[{"data":1,"prerenderedAt":1253},["ShallowReactive",2],{"site-nav-content":3,"blog:/blog/what-auditors-are-asking-for":178,"blog-index-copy":449,"blog:/blog/what-auditors-are-asking-for:surround":470,"hiring-banner-content":1222,"site-cta-content":1234},{"header":4,"productNav":9,"nav":42,"footer":61,"askAI":131,"id":162,"title":163,"archived":164,"authors":165,"badge":165,"body":166,"date":165,"definedTerm":165,"department":165,"description":170,"extension":173,"eyebrow":165,"faqHeader":165,"faqs":165,"footerBand":165,"headline":165,"image":165,"industry":165,"jobType":165,"listed":130,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":174,"relatedHeading":165,"seo":175,"series":165,"sitemap":164,"status":165,"stem":176,"subhead":165,"tags":165,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":177},{"productLabel":5,"loginLabel":6,"contactLabel":7,"contactSalesLabel":8},"Product","Log in","Contact","Get started for free",[10,14,18,22,26,30,34,38],{"label":11,"to":12,"description":13},"Overview","/overview","Seven layers. One closed loop.",{"label":15,"to":16,"description":17},"Conflux","/product/conflux","Where your team, workstreams, and agents meet.",{"label":19,"to":20,"description":21},"Agent Teams","/product/agent-teams","Specialist teams - governed from day one.",{"label":23,"to":24,"description":25},"Lifecycle Graph","/product/lifecycle-graph","Intelligence that compounds across every interaction.",{"label":27,"to":28,"description":29},"Company Wiki","/product/wiki","Playbooks and policies where expertise stays.",{"label":31,"to":32,"description":33},"Workstreams","/product/workstreams","From brief to signed-off deliverable on one canvas.",{"label":35,"to":36,"description":37},"Perception Console","/product/perception","Ask your whole business in plain English.",{"label":39,"to":40,"description":41},"Governance","/product/governance","Frontier AI you can actually sign off on.",[43,46,49,52,55,58],{"label":44,"to":45},"Models","/models",{"label":47,"to":48},"Pricing","/pricing",{"label":50,"to":51},"Integrations","/integrations",{"label":53,"to":54},"Security","/security",{"label":56,"to":57},"Partners","/partners",{"label":59,"to":60},"Insights","/blog",{"productHeading":5,"companyHeading":62,"legalHeading":63,"docsLabel":64,"docsUrl":65,"statementLines":66,"copyright":69,"companyLinks":70,"legalLinks":100,"socialLinks":110,"bottomLinks":120},"Company","Legal","Docs","https://docs.gonimbus.ai",[67,68],"Stop training someone else's model.","Control your AI.","© 2026 Nimbus Intelligence, Inc. All rights reserved.",[71,72,73,74,75,78,81,84,87,90,92,95,98],{"label":47,"to":48},{"label":50,"to":51},{"label":53,"to":54},{"label":59,"to":60},{"label":76,"to":77},"Glossary","/glossary",{"label":79,"to":80},"Compare","/compare",{"label":82,"to":83},"Evaluate","/evaluate",{"label":85,"to":86},"Problems","/problems",{"label":88,"to":89},"Use cases","/use-cases",{"label":91,"to":57},"Partner Program",{"label":93,"to":94},"Careers","/careers",{"label":96,"to":97},"System status","/status",{"label":7,"to":99},"/contact",[101,104,107],{"label":102,"to":103},"Terms of Service","/terms",{"label":105,"to":106},"Privacy Policy","/privacy",{"label":108,"to":109},"Compliance","/compliance",[111,114,117],{"label":112,"href":113},"LinkedIn","https://www.linkedin.com/company/gonimbusai/",{"label":115,"href":116},"X","https://x.com/gonimbusai",{"label":118,"href":119},"Instagram","https://www.instagram.com/gonimbus_ai/",[121,123,125,126,127],{"label":122,"to":103},"Terms",{"label":124,"to":106},"Privacy",{"label":108,"to":109},{"label":96,"to":97},{"label":128,"to":129,"external":130},"LLMs.txt","/llms.txt",true,{"text":132,"prompt":133},"Ask AI about Nimbus",{"I'm researching enterprise intelligence platforms and want to know how Nimbus combines perception, collaboration, and autonomous agents to drive strategic decision-making":134,"platforms":136},{" Summarize the highlights from Nimbus's website":135},"https://gonimbus.ai",[137,142,147,152,157],{"name":138,"label":139,"icon":140,"hrefPrefix":141},"chatgpt","ChatGPT","simple-icons:openai","https://chatgpt.com/?prompt=",{"name":143,"label":144,"icon":145,"hrefPrefix":146},"perplexity","Perplexity","mdi:magnify","https://www.perplexity.ai/search/new?q=",{"name":148,"label":149,"icon":150,"hrefPrefix":151},"grok","Grok","simple-icons:x","https://x.com/i/grok?text=",{"name":153,"label":154,"icon":155,"hrefPrefix":156},"claude","Claude","simple-icons:anthropic","https://claude.ai/new?q=",{"name":158,"label":159,"icon":160,"hrefPrefix":161},"google-ai","Google AI","simple-icons:google","https://www.google.com/search?udm=50&aep=11&q=","content/shared/nav.md","Site navigation",false,null,{"type":167,"value":168,"toc":169},"minimark",[],{"title":170,"searchDepth":171,"depth":171,"links":172},"",2,[],"md","/shared/nav",{"title":163,"description":170},"shared/nav","rDEv5cVG6P2l9ATcdQv2n6VOQiSL5ioOutyfvGevcD0",{"id":179,"title":180,"archived":164,"authors":181,"badge":184,"body":186,"date":423,"definedTerm":165,"department":165,"description":424,"extension":173,"eyebrow":165,"faqHeader":425,"faqs":428,"footerBand":165,"headline":165,"image":165,"industry":165,"jobType":165,"listed":164,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":441,"relatedHeading":165,"seo":442,"series":443,"sitemap":130,"status":165,"stem":444,"subhead":165,"tags":445,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":448},"content/blog/what-auditors-are-asking-for.md","What