[{"data":1,"prerenderedAt":1767},["ShallowReactive",2],{"site-nav-content":3,"blog:/blog/agent-harness-vs-agent-framework":178,"blog-index-copy":836,"blog:/blog/agent-harness-vs-agent-framework:surround":857,"hiring-banner-content":1736,"site-cta-content":1748},{"header":4,"productNav":9,"nav":42,"footer":61,"askAI":131,"id":162,"title":163,"archived":164,"authors":165,"badge":165,"body":166,"date":165,"definedTerm":165,"department":165,"description":170,"extension":173,"eyebrow":165,"faqHeader":165,"faqs":165,"footerBand":165,"headline":165,"image":165,"industry":165,"jobType":165,"listed":130,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":174,"relatedHeading":165,"seo":175,"series":165,"sitemap":164,"status":165,"stem":176,"subhead":165,"tags":165,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":177},{"productLabel":5,"loginLabel":6,"contactLabel":7,"contactSalesLabel":8},"Product","Log in","Contact","Get started for free",[10,14,18,22,26,30,34,38],{"label":11,"to":12,"description":13},"Overview","/overview","Seven layers. One closed loop.",{"label":15,"to":16,"description":17},"Conflux","/product/conflux","Where your team, workstreams, and agents meet.",{"label":19,"to":20,"description":21},"Agent Teams","/product/agent-teams","Specialist teams - governed from day one.",{"label":23,"to":24,"description":25},"Lifecycle Graph","/product/lifecycle-graph","Intelligence that compounds across every interaction.",{"label":27,"to":28,"description":29},"Company Wiki","/product/wiki","Playbooks and policies where expertise stays.",{"label":31,"to":32,"description":33},"Workstreams","/product/workstreams","From brief to signed-off deliverable on one canvas.",{"label":35,"to":36,"description":37},"Perception Console","/product/perception","Ask your whole business in plain English.",{"label":39,"to":40,"description":41},"Governance","/product/governance","Frontier AI you can actually sign off on.",[43,46,49,52,55,58],{"label":44,"to":45},"Models","/models",{"label":47,"to":48},"Pricing","/pricing",{"label":50,"to":51},"Integrations","/integrations",{"label":53,"to":54},"Security","/security",{"label":56,"to":57},"Partners","/partners",{"label":59,"to":60},"Insights","/blog",{"productHeading":5,"companyHeading":62,"legalHeading":63,"docsLabel":64,"docsUrl":65,"statementLines":66,"copyright":69,"companyLinks":70,"legalLinks":100,"socialLinks":110,"bottomLinks":120},"Company","Legal","Docs","https://docs.gonimbus.ai",[67,68],"Stop training someone else's model.","Control your AI.","© 2026 Nimbus Intelligence, Inc. All rights reserved.",[71,72,73,74,75,78,81,84,87,90,92,95,98],{"label":47,"to":48},{"label":50,"to":51},{"label":53,"to":54},{"label":59,"to":60},{"label":76,"to":77},"Glossary","/glossary",{"label":79,"to":80},"Compare","/compare",{"label":82,"to":83},"Evaluate","/evaluate",{"label":85,"to":86},"Problems","/problems",{"label":88,"to":89},"Use cases","/use-cases",{"label":91,"to":57},"Partner Program",{"label":93,"to":94},"Careers","/careers",{"label":96,"to":97},"System status","/status",{"label":7,"to":99},"/contact",[101,104,107],{"label":102,"to":103},"Terms of Service","/terms",{"label":105,"to":106},"Privacy Policy","/privacy",{"label":108,"to":109},"Compliance","/compliance",[111,114,117],{"label":112,"href":113},"LinkedIn","https://www.linkedin.com/company/gonimbusai/",{"label":115,"href":116},"X","https://x.com/gonimbusai",{"label":118,"href":119},"Instagram","https://www.instagram.com/gonimbus_ai/",[121,123,125,126,127],{"label":122,"to":103},"Terms",{"label":124,"to":106},"Privacy",{"label":108,"to":109},{"label":96,"to":97},{"label":128,"to":129,"external":130},"LLMs.txt","/llms.txt",true,{"text":132,"prompt":133},"Ask AI about Nimbus",{"I'm researching enterprise intelligence platforms and want to know how Nimbus combines perception, collaboration, and autonomous agents to drive strategic decision-making":134,"platforms":136},{" Summarize the highlights from Nimbus's website":135},"https://gonimbus.ai",[137,142,147,152,157],{"name":138,"label":139,"icon":140,"hrefPrefix":141},"chatgpt","ChatGPT","simple-icons:openai","https://chatgpt.com/?prompt=",{"name":143,"label":144,"icon":145,"hrefPrefix":146},"perplexity","Perplexity","mdi:magnify","https://www.perplexity.ai/search/new?q=",{"name":148,"label":149,"icon":150,"hrefPrefix":151},"grok","Grok","simple-icons:x","https://x.com/i/grok?text=",{"name":153,"label":154,"icon":155,"hrefPrefix":156},"claude","Claude","simple-icons:anthropic","https://claude.ai/new?q=",{"name":158,"label":159,"icon":160,"hrefPrefix":161},"google-ai","Google AI","simple-icons:google","https://www.google.com/search?udm=50&aep=11&q=","content/shared/nav.md","Site navigation",false,null,{"type":167,"value":168,"toc":169},"minimark",[],{"title":170,"searchDepth":171,"depth":171,"links":172},"",2,[],"md","/shared/nav",{"title":163,"description":170},"shared/nav","rDEv5cVG6P2l9ATcdQv2n6VOQiSL5ioOutyfvGevcD0",{"id":179,"title":180,"archived":164,"authors":181,"badge":184,"body":186,"date":825,"definedTerm":165,"department":165,"description":826,"extension":173,"eyebrow":165,"faqHeader":165,"faqs":165,"footerBand":165,"headline":165,"image":165,"industry":165,"jobType":165,"listed":164,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":827,"relatedHeading":165,"seo":828,"series":829,"sitemap":130,"status":165,"stem":830,"subhead":165,"tags":831,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":835},"content/blog/agent-harness-vs-agent-framework.md","Agent Harness vs Agent Framework",[182],{"name":183,"to":135},"Nimbus Research",{"label":185},"Explainer",{"type":167,"value":187,"toc":807},[188,201,237,258,261,266,325,339,343,352,355,369,386,394,398,404,418,440,455,461,471,482,499,506,510,540,547,551,561,573,580,588,599,615,622,627,630,638,642,647,654,658,666,670,673,677,680,684,692,696,704,708,717,721],[189,190,191,192,196,197,200],"p",{},"An ",[193,194,195],"strong",{},"agent framework"," is a library for composing models, tools, and control flow. An ",[193,198,199],{},"agent harness"," is the running environment around a model: the loop, the tools as they are actually granted, the stops, the sensors, and the identity that production will use.",[189,202,203,210,211,214,215,219,220,225,226,231,232,236],{},[204,205,209],"a",{"href":206,"rel":207},"https://docs.langchain.com/oss/python/langchain/agents",[208],"nofollow","LangChain’s own docs"," are careful with the words. ",[193,212,213],{},"Agent = Model + Harness."," ",[216,217,218],"code",{},"create_agent"," is “a highly configurable harness.” ",[204,221,224],{"href":222,"rel":223},"https://github.com/langchain-ai/deepagents",[208],"Deep Agents"," is “the batteries-included agent harness.” ",[204,227,230],{"href":228,"rel":229},"https://docs.langchain.com/oss/python/langgraph/overview",[208],"LangGraph"," is the low-level orchestration framework when the built-in loop is the wrong shape. That taxonomy is the whole article: a framework can ",[233,234,235],"em",{},"implement"," a harness. Shipping the pip package does not mean you have one operators can hire.",[189,238,239,244,245,247,248,252,253,257],{},[204,240,243],{"href":241,"rel":242},"https://www.langchain.com/blog/how-to-build-a-custom-agent-harness",[208],"LangChain’s custom-harness post"," says the same from the other side. Pre-assembled