[{"data":1,"prerenderedAt":1104},["ShallowReactive",2],{"site-nav-content":3,"blog:/blog/rbac-for-enterprise-ai":178,"blog-index-copy":406,"blog:/blog/rbac-for-enterprise-ai:surround":427,"hiring-banner-content":1073,"site-cta-content":1085},{"header":4,"productNav":9,"nav":42,"footer":61,"askAI":131,"id":162,"title":163,"archived":164,"authors":165,"badge":165,"body":166,"date":165,"definedTerm":165,"department":165,"description":170,"extension":173,"eyebrow":165,"faqHeader":165,"faqs":165,"footerBand":165,"headline":165,"image":165,"industry":165,"jobType":165,"listed":130,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":174,"relatedHeading":165,"seo":175,"series":165,"sitemap":164,"status":165,"stem":176,"subhead":165,"tags":165,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":177},{"productLabel":5,"loginLabel":6,"contactLabel":7,"contactSalesLabel":8},"Product","Log in","Contact","Get started for free",[10,14,18,22,26,30,34,38],{"label":11,"to":12,"description":13},"Overview","/overview","Seven layers. One closed loop.",{"label":15,"to":16,"description":17},"Conflux","/product/conflux","Where your team, workstreams, and agents meet.",{"label":19,"to":20,"description":21},"Agent Teams","/product/agent-teams","Specialist teams - governed from day one.",{"label":23,"to":24,"description":25},"Lifecycle Graph","/product/lifecycle-graph","Intelligence that compounds across every interaction.",{"label":27,"to":28,"description":29},"Company Wiki","/product/wiki","Playbooks and policies where expertise stays.",{"label":31,"to":32,"description":33},"Workstreams","/product/workstreams","From brief to signed-off deliverable on one canvas.",{"label":35,"to":36,"description":37},"Perception Console","/product/perception","Ask your whole business in plain English.",{"label":39,"to":40,"description":41},"Governance","/product/governance","Frontier AI you can actually sign off on.",[43,46,49,52,55,58],{"label":44,"to":45},"Models","/models",{"label":47,"to":48},"Pricing","/pricing",{"label":50,"to":51},"Integrations","/integrations",{"label":53,"to":54},"Security","/security",{"label":56,"to":57},"Partners","/partners",{"label":59,"to":60},"Insights","/blog",{"productHeading":5,"companyHeading":62,"legalHeading":63,"docsLabel":64,"docsUrl":65,"statementLines":66,"copyright":69,"companyLinks":70,"legalLinks":100,"socialLinks":110,"bottomLinks":120},"Company","Legal","Docs","https://docs.gonimbus.ai",[67,68],"Stop training someone else's model.","Control your AI.","© 2026 Nimbus Intelligence, Inc. All rights reserved.",[71,72,73,74,75,78,81,84,87,90,92,95,98],{"label":47,"to":48},{"label":50,"to":51},{"label":53,"to":54},{"label":59,"to":60},{"label":76,"to":77},"Glossary","/glossary",{"label":79,"to":80},"Compare","/compare",{"label":82,"to":83},"Evaluate","/evaluate",{"label":85,"to":86},"Problems","/problems",{"label":88,"to":89},"Use cases","/use-cases",{"label":91,"to":57},"Partner Program",{"label":93,"to":94},"Careers","/careers",{"label":96,"to":97},"System status","/status",{"label":7,"to":99},"/contact",[101,104,107],{"label":102,"to":103},"Terms of Service","/terms",{"label":105,"to":106},"Privacy Policy","/privacy",{"label":108,"to":109},"Compliance","/compliance",[111,114,117],{"label":112,"href":113},"LinkedIn","https://www.linkedin.com/company/gonimbusai/",{"label":115,"href":116},"X","https://x.com/gonimbusai",{"label":118,"href":119},"Instagram","https://www.instagram.com/gonimbus_ai/",[121,123,125,126,127],{"label":122,"to":103},"Terms",{"label":124,"to":106},"Privacy",{"label":108,"to":109},{"label":96,"to":97},{"label":128,"to":129,"external":130},"LLMs.txt","/llms.txt",true,{"text":132,"prompt":133},"Ask AI about Nimbus",{"I'm researching enterprise intelligence platforms and want to know how Nimbus combines perception, collaboration, and autonomous agents to drive strategic decision-making":134,"platforms":136},{" Summarize the highlights from Nimbus's website":135},"https://gonimbus.ai",[137,142,147,152,157],{"name":138,"label":139,"icon":140,"hrefPrefix":141},"chatgpt","ChatGPT","simple-icons:openai","https://chatgpt.com/?prompt=",{"name":143,"label":144,"icon":145,"hrefPrefix":146},"perplexity","Perplexity","mdi:magnify","https://www.perplexity.ai/search/new?q=",{"name":148,"label":149,"icon":150,"hrefPrefix":151},"grok","Grok","simple-icons:x","https://x.com/i/grok?text=",{"name":153,"label":154,"icon":155,"hrefPrefix":156},"claude","Claude","simple-icons:anthropic","https://claude.ai/new?q=",{"name":158,"label":159,"icon":160,"hrefPrefix":161},"google-ai","Google AI","simple-icons:google","https://www.google.com/search?udm=50&aep=11&q=","content/shared/nav.md","Site