are auditors asking for around AI?",[182],{"name":183,"to":135},"Nimbus Research",{"label":185},"Evaluation",{"type":167,"value":187,"toc":416},[188,192,195,214,218,221,228,234,237,240,243,250,253,257,260,269,278,286,295,303,306,310,313,316,319,338,341,344,347,355,359,362,382,389,392,395,399,402,405,408],[189,190,191],"p",{},"Auditors asking about AI usually want to follow one change: who decided, whether software could write without a person, and which rulebook you claim to follow. They pick a journal, a credit, a customer email, or a model connection, and they walk it from prompt to record.",[189,193,194],{},"This is showing up now because models sit on live systems, and existing control texts already care how a number became the number. You do not need every framework on day one. You need artefacts you can produce without asking anyone to remember.",[189,196,197,198,203,204,208,209,213],{},"This guide is a first evidence pack you can start this quarter. ",[199,200,202],"a",{"href":201},"what-is-ai-governance","What is AI governance"," is the rest of the access picture. ",[199,205,207],{"href":206},"rbac-for-enterprise-ai","RBAC for enterprise AI"," is who may see the job. ",[199,210,212],{"href":211},"what-is-write-back-governance","Write-back governance"," is the write checklist.",[215,216,180],"h2",{"id":217},"what-are-auditors-asking-for-around-ai",[189,219,220],{},"Two operational questions arrive first.",[189,222,223,227],{},[224,225,226],"strong",{},"Can you show who decided?"," A named person, on a clock the company trusts, bound to a quote that matches the write. “The team aligned” is not an answer. “The channel approved” is not an answer. “The bot user posted” is not an answer.",[189,229,230,233],{},[224,231,232],{},"Can you show the model did not write unchecked?"," Write-back means the AI changes a live system. Fail-closed means if nobody approves, nothing happens. A prompt that says “ask first” is not the gate. A weekly sampling of logs is not the gate if the write already landed.",[189,235,236],{},"Role-based access control (RBAC) means who is allowed to do what. It explains why that person, and not a guest, was offered the button. Auditors understand roles. They do not understand “the workspace.”",[189,238,239],{},"A payload is the exact change: fields, old and new values, target record — or the exact text and recipient for a message.",[189,241,242],{},"Then comes the mapping question: which framework applies to us? Not every company is under every text. Pretending otherwise produces a pile of mappings and no artefact.",[189,244,245,249],{},[199,246,248],{"href":247},"collaborative-ai-for-legal-and-compliance-review","Collaborative AI for legal and compliance review"," still needs a signer when the review becomes a filing. Several departments on one job is not a shared identity.",[189,251,252],{},"If the decision was “we will not write,” that is still a decision. Store it. A read-only connector with a date and an owner is evidence.",[215,254,256],{"id":255},"why-is-this-showing-up-now","Why is this showing up now?",[189,258,259],{},"Models are in the path of records that already had auditors: financial reporting, customer commitments, legal filings, operational tickets.",[189,261,262,268],{},[199,263,267],{"href":264,"rel":265},"https://www.govinfo.gov/content/pkg/PLAW-107publ204/html/PLAW-107publ204.htm",[266],"nofollow","Sarbanes-Oxley"," (2002) is still the text many US-listed teams feel first. Internal control over financial reporting does not care that the proposer is a model. If AI can post, the control environment includes that path.",[189,270,271,272,277],{},"NIST’s ",[199,273,276],{"href":274,"rel":275},"https://www.nist.gov/itl/ai-risk-management-framework",[266],"AI Risk Management Framework"," (2023) is organised as govern, map, measure, and manage. Measure, here, is the stored outcome, including the no. Govern is the roles and the owners. The framework will not click the refuse button for you.",[189,279,280,285],{},[199,281,284],{"href":282,"rel":283},"https://www.iso.org/standard/81230.html",[266],"ISO/IEC 42001"," (2023) adds a management system for AI: policies, roles, risk assessment, documented processes, and evidence that those processes run. Useful if you will be asked for a certificate. Not a substitute for a payload screen.",[189,287,288,289,294],{},"The ",[199,290,293],{"href":291,"rel":292},"https://eur-lex.europa.eu/eli/reg/2024/1689/oj",[266],"EU AI Act"," (2024/1689) is from 2024. A deployer is the organisation that uses an AI system under its authority, as the Act defines that role. You may also be a provider if you place a system on the market. Map the role with counsel. Human oversight that cannot refuse a write is not oversight.",[189,296,297,302],{},[199,298,301],{"href":299,"rel":300},"https://eur-lex.europa.eu/eli/reg/2022/2554/oj",[266],"DORA"," (2022) is about digital operational