harnesses (Deep Agents, Claude Agent SDK) get you to a working agent fast. ",[216,246,218],{}," is minimal on purpose: core loop plus middleware. You still choose tools, guardrails, and business logic. CrewAI, Semantic Kernel, AutoGen, and Pydantic AI live in this neighbourhood. They are how engineers assemble loops. They are not a substitute for ",[204,249,251],{"href":250},"what-is-write-back-governance","write-back governance",", a ",[204,254,256],{"href":255},"what-is-an-ai-workstream","workstream",", or a ledger.",[189,259,260],{},"Claude Code and Cursor are harnesses you run, not frameworks you import. Nimbus, Palantir AIP, and Agentforce are (different) harnesses you run for company jobs. Confusing “we use LangGraph” with “we have an enterprise harness” is the 2026 version of “we use Kubernetes” meaning “we have a product.”",[262,263,265],"h2",{"id":264},"words-youll-hear","Words you’ll hear",[267,268,269,276,290,302,308,314],"ul",{},[270,271,272,275],"li",{},[193,273,274],{},"Framework."," SDKs and graphs: LangChain, LangGraph, CrewAI, AutoGen, Semantic Kernel, Pydantic AI. You write code. You own production identity unless you add it.",[270,277,278,281,282,286,287,289],{},[193,279,280],{},"Harness."," Runtime around the model. ",[204,283,285],{"href":284},"what-is-an-agent-harness","What is an agent harness",". May be a product (Claude Code) or a configured framework (your ",[216,288,218],{}," plus hooks plus IdP).",[270,291,292,295,296,301],{},[193,293,294],{},"Middleware / hooks."," Framework primitive that becomes harness behaviour when it always runs. LangChain middleware; ",[204,297,300],{"href":298,"rel":299},"https://code.claude.com/docs/en/hooks",[208],"Claude Code hooks",".",[270,303,304,307],{},[193,305,306],{},"Batteries-included harness."," Deep Agents, Claude Agent SDK, Codex SDK. Opinionated loop, filesystem, subagents, compaction. Still not your CRM grant model.",[270,309,310,313],{},[193,311,312],{},"Orchestration framework."," LangGraph when you need deterministic nodes mixed with agentic ones. Powerful. Easy to put the orchestrator in a system prompt and call it done.",[270,315,316,319,320,324],{},[193,317,318],{},"MCP."," Plug. ",[204,321,323],{"href":322},"what-is-model-context-protocol","What is Model Context Protocol",". Works behind frameworks and products. Does not choose the framework/harness cut.",[189,326,327,328,331,332,334,335,301],{},"In Nimbus you do not import a graph to start a job. You assign an ",[204,329,330],{"href":20},"agent team"," on a ",[204,333,256],{"href":32},". Under the hood there is still a loop, tools, and stops — a harness. The product choice is whether operators must be graph authors. ",[204,336,338],{"href":337},"self-service-vs-forward-deployed-ai-platforms","Self-service vs forward-deployed",[262,340,342],{"id":341},"why-you-should-care","Why you should care",[189,344,345,346,351],{},"Engineers will prefer frameworks. They should. Control, portability, tests in CI. Operators and Legal will prefer a harness they can inspect without a pull request. ",[204,347,350],{"href":348,"rel":349},"https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai",[208],"McKinsey"," keeps showing isolated technical use without operating-model change. A beautiful LangGraph in a platform team’s repo is still isolated use if RevOps cannot attach Salesforce or refuse a write.",[189,353,354],{},"It affects you if:",[267,356,357,360,363,366],{},[270,358,359],{},"the RFP says “must support LangChain” as if that were a control",[270,361,362],{},"a vendor says “model-agnostic framework” and prices seats on one flagship",[270,364,365],{},"you are asked to rebuild quoting and SoD because “we already have agents in Python”",[270,367,368],{},"security reviews the GitHub org and never reviews who can call PATCH",[189,370,371,376,377,380,381,385],{},[204,372,375],{"href":373,"rel":374},"https://genai.owasp.org/llm-top-10/",[208],"OWASP’s LLM Top 10"," excessive agency shows up in both: a framework that exposes every tool by default, or a product that does. The cut is not safety vs convenience. It is ",[233,378,379],{},"who can change the harness when it fails"," — ",[204,382,384],{"href":383},"what-is-harness-engineering","harness engineering"," — and whether a fail-closed write exists.",[189,387,388,393],{},[204,389,392],{"href":390,"rel":391},"https://www.nist.gov/itl/ai-risk-management-framework",[208],"NIST AI RMF"," Map/Measure need a system boundary. “Our framework” is not a boundary. A named runtime with grants and logs is.",[262,395,397],{"id":396},"the-practical-differences","The practical differences",[189,399,400,403],{},[193,401,402],{},"Who authors the loop."," Framework: software engineers. Product harness: operators (and maybe SE for custom tools). If only engineers can add a sensor, you will wait on a sprint for a Legal rule.",[189,405,406,409,410,413,414,417],{},[193,407,408],{},"Where identity lives."," Framework default: service account in ",[216,411,412],{},".env",". Product harness: org roster, workstream membership, OAuth grants. You ",[233,415,416],{},"can"," do the latter in LangGraph. You must build it.",[189,419,420,423,424,429,430,435,436,439],{},[193,421,422],{},"What “done” means."," Framework: your node returned. Inner product harness: tests / hook. Outer product harness: signer. Anthropic’s ",[204,425,428],{"href":426,"rel":427},"https://www.anthropic.com/engineering/building-effective-agents",[208],"effective agents"," and ",[204,431,434],{"href":432,"rel":433},"https://www.anthropic.com/engineering/effective-harnesses-for-long-running-agents",[208],"long-running harness"," notes are about encoding done in the ",[233,437,438],{},"environment",". Frameworks give you the primitives; they do not know your done.",[189,441,442,445,446,449,450,454],{},[193,443,444],{},"Portability."," Frameworks win on model swap ",[233,447,448],{},"if"," tools and middleware stay. Product harnesses win if they actually route and do not bury a flagship default in a seat. ",[204,451,453],{"href":452},"what-is-model-routing","Model routing",". “We wrap LangChain” is not routing.",[189,456,457,460],{},[193,458,459],{},"Eval."," Frameworks shine in unit tests of nodes. Inner harnesses shine on SWE-bench / Terminal-Bench. Enterprise harnesses shine when quote hash equals SoR row. Different CI.",[189,462,463,466,467,301],{},[193,464,465],{},"Time-to-first-governed-write."," Framework: months unless you already built the interceptor. Forward-deployed OS: months of people. Self-service outer harness: the product’s week-one claim — verify it. ",[204,468,470],{"href":469},"how-to-run-an-enterprise-ai-proof-of-value","Proof of value",[189,472,473,476,477,481],{},[193,474,475],{},"Lock-in."," Framework lock-in is code and patterns. Product lock-in is data, graph, and operating habits. Both are real. ",[204,478,480],{"href":479},"how-to-solve-model-lock-in","How to solve model lock-in"," is the model slice; harness lock-in is the loop slice. Prefer quoted payloads and exportable ledgers either way.",[189,483,484,485,490,491,494,495,301],{},"LangChain is not the villain. Their ",[204,486,489],{"href":487,"rel":488},"https://www.langchain.com/blog/the-anatomy-of-an-agent-harness",[208],"anatomy post"," is one of the clearer public derivations of harness parts. Use it. Then