navigation",false,null,{"type":167,"value":168,"toc":169},"minimark",[],{"title":170,"searchDepth":171,"depth":171,"links":172},"",2,[],"md","/shared/nav",{"title":163,"description":170},"shared/nav","rDEv5cVG6P2l9ATcdQv2n6VOQiSL5ioOutyfvGevcD0",{"id":179,"title":180,"archived":164,"authors":181,"badge":184,"body":186,"date":383,"definedTerm":384,"department":165,"description":385,"extension":173,"eyebrow":165,"faqHeader":386,"faqs":389,"footerBand":165,"headline":165,"image":165,"industry":165,"jobType":165,"listed":164,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":399,"relatedHeading":165,"seo":400,"series":401,"sitemap":130,"status":165,"stem":402,"subhead":165,"tags":403,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":405},"content/blog/rbac-for-enterprise-ai.md","What is RBAC for enterprise AI, and why should you care?",[182],{"name":183,"to":135},"Nimbus Research",{"label":185},"Explainer",{"type":167,"value":187,"toc":377},[188,192,195,204,209,219,232,235,250,253,257,266,269,283,286,290,293,296,321,327,331,338,353,364],[189,190,191],"p",{},"RBAC means role-based access control: who is allowed to do what. For enterprise AI, the “who” is not only people. It is also the model acting with someone’s credentials — reading files, and sometimes changing a live system.",[189,193,194],{},"You should care because a fluent answer can still be the wrong change in the wrong place. Access rules are how you keep AI useful without pretending every user should see every record.",[189,196,197,198,203],{},"This guide explains the idea, why it shows up in vendor conversations, and a practical way to start. It is not a claim that one product has solved it. ",[199,200,202],"a",{"href":201},"what-is-ai-governance","What is AI governance"," is the parent definition.",[205,206,208],"h2",{"id":207},"what-is-rbac-for-enterprise-ai","What is RBAC for enterprise AI?",[189,210,211,212,218],{},"Classic RBAC, described by Ferraiolo and Kuhn in a ",[199,213,217],{"href":214,"rel":215},"https://csrc.nist.gov/files/pubs/conference/1992/10/13/rolebased-access-controls/final/docs/ferraiolo-kuhn-92.pdf",[216],"nofollow","NIST paper"," (1992), assigns permissions to roles, then roles to people. Enterprise AI adds three extra questions:",[220,221,222,226,229],"ul",{},[223,224,225],"li",{},"Which jobs and files can this person (and this model) see?",[223,227,228],{},"Which tools can it call?",[223,230,231],{},"If it can change a live system, who must approve, and is that approval stored?",[189,233,234],{},"A chatbot login answers “may this person talk to the bot?” That is necessary. It is not the same as answering the three questions above.",[189,236,237,238,243,244,249],{},"NIST’s ",[199,239,242],{"href":240,"rel":241},"https://www.nist.gov/itl/ai-risk-management-framework",[216],"AI Risk Management Framework"," (2023) and ",[199,245,248],{"href":246,"rel":247},"https://csrc.nist.gov/pubs/sp/800-207/final",[216],"SP 800-207"," (2020) on zero trust are the public-sector language for the same idea: do not assume a session is trusted just because it authenticated.",[189,251,252],{},"Guests, members, and admins are the people side of the same idea: who is on the job. The model side is which tools that session may call. Both belong in RBAC. Do not treat a chatbot login as the whole answer.",[205,254,256],{"id":255},"why-should-you-care-about-rbac-for-ai","Why should you care about RBAC for AI?",[189,258,259,260,265],{},"IBM’s ",[199,261,264],{"href":262,"rel":263},"https://newsroom.ibm.com/2024-07-30-ibm-report-escalating-data-breach-disruption-pushes-costs-to-new-highs",[216],"Cost of a Data Breach"," report (2024) put the global average breach cost at $4.88 million. You do not need a breach for RBAC to matter. You need a customer record changed without a name next to the change, or a contractor who still sees a workstream after the project ended.",[189,267,268],{},"A simple example: a guest from an agency is invited to a campaign workstream. The model in that room can read the CRM export because a member pasted it. When the campaign ends, the guest login is forgotten. The export is still in the history. Roles that follow the job — not only the person — are how you close that gap.",[189,270,271,272,277,278,282],{},"Microsoft and LinkedIn’s ",[199,273,276],{"href":274,"rel":275},"https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part",[216],"Work Trend Index"," (2024) found that 78% of AI users bring their own tools (BYOAI). That is ",[199,279,281],{"href":280},"what-is-shadow-ai","shadow AI",": useful, and outside the roles you think you assigned.",[189,284,285],{},"You should care if you have guests on a job, if AI can write to CRM or finance systems, or if an auditor might ask who approved a machine-initiated