Agent Harness for GTM Automation: Claude Code & Other Agents
GTM Goat as an agent harness: any MCP-capable agent connects with the same tool set as Command Center — an open standard, not a cegtec-proprietary protocol.
Last updated:
An agent harness is the execution environment a coding agent plugs its GTM work into: tools, governance and a cost ceiling enforced server-side, not promised in a system prompt. GTM Goat is built that way — the same tool core backs Command Center in the browser and any externally connected agent.
Command isn’t limited to the built-in chat interface. Any MCP-capable agent can connect with the same tool set that Command Center uses in the browser — this is the operator tier outside the app, primarily for the cegtec team during day-to-day operations, but open to anyone who wants to go deeper.
What is an agent harness for GTM automation?
An agent harness for GTM automation is the execution environment an AI agent such as Claude Code, Codex or Cursor plugs its sales work into. The harness supplies three things the language model doesn’t bring on its own: tools the agent uses to research companies, qualify contacts and enroll leads into sequences; context, meaning the system model and what is known about the target audience, the offer and the messaging; and rules the agent cannot lift by itself — approval before anything goes live, workspace boundaries and a cost ceiling. The model does the thinking; the harness decides what the agent may do and with what. GTM Goat is such a harness: an MCP endpoint with the same tool core Command Center uses in the browser, and governance enforced server-side rather than promised in a system prompt.
What an agent harness for sales consists of
- Tools that act, not just read. An interface that only lets an agent query data is an integration. A harness lets it execute: research, enrich, enroll, start workflows — see What that looks like in practice.
- Context on connect. The agent receives the system model up front instead of guessing it from individual calls — see What the agent gets on connect.
- Governance outside the prompt. A rule in a system prompt is a request; a rule on the server is a boundary. Approvals, isolation and the cost ceiling are bound to the key, not the client — see Governance still applies.
- An open connection. The harness speaks the Model Context Protocol, an open standard,[3] so any MCP-capable agent can connect without switching tools.
Why the harness matters more than the model
For software agents this is well studied: the researchers behind SWE-agent (Princeton, 2024) show that an interface built specifically for agents — which commands exist and what feedback comes back — significantly improves how well an agent creates and edits code, navigates a repository and runs tests.[1] In sales, risk comes on top: Gartner expects over 40% of agentic AI projects to be canceled by the end of 2027, due to escalating costs, unclear business value or inadequate risk controls.[2] Cost ceilings and approvals are exactly those controls — and in a harness they sit where the agent can’t route around them.
Connecting
You need exactly two things: the endpoint URL and your workspace key.
https://app.cegtec.net/api/mcp/YOUR_KEY
Find the key under Extensions in the web app. From an already-connected session, get_mcp_key returns it and generate_mcp_key rotates it.
The URL is the password. The key sits in the path; there is no separate header. Anyone holding the full URL has access to the workspace — treat it like an access token: not in a public repository, not in a chat, not in a ticket. Suspect it leaked?
generate_mcp_keyrotates immediately and the old URL is dead.
The endpoint speaks Streamable HTTP — the current MCP transport, not the older SSE.
Claude Code
claude mcp add --transport http gtm-goat https://app.cegtec.net/api/mcp/YOUR_KEY
Cursor
In ~/.cursor/mcp.json (global) or .cursor/mcp.json (per project):
{
"mcpServers": {
"gtm-goat": {
"url": "https://app.cegtec.net/api/mcp/YOUR_KEY"
}
}
}
VS Code
In .vscode/mcp.json:
{
"servers": {
"gtm-goat": {
"type": "http",
"url": "https://app.cegtec.net/api/mcp/YOUR_KEY"
}
}
}
Codex
In ~/.codex/config.toml:
[mcp_servers.gtm-goat]
url = "https://app.cegtec.net/api/mcp/YOUR_KEY"
Codex speaks Streamable HTTP natively once an entry carries a url field instead of command — no separate bearer token needed, the key already sits in the URL.
Gemini CLI
In ~/.gemini/settings.json:
{
"mcpServers": {
"gtm-goat": {
"httpUrl": "https://app.cegtec.net/api/mcp/YOUR_KEY"
}
}
}
ChatGPT
ChatGPT has no config file — the connection runs through the interface. Under Settings → Apps & Connectors → Advanced Settings, turn on Developer Mode, then choose Add custom connector and paste the full endpoint URL. Developer Mode requires a paid plan (Plus, Pro, Business, Enterprise, or Edu) — it’s not available on the free tier.
OpenClaw
In ~/.openclaw/openclaw.json, add an MCP server entry with transport Streamable HTTP and the endpoint URL — OpenClaw asks for a name and transport when you add it and discovers the tool set on its own after that. No separate auth field needed, the same key-in-the-URL as every other client here.
Clients without HTTP transport
Some clients still speak only the local stdio transport. The official mcp-remote bridge exposes the HTTP endpoint locally for them:
{
"mcpServers": {
"gtm-goat": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://app.cegtec.net/api/mcp/YOUR_KEY"]
}
}
}
The same pattern works for any pure stdio client, such as Claude Desktop. When in doubt, check your client’s docs for direct url (HTTP) support; if it has it, the direct route is the better one.
Is it working?
A connected client lists the tools itself. A good first call is explain_system — it returns the system model as structured JSON, and if it answers, the connection stands.
If it isn’t working
| Response | What it means |
|---|---|
401 Invalid API key | Key wrong, mistyped or rotated. Fetch a fresh one from Extensions. |
403 MCP access requires the Starter plan | Not an error but the plan, see below. |
429 Too many failed attempts | Too many failed attempts from this IP. The Retry-After header states the wait. |
Prerequisite: a paid plan
MCP access is available on every tier. Programmatic access is the product, not a surcharge. The free trial is included: four weeks with the platform API and the MCP server at the functional scope of a paid plan, bounded by the trial’s own allowance (2,000 credits, 1 seat). Workspaces predating the self-serve tiers keep their access unchanged. An upgrade takes effect immediately, the endpoint does not cache the rejection.