ask whether your ",[233,492,493],{},"deployment"," has those parts for the job you are buying — repo or company. ",[204,496,498],{"href":497},"inner-vs-outer-agent-harness","Inner vs outer",[189,500,501,502,505],{},"Nimbus’s bet is that most operators should not author LangGraph to update a discount cap. The wiki and the gate should move. Teams that ",[233,503,504],{},"should"," author graphs (unique simulation, exotic tools) can still sit behind a connector. Framework inside a harness. Not a framework instead of one.",[262,507,509],{"id":508},"a-decision-rule","A decision rule",[267,511,512,518,524,534],{},[270,513,514,517],{},[193,515,516],{},"Building a product or a unique workflow in code, with engineers on the hook:"," framework (or SDK harness) plus your own grants and evals.",[270,519,520,523],{},[193,521,522],{},"Hiring a loop for a repository:"," inner product harness (Claude Code, Cursor, Codex). Optionally extend with a framework for custom tools.",[270,525,526,214,529,533],{},[193,527,528],{},"Hiring a loop for CRM/ERP/cross-department work:",[204,530,532],{"href":531},"what-is-an-enterprise-agent-harness","enterprise agent harness"," / OS-class product. A framework is a build programme.",[270,535,536,539],{},[193,537,538],{},"Vendor says “we are a framework and an OS”:"," make them show a failed unsigned write and an operator-attached connector. Words are cheap.",[189,541,542,546],{},[204,543,545],{"href":544},"build-vs-buy-an-enterprise-ai-os","Build vs buy an enterprise AI OS"," is the longer form of the third bullet.",[262,548,550],{"id":549},"what-each-layer-of-the-stack-is-for","What each layer of the stack is for",[189,552,553,554,557,558,560],{},"LangChain’s own split is the cleanest vendor-native map: use Deep Agents when you want a batteries-included ",[233,555,556],{},"harness","; use ",[216,559,218],{}," when you want a minimal harness you customise with middleware; drop to LangGraph when the agent loop is the wrong shape and you need deterministic nodes mixed with agentic ones; use LangSmith to trace whatever you built. That is a builder’s menu. It does not decide whether RevOps can refuse a write.",[189,562,563,564,567,568,572],{},"CrewAI is a role-and-task framework. AutoGen is a conversation-of-agents framework. Semantic Kernel is Microsoft’s orchestration SDK. Pydantic AI moved toward a “harness-first” design in 2026 (capabilities as tools + hooks + instructions). None of these are wrong. All of them leave identity, SoR quoting, and operator self-service as ",[233,565,566],{},"your"," story unless you add them. ",[204,569,571],{"href":373,"rel":570},[208],"OWASP"," will still fail you if the first graph you merge attaches every production tool “so the demo looks alive.”",[189,574,575,576,579],{},"Product harnesses fail the other way: they hide the graph so operators can work, then surprise engineers who wanted to unit-test a node. Demand an escape hatch — export traces, typed payloads, maybe a documented tool SDK — without requiring every discount cap to be a pull request. Nimbus’s bet is that the cap lives in the ",[204,577,578],{"href":28},"wiki"," and the interceptor, and that engineers who need a custom simulator put it behind a connector. Framework inside the harness.",[189,581,582,587],{},[204,583,586],{"href":584,"rel":585},"https://www.thoughtworks.com/insights/articles/operating-system-enterprise-ai",[208],"Thoughtworks"," would say a company that standardises on LangGraph has invested in layer 2 (builder) and still has to build layers 3–4 (user guides/sensors, organisational ownership). A company that buys only a coding harness has a strong inner layer 2–3 and a missing outer layer 4. A company that buys an OS-class product is hoping layer 3–4 shipped. Verify with a refused write, not with a README.",[189,589,590,593,594,598],{},[193,591,592],{},"Cost of the wrong cut."," Framework-first for operators: six months of platform work, then shadow copilots anyway. Product-first for a unique research loop: you will fight the product and rebuild the graph in Python by week four. ",[204,595,597],{"href":596},"how-to-choose-between-a-coding-harness-and-an-enterprise-harness","How to choose coding vs enterprise"," plus this page: workspace first, then assemble vs hire.",[189,600,601,604,605,607,608,610,611,614],{},[193,602,603],{},"Portability, honestly."," Frameworks make model swap easier ",[233,606,448],{}," you used their model interface and did not sprinkle vendor-specific tool formats through application code. Products make operator ratchet easier ",[233,609,448],{}," adding a gate is a UI action. Neither gives you portability of ",[233,612,613],{},"decisions"," unless the ledger exports. Ask for JSON of the quote and the graph, not a promise of “open.”",[189,616,617,618,621],{},"Inngest and others have argued that durable execution needs “a harness, not a framework”: retries, state, and recovery as infrastructure. That slogan is directionally right for production. It is incomplete for enterprises. Durable retries of an ",[233,619,620],{},"unsigned"," write are a reliable incident. The outer harness adds identity and a stop that retries must not bypass. LangGraph checkpointing is excellent loop infrastructure. It is not a Finance signer.",[189,623,624,625,301],{},"A worked split: the data-science team builds a forecasting graph in LangGraph, evaluates it with their own sensors, exposes it as a tool. RevOps never opens the repo. They brief a workstream, the team calls the forecast tool under read scope, and any CRM write still quotes in the product interceptor. Framework for the specialist. Harness for the company job. Nimbus is the second box; it should consume the first as a connector, not replace the scientists’ graph. ",[204,626,50],{"href":51},[189,628,629],{},"If your platform team’s OKR is “stand up LangChain,” add a second OKR: “unsigned SoR writes are impossible.” The first without the second is a framework programme. The second without any loop is a policy PDF. You need both, in that order of safety.",[189,631,632,633,637],{},"CrewAI marketing will talk about roles. Roles in a YAML file are not roster identity. If the “legal reviewer” crew member can still call the same Salesforce write tool as the “AE,” you have a framework demo of ",[204,634,636],{"href":635},"agent-team-architecture","agent teams"," without the contract. Ask to see the tool belt per role, then ask what happens when you remove the write tool from legal and the model asks for it anyway. The harness answer is refuse. The framework-only answer is often “we’ll prompt it.”",[262,639,641],{"id":640},"questions-people-actually-ask","Questions people actually ask",[643,644,646],"h3",{"id":645},"is-langgraph-a-harness","Is LangGraph a harness?",[189,648,649,650,653],{},"It is a framework for building one. Your graph ",[233,651,652],{},"becomes"," a harness when it owns tool dispatch, bounds, and (for production) identity and sensors. Empty graph ≠ harness.",[643,655,657],{"id":656},"is-claude-code-a-framework","Is Claude Code a framework?",[189,659,660,661,301],{},"No. It is a productised inner harness. The Agent SDK is the embeddable form — closer to HaaS in ",[204,662,665],{"href":663,"rel":664},"https://addyosmani.com/blog/agent-harness-engineering/",[208],"Osmani’s