change. If AI only summarises public wiki pages, the stakes are lower — you can still use roles so the wiki is not everyone’s dump of customer data.",[205,287,289],{"id":288},"how-do-you-apply-it-when-ai-can-change-records","How do you apply it when AI can change records?",[189,291,292],{},"Write-back means the AI changes a live system. Fail-closed means if nobody approves, nothing happens. Payload means the exact change, shown before it goes out.",[189,294,295],{},"A practical sequence:",[297,298,299,307,310,318],"ol",{},[223,300,301,302,306],{},"Keep the model from writing until you can name the object class and the signer. ",[199,303,305],{"href":304},"what-is-write-back-governance","Write-back governance"," is the checklist.",[223,308,309],{},"For each write, name the approver role — not “the channel”.",[223,311,312,313,317],{},"Store the payload and the decision so you can reopen them. ",[199,314,316],{"href":315},"what-auditors-are-asking-for","What auditors are asking for"," is the evidence pack.",[223,319,320],{},"When someone leaves the job, remove them from the roster the same week.",[189,322,323,326],{},[199,324,325],{"href":280},"Shadow AI"," is what happens when the unofficial path never got those roles.",[205,328,330],{"id":329},"what-should-you-ask-a-vendor","What should you ask a vendor?",[189,332,333,334,337],{},"A short list of demo questions lives in ",[199,335,336],{"href":315},"what auditors are asking for",". In one sentence: can they show who could see a job, which tool ran, and who approved a write — without a screenshot hunt?",[189,339,340,341,346,347,352],{},"The ",[199,342,345],{"href":343,"rel":344},"https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689",[216],"EU AI Act"," (2024/1689) and ",[199,348,351],{"href":349,"rel":350},"https://www.iso.org/standard/81230.html",[216],"ISO/IEC 42001"," are reasons those questions are showing up in procurement. You do not have to implement every clause on day one. You do need an answer you could give an auditor.",[189,354,355,356,359,360,363],{},"Nimbus’s ",[199,357,358],{"href":40},"governance"," and ",[199,361,362],{"href":54},"security"," pages describe how we approach this. Other vendors will have their own. The useful test is the same: roles on the job, not only on the chat login.",[189,365,366,367,371,372,376],{},"For how teams share the job once access is clear, see ",[199,368,370],{"href":369},"what-is-collaborative-ai","what is collaborative AI",". For where the decision should live after the thread ends, see ",[199,373,375],{"href":374},"search-is-not-memory","search is not memory",".",{"title":170,"searchDepth":171,"depth":171,"links":378},[379,380,381,382],{"id":207,"depth":171,"text":208},{"id":255,"depth":171,"text":256},{"id":288,"depth":171,"text":289},{"id":329,"depth":171,"text":330},"2026-08-27","RBAC","RBAC is who is allowed to do what. For enterprise AI it has to cover the model as well as the people — what it can read, what it can change, and who can stop it. A plain-language guide.",{"eyebrow":387,"title":388},"Short answers","Roles when the user is a model",[390,393,396],{"question":391,"answer":392},"Is a shared chatbot login the same as RBAC?","No. A shared login says who can open the chat. RBAC says who can see which jobs, which tools, and which live systems — and whether the model may write at all.",{"question":394,"answer":395},"Do we need RBAC if AI is read-only?","You still need it for what the model can see. Read-only reduces the chance of a bad write. It does not decide which customer files belong in whose session.",{"question":397,"answer":398},"Where should we start?","Name who can approve a change to a live system, keep AI from writing until that is clear, and list unofficial tools. The auditors guide on this site is a first evidence pack.","/blog/rbac-for-enterprise-ai",{"title":180,"description":385},"explainer","blog/rbac-for-enterprise-ai",[401,384,404],"access","g2P_DB_QD94yq1LoWlZBKGVnScVo4TxpXZx40Kjx12Y",{"hero":407,"id":409,"title":410,"archived":164,"authors":165,"badge":165,"body":411,"date":165,"definedTerm":165,"department":165,"description":415,"extension":173,"eyebrow":416,"faqHeader":165,"faqs":165,"footerBand":417,"headline":165,"image":165,"industry":165,"jobType":165,"listed":130,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":60,"relatedHeading":423,"seo":424,"series":165,"sitemap":130,"status":165,"stem":425,"subhead":165,"tags":165,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":426},{"filename":408},"u2221455217_Flat_design_of_a_futuristic_minimalist_landscape__5d589295-cdea-4ea9-a262-be766881accf_1.png","content/blog/index.md","Exploring the future of