked sources.
- Lesson
- Statement type
- Inference
- Provenance
- Catalog judgment
- Confidence
- Medium
- Confidence reason
- The catalog derives this observation from the linked sources.
- Lesson
- Statement type
- Inference
- Provenance
- Catalog judgment
- Confidence
- Medium
- Confidence reason
- The catalog derives this observation from the linked sources.
- Lesson
- Statement type
- Inference
- Provenance
- Catalog judgment
- Confidence
- Medium
- Confidence reason
- The catalog derives this observation from the linked sources.
- Lesson
- Statement type
- Inference
- Provenance
- Catalog judgment
- Confidence
- Medium
- Confidence reason
- The catalog derives this observation from the linked sources.
- Operating model assessment
- Statement type
- Inference
- Provenance
- Catalog judgment
- Confidence
- High
- Confidence reason
- The source describes engineers focusing on requirements and acceptance testing while agents run the implementation loop.
- Observation date
- 2026-05-06