resilience for financial entities and their ICT third parties. If you are in that sector, the AI vendor is an ICT provider conversation, not only an innovation conversation.",[189,304,305],{},"Customers and boards ask for structure even when a text is voluntary. That is why the questions arrive before a regulator has written your company’s name.",[215,307,309],{"id":308},"how-do-you-prepare-evidence-without-a-huge-project","How do you prepare evidence without a huge project?",[189,311,312],{},"Do the one-change walk before anyone external does.",[189,314,315],{},"Pick a change a model proposed. Follow it from prompt to record. See whether you can produce a named person, a frozen payload, and a stored outcome without anyone’s memory.",[189,317,318],{},"Show:",[320,321,322,326,329,332,335],"ul",{},[323,324,325],"li",{},"A connector in read-only mode, and a failed write attempt.",[323,327,328],{},"One object class with a frozen payload and a named signer — or a dated decision that no class is enabled yet.",[323,330,331],{},"The live system’s own validation still firing, if a write ran.",[323,333,334],{},"A success and a rejection.",[323,336,337],{},"A person who was removed and could not sign the next day.",[189,339,340],{},"If you cannot show the failed attempt, assume an auditor will treat write as on.",[189,342,343],{},"Unchecked also includes send. A customer message is a write to the relationship. If mail can go out because the connector was on for retrieval, that is an unchecked write with no field names to screenshot.",[189,345,346],{},"Do not start with a coverage matrix against every clause. Breadth without a sample fails the first request. Depth on one change lets you map the same artefact twice if two texts apply.",[189,348,349,354],{},[199,350,353],{"href":351,"rel":352},"https://www.law.cornell.edu/rules/frcp/rule_37",[266],"Federal Rule of Civil Procedure 37(e)"," (2015) is about preserving electronically stored information you should have kept. Chat retention sliders are not that programme. Put approvals where a new manager can find them.",[215,356,358],{"id":357},"what-is-a-reasonable-first-evidence-pack","What is a reasonable first evidence pack?",[189,360,361],{},"One page plus exports:",[320,363,364,367,370,373,376,379],{},[323,365,366],{},"Job name, system, connector mode, date, owner.",[323,368,369],{},"Roster: guest, member, admin, signer — or “signer not yet named; write off.”",[323,371,372],{},"One stored refusal (sandbox is fine).",[323,374,375],{},"One stored success if you have enabled a class; otherwise omit.",[323,377,378],{},"Clock and retention note: where the artefact lives, how long, who can export it without a vendor ticket.",[323,380,381],{},"Which texts you claim: SOX ICFR if you file; NIST AI RMF as structure; ISO 42001 if you are on that path; EU AI Act role if in scope; DORA if you are a financial entity.",[189,383,384,385,388],{},"Your ",[199,386,387],{"href":109},"compliance"," programme should hold that page.",[189,390,391],{},"ISO 42001, if you take it seriously, adds an owner for AI, a statement of which systems models may connect to and in which mode, a way to handle incidents and model or prompt changes that alter write behaviour, and records that last longer than a chat default. It does not add object-level tokens. You can be certified and still have an admin token on a model. Ask the auditor of that management system to sample a stored rejection from a live job.",[189,393,394],{},"For deployers under the EU AI Act, the operational match is: know you are using AI, use it as intended, monitor, keep required records, and ensure human oversight where the Act requires it. “The vendor is the provider” does not move your ERP posting into their audit file. Your token, your records, your signer. High-risk classification is legal work. This guide will not guess it.",[215,396,398],{"id":397},"how-do-you-start-this-quarter","How do you start this quarter?",[189,400,401],{},"This month: pick one real job. Run the one-change walk. Write the one-page pack. Fill blanks as findings, not as a reason to delay the page.",[189,403,404],{},"Next month: fix the first hole — usually the stored no, the read-only proof, or the named signer.",[189,406,407],{},"If you cannot complete the walk, keeping write off is the honest state of the control. Mapping will not replace it.",[189,409,410,412,413,415],{},[199,411,212],{"href":211}," and ",[199,414,207],{"href":206}," are the two product habits that make the pack easier to gather later.",{"title":170,"searchDepth":171,"depth":171,"links":417},[418,419,420,421,422],{"id":217,"depth":171,"text":180},{"id":255,"depth":171,"text":256},{"id":308,"depth":171,"text":309},{"id":357,"depth":171,"text":358},{"id":397,"depth":171,"text":398},"2026-09-06","Who decided, did the model write unchecked, and which rulebook applies. How to prepare a first evidence pack this quarter without a huge project.",{"eyebrow":426,"title":427},"Short answers","One change you can walk",[429,432,435,438],{"question":430,"answer":431},"If we are not in the EU, can we ignore the AI Act?","You can ignore it as a legal duty only if you are not in its scope. You should still answer the