intelligence.",{"type":167,"value":412,"toc":413},[],{"title":170,"searchDepth":171,"depth":171,"links":414},[],"Deep dives into pre-cognitive intelligence, sentient enterprises, and the evolving landscape of AI-driven business transformation.","Latest Research",{"headline":418,"description":419,"primaryLabel":420,"primaryTo":421,"secondaryLabel":422,"secondaryTo":12},"Stay at the frontier.","Subscribe for product updates and new insights.","Subscribe","/newsletter","Explore the platform","More research",{"title":410,"description":415},"blog/index","BFSWGYO9bcTlaulivKYWyg08_DJHsdGg3OC6g_CG1Hw",[428,165],{"id":429,"title":430,"archived":164,"authors":431,"badge":433,"body":434,"date":1063,"definedTerm":165,"department":165,"description":1064,"extension":173,"eyebrow":165,"faqHeader":165,"faqs":165,"footerBand":165,"headline":165,"image":165,"industry":165,"jobType":165,"listed":164,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":1065,"relatedHeading":165,"seo":1066,"series":401,"sitemap":130,"status":165,"stem":1067,"subhead":165,"tags":1068,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":1072},"content/blog/agent-harness-vs-agent-framework.md","Agent Harness vs Agent Framework",[432],{"name":183,"to":135},{"label":185},{"type":167,"value":435,"toc":1045},[436,448,482,502,505,509,565,579,583,592,595,609,626,633,637,643,657,678,693,699,709,720,737,744,748,778,785,789,799,811,818,826,837,853,860,865,868,876,880,885,892,896,904,908,911,915,918,922,930,934,942,946,955,959],[189,437,438,439,443,444,447],{},"An ",[440,441,442],"strong",{},"agent framework"," is a library for composing models, tools, and control flow. An ",[440,445,446],{},"agent harness"," is the running environment around a model: the loop, the tools as they are actually granted, the stops, the sensors, and the identity that production will use.",[189,449,450,455,456,459,460,464,465,470,471,476,477,481],{},[199,451,454],{"href":452,"rel":453},"https://docs.langchain.com/oss/python/langchain/agents",[216],"LangChain’s own docs"," are careful with the words. ",[440,457,458],{},"Agent = Model + Harness."," ",[461,462,463],"code",{},"create_agent"," is “a highly configurable harness.” ",[199,466,469],{"href":467,"rel":468},"https://github.com/langchain-ai/deepagents",[216],"Deep Agents"," is “the batteries-included agent harness.” ",[199,472,475],{"href":473,"rel":474},"https://docs.langchain.com/oss/python/langgraph/overview",[216],"LangGraph"," is the low-level orchestration framework when the built-in loop is the wrong shape. That taxonomy is the whole article: a framework can ",[478,479,480],"em",{},"implement"," a harness. Shipping the pip package does not mean you have one operators can hire.",[189,483,484,489,490,492,493,496,497,501],{},[199,485,488],{"href":486,"rel":487},"https://www.langchain.com/blog/how-to-build-a-custom-agent-harness",[216],"LangChain’s custom-harness post"," says the same from the other side. Pre-assembled harnesses (Deep Agents, Claude Agent SDK) get you to a working agent fast. ",[461,491,463],{}," is minimal on purpose: core loop plus middleware. You still choose tools, guardrails, and business logic. CrewAI, Semantic Kernel, AutoGen, and Pydantic AI live in this neighbourhood. They are how engineers assemble loops. They are not a substitute for ",[199,494,495],{"href":304},"write-back governance",", a ",[199,498,500],{"href":499},"what-is-an-ai-workstream","workstream",", or a ledger.",[189,503,504],{},"Claude Code and Cursor are harnesses you run, not frameworks you import. Nimbus, Palantir AIP, and Agentforce are (different) harnesses you run for company jobs. Confusing “we use LangGraph” with “we have an enterprise harness” is the 2026 version of “we use Kubernetes” meaning “we have a product.”",[205,506,508],{"id":507},"words-youll-hear","Words you’ll hear",[220,510,511,517,531,542,548,554],{},[223,512,513,516],{},[440,514,515],{},"Framework."," SDKs and graphs: LangChain, LangGraph, CrewAI, AutoGen, Semantic Kernel, Pydantic AI. You write code. You own production identity unless you add it.",[223,518,519,522,523,527,528,530],{},[440,520,521],{},"Harness."," Runtime around the model. ",[199,524,526],{"href":525},"what-is-an-agent-harness","What is an agent harness",". May be a product (Claude Code) or a configured framework (your ",[461,529,463],{}," plus hooks plus IdP).",[223,532,533,536,537,376],{},[440,534,535],{},"Middleware / hooks."," Framework primitive that becomes harness behaviour when it always runs. LangChain middleware; ",[199,538,541],{"href":539,"rel":540},"https://code.claude.com/docs/en/hooks",[216],"Claude Code hooks",[223,543,544,547],{},[440,545,546],{},"Batteries-included harness."," Deep Agents, Claude Agent SDK, Codex SDK. Opinionated