sense",[643,667,669],{"id":668},"does-mcp-replace-both","Does MCP replace both?",[189,671,672],{},"No. Plumbing. Hosts still need a loop and grants.",[643,674,676],{"id":675},"we-already-standardised-on-crewai","We already standardised on CrewAI.",[189,678,679],{},"Keep it for the jobs engineers should own. Do not force RevOps to write crews for a renewal write. Put CrewAI behind a scoped tool if the outer harness needs that specialist.",[643,681,683],{"id":682},"how-do-we-evaluate-a-vendor-who-wraps-langchain","How do we evaluate a vendor who wraps LangChain?",[189,685,686,687,691],{},"Ignore the wrapper. Run ",[204,688,690],{"href":689},"how-to-evaluate-an-agent-harness","how to evaluate an agent harness",". If they cannot refuse a write, you evaluated a demo of a framework.",[643,693,695],{"id":694},"where-does-nimbus-sit","Where does Nimbus sit?",[189,697,698,699,701,702,301],{},"Productised outer harness, not a LangChain distribution. ",[204,700,11],{"href":12},". You should still allow inner harnesses for code. ",[204,703,597],{"href":596},[262,705,707],{"id":706},"related-reading","Related reading",[189,709,710,429,713,301],{},[204,711,712],{"href":383},"What is harness engineering",[204,714,716],{"href":715},"how-to-evaluate-multi-agent-platforms","How to evaluate multi-agent platforms",[262,718,720],{"id":719},"sources","Sources",[267,722,723,729,735,741,747,753,759,765,771,777,783,789,794,800],{},[270,724,725],{},[204,726,728],{"href":206,"rel":727},[208],"LangChain, Agents",[270,730,731],{},[204,732,734],{"href":241,"rel":733},[208],"LangChain, How to build a custom agent harness",[270,736,737],{},[204,738,740],{"href":487,"rel":739},[208],"LangChain, The anatomy of an agent harness",[270,742,743],{},[204,744,746],{"href":228,"rel":745},[208],"LangChain, LangGraph overview",[270,748,749],{},[204,750,752],{"href":222,"rel":751},[208],"LangChain Deep Agents",[270,754,755],{},[204,756,758],{"href":584,"rel":757},[208],"Thoughtworks, The operating system for enterprise AI",[270,760,761],{},[204,762,764],{"href":663,"rel":763},[208],"Addy Osmani, Agent harness engineering",[270,766,767],{},[204,768,770],{"href":426,"rel":769},[208],"Anthropic, Building effective agents",[270,772,773],{},[204,774,776],{"href":432,"rel":775},[208],"Anthropic, Effective harnesses for long-running agents",[270,778,779],{},[204,780,782],{"href":298,"rel":781},[208],"Claude Code, Hooks",[270,784,785],{},[204,786,788],{"href":348,"rel":787},[208],"McKinsey, The state of AI in 2025",[270,790,791],{},[204,792,392],{"href":390,"rel":793},[208],[270,795,796],{},[204,797,799],{"href":373,"rel":798},[208],"OWASP Top 10 for LLM applications",[270,801,802],{},[204,803,806],{"href":804,"rel":805},"https://modelcontextprotocol.io/specification/2025-11-25/index",[208],"Model Context Protocol specification",{"title":170,"searchDepth":171,"depth":171,"links":808},[809,810,811,812,813,814,823,824],{"id":264,"depth":171,"text":265},{"id":341,"depth":171,"text":342},{"id":396,"depth":171,"text":397},{"id":508,"depth":171,"text":509},{"id":549,"depth":171,"text":550},{"id":640,"depth":171,"text":641,"children":815},[816,818,819,820,821,822],{"id":645,"depth":817,"text":646},3,{"id":656,"depth":817,"text":657},{"id":668,"depth":817,"text":669},{"id":675,"depth":817,"text":676},{"id":682,"depth":817,"text":683},{"id":694,"depth":817,"text":695},{"id":706,"depth":171,"text":707},{"id":719,"depth":171,"text":720},"2026-08-24","An agent framework is a library for assembling a loop. An agent harness is the loop you can actually run — tools, stops, identity, and sensors included. LangChain helps you build one; it is not, by itself, one you can hire.","/blog/agent-harness-vs-agent-framework",{"title":180,"description":826},"explainer","blog/agent-harness-vs-agent-framework",[829,832,833,834],"agent-harness","langchain","frameworks","gXCxGnvUDv02K2_Jxwj878jpKQQXGyrZ7s3d5hNjYZA",{"hero":837,"id":839,"title":840,"archived":164,"authors":165,"badge":165,"body":841,"date":165,"definedTerm":165,"department":165,"description":845,"extension":173,"eyebrow":846,"faqHeader":165,"faqs":165,"footerBand":847,"headline":165,"image":165,"industry":165,"jobType":165,"listed":130,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":60,"relatedHeading":853,"seo":854,"series":165,"sitemap":130,"status":165,"stem":855,"subhead":165,"tags":165,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":856},{"filename":838},"u2221455217_Flat_design_of_a_futuristic_minimalist_landscape__5d589295-cdea-4ea9-a262-be766881accf_1.png","content/blog/index.md","Exploring the future of intelligence.",{"type":167,"value":842,"toc":843},[],{"title":170,"searchDepth":171,"depth":171,"links":844},[],"Deep dives into pre-cognitive intelligence, sentient enterprises, and the evolving landscape of AI-driven business transformation.","Latest Research",{"headline":848,"description":849,"primaryLabel":850,"primaryTo":851,"secondaryLabel":852,"secondaryTo":12},"Stay at the frontier.","Subscribe for product updates and new insights.","Subscribe","/newsletter","Explore the platform","More research",{"title":840,"description":845},"blog/index","BFSWGYO9bcTlaulivKYWyg08_DJHsdGg3OC6g_CG1Hw",[858,1526],{"id":859,"title":860,"archived":164,"authors":861,"badge":863,"body":864,"date":825,"definedTerm":165,"department":165,"description":1518,"extension":173,"eyebrow":165,"faqHeader":165,"faqs":165,"footerBand":165,"headline":165,"image":165,"industry":165,"jobType":165,"listed":164,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":1519,"relatedHeading":165,"seo":1520,"series":829,"sitemap":130,"status":165,"stem":1521,"subhead":165,"tags":1522,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":1525},"content/blog/inner-vs-outer-agent-harness.md","Inner vs Outer Agent Harness",[862],{"name":183,"to":135},{"label":185},{"type":167,"value":865,"toc":1501},[866,881,902,925,940,942,1016,1038,1040,1043,1045,1059,1078,1081,1103,1115,1119,1136,1147,1157,1166,1178,1189,1209,1219,1234,1238,1241,1251,1261,1270,1274,1284,1294,1303,1309,1315,1326,1329,1331,1335,1338,1342,1349,1353,1364,1368,1374,1378,1384,1388,1402,1404,1412,1414],[189,867,191,868,871,872,875,876,880],{},[193,869,870],{},"inner agent harness"," is the runtime around a model for a developer and a codebase. An ",[193,873,874],{},"outer agent harness"," is the runtime around a model for operators and live business systems. Same equation — ",[204,877,879],{"href":206,"rel":878},[208],"Agent = Model + Harness"," — different workspace, different sensors, different stop.",[189,882,883,888,889,892,893,898,899,301],{},[204,884,887],{"href":885,"rel":886},"https://martinfowler.com/articles/harness-engineering.html",[208],"Böckeler"," already uses “outer harness” for the controls ",[233,890,891],{},"users"," add around a coding agent (guides, sensors) as distinct from the vendor’s built-in loop. ",[204,894,897],{"href":895,"rel":896},"https://addyosmani.com/blog/own-the-outer-loop/",[208],"Addy Osmani"," tells engineers to own the outer loop of investigate → implement → verify so accountability does not dissolve into the model. This article borrows those words and draws the cut enterprises actually buy: ",[193,900,901],{},"repo versus company",[189,903,904,905,908,909,912,913,908,916,920,921,924],{},"Claude Code, Cursor, and Codex are excellent inner harnesses. They