Y Combinator Open-Sourced 'qm': A Multiplayer Agent Harness Every AI Automation Agency Should Know About

YC's open-source qm framework gives every teammate a scoped AI agent workspace with shared memory, permissions, and full audit trails.

Y Combinator Open-Sourced 'qm': A Multiplayer Agent Harness Every AI Automation Agency Should Know About

By Hadidiz Flow Team • August 3, 2026 • Automation

AI Agents Are Moving From "Personal Assistant" to "Team Infrastructure"

Most AI agent tools so far have been built around a single user talking to a single assistant. Y Combinator just open-sourced something built for a different reality: a company where every employee has their own AI agent, all of them working inside shared channels, shared projects, and shared accountability. The project is called qm — a "multiplayer agent harness for work" — and it landed on Hacker News' front page with over 600 points, a strong signal that this is resonating well beyond YC's own portfolio.

For agencies building automation and AI workflows for clients, qm is worth a close look, because it's less a chatbot and more a blueprint for how AI agents should actually be deployed inside a real organization.

What qm Actually Is

qm gives each person in a company their own isolated agent workspace — scoped memory, files, a keychain view, permissions, scheduled jobs (crons), even web apps — all separate from everyone else's. But it's not purely individual: people and their agents can also collaborate together inside channels, group messages, and shared projects, the same way a human team would work in Slack.

Critically, the agent acts as the person it's working for — using their credentials and permissions — with every action logged and auditable. That's a meaningful design choice: it means an agent's mistakes and access are bounded by the same limits as the human it represents, not by some separate all-powerful service account.

The Security Model Is the Interesting Part

qm ships with three built-in security postures, and the choice between them says a lot about how seriously the project takes agent risk:

  • Strict — requires human approval on every single tool call.
  • Auto (the default) — runs a classifier in front of external data before it ever reaches the model, screening for prompt injection and unsafe instructions automatically.
  • Dangerous — turns screening off entirely, for teams that want full autonomy and accept the risk.

This tiered approach matters for agencies because it gives you a real answer to the question every client eventually asks: "what stops the agent from doing something it shouldn't?" Instead of a vague promise, qm gives you a configurable, auditable policy layer.

Built to Be Model-Agnostic

qm isn't tied to one AI vendor. The same core architecture is designed to work with Claude Code, Codex, OpenCode, and Pi, so teams aren't locked into a single model provider's roadmap or pricing. That flexibility is increasingly important as model pricing and capabilities shift month to month — an agency building infrastructure today doesn't want to re-architect it if the best model changes in six months.

The whole project is released under an MIT license, meaning it can be self-hosted, forked, and customized freely — no seat licensing, no vendor gate.

Why This Matters for Automation Agencies

Most client-facing AI automation work eventually runs into the same wall: a single assistant can only go so far before a business needs multiple agents doing different jobs, working within different permission boundaries, and leaving an audit trail a client's IT or compliance team can actually review. qm is one of the first credible, open-source attempts to solve that at the "whole company" level rather than the "one user, one bot" level:

  • Per-person scoping makes it straightforward to give each department or client-facing role its own bounded agent.
  • Built-in audit logging gives you something concrete to show clients who ask how AI actions are tracked.
  • The classifier-based Auto mode offers a reasonable default security posture without requiring you to build injection detection yourself.
  • Model-agnostic design protects the automation you build today from becoming obsolete if the underlying model landscape shifts.

It's early — this is a fresh open-source release, not a mature, battle-tested platform — but the architecture reflects genuine thinking about how AI agents should be deployed at company scale, which makes it a strong one to evaluate before building similar infrastructure from scratch.

Key Takeaways

  • YC open-sourced qm, a "multiplayer agent harness" giving each employee their own scoped AI agent workspace with shared collaboration channels.
  • Agents act with the permissions of the person they represent, with all actions logged and auditable — not a separate all-access service account.
  • Three built-in security postures (Strict, Auto, Dangerous) give teams a configurable answer to agent-safety questions.
  • The framework is model-agnostic, working with Claude Code, Codex, OpenCode, and Pi, and is released under MIT license for self-hosting.
  • It's a strong reference architecture for agencies designing multi-agent, multi-permission AI systems for clients — worth evaluating even if you don't adopt it outright.
Weekly newsletter

No spam. Just the latest news and tips, interesting articles, and exclusive interviews in your inbox every week.

Read our privacy policy
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Read more from our blog
We transform your idea into an App Professionally Quickly

Our cutting-edge features simplify collaboration and creativity, making your workflow intuitive and efficient. Transform your vision into reality effortlessly with Hadidiz Flow.