loop, filesystem, subagents, compaction. Still not your CRM grant model.",[223,549,550,553],{},[440,551,552],{},"Orchestration framework."," LangGraph when you need deterministic nodes mixed with agentic ones. Powerful. Easy to put the orchestrator in a system prompt and call it done.",[223,555,556,559,560,564],{},[440,557,558],{},"MCP."," Plug. ",[199,561,563],{"href":562},"what-is-model-context-protocol","What is Model Context Protocol",". Works behind frameworks and products. Does not choose the framework/harness cut.",[189,566,567,568,571,572,574,575,376],{},"In Nimbus you do not import a graph to start a job. You assign an ",[199,569,570],{"href":20},"agent team"," on a ",[199,573,500],{"href":32},". Under the hood there is still a loop, tools, and stops — a harness. The product choice is whether operators must be graph authors. ",[199,576,578],{"href":577},"self-service-vs-forward-deployed-ai-platforms","Self-service vs forward-deployed",[205,580,582],{"id":581},"why-you-should-care","Why you should care",[189,584,585,586,591],{},"Engineers will prefer frameworks. They should. Control, portability, tests in CI. Operators and Legal will prefer a harness they can inspect without a pull request. ",[199,587,590],{"href":588,"rel":589},"https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai",[216],"McKinsey"," keeps showing isolated technical use without operating-model change. A beautiful LangGraph in a platform team’s repo is still isolated use if RevOps cannot attach Salesforce or refuse a write.",[189,593,594],{},"It affects you if:",[220,596,597,600,603,606],{},[223,598,599],{},"the RFP says “must support LangChain” as if that were a control",[223,601,602],{},"a vendor says “model-agnostic framework” and prices seats on one flagship",[223,604,605],{},"you are asked to rebuild quoting and SoD because “we already have agents in Python”",[223,607,608],{},"security reviews the GitHub org and never reviews who can call PATCH",[189,610,611,616,617,620,621,625],{},[199,612,615],{"href":613,"rel":614},"https://genai.owasp.org/llm-top-10/",[216],"OWASP’s LLM Top 10"," excessive agency shows up in both: a framework that exposes every tool by default, or a product that does. The cut is not safety vs convenience. It is ",[478,618,619],{},"who can change the harness when it fails"," — ",[199,622,624],{"href":623},"what-is-harness-engineering","harness engineering"," — and whether a fail-closed write exists.",[189,627,628,632],{},[199,629,631],{"href":240,"rel":630},[216],"NIST AI RMF"," Map/Measure need a system boundary. “Our framework” is not a boundary. A named runtime with grants and logs is.",[205,634,636],{"id":635},"the-practical-differences","The practical differences",[189,638,639,642],{},[440,640,641],{},"Who authors the loop."," Framework: software engineers. Product harness: operators (and maybe SE for custom tools). If only engineers can add a sensor, you will wait on a sprint for a Legal rule.",[189,644,645,648,649,652,653,656],{},[440,646,647],{},"Where identity lives."," Framework default: service account in ",[461,650,651],{},".env",". Product harness: org roster, workstream membership, OAuth grants. You ",[478,654,655],{},"can"," do the latter in LangGraph. You must build it.",[189,658,659,662,663,359,668,673,674,677],{},[440,660,661],{},"What “done” means."," Framework: your node returned. Inner product harness: tests / hook. Outer product harness: signer. Anthropic’s ",[199,664,667],{"href":665,"rel":666},"https://www.anthropic.com/engineering/building-effective-agents",[216],"effective agents",[199,669,672],{"href":670,"rel":671},"https://www.anthropic.com/engineering/effective-harnesses-for-long-running-agents",[216],"long-running harness"," notes are about encoding done in the ",[478,675,676],{},"environment",". Frameworks give you the primitives; they do not know your done.",[189,679,680,683,684,687,688,692],{},[440,681,682],{},"Portability."," Frameworks win on model swap ",[478,685,686],{},"if"," tools and middleware stay. Product harnesses win if they actually route and do not bury a flagship default in a seat. ",[199,689,691],{"href":690},"what-is-model-routing","Model routing",". “We wrap LangChain” is not routing.",[189,694,695,698],{},[440,696,697],{},"Eval."," Frameworks shine in unit tests of nodes. Inner harnesses shine on SWE-bench / Terminal-Bench. Enterprise harnesses shine when quote hash equals SoR row. Different CI.",[189,700,701,704,705,376],{},[440,702,703],{},"Time-to-first-governed-write."," Framework: months unless you already built the interceptor. Forward-deployed OS: months of people. Self-service outer harness: the product’s week-one claim — verify it. ",[199,706,708],{"href":707},"how-to-run-an-enterprise-ai-proof-of-value","Proof