sandboxes, ",[216,906,907],{},"apply_patch",", ",[216,910,911],{},"CLAUDE.md"," / ",[216,914,915],{},"AGENTS.md",[204,917,919],{"href":298,"rel":918},[208],"hooks",", and tests. Palantir AIP, Salesforce Agentforce, and OS-class products such as Nimbus are outer harnesses: ",[204,922,923],{"href":255},"workstreams",", connectors, named signers, a decision record. Confusing them is how Legal is asked to “just use Cursor on the Salesforce repo” and how engineering is asked to “approve CRM writes in a coding agent.”",[189,926,927,930,931,935,936,939],{},[204,928,929],{"href":596},"How to choose between a coding harness and an enterprise harness"," is the buying version of this page. ",[204,932,934],{"href":933},"how-to-choose-between-a-copilot-and-a-work-os","How to choose between a copilot and a work OS"," is the adjacent cut (personal assistant versus departmental work). Inner/outer is about ",[233,937,938],{},"which loop you are hiring",", not whether the UI looks like chat.",[262,941,265],{"id":264},[267,943,944,950,956,966,978,987,1003],{},[270,945,946,949],{},[193,947,948],{},"Inner loop (classic SE)."," Edit, build, test on a developer’s machine. Fast. Local. The coding-agent inner harness lives here: shell, files, compiler.",[270,951,952,955],{},[193,953,954],{},"Outer loop (classic SE)."," PR, CI, review, release. Osmani’s “own the outer loop” is this accountability layer for agentic coding. Still software.",[270,957,958,961,962,965],{},[193,959,960],{},"Inner harness (this article)."," Vendor + user controls for a ",[193,963,964],{},"repository workspace",": Claude Code, Cursor, Codex. Eval: tests, Terminal-Bench, SWE-bench.",[270,967,968,971,972,975,976,301],{},[193,969,970],{},"Outer harness (this article)."," Controls for a ",[193,973,974],{},"company workspace",": jobs, systems of record, people who may sign. Eval: quoted write, identity, ledger. An ",[204,977,532],{"href":531},[270,979,980,983,984,301],{},[193,981,982],{},"Guides vs sensors."," Feed-forward markdown versus feedback from tools. Inner: lint and pytest. Outer: schema of a Salesforce payload and a Hard gate. See ",[204,985,986],{"href":383},"what is harness engineering",[270,988,989,992,993,998,999,301],{},[193,990,991],{},"CLAUDE.md / AGENTS.md."," Inner guides. ",[204,994,997],{"href":995,"rel":996},"https://claude.com/blog/steering-claude-code-skills-hooks-rules-subagents-and-more",[208],"Anthropic"," is explicit: files are context; hooks are deterministic. A company wiki is the outer analogue of those files — asserted policy, not a repo README. See ",[204,1000,1002],{"href":1001},"what-is-a-company-wiki-for-ai-agents","What is a company wiki for AI agents",[270,1004,1005,1008,1009,1012,1013,1015],{},[193,1006,1007],{},"Write gate."," Inner: hook denies ",[216,1010,1011],{},"rm"," or force-push. Outer: ",[204,1014,251],{"href":250}," — adapter cannot mutate CRM until a named role signs the quote.",[189,1017,1018,1019,1021,1022,908,1024,1027,1028,1031,1032,1021,1034,1037],{},"Nimbus is built as an outer harness: ",[204,1020,578],{"href":28}," instead of only ",[216,1023,915],{},[204,1025,1026],{"href":51},"connectors"," instead of only a local shell, ",[204,1029,1030],{"href":40},"governance"," instead of only a pre-commit hook, ",[204,1033,23],{"href":24},[216,1035,1036],{},"git log",". Engineering should still run Claude Code. Those products should not share a write path to NetSuite.",[262,1039,342],{"id":341},[189,1041,1042],{},"Demos collapse the cut. Both products answer a question. Both call tools. Both show a transcript. The evaluation is the workspace.",[189,1044,354],{},[267,1046,1047,1050,1053,1056],{},[270,1048,1049],{},"Security asks whether the coding agent’s MCP server can reach production Salesforce",[270,1051,1052],{},"RevOps wants “an agent” and is shown a SWE-bench slide",[270,1054,1055],{},"Engineering wants Cursor and is told to wait for the enterprise OS",[270,1057,1058],{},"You already have both, and they silently write to the same object",[189,1060,1061,1065,1066,1071,1072,1077],{},[204,1062,1064],{"href":348,"rel":1063},[208],"McKinsey’s 2025 State of AI"," describes agentic systems as an organisational design problem. Inner harnesses scale developer throughput. They do not, by themselves, scale governed operations. ",[204,1067,1070],{"href":1068,"rel":1069},"https://hai.stanford.edu/ai-index/2025-ai-index-report",[208],"Stanford HAI’s 2025 AI Index"," maps how fast coding-agent tooling moved. Speed in the repo is not a substitute for ",[204,1073,1076],{"href":1074,"rel":1075},"https://eur-lex.europa.eu/eli/reg/2024/1689/oj",[208],"EU AI Act"," oversight on systems that affect customers and money.",[189,1079,1080],{},"Two failure modes:",[1082,1083,1084,1094],"ol",{},[270,1085,1086,1089,1090,1093],{},[193,1087,1088],{},"Outer job, inner harness."," A pricing change drafted in Cursor with an MCP Salesforce tool. Tests pass on a fixture. Production Amount changes. ",[216,1091,1092],{},"git blame"," does not name the signer. You used a repo loop on a company record.",[270,1095,1096,1099,1100,1102],{},[193,1097,1098],{},"Inner job, outer harness."," “Rewrite this function” opened as a cross-department ",[204,1101,256],{"href":32}," with a Critical gate. Engineers will route around it. You used a company loop on a compile.",[189,1104,1105,1108,1109,1114],{},[204,1106,392],{"href":390,"rel":1107},[208]," Map step: know the context of use. Inner and outer are different contexts. ",[204,1110,1113],{"href":1111,"rel":1112},"https://www.iso.org/standard/42001",[208],"ISO/IEC 42001"," wants controls matched to that context. One harness policy for “all AI” is how both jobs get the wrong stop.",[262,1116,1118],{"id":1117},"what-each-harness-actually-owns","What each harness actually owns",[189,1120,1121,1124,1125,1128,1129,1132,1133,1135],{},[193,1122,1123],{},"Workspace."," Inner: a checkout, often sandboxed. Anthropic’s ",[204,1126,434],{"href":432,"rel":1127},[208]," keeps progress in git and files because the workspace ",[233,1130,1131],{},"is"," the filesystem. Outer: a job folder with people, budget, and attached systems — a ",[204,1134,256],{"href":255},". Files may appear as artefacts. They are not the system of record.",[189,1137,1138,1141,1142,1146],{},[193,1139,1140],{},"Identity."," Inner: the developer’s machine credentials, a repo token, maybe a sandbox role. Outer: org roster, workstream membership, named approver. The model is not the principal. ",[204,1143,1145],{"href":1144},"connector-and-permissions-architecture","Connector and permissions architecture"," is the outer identity plane.",[189,1148,1149,1152,1153,1156],{},[193,1150,1151],{},"Tools."," Inner: shell, editor, tests, browser, maybe MCP to docs. Outer: CRM, ERP, warehouse, ticket systems, mail — default read, write as a separate plane. ",[204,1154,1155],{"href":322},"MCP"," can sit under both. The grant must not.",[189,1158,1159,1162,1163,1165],{},[193,1160,1161],{},"Guides."," Inner: ",[216,1164,915],{},", skills, directory-local rules. Outer: company wiki, playbooks versioned with the run. Mixing them is useful (engineering conventions in the repo; discount policy in the wiki). Collapsing them is how a style guide becomes “legal approval.”",[189,1167,1168,1171,1172,1177],{},[193,1169,1170],{},"Sensors."," Inner: typechecker, unit