same operational questions — who decided, and did the model write unchecked — because auditors and customers will ask them in other words.",{"question":433,"answer":434},"Does ISO 42001 certification mean our CRM writes are governed?","No. Certification speaks to a management system. It does not replace a named person on a payload, a stored rejection, or a connector that can be read-only. Ask to see those artefacts in your product, not only the certificate.",{"question":436,"answer":437},"What is the smallest evidence pack that still helps?","One change a model proposed: named person, frozen payload, stored outcome including a no, plus the connector mode and the roster on that job. Map that pack to whichever texts apply. Do not start with a matrix of empty controls.",{"question":439,"answer":440},"Do we need this if AI is still read-only?","A dated decision to stay read-only, with an owner and the connector name, is evidence. You need the full write pack before the first production write class.","/blog/what-auditors-are-asking-for",{"title":180,"description":424},"evaluation","blog/what-auditors-are-asking-for",[443,446,447,293,387],"audit","ISO 42001","EfFv_YZ08TZJm4MDym8B05aD4MGOwabpfOQ5EtWvDxw",{"hero":450,"id":452,"title":453,"archived":164,"authors":165,"badge":165,"body":454,"date":165,"definedTerm":165,"department":165,"description":458,"extension":173,"eyebrow":459,"faqHeader":165,"faqs":165,"footerBand":460,"headline":165,"image":165,"industry":165,"jobType":165,"listed":130,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":60,"relatedHeading":466,"seo":467,"series":165,"sitemap":130,"status":165,"stem":468,"subhead":165,"tags":165,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":469},{"filename":451},"u2221455217_Flat_design_of_a_futuristic_minimalist_landscape__5d589295-cdea-4ea9-a262-be766881accf_1.png","content/blog/index.md","Exploring the future of intelligence.",{"type":167,"value":455,"toc":456},[],{"title":170,"searchDepth":171,"depth":171,"links":457},[],"Deep dives into pre-cognitive intelligence, sentient enterprises, and the evolving landscape of AI-driven business transformation.","Latest Research",{"headline":461,"description":462,"primaryLabel":463,"primaryTo":464,"secondaryLabel":465,"secondaryTo":12},"Stay at the frontier.","Subscribe for product updates and new insights.","Subscribe","/newsletter","Explore the platform","More research",{"title":453,"description":458},"blog/index","BFSWGYO9bcTlaulivKYWyg08_DJHsdGg3OC6g_CG1Hw",[471,165],{"id":472,"title":473,"archived":164,"authors":474,"badge":476,"body":477,"date":1212,"definedTerm":165,"department":165,"description":1213,"extension":173,"eyebrow":165,"faqHeader":165,"faqs":165,"footerBand":165,"headline":165,"image":165,"industry":165,"jobType":165,"listed":164,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":1214,"relatedHeading":165,"seo":1215,"series":443,"sitemap":130,"status":165,"stem":1216,"subhead":165,"tags":1217,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":1221},"content/blog/how-to-choose-between-a-coding-harness-and-an-enterprise-harness.md","How to Choose Between a Coding Harness and an Enterprise Harness",[475],{"name":183,"to":135},{"label":185},{"type":167,"value":478,"toc":1194},[479,496,514,534,542,546,628,645,649,652,664,683,689,695,708,712,718,724,734,746,760,774,778,784,790,800,810,816,823,827,879,893,907,911,922,931,947,959,968,971,979,994,1001,1004,1024,1028,1033,1036,1040,1051,1055,1058,1062,1065,1069,1081,1085,1094,1098],[189,480,481,482,485,486,489,490,495],{},"Choosing between a ",[224,483,484],{},"coding harness"," and an ",[224,487,488],{},"enterprise harness"," is choosing the workspace. A coding harness (Claude Code, Cursor, Codex, open shells) wraps a model for a developer and a repository. An enterprise harness wraps a model for operators and systems of record. Same equation — ",[199,491,494],{"href":492,"rel":493},"https://docs.langchain.com/oss/python/langchain/agents",[266],"Agent = Model + Harness"," — different loop.",[189,497,498,499,503,504,508,509,513],{},"This is the buying companion to ",[199,500,502],{"href":501},"inner-vs-outer-agent-harness","inner vs outer agent harness",". It sits beside ",[199,505,507],{"href":506},"how-to-choose-between-a-copilot-and-a-work-os","how to choose between a copilot and a work OS",": copilots are personal assistants; coding harnesses are ",[510,511,512],"em",{},"agentic"," inner loops with tools and tests; enterprise harnesses are outer loops with grants and signers. Do not collapse all three into “we need ChatGPT.”",[189,515,516,521,522,527,528,533],{},[199,517,520],{"href":518,"rel":519},"https://martinfowler.com/articles/harness-engineering.html",[266],"Böckeler"," documents how coding-agent users add guides and sensors. ",[199,523,526],{"href":524,"rel":525},"https://addyosmani.com/blog/own-the-outer-loop/",[266],"Osmani"," tells engineers to own verify-and-release. ",[199,529,532],{"href":530,"rel":531},"https://www.thoughtworks.com/insights/articles/operating-system-enterprise-ai",[266],"Thoughtworks"," argues the organisational layer is still the gap. The purchase mistake is using one budget line for all three