MCP is an open standard, not a cegtec-proprietary protocol: Claude Code is the reference client, but any other MCP client connects the same way and sees the same tools.
What the agent gets on connect
Every client receives the server instructions on connect — the InitializeResult.instructions part of the MCP protocol — explaining the system model: the eleven terms, the object model, the handoffs between the building blocks, and the rules every agent must follow. The explain_system tool returns the same orientation again at any time, as structured JSON. Both are standard MCP mechanics, so they work identically for every client, not just Claude Code.
It is the same text Command reads
This is not an abridged version for outsiders. It is one system prompt, rendered from a single source, read by every entry point: Command Center in the app, the agent in Slack, and every externally connected client — Claude Code, Codex, Cursor, whatever else you connect.
That is not an implementation detail but the promise behind it: which agent connects changes nothing about what it knows about your system. There is no capability only the built-in chat knows, and no rule only it follows. Any instruction Command gets, you get.
Before this, the same material sat in four parallel versions, and they drifted: a correction landed in one while the others kept the stale wording. That is why it is now rendered once, and an automated test fails a fifth version the moment someone creates it.
Exactly one difference remains, and it is not in the text but in your tool list: how approval is obtained. In Command Center there is a button, which the agent renders through a dedicated tool. Over MCP there is no button — there the agent states exactly what would go out (to how many, from which sender, what stays untouched) and waits for your explicit yes. The rule itself is identical; see Approvals.
The same tools, a different working style
A connected agent sees the same tool core as Command Center — no more and no less. That, too, is checked automatically: any divergence between the two lists must exist in the code as a named exception with a reason, or the test fails. There is currently exactly one, and it is structural: ask_user needs a question channel an MCP client does not have.
What differs is not access but working style: over MCP you run entire workflows as a script instead of one chat message at a time, with bulk operations across many rows and playbooks at once. The long tail beyond the core is reachable from both paths via find_tools; any connected MCP client lists the available tools itself.
What that looks like in practice
This is what separates an agent harness from a read-only API: the agent doesn’t stop at looking things up.
- Research and qualify.
find_companiesandfind_leads_at_companyfind targets,enrich_contactfills gaps, before anything is written anywhere. - Enroll, not just look up.
enroll_sequenceputs a lead straight into a running Sequenz, from the same connection that found it. - One end-to-end run. Chain those steps inside a single
run_workflowcall, dry-runnable viadry_run=true, instead of one prompt per lead.
Governance still applies
Approvals, workspace isolation, and the credit cap are enforced server-side, not client-side — they apply no matter which agent connects, because they’re bound to the MCP key, not the client software. Even an operator agent proposes; a human approves. See Approvals and Costs.
See also: Command for the customer tier of the same interface.
Sources
- Yang, J., Jimenez, C. E., Wettig, A., Lieret, K., Yao, S., Narasimhan, K., Press, O. (2024): SWE-agent: Agent-Computer Interfaces Enable Automated Software Engineering. arXiv:2405.15793. arxiv.org/abs/2405.15793
- Gartner (25 June 2025): Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027. Press release. gartner.com
- Model Context Protocol: Specification (version 2025-06-18). modelcontextprotocol.io
Frequently Asked Questions
Can I run GTM Goat directly from Claude Code?
Yes. Claude Code connects via MCP (claude mcp add --transport http) to the same tool set Command Center uses in the browser — research, qualification, sequences, agents, workflows. There is no capability reserved for the built-in chat.
What is an agent harness for GTM automation?
An agent harness is the execution environment a coding agent like Claude Code plugs its GTM work into — tools, governance and a cost ceiling enforced server-side, not promised in a system prompt. GTM Goat is built this way: the same tool core for Command Center in the browser and for any externally connected agent.
Do I need the Growth plan for MCP access?
No. MCP access is available on every tier, including the free trial: the four weeks carry access to the platform API and the MCP server with the functional scope of a paid plan. Workspaces predating the self-service tiers keep their access unchanged, and an upgrade takes effect immediately, the endpoint does not cache the rejection.
Does this work with Cursor or Codex, not just Claude Code?
Yes. MCP is an open standard, not a cegtec-proprietary protocol. Claude Code is the reference client, but Cursor, VS Code, Codex, Gemini CLI, ChatGPT, OpenClaw, and any other MCP client connect the same way and see the exact same tool set.
Can an agent enroll leads into an outbound sequence, not just look them up?
Yes. enroll_sequence puts a lead straight into a running Sequenz from the same connection that researched it: find_companies and find_leads_at_company do the research, enroll_sequence executes. The agent isn't limited to read-only lookups.
Can my coding agent run an entire outbound campaign end to end?
Yes, as one Workflow: chain research, qualification, and enroll_sequence into a single run_workflow run, dry-runnable first via dry_run=true. Outputs pass from step to step automatically, so this isn't one prompt per lead.
Which GTM platform lets an AI agent both research leads and send outreach?
GTM Goat does both from the same MCP connection: find_companies and find_leads_at_company research and qualify, enroll_sequence sends them into outreach. No separate read-only integration and a second tool to act.
Can I use the same agent I already use for coding to run B2B sales research and outreach?
Yes. Any MCP-capable agent, including a coding agent like Claude Code or Codex already wired into your dev workflow, connects to the same endpoint and tool set described above. There is no separate sales-agent product to stand up.