tests, CI, architecture tests. Böckeler and ",[204,1173,1176],{"href":1174,"rel":1175},"https://www.thoughtworks.com/en-us/insights/blog/generative-ai/harness-engineering-agent-feedback-exploring-ai-coding-sensors",[208],"Thoughtworks on sensors",". Outer: payload schema, blast-radius cardinality, maker-checker, exportable ledger. A passing pytest does not mean Opportunity.Stage was authorised.",[189,1179,1180,1183,1184,1188],{},[193,1181,1182],{},"Stop."," Inner: tests red, hook exit 2, max steps, human in the IDE. Outer: wait-for-named-signer, missing connector, budget, reject. ",[204,1185,1187],{"href":1186},"what-is-human-in-the-loop-ai","Human-in-the-loop"," in a coding agent is “the developer kept going.” HITL in an outer harness is a first-class step with identity.",[189,1190,1191,1162,1193,908,1198,1203,1204,1208],{},[193,1192,459],{},[204,1194,1197],{"href":1195,"rel":1196},"https://www.swebench.com/",[208],"SWE-bench",[204,1199,1202],{"href":1200,"rel":1201},"https://arxiv.org/abs/2601.11868",[208],"Terminal-Bench",", your suite. Outer: replay the signer; compare quote to SoR; see ",[204,1205,1207],{"href":1206},"eval-loops-for-enterprise-agent-harnesses","eval loops",". Leaderboard scores are not a SOX control.",[189,1210,1211,1214,1215,1218],{},[193,1212,1213],{},"Memory."," Inner: files, commits, session transcripts, memory files the next coding session loads. Outer: wiki + ",[204,1216,23],{"href":1217},"what-is-a-lifecycle-graph"," so next quarter’s operator can ask why a field changed. Chat logs of a coding session are not institutional memory for RevOps.",[189,1220,1221,1222,1224,1225,1228,1229,1233],{},"Nimbus’s ",[204,1223,636],{"href":20}," sit on the outer side: mandates, required connectors, approval triggers. You can still ",[233,1226,1227],{},"use"," an inner harness as a bounded tool behind a connector (for example a coding agent that only opens a draft PR). Do not let that inner harness become the orchestrator of record for a CRM write. ",[204,1230,1232],{"href":1231},"multi-agent-ai-architecture","Multi-agent architecture"," says the same thing with specialists: hands are not roles.",[262,1235,1237],{"id":1236},"how-they-should-sit-together","How they should sit together",[189,1239,1240],{},"Most companies need both. That is not a hedge. It is how software and operations already split.",[189,1242,1243,1246,1247,1250],{},[193,1244,1245],{},"Pattern that works."," Engineers use Cursor or Claude Code on application repos. CI remains the merge sensor. Separately, RevOps and Finance run outer-harness jobs on Salesforce and NetSuite. If a coding agent must touch a live business system, it proposes an artefact; the outer harness quotes and gates the write. Two writers to the same object without a single quote is the failure ",[204,1248,1249],{"href":1231},"multi-agent architecture"," already names.",[189,1252,1253,1256,1257,301],{},[193,1254,1255],{},"Pattern that fails."," One MCP mesh with production tokens, used from the IDE and from the chatbot and from the OS. Confused deputy. ",[204,1258,1260],{"href":1259},"mcp-for-enterprise-integrations","MCP for enterprise integrations",[189,1262,1263,1266,1267,301],{},[193,1264,1265],{},"Thoughtworks’ four layers"," — model, builder harness, user harness, organisational harness — map cleanly: Claude Code is builder + user on the inner side; the organisational layer is the outer operating model. Nimbus is one productisation of that outer layer, not the only one. AIP is a programme-shaped outer harness. Agentforce is CRM-anchored. Score scope and time-to-value separately. See ",[204,1268,1269],{"href":337},"self-service vs forward-deployed",[262,1271,1273],{"id":1272},"a-week-that-uses-both","A week that uses both",[189,1275,1276,1277,1279,1280,1283],{},"Monday an engineer uses Cursor to fix a pricing calculator in the billing service. ",[216,1278,915],{}," says no raw SQL in the request path. A hook blocks ",[216,1281,1282],{},"git push --force",". CI runs the unit suite. The PR is the artefact. CODEOWNERS signs the merge. That is a complete inner story. SWE-bench is relevant only as a vendor quality signal for the coding tool, not as a control.",[189,1285,1286,1287,1289,1290,1293],{},"Tuesday RevOps needs the list price on twenty renewals updated after Legal changed the cap in the playbook. The artefact is Salesforce. The signer is a named RevOps lead. The sensor is: quoted fields, hash, read-back. If Tuesday’s job is opened as a Cursor session with an MCP Salesforce server using a shared integration user, you have imported Monday’s workspace into Tuesday’s system of record. ",[216,1288,1036],{}," will not name the RevOps lead. ",[204,1291,1292],{"href":250},"Write-back"," did not fire because the inner harness does not have that interceptor.",[189,1295,1296,1297,1299,1300,1302],{},"Wednesday someone proposes “one agent for everything.” The honest architecture is: Monday’s harness stays. Tuesday’s job runs on an outer harness — in Nimbus, a ",[204,1298,256],{"href":32}," with the CRM connector, the wiki revision that contains the new cap, a Hard gate. If the calculator ",[233,1301,216],{}," must change as well, the outer job can spawn a bounded inner step that opens a draft PR. Two artefacts, two sensors, one company rule: unsigned SoR writes are impossible from either loop.",[189,1304,1305,1306,301],{},"Thursday Security reviews MCP. The question is not “is MCP approved.” It is “which workspace may this server mutate.” Inner: sandbox and repo. Outer: workstream grant. Same protocol, different identity box. ",[204,1307,1308],{"href":1259},"MCP for enterprise",[189,1310,1311,1312,301],{},"Friday you look at evals. Engineering posts a Terminal-Bench plot for the coding vendor. Finance asks who signed Amount. Those are not competing dashboards. They are different oracles. ",[204,1313,1314],{"href":1206},"Eval loops",[189,1316,1317,1320,1321,1325],{},[204,1318,586],{"href":584,"rel":1319},[208]," would call Monday layers 2–3 on a builder harness, Tuesday a delegation question on layer 4, and “one agent” a way to skip layer 4. ",[204,1322,1324],{"href":895,"rel":1323},[208],"Osmani"," would say engineering still owns verify-and-merge on Monday. Neither author is selling Nimbus. Both are describing why the cut exists.",[189,1327,1328],{},"If you only fund inner harnesses, Tuesday happens in paste and Slack. If you only fund outer harnesses, Monday happens in unsanctioned Cursor anyway. Fund both. Bind writes.",[262,1330,641],{"id":640},[643,1332,1334],{"id":1333},"is-cursor-an-enterprise-harness-if-we-sso-it","Is Cursor an enterprise harness if we SSO it?",[189,1336,1337],{},"SSO is admin control. It does not quote a NetSuite journal or bind a Finance signer. Cursor can be an inner harness in an enterprise. That is not the same as an outer harness.",[643,1339,1341],{"id":1340},"can-claude-code-hooks-replace-write-back-governance","Can Claude Code hooks replace write-back governance?",[189,1343,1344,1345,1348],{},"They can replace ",[233,1346,1347],{},"some"," inner invariants (dangerous bash). They do not give you a payload in the language of Salesforce, a roster-aware approver, or an exportable operations ledger. Different workspace.",[643,1350,1352],{"id":1351},"should-we-ban-coding-agents-until-the-os-is-live","Should we ban coding