layers.",[189,535,536,541],{},[199,537,540],{"href":538,"rel":539},"https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai",[266],"McKinsey’s 2025 State of AI"," is the organisational backdrop: usage is easy; scale is redesign. A Cursor rollout can scale pull requests. It will not, by itself, scale governed CRM writes. An OS-class rollout can scale those writes. It will annoy engineers if you force “rewrite this function” through a Critical gate.",[215,543,545],{"id":544},"words-youll-hear","Words you’ll hear",[320,547,548,575,586,608,618],{},[323,549,550,553,554,558,559,562,563,568,569,574],{},[224,551,552],{},"Coding / inner harness."," Repo workspace, sandbox, ",[555,556,557],"code",{},"AGENTS.md"," / ",[555,560,561],{},"CLAUDE.md",", hooks, CI. Eval: ",[199,564,567],{"href":565,"rel":566},"https://www.swebench.com/",[266],"SWE-bench",", ",[199,570,573],{"href":571,"rel":572},"https://arxiv.org/abs/2601.11868",[266],"Terminal-Bench",", your tests.",[323,576,577,580,581,585],{},[224,578,579],{},"Enterprise / outer harness."," Job workspace, connectors, roster, write quotes, ledger. Eval: signed payload vs SoR. ",[199,582,584],{"href":583},"what-is-an-enterprise-agent-harness","What is an enterprise agent harness",".",[323,587,588,591,592,568,597,568,602,607],{},[224,589,590],{},"Copilot."," Personal completion surface. Often no repo loop. ",[199,593,596],{"href":594,"rel":595},"https://openai.com/business/chatgpt-enterprise/",[266],"ChatGPT Enterprise",[199,598,601],{"href":599,"rel":600},"https://www.microsoft.com/en-us/microsoft-365/copilot",[266],"Microsoft 365 Copilot",[199,603,606],{"href":604,"rel":605},"https://www.anthropic.com/news/claude-for-work",[266],"Claude for Work",". Keep for mail. Do not hand it the NetSuite token.",[323,609,610,613,614,585],{},[224,611,612],{},"Framework."," How you assemble a loop in code. Not a purchase of a company workspace. ",[199,615,617],{"href":616},"agent-harness-vs-agent-framework","Harness vs framework",[323,619,620,623,624,585],{},[224,621,622],{},"MCP."," Plug into either. Dangerous when both share a production write server. ",[199,625,627],{"href":626},"mcp-for-enterprise-integrations","MCP for enterprise",[189,629,630,631,568,634,568,637,640,641,585],{},"Nimbus is an enterprise / outer option: ",[199,632,633],{"href":32},"workstreams",[199,635,636],{"href":20},"teams",[199,638,639],{"href":40},"governance",". Claude Code is a coding / inner option. The rational stack is both, with a hard rule: no unsigned SoR writes from the inner harness. ",[199,642,644],{"href":643},"how-to-solve-unapproved-crm-writes-from-ai","How to solve unapproved CRM writes",[215,646,648],{"id":647},"why-the-choice-is-usually-both","Why the choice is usually “both”",[189,650,651],{},"The tools look similar in a first meeting. Both stream tokens. Both call tools. Both have “agents” on the website. The evaluation is what happens after the answer.",[189,653,654,657,658,663],{},[224,655,656],{},"Buy a coding harness when"," the artefact is code in a repo you already trust with CI: features, refactors, tests, developer docs, infra-as-code that merges through the same gates humans use. ",[199,659,662],{"href":660,"rel":661},"https://www.anthropic.com/engineering/effective-harnesses-for-long-running-agents",[266],"Anthropic’s long-running harness"," is this world: git, progress files, end-to-end checks.",[189,665,666,669,670,673,674,673,678,682],{},[224,667,668],{},"Buy an enterprise harness when"," the artefact is a change to Salesforce, NetSuite, a policy commitment, or a cross-department decision that must be replayed. ",[199,671,672],{"href":211},"Write-back",". ",[199,675,677],{"href":676},"what-is-human-in-the-loop-ai","HITL",[199,679,681],{"href":274,"rel":680},[266],"NIST RMF"," context of use is operations, not a checkout.",[189,684,685,688],{},[224,686,687],{},"Keep a copilot when"," the job is a paragraph in a mailbox. Do not scale it into an approval architecture.",[189,690,691,694],{},[224,692,693],{},"Build on a framework when"," engineers own a unique loop and will maintain grants. That is a programme, not a seat.",[189,696,697,702,703,707],{},[199,698,701],{"href":699,"rel":700},"https://hai.stanford.edu/ai-index/2025-ai-index-report",[266],"Stanford HAI’s 2025 AI Index"," charts the explosion of coding-agent tooling. Procurement that only reads that chart will under-buy the outer layer. Procurement that only reads ",[199,704,447],{"href":705,"rel":706},"https://www.iso.org/standard/42001",[266]," will over-process inner loops and lose developers.",[215,709,711],{"id":710},"decision-tests","Decision tests",[189,713,714,717],{},[224,715,716],{},"1. What is the system of record for the outcome?"," Git: inner. CRM/ERP/customer commitment: outer. Both: two harnesses, one write plane (the outer quotes).",[189,719,720,723],{},[224,721,722],{},"2. Who is the signer?"," The author of the PR (inner, plus CODEOWNERS). A named RevOps/Finance/Legal role (outer). If you cannot name the role, you are not ready to buy the outer write path — buy read-only first.",[189,725,726,729,730,585],{},[224,727,728],{},"3. What is the independent sensor?"," Pytest / tsc / CI (inner). Payload schema + SoR read-back (outer). “The model said it was fine” is neither. ",[199,731,733],{"href":732},"eval-loops-for-enterprise-agent-harnesses","Eval loops",[189,735,736,739,740,745],{},[224,737,738],{},"4. What identity should the tools use?"," Developer sandbox and repo token (inner). Workstream-scoped OAuth (outer). A shared MCP god account fails both ",[199,741,744],{"href":742,"rel":743},"https://genai.owasp.org/llm-top-10/",[266],"OWASP"," and SoD.",[189,747,748,751,752,754,755,759],{},[224,749,750],{},"5. How will you ratchet failures?"," Inner: ",[555,753,557],{}," + hooks + tests (",[199,756,758],{"href":757},"what-is-harness-engineering","harness engineering","). Outer: wiki revision + gate tier + graph. If your plan is “we’ll prompt better,” you have not chosen a harness. You have chosen hope.",[189,761,762,765,766,673,770,585],{},[224,763,764],{},"6. Time-to-value and staffing."," Cursor can be a week for a team that already has CI. AIP can be a programme. Nimbus-style self-service claims a product week for a standard write — verify with a ",[199,767,769],{"href":768},"how-to-run-an-enterprise-ai-proof-of-value","PoV",[199,771,773],{"href":772},"self-service-vs-forward-deployed-ai-platforms","Self-service vs FDE",[215,775,777],{"id":776},"anti-patterns","Anti-patterns",[189,779,780,783],{},[224,781,782],{},"Cursor for Salesforce."," MCP connected to production. Tests on fixtures. Amount changes. No signer in the ledger. Inner loop on an outer record.",[189,785,786,789],{},[224,787,788],{},"Work OS for a one-line refactor."," Critical gate, three departments. Engineers route around. Outer loop on an inner job.",[189,791,792,795,796,585],{},[224,793,794],{},"One mesh to rule them."," IDE, chatbot, and OS all write through the same server. Two writers. ",[199,797,799],{"href":798},"multi-agent-ai-architecture","Multi-agent architecture",[189,801,802,805,806,585],{},[224,803,804],{},"Benchmark shopping."," Buying Agentforce because of a coding leaderboard, or buying Claude Code because of a governance white paper. Wrong evidence. ",[199,807,809],{"href":808},"how-to-evaluate-an-agent-harness","How to evaluate an agent harness",[189,811,812,815],{},[224,813,814],{},"Banning inner harnesses until the OS ships."," Usually slows software and does not stop paste-into-CRM. Ban the write path; allow the compile path.",[189,817,818,819,822],{},"Nimbus should lose the inner job on purpose. If a vendor tries to replace Claude Code for application engineering, ask for sandbox, hooks, and merge sensors — ",[199,820,821],{"href":808},"evaluate the harness"," — and expect to keep a coding tool anyway. If a coding-tool vendor tries to replace the OS for NetSuite journals, ask for quoted GL lines and a Finance signer.",[215,824,826],{"id":825},"a-simple-portfolio","A simple portfolio",[828,829,830,843],"table",{},[831,832,833],"thead",{},[834,835,836,840],"tr",{},[837,838,839],"th",{},"Job",[837,841,842],{},"Buy",[844,845,846,855,863,871],"tbody",{},[834,847,848,852],{},[849,850,851],"td",{},"Mail, slides, one-off Q&A",[849,853,854],{},"Copilot",[834,856,857,860],{},[849,858,859],{},"Application and infra repos",[849,861,862],{},"Coding harness",[834,864,865,868],{},[849,866,867],{},"Cross-department SoR writes",[849,869,870],{},"Enterprise harness",[834,872,873,876],{},[849,874,875],{},"Unique simulation / exotic tools",[849,877,878],{},"Framework + your grants",[189,880,881,882,885,886,888,889,892],{},"Most enterprises tick all four rows. Budget them separately. Share policy ",[510,883,884],{},"intent"," (discount cap) via wiki and via ",[555,887,557],{}," where relevant; share ",[510,890,891],{},"enforcement"," only on the plane that can execute the write.",[189,894,895,896,898,899,902,903,906],{},"See ",[199,897,11],{"href":12}," for how Nimbus maps to the third row, ",[199,900,901],{"href":45},"models"," for routing, ",[199,904,905],{"href":51},"integrations"," for connectors. See Claude Code / Cursor docs for the second. Do not let a single SOW blur the rows.",[215,908,910],{"id":909},"procurement-sequence-that-does-not-waste-a-quarter","Procurement sequence that does not waste a quarter",[189,912,913,916,917,921],{},[224,914,915],{},"Week 1 — inventory loops, not vendors."," List jobs that already have a finish line. Tag each: git artefact, SoR artefact, mailbox artefact, unique research. You now have four shopping lists. ",[199,918,920],{"href":538,"rel":919},[266],"McKinsey"," programmes that skip this step buy one platform and force every row into it.",[189,923,924,927,928,585],{},[224,925,926],{},"Week 2 — freeze the write rule."," Unsigned SoR writes are impossible from copilots, coding agents, frameworks, and the OS. That rule is cheaper than any bake-off. It also tells Security what to revoke this month (god MCP servers). ",[199,929,930],{"href":643},"Unapproved CRM writes",[189,932,933,936,937,942,943,946],{},[224,934,935],{},"Week 3 — inner bake-off only if you lack a coding harness."," Hooks, sandbox, CI independence, model swap on the same tools. Terminal-Bench and SWE-bench as vendor quality, not as Legal’s control. ",[199,938,941],{"href":939,"rel":940},"https://code.claude.com/docs/en/hooks",[266],"Anthropic hooks"," vs Cursor