of value",[189,710,711,714,715,719],{},[440,712,713],{},"Lock-in."," Framework lock-in is code and patterns. Product lock-in is data, graph, and operating habits. Both are real. ",[199,716,718],{"href":717},"how-to-solve-model-lock-in","How to solve model lock-in"," is the model slice; harness lock-in is the loop slice. Prefer quoted payloads and exportable ledgers either way.",[189,721,722,723,728,729,732,733,376],{},"LangChain is not the villain. Their ",[199,724,727],{"href":725,"rel":726},"https://www.langchain.com/blog/the-anatomy-of-an-agent-harness",[216],"anatomy post"," is one of the clearer public derivations of harness parts. Use it. Then ask whether your ",[478,730,731],{},"deployment"," has those parts for the job you are buying — repo or company. ",[199,734,736],{"href":735},"inner-vs-outer-agent-harness","Inner vs outer",[189,738,739,740,743],{},"Nimbus’s bet is that most operators should not author LangGraph to update a discount cap. The wiki and the gate should move. Teams that ",[478,741,742],{},"should"," author graphs (unique simulation, exotic tools) can still sit behind a connector. Framework inside a harness. Not a framework instead of one.",[205,745,747],{"id":746},"a-decision-rule","A decision rule",[220,749,750,756,762,772],{},[223,751,752,755],{},[440,753,754],{},"Building a product or a unique workflow in code, with engineers on the hook:"," framework (or SDK harness) plus your own grants and evals.",[223,757,758,761],{},[440,759,760],{},"Hiring a loop for a repository:"," inner product harness (Claude Code, Cursor, Codex). Optionally extend with a framework for custom tools.",[223,763,764,459,767,771],{},[440,765,766],{},"Hiring a loop for CRM/ERP/cross-department work:",[199,768,770],{"href":769},"what-is-an-enterprise-agent-harness","enterprise agent harness"," / OS-class product. A framework is a build programme.",[223,773,774,777],{},[440,775,776],{},"Vendor says “we are a framework and an OS”:"," make them show a failed unsigned write and an operator-attached connector. Words are cheap.",[189,779,780,784],{},[199,781,783],{"href":782},"build-vs-buy-an-enterprise-ai-os","Build vs buy an enterprise AI OS"," is the longer form of the third bullet.",[205,786,788],{"id":787},"what-each-layer-of-the-stack-is-for","What each layer of the stack is for",[189,790,791,792,795,796,798],{},"LangChain’s own split is the cleanest vendor-native map: use Deep Agents when you want a batteries-included ",[478,793,794],{},"harness","; use ",[461,797,463],{}," when you want a minimal harness you customise with middleware; drop to LangGraph when the agent loop is the wrong shape and you need deterministic nodes mixed with agentic ones; use LangSmith to trace whatever you built. That is a builder’s menu. It does not decide whether RevOps can refuse a write.",[189,800,801,802,805,806,810],{},"CrewAI is a role-and-task framework. AutoGen is a conversation-of-agents framework. Semantic Kernel is Microsoft’s orchestration SDK. Pydantic AI moved toward a “harness-first” design in 2026 (capabilities as tools + hooks + instructions). None of these are wrong. All of them leave identity, SoR quoting, and operator self-service as ",[478,803,804],{},"your"," story unless you add them. ",[199,807,809],{"href":613,"rel":808},[216],"OWASP"," will still fail you if the first graph you merge attaches every production tool “so the demo looks alive.”",[189,812,813,814,817],{},"Product harnesses fail the other way: they hide the graph so operators can work, then surprise engineers who wanted to unit-test a node. Demand an escape hatch — export traces, typed payloads, maybe a documented tool SDK — without requiring every discount cap to be a pull request. Nimbus’s bet is that the cap lives in the ",[199,815,816],{"href":28},"wiki"," and the interceptor, and that engineers who need a custom simulator put it behind a connector. Framework inside the harness.",[189,819,820,825],{},[199,821,824],{"href":822,"rel":823},"https://www.thoughtworks.com/insights/articles/operating-system-enterprise-ai",[216],"Thoughtworks"," would say a company that standardises on LangGraph has invested in layer 2 (builder) and still has to build layers 3–4 (user guides/sensors, organisational ownership). A company that buys only a coding harness has a strong inner layer 2–3 and a missing outer layer 4. A company that buys an OS-class product is hoping layer 3–4 shipped. Verify with a refused write, not with a README.",[189,827,828,831,832,836],{},[440,829,830],{},"Cost of the wrong cut."," Framework-first for operators: six months of platform work, then shadow copilots anyway. Product-first for a unique research loop: you will fight the product and rebuild