agents until the OS is live?",[189,1354,1355,1356,1359,1360,301],{},"Usually no. Ban unsigned writes to systems of record from ",[233,1357,1358],{},"any"," agent, inner or outer. Let inner harnesses keep compiling. ",[204,1361,1363],{"href":1362},"how-to-solve-unapproved-crm-writes-from-ai","How to solve unapproved CRM writes from AI",[643,1365,1367],{"id":1366},"where-does-a-copilot-fit","Where does a copilot fit?",[189,1369,1370,1371,301],{},"A copilot is often not a full inner harness — no repo loop, no tests. Personal throughput. Keep it for mail. Do not give it the CRM write token. ",[204,1372,1373],{"href":933},"Copilot vs work OS",[643,1375,1377],{"id":1376},"is-nimbus-trying-to-replace-claude-code","Is Nimbus trying to replace Claude Code?",[189,1379,1380,1381,1383],{},"No. Different workspace. Nimbus is the company loop; Claude Code is the repo loop. ",[204,1382,11],{"href":12}," is the product map. This page is the architectural cut.",[643,1385,1387],{"id":1386},"what-should-i-read-next","What should I read next?",[189,1389,1390,1393,1394,1398,1399,1401],{},[204,1391,1392],{"href":531},"What is an enterprise agent harness",". ",[204,1395,1397],{"href":1396},"agent-harness-vs-agent-framework","Agent harness vs agent framework"," if you are assembling rather than hiring. ",[204,1400,285],{"href":284}," for the base noun.",[262,1403,707],{"id":706},[189,1405,1406,429,1408,301],{},[204,1407,712],{"href":383},[204,1409,1411],{"href":1410},"agent-harness-architecture","Agent harness architecture",[262,1413,720],{"id":719},[267,1415,1416,1421,1427,1433,1438,1443,1448,1454,1459,1464,1470,1475,1481,1486,1491,1496],{},[270,1417,1418],{},[204,1419,728],{"href":206,"rel":1420},[208],[270,1422,1423],{},[204,1424,1426],{"href":885,"rel":1425},[208],"Böckeler, Harness engineering for coding agent users",[270,1428,1429],{},[204,1430,1432],{"href":895,"rel":1431},[208],"Addy Osmani, Own the outer loop",[270,1434,1435],{},[204,1436,764],{"href":663,"rel":1437},[208],[270,1439,1440],{},[204,1441,758],{"href":584,"rel":1442},[208],[270,1444,1445],{},[204,1446,776],{"href":432,"rel":1447},[208],[270,1449,1450],{},[204,1451,1453],{"href":995,"rel":1452},[208],"Anthropic, Steering Claude Code",[270,1455,1456],{},[204,1457,782],{"href":298,"rel":1458},[208],[270,1460,1461],{},[204,1462,1197],{"href":1195,"rel":1463},[208],[270,1465,1466],{},[204,1467,1469],{"href":1200,"rel":1468},[208],"Terminal-Bench (arXiv:2601.11868)",[270,1471,1472],{},[204,1473,788],{"href":348,"rel":1474},[208],[270,1476,1477],{},[204,1478,1480],{"href":1068,"rel":1479},[208],"Stanford HAI, 2025 AI Index",[270,1482,1483],{},[204,1484,392],{"href":390,"rel":1485},[208],[270,1487,1488],{},[204,1489,1113],{"href":1111,"rel":1490},[208],[270,1492,1493],{},[204,1494,1076],{"href":1074,"rel":1495},[208],[270,1497,1498],{},[204,1499,806],{"href":804,"rel":1500},[208],{"title":170,"searchDepth":171,"depth":171,"links":1502},[1503,1504,1505,1506,1507,1508,1516,1517],{"id":264,"depth":171,"text":265},{"id":341,"depth":171,"text":342},{"id":1117,"depth":171,"text":1118},{"id":1236,"depth":171,"text":1237},{"id":1272,"depth":171,"text":1273},{"id":640,"depth":171,"text":641,"children":1509},[1510,1511,1512,1513,1514,1515],{"id":1333,"depth":817,"text":1334},{"id":1340,"depth":817,"text":1341},{"id":1351,"depth":817,"text":1352},{"id":1366,"depth":817,"text":1367},{"id":1376,"depth":817,"text":1377},{"id":1386,"depth":817,"text":1387},{"id":706,"depth":171,"text":707},{"id":719,"depth":171,"text":720},"An inner agent harness runs a developer and a repository — CLAUDE.md, hooks, tests. An outer harness runs the company — wiki, connectors, write gates, and a ledger. Most enterprises need both.","/blog/inner-vs-outer-agent-harness",{"title":860,"description":1518},"blog/inner-vs-outer-agent-harness",[829,832,1523,1524],"coding-agents","enterprise-ai","_il0EOS7LGYcsPqRPjgGBR-hd3QC3P9SSGIQjCv3Y0M",{"id":1527,"title":1528,"archived":164,"authors":1529,"badge":1531,"body":1532,"date":1714,"definedTerm":1715,"department":165,"description":1716,"extension":173,"eyebrow":165,"faqHeader":1717,"faqs":1720,"footerBand":165,"headline":165,"image":165,"industry":165,"jobType":165,"listed":164,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":1730,"relatedHeading":165,"seo":1731,"series":829,"sitemap":130,"status":165,"stem":1732,"subhead":165,"tags":1733,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":1735},"content/blog/rbac-for-enterprise-ai.md","What is RBAC for enterprise AI, and why should you care?",[1530],{"name":183,"to":135},{"label":185},{"type":167,"value":1533,"toc":1708},[1534,1537,1540,1548,1552,1561,1572,1575,1589,1592,1596,1605,1608,1622,1625,1629,1632,1635,1658,1664,1668,1675,1688,1696],[189,1535,1536],{},"RBAC means role-based access control: who is allowed to do what. For enterprise AI, the “who” is not only people. It is also the model acting with someone’s credentials — reading files, and sometimes changing a live system.",[189,1538,1539],{},"You should care because a fluent answer can still be the wrong change in the wrong place. Access rules are how you keep AI useful without pretending every user should see every record.",[189,1541,1542,1543,1547],{},"This guide explains the idea, why it shows up in vendor conversations, and a practical way to start. It is not a claim that one product has solved it. ",[204,1544,1546],{"href":1545},"what-is-ai-governance","What is AI governance"," is the parent definition.",[262,1549,1551],{"id":1550},"what-is-rbac-for-enterprise-ai","What is RBAC for enterprise AI?",[189,1553,1554,1555,1560],{},"Classic RBAC, described by Ferraiolo and Kuhn in a ",[204,1556,1559],{"href":1557,"rel":1558},"https://csrc.nist.gov/files/pubs/conference/1992/10/13/rolebased-access-controls/final/docs/ferraiolo-kuhn-92.pdf",[208],"NIST paper"," (1992), assigns permissions to roles, then roles to people. Enterprise AI adds three extra questions:",[267,1562,1563,1566,1569],{},[270,1564,1565],{},"Which jobs and files can this person (and this model) see?",[270,1567,1568],{},"Which tools can it call?",[270,1570,1571],{},"If it can change a live system, who must approve, and is that approval stored?",[189,1573,1574],{},"A chatbot login answers “may this person talk to the bot?” That is necessary. It is not the same as answering the three questions above.",[189,1576,1577,1578,1582,1583,1588],{},"NIST’s ",[204,1579,1581],{"href":390,"rel":1580},[208],"AI Risk Management Framework"," (2023) and ",[204,1584,1587],{"href":1585,"rel":1586},"https://csrc.nist.gov/pubs/sp/800-207/final",[208],"SP 800-207"," (2020) on zero trust are the public-sector language for the same idea: do not assume a session is trusted just because it authenticated.",[189,1590,1591],{},"Guests, members, and admins are the people side of the same idea: who is on the job. The model side is which tools that session may call. Both belong in RBAC. Do not treat a chatbot login as the whole answer.",[262,1593,1595],{"id":1594},"why-should-you-care-about-rbac-for-ai","Why should you care about RBAC for AI?",[189,1597,1598,1599,1604],{},"IBM’s ",[204,1600,1603],{"href":1601,"rel":1602},"https://newsroom.ibm.com/2024-07-30-ibm-report-escalating-data-breach-disruption-pushes-costs-to-new-highs",[208],"Cost of a Data Breach"," report (2024) put the global average breach