rules vs Codex — pick for ",[510,944,945],{},"your"," repos.",[189,948,949,952,953,956,957,585],{},[224,950,951],{},"Week 4 — outer bake-off only for SoR jobs."," Run the refuse/replay script from ",[199,954,955],{"href":808},"how to evaluate an agent harness",". Include Nimbus, AIP, Agentforce, or a LangGraph programme as fits the staffing model. ",[199,958,773],{"href":772},[189,960,961,964,965,967],{},[224,962,963],{},"Do not"," hold week 3 until week 4 ships. Engineers will adopt inner tools anyway; you will only lose the chance to standardise hooks. ",[224,966,963],{}," skip week 4 because week 3’s coding agent “can also call Salesforce.” That is the anti-pattern.",[189,969,970],{},"Budget: copilot seats (predictable, personal); coding harness seats or usage (developer count); enterprise harness by work, not by mailbox count if you care about routing. Mixing all three into one “AI budget” is how flagship models burn on classify and how CRM writes go unquoted to save a line item.",[189,972,973,974,978],{},"Thoughtworks’ ",[199,975,977],{"href":530,"rel":976},[266],"organisational harness"," is the steering cadence after purchase: incidents become controls across both inner and outer. Buy tools that allow that ratchet. A coding harness that forbids custom hooks, or an OS that forbids adding a gate without FDE, will stall week 5.",[189,980,981,982,985,986,989,990,993],{},"Expect political arguments that are actually workspace arguments. Engineering will say the OS is slow. They are right for a one-line refactor. RevOps will say Cursor is unsafe. They are right for a production Opportunity. The CISO will say “one approved agent.” Translate: one ",[510,983,984],{},"write rule",", many loops. ",[199,987,293],{"href":291,"rel":988},[266]," oversight can be satisfied per system of use, not per brand. ",[199,991,681],{"href":274,"rel":992},[266]," Map is the same advice.",[189,995,996,997,1000],{},"If budget forces a single purchase this half, buy the loop that matches the ",[510,998,999],{},"highest-harm"," unfinished job. Ungoverned CRM writes usually outrank “we could use a better coding agent” — paste already exists; unsigned APIs are new blast radius. If the highest-harm job is shipping software and SoR writes are still human, buy the coding harness and freeze the write rule until the outer product lands. Either way, write the rule down before the PO.",[189,1002,1003],{},"Nimbus should win the outer row on self-service quoting and graph export, and should lose the inner row on purpose. If a bake-off ranks us against Claude Code on SWE-bench, the scorecard is wrong. If it ranks us against a copilot on mail quality, also wrong. Rank us against AIP and Agentforce on the refuse/replay script, and against “we’ll build LangGraph” on time-to-first-governed-write.",[189,1005,1006,1007,1010,1011,1014,1015,1018,1019,1023],{},"The copilot row still matters. People will keep ",[199,1008,596],{"href":594,"rel":1009},[266]," for drafts. That is healthy if the write path is the easy official one. Banning unofficial ",[510,1012,1013],{},"drafts"," usually fails; making unofficial ",[510,1016,1017],{},"writes"," fail-closed usually works. ",[199,1020,1022],{"href":1021},"what-is-shadow-ai","Shadow AI"," is often a write-path problem wearing a chat-policy costume.",[215,1025,1027],{"id":1026},"questions-people-actually-ask","Questions people actually ask",[1029,1030,1032],"h3",{"id":1031},"we-already-paid-for-github-copilot","We already paid for GitHub Copilot.",[189,1034,1035],{},"That is often a completion copilot, not a full coding harness. You may still want Claude Code or Cursor for agentic repo work. Evaluate hooks and tests, not the seat.",[1029,1037,1039],{"id":1038},"can-the-enterprise-harness-include-a-coding-specialist","Can the enterprise harness include a coding specialist?",[189,1041,1042,1043,1046,1047,585],{},"Yes, as a ",[510,1044,1045],{},"bounded tool"," that opens a draft PR. The SoR write still quotes in the outer harness. Specialists are hands. ",[199,1048,1050],{"href":1049},"agent-team-architecture","Agent teams",[1029,1052,1054],{"id":1053},"what-if-legal-wants-one-vendor","What if Legal wants one vendor?",[189,1056,1057],{},"One vendor for identity and logging is reasonable. One vendor for repo loop and CRM loop is how you get a mediocre both. Prefer two harnesses and one interceptor rule: unsigned SoR writes are impossible everywhere.",[1029,1059,1061],{"id":1060},"how-do-we-score-nimbus-vs-claude-code-in-a-bake-off","How do we score Nimbus vs Claude Code in a bake-off?",[189,1063,1064],{},"Different jobs. Run inner tests on a repo. Run outer tests on a quoted CRM write. A combined “winner” is a category error unless you only have one job.",[1029,1066,1068],{"id":1067},"what-should-i-read-next","What should I read next?",[189,1070,1071,1074,1075,1077,1078,1080],{},[199,1072,1073],{"href":501},"Inner vs outer"," for architecture. ",[199,1076,809],{"href":808}," for the live tests. ",[199,1079,584],{"href":583}," for the outer object.",[215,1082,1084],{"id":1083},"related-reading","Related reading",[189,1086,1087,412,1090,585],{},[199,1088,1089],{"href":506},"How to choose between a copilot and a work