the graph in Python by week four. ",[199,833,835],{"href":834},"how-to-choose-between-a-coding-harness-and-an-enterprise-harness","How to choose coding vs enterprise"," plus this page: workspace first, then assemble vs hire.",[189,838,839,842,843,845,846,848,849,852],{},[440,840,841],{},"Portability, honestly."," Frameworks make model swap easier ",[478,844,686],{}," you used their model interface and did not sprinkle vendor-specific tool formats through application code. Products make operator ratchet easier ",[478,847,686],{}," adding a gate is a UI action. Neither gives you portability of ",[478,850,851],{},"decisions"," unless the ledger exports. Ask for JSON of the quote and the graph, not a promise of “open.”",[189,854,855,856,859],{},"Inngest and others have argued that durable execution needs “a harness, not a framework”: retries, state, and recovery as infrastructure. That slogan is directionally right for production. It is incomplete for enterprises. Durable retries of an ",[478,857,858],{},"unsigned"," write are a reliable incident. The outer harness adds identity and a stop that retries must not bypass. LangGraph checkpointing is excellent loop infrastructure. It is not a Finance signer.",[189,861,862,863,376],{},"A worked split: the data-science team builds a forecasting graph in LangGraph, evaluates it with their own sensors, exposes it as a tool. RevOps never opens the repo. They brief a workstream, the team calls the forecast tool under read scope, and any CRM write still quotes in the product interceptor. Framework for the specialist. Harness for the company job. Nimbus is the second box; it should consume the first as a connector, not replace the scientists’ graph. ",[199,864,50],{"href":51},[189,866,867],{},"If your platform team’s OKR is “stand up LangChain,” add a second OKR: “unsigned SoR writes are impossible.” The first without the second is a framework programme. The second without any loop is a policy PDF. You need both, in that order of safety.",[189,869,870,871,875],{},"CrewAI marketing will talk about roles. Roles in a YAML file are not roster identity. If the “legal reviewer” crew member can still call the same Salesforce write tool as the “AE,” you have a framework demo of ",[199,872,874],{"href":873},"agent-team-architecture","agent teams"," without the contract. Ask to see the tool belt per role, then ask what happens when you remove the write tool from legal and the model asks for it anyway. The harness answer is refuse. The framework-only answer is often “we’ll prompt it.”",[205,877,879],{"id":878},"questions-people-actually-ask","Questions people actually ask",[881,882,884],"h3",{"id":883},"is-langgraph-a-harness","Is LangGraph a harness?",[189,886,887,888,891],{},"It is a framework for building one. Your graph ",[478,889,890],{},"becomes"," a harness when it owns tool dispatch, bounds, and (for production) identity and sensors. Empty graph ≠ harness.",[881,893,895],{"id":894},"is-claude-code-a-framework","Is Claude Code a framework?",[189,897,898,899,376],{},"No. It is a productised inner harness. The Agent SDK is the embeddable form — closer to HaaS in ",[199,900,903],{"href":901,"rel":902},"https://addyosmani.com/blog/agent-harness-engineering/",[216],"Osmani’s sense",[881,905,907],{"id":906},"does-mcp-replace-both","Does MCP replace both?",[189,909,910],{},"No. Plumbing. Hosts still need a loop and grants.",[881,912,914],{"id":913},"we-already-standardised-on-crewai","We already standardised on CrewAI.",[189,916,917],{},"Keep it for the jobs engineers should own. Do not force RevOps to write crews for a renewal write. Put CrewAI behind a scoped tool if the outer harness needs that specialist.",[881,919,921],{"id":920},"how-do-we-evaluate-a-vendor-who-wraps-langchain","How do we evaluate a vendor who wraps LangChain?",[189,923,924,925,929],{},"Ignore the wrapper. Run ",[199,926,928],{"href":927},"how-to-evaluate-an-agent-harness","how to evaluate an agent harness",". If they cannot refuse a write, you evaluated a demo of a framework.",[881,931,933],{"id":932},"where-does-nimbus-sit","Where does Nimbus sit?",[189,935,936,937,939,940,376],{},"Productised outer harness, not a LangChain distribution. ",[199,938,11],{"href":12},". You should still allow inner harnesses for code. ",[199,941,835],{"href":834},[205,943,945],{"id":944},"related-reading","Related reading",[189,947,948,359,951,376],{},[199,949,950],{"href":623},"What is harness engineering",[199,952,954],{"href":953},"how-to-evaluate-multi-agent-platforms","How to evaluate multi-agent platforms",[205,956,958],{"id":957},"sources","Sources",[220,960,961,967,973,979,985,991,997,1003,1009,1015,1021,1027,1032,1038],{},[223,962,963],{},[199,964,966],{"href":452,"rel":965},[216],"LangChain, Agents",[223,968,969],{},[199,970,972],{"href":486,"rel":971},[216],"LangChain, How