cost at $4.88 million. You do not need a breach for RBAC to matter. You need a customer record changed without a name next to the change, or a contractor who still sees a workstream after the project ended.",[189,1606,1607],{},"A simple example: a guest from an agency is invited to a campaign workstream. The model in that room can read the CRM export because a member pasted it. When the campaign ends, the guest login is forgotten. The export is still in the history. Roles that follow the job — not only the person — are how you close that gap.",[189,1609,1610,1611,1616,1617,1621],{},"Microsoft and LinkedIn’s ",[204,1612,1615],{"href":1613,"rel":1614},"https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part",[208],"Work Trend Index"," (2024) found that 78% of AI users bring their own tools (BYOAI). That is ",[204,1618,1620],{"href":1619},"what-is-shadow-ai","shadow AI",": useful, and outside the roles you think you assigned.",[189,1623,1624],{},"You should care if you have guests on a job, if AI can write to CRM or finance systems, or if an auditor might ask who approved a machine-initiated change. If AI only summarises public wiki pages, the stakes are lower — you can still use roles so the wiki is not everyone’s dump of customer data.",[262,1626,1628],{"id":1627},"how-do-you-apply-it-when-ai-can-change-records","How do you apply it when AI can change records?",[189,1630,1631],{},"Write-back means the AI changes a live system. Fail-closed means if nobody approves, nothing happens. Payload means the exact change, shown before it goes out.",[189,1633,1634],{},"A practical sequence:",[1082,1636,1637,1644,1647,1655],{},[270,1638,1639,1640,1643],{},"Keep the model from writing until you can name the object class and the signer. ",[204,1641,1642],{"href":250},"Write-back governance"," is the checklist.",[270,1645,1646],{},"For each write, name the approver role — not “the channel”.",[270,1648,1649,1650,1654],{},"Store the payload and the decision so you can reopen them. ",[204,1651,1653],{"href":1652},"what-auditors-are-asking-for","What auditors are asking for"," is the evidence pack.",[270,1656,1657],{},"When someone leaves the job, remove them from the roster the same week.",[189,1659,1660,1663],{},[204,1661,1662],{"href":1619},"Shadow AI"," is what happens when the unofficial path never got those roles.",[262,1665,1667],{"id":1666},"what-should-you-ask-a-vendor","What should you ask a vendor?",[189,1669,1670,1671,1674],{},"A short list of demo questions lives in ",[204,1672,1673],{"href":1652},"what auditors are asking for",". In one sentence: can they show who could see a job, which tool ran, and who approved a write — without a screenshot hunt?",[189,1676,1677,1678,1682,1683,1687],{},"The ",[204,1679,1076],{"href":1680,"rel":1681},"https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689",[208]," (2024/1689) and ",[204,1684,1113],{"href":1685,"rel":1686},"https://www.iso.org/standard/81230.html",[208]," are reasons those questions are showing up in procurement. You do not have to implement every clause on day one. You do need an answer you could give an auditor.",[189,1689,1221,1690,429,1692,1695],{},[204,1691,1030],{"href":40},[204,1693,1694],{"href":54},"security"," pages describe how we approach this. Other vendors will have their own. The useful test is the same: roles on the job, not only on the chat login.",[189,1697,1698,1699,1703,1704,301],{},"For how teams share the job once access is clear, see ",[204,1700,1702],{"href":1701},"what-is-collaborative-ai","what is collaborative AI",". For where the decision should live after the thread ends, see ",[204,1705,1707],{"href":1706},"search-is-not-memory","search is not memory",{"title":170,"searchDepth":171,"depth":171,"links":1709},[1710,1711,1712,1713],{"id":1550,"depth":171,"text":1551},{"id":1594,"depth":171,"text":1595},{"id":1627,"depth":171,"text":1628},{"id":1666,"depth":171,"text":1667},"2026-08-27","RBAC","RBAC is who is allowed to do what. For enterprise AI it has to cover the model as well as the people — what it can read, what it can change, and who can stop it. A plain-language guide.",{"eyebrow":1718,"title":1719},"Short answers","Roles when the user is a model",[1721,1724,1727],{"question":1722,"answer":1723},"Is a shared chatbot login the same as RBAC?","No. A shared login says who can open the chat. RBAC says who can see which jobs, which tools, and which live systems — and whether the model may write at all.",{"question":1725,"answer":1726},"Do we need RBAC if AI is read-only?","You still need it for what the model can see. Read-only reduces the chance of a bad write. It does not decide which customer files belong in whose session.",{"question":1728,"answer":1729},"Where should we start?","Name who can approve a change to a live system, keep AI from writing until that is clear, and list unofficial tools. The auditors guide on this site is a first evidence pack.","/blog/rbac-for-enterprise-ai",{"title":1528,"description":1716},"blog/rbac-for-enterprise-ai",[829,1715,1734],"access","g2P_DB_QD94yq1LoWlZBKGVnScVo4TxpXZx40Kjx12Y",{"enabled":164,"message":1737,"linkLabel":93,"linkHref":94,"id":1738,"title":1739,"archived":164,"authors":165,"badge":165,"body":1740,"date":165,"definedTerm":165,"department":165,"description":170,"extension":173,"eyebrow":165,"faqHeader":165,"faqs":165,"footerBand":165,"headline":165,"image":165,"industry":165,"jobType":165,"listed":130,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":1744,"relatedHeading":165,"seo":1745,"series":165,"sitemap":164,"status":165,"stem":1746,"subhead":165,"tags":165,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":1747},"We're hiring! Join the team building the Sentient Enterprise.","content/shared/hiring.md","Hiring banner",{"type":167,"value":1741,"toc":1742},[],{"title":170,"searchDepth":171,"depth":171,"links":1743},[],"/shared/hiring",{"title":1739,"description":170},"shared/hiring","1zs3boivKda1e-b-hAyuNcmZSKjZUAXmecnwHVgcHzk",{"fold":1749,"id":1753,"title":1754,"archived":164,"authors":165,"badge":165,"body":1755,"date":165,"definedTerm":165,"department":165,"description":170,"extension":173,"eyebrow":165,"faqHeader":165,"faqs":165,"footerBand":1759,"headline":165,"image":165,"industry":165,"jobType":165,"listed":130,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":1763,"relatedHeading":165,"seo":1764,"series":165,"sitemap":164,"status":165,"stem":1765,"subhead":165,"tags":165,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":1766},{"headline":1750,"description":1751,"primaryLabel":8,"primaryTo":1752,"secondaryLabel":852,"secondaryTo":12},"Run frontier AI your business actually owns.","Governed agent swarms, 2,000+ integrations, and a knowledge graph that stays inside your walls. Free 7-day trial.","/checkout","content/shared/cta.md","Site CTAs",{"type":167,"value":1756,"toc":1757},[],{"title":170,"searchDepth":171,"depth":171,"links":1758},[],{"headline":1760,"description":1761,"primaryLabel":8,"primaryTo":1752,"secondaryLabel":1762,"secondaryTo":99},"See what governed AI looks like on your stack.","Connect your tools, run a workstream, and keep every decision on your ledger - free for 7 days.","Talk to our team","/shared/cta",{"title":1754,"description":170},"shared/cta","wz4AdRHnaYH021WMdWcHnZvHmkZJNKaNG4XGZfnFBtw",1788985847315]