OS",[199,1091,1093],{"href":1092},"build-vs-buy-an-enterprise-ai-os","Build vs buy an enterprise AI OS",[215,1095,1097],{"id":1096},"sources","Sources",[320,1099,1100,1106,1112,1118,1124,1130,1136,1142,1147,1152,1158,1164,1170,1176,1181,1187],{},[323,1101,1102],{},[199,1103,1105],{"href":492,"rel":1104},[266],"LangChain, Agents",[323,1107,1108],{},[199,1109,1111],{"href":518,"rel":1110},[266],"Böckeler, Harness engineering for coding agent users",[323,1113,1114],{},[199,1115,1117],{"href":524,"rel":1116},[266],"Addy Osmani, Own the outer loop",[323,1119,1120],{},[199,1121,1123],{"href":530,"rel":1122},[266],"Thoughtworks, The operating system for enterprise AI",[323,1125,1126],{},[199,1127,1129],{"href":660,"rel":1128},[266],"Anthropic, Effective harnesses for long-running agents",[323,1131,1132],{},[199,1133,1135],{"href":604,"rel":1134},[266],"Anthropic, Claude for Work",[323,1137,1138],{},[199,1139,1141],{"href":594,"rel":1140},[266],"OpenAI, ChatGPT Enterprise",[323,1143,1144],{},[199,1145,601],{"href":599,"rel":1146},[266],[323,1148,1149],{},[199,1150,567],{"href":565,"rel":1151},[266],[323,1153,1154],{},[199,1155,1157],{"href":571,"rel":1156},[266],"Terminal-Bench (arXiv:2601.11868)",[323,1159,1160],{},[199,1161,1163],{"href":538,"rel":1162},[266],"McKinsey, The state of AI in 2025",[323,1165,1166],{},[199,1167,1169],{"href":699,"rel":1168},[266],"Stanford HAI, 2025 AI Index",[323,1171,1172],{},[199,1173,1175],{"href":274,"rel":1174},[266],"NIST AI RMF",[323,1177,1178],{},[199,1179,284],{"href":705,"rel":1180},[266],[323,1182,1183],{},[199,1184,1186],{"href":742,"rel":1185},[266],"OWASP Top 10 for LLM applications",[323,1188,1189],{},[199,1190,1193],{"href":1191,"rel":1192},"https://modelcontextprotocol.io/specification/2025-11-25/index",[266],"Model Context Protocol specification",{"title":170,"searchDepth":171,"depth":171,"links":1195},[1196,1197,1198,1199,1200,1201,1202,1210,1211],{"id":544,"depth":171,"text":545},{"id":647,"depth":171,"text":648},{"id":710,"depth":171,"text":711},{"id":776,"depth":171,"text":777},{"id":825,"depth":171,"text":826},{"id":909,"depth":171,"text":910},{"id":1026,"depth":171,"text":1027,"children":1203},[1204,1206,1207,1208,1209],{"id":1031,"depth":1205,"text":1032},3,{"id":1038,"depth":1205,"text":1039},{"id":1053,"depth":1205,"text":1054},{"id":1060,"depth":1205,"text":1061},{"id":1067,"depth":1205,"text":1068},{"id":1083,"depth":171,"text":1084},{"id":1096,"depth":171,"text":1097},"2026-08-24","A coding harness runs a repository — Claude Code, Cursor, Codex. An enterprise harness runs company jobs with connectors and signers. Most organisations need both; they are not substitutes.","/blog/how-to-choose-between-a-coding-harness-and-an-enterprise-harness",{"title":473,"description":1213},"blog/how-to-choose-between-a-coding-harness-and-an-enterprise-harness",[443,1218,1219,1220],"agent-harness","coding-agents","enterprise-ai","zypj0rFuSxQgNAtRx0gY8CyrewpGlXGHc6zrzz32V4g",{"enabled":164,"message":1223,"linkLabel":93,"linkHref":94,"id":1224,"title":1225,"archived":164,"authors":165,"badge":165,"body":1226,"date":165,"definedTerm":165,"department":165,"description":170,"extension":173,"eyebrow":165,"faqHeader":165,"faqs":165,"footerBand":165,"headline":165,"image":165,"industry":165,"jobType":165,"listed":130,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":1230,"relatedHeading":165,"seo":1231,"series":165,"sitemap":164,"status":165,"stem":1232,"subhead":165,"tags":165,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":1233},"We're hiring! Join the team building the Sentient Enterprise.","content/shared/hiring.md","Hiring banner",{"type":167,"value":1227,"toc":1228},[],{"title":170,"searchDepth":171,"depth":171,"links":1229},[],"/shared/hiring",{"title":1225,"description":170},"shared/hiring","1zs3boivKda1e-b-hAyuNcmZSKjZUAXmecnwHVgcHzk",{"fold":1235,"id":1239,"title":1240,"archived":164,"authors":165,"badge":165,"body":1241,"date":165,"definedTerm":165,"department":165,"description":170,"extension":173,"eyebrow":165,"faqHeader":165,"faqs":165,"footerBand":1245,"headline":165,"image":165,"industry":165,"jobType":165,"listed":130,"location":165,"navigation":130,"openRoles":165,"pageLayout":165,"path":1249,"relatedHeading":165,"seo":1250,"series":165,"sitemap":164,"status":165,"stem":1251,"subhead":165,"tags":165,"video":165,"whyJoin":165,"workplaceType":165,"__hash__":1252},{"headline":1236,"description":1237,"primaryLabel":8,"primaryTo":1238,"secondaryLabel":465,"secondaryTo":12},"Run frontier AI your business actually owns.","Governed agent swarms, 2,000+ integrations, and a knowledge graph that stays inside your walls. Free 7-day trial.","/checkout","content/shared/cta.md","Site CTAs",{"type":167,"value":1242,"toc":1243},[],{"title":170,"searchDepth":171,"depth":171,"links":1244},[],{"headline":1246,"description":1247,"primaryLabel":8,"primaryTo":1238,"secondaryLabel":1248,"secondaryTo":99},"See what governed AI looks like on your stack.","Connect your tools, run a workstream, and keep every decision on your ledger - free for 7 days.","Talk to our team","/shared/cta",{"title":1240,"description":170},"shared/cta","wz4AdRHnaYH021WMdWcHnZvHmkZJNKaNG4XGZfnFBtw",1788985847178]