to build a custom agent harness",[223,974,975],{},[199,976,978],{"href":725,"rel":977},[216],"LangChain, The anatomy of an agent harness",[223,980,981],{},[199,982,984],{"href":473,"rel":983},[216],"LangChain, LangGraph overview",[223,986,987],{},[199,988,990],{"href":467,"rel":989},[216],"LangChain Deep Agents",[223,992,993],{},[199,994,996],{"href":822,"rel":995},[216],"Thoughtworks, The operating system for enterprise AI",[223,998,999],{},[199,1000,1002],{"href":901,"rel":1001},[216],"Addy Osmani, Agent harness engineering",[223,1004,1005],{},[199,1006,1008],{"href":665,"rel":1007},[216],"Anthropic, Building effective agents",[223,1010,1011],{},[199,1012,1014],{"href":670,"rel":1013},[216],"Anthropic, Effective harnesses for long-running agents",[223,1016,1017],{},[199,1018,1020],{"href":539,"rel":1019},[216],"Claude Code, Hooks",[223,1022,1023],{},[199,1024,1026],{"href":588,"rel":1025},[216],"McKinsey, The state of AI in 2025",[223,1028,1029],{},[199,1030,631],{"href":240,"rel":1031},[216],[223,1033,1034],{},[199,1035,1037],{"href":613,"rel":1036},[216],"OWASP Top 10 for LLM applications",[223,1039,1040],{},[199,1041,1044],{"href":1042,"rel":1043},"https://modelcontextprotocol.io/specification/2025-11-25/index",[216],"Model Context Protocol specification",{"title":170,"searchDepth":171,"depth":171,"links":1046},[1047,1048,1049,1050,1051,1052,1061,1062],{"id":507,"depth":171,"text":508},{"id":581,"depth":171,"text":582},{"id":635,"depth":171,"text":636},{"id":746,"depth":171,"text":747},{"id":787,"depth":171,"text":788},{"id":878,"depth":171,"text":879,"children":1053},[1054,1056,1057,1058,1059,1060],{"id":883,"depth":1055,"text":884},3,{"id":894,"depth":1055,"text":895},{"id":906,"depth":1055,"text":907},{"id":913,"depth":1055,"text":914},{"id":920,"depth":1055,"text":921},{"id":932,"depth":1055,"text":933},{"id":944,"depth":171,"text":945},{"id":957,"depth":171,"text":958},"2026-08-24","An agent framework is a library for assembling a loop. An agent harness is the loop you can actually run — tools, stops, identity, and sensors included. LangChain helps you build one; it is not, by itself, one you can hire.","/blog/agent-harness-vs-agent-framework",{"title":430,"description":1064},"blog/agent-harness-vs-agent-framework",[401,1069,1070,1071],"agent-harness","langchain","frameworks","gXCxGnvUDv02K2_Jxwj878jpKQQXGyrZ7s3d5hNjYZA",{"enabled":164,"message":1074,"linkLabel":93,"linkHref":94,"id":1075,"title":1076,"archived":164,"authors":165,"badge":165,"body":1077,"date":165,"definedTerm":165,"department":165,"description":170,"extension":173,"eyebrow":165,"faqHeader":165,"faqs":165,"footerBand":165,"headline":165,"image":165,"industry":165,"jobType":165,"listed":130,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":1081,"relatedHeading":165,"seo":1082,"series":165,"sitemap":164,"status":165,"stem":1083,"subhead":165,"tags":165,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":1084},"We're hiring! Join the team building the Sentient Enterprise.","content/shared/hiring.md","Hiring banner",{"type":167,"value":1078,"toc":1079},[],{"title":170,"searchDepth":171,"depth":171,"links":1080},[],"/shared/hiring",{"title":1076,"description":170},"shared/hiring","1zs3boivKda1e-b-hAyuNcmZSKjZUAXmecnwHVgcHzk",{"fold":1086,"id":1090,"title":1091,"archived":164,"authors":165,"badge":165,"body":1092,"date":165,"definedTerm":165,"department":165,"description":170,"extension":173,"eyebrow":165,"faqHeader":165,"faqs":165,"footerBand":1096,"headline":165,"image":165,"industry":165,"jobType":165,"listed":130,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":1100,"relatedHeading":165,"seo":1101,"series":165,"sitemap":164,"status":165,"stem":1102,"subhead":165,"tags":165,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":1103},{"headline":1087,"description":1088,"primaryLabel":8,"primaryTo":1089,"secondaryLabel":422,"secondaryTo":12},"Run frontier AI your business actually owns.","Governed agent swarms, 2,000+ integrations, and a knowledge graph that stays inside your walls. Free 7-day trial.","/checkout","content/shared/cta.md","Site CTAs",{"type":167,"value":1093,"toc":1094},[],{"title":170,"searchDepth":171,"depth":171,"links":1095},[],{"headline":1097,"description":1098,"primaryLabel":8,"primaryTo":1089,"secondaryLabel":1099,"secondaryTo":99},"See what governed AI looks like on your stack.","Connect your tools, run a workstream, and keep every decision on your ledger - free for 7 days.","Talk to our team","/shared/cta",{"title":1091,"description":170},"shared/cta","wz4AdRHnaYH021WMdWcHnZvHmkZJNKaNG4XGZfnFBtw",1788985847736]