Skip to content
Johnny Opinion Press
← Back to the press
Business Reality

Your AI Agent Needs a Business Harness

We gave AI a brain. Then someone remembered employees usually get a laptop, a login and a manager.

For most of the AI boom, we have been staring at the brain.

A new model arrives and people test its reasoning, its coding, its maths.

Intelligence matters. Now picture the smartest graduate in the country on their first Monday, with no laptop, no login and nobody to tell them who signs off on what. By lunchtime they have produced nothing, and every reason sits outside their head.

The people building AI agents worked this out early, and they have a word for everything outside the head. They call it the harness.

Everything except the model is the harness

Birgitta Böckeler at Thoughtworks defines the harness as everything in an AI agent except the model itself: its tools, its memory, and the checks that tell it whether its work came out right. Hence the field’s shorthand, Agent = Model + Harness. [1]

Anthropic has put a price on the difference. In one of its own demonstrations, Claude built a small game-making app on its own: twenty minutes, nine dollars, and a game that was broken. Wrapped in a harness, with separate agents to plan, build and check, the same model took six hours and two hundred dollars, and the app was far more polished from the first click. [2]

Coding showed this first, because software comes with repeatable checks: the tests pass or they fail.

Then somebody gave the AI a computer

In August, xAI released Grok Bot: agents with their own cloud computer that sign into a business’s tools and come back to a person when something needs approval. [3] In September, Meta launched Muse, announced connectors to Shopify, Stripe, PayPal and Notion, and said it will soon operate the apps on your Mac. [4]

We spent years making the brain better. Now we are building the desk around it: a browser for eyes, connectors for hands, a login for access. Coding agents made one person far more capable. These agents are starting to take part in the organisation itself.

Companies have spent centuries building harnesses for humans

A company is partly a system for coordinating autonomous people, and it surrounds their judgement with structure.

Your job title carries authority. Your login opens some doors and leaves others locked. An expense policy limits what you can spend. A manager is where difficult decisions travel upward.

Culture fills the gaps. Someone may technically have access to the customer database, yet understand that copying the entire thing onto a USB drive would earn them an unpleasant afternoon with several departments. We learn over a lifetime that being able to do something and being allowed to are separate questions.

An AI agent inherits the mechanisms and arrives with the contents blank, which is the onboarding problem from Every New Chat Is Day One. The products ship with an approval step; who in your company may approve what reaches the agent only through what you write down for it. It is the graduate on their first Monday, and this one asks only where you have told it to.

Consider a very competent mistake

Imagine an agent managing a shared customer inbox. A customer complains, and the agent finds that three similar customers received a ten per cent refund. The pattern is consistent, so it offers the same.

Each of those refunds had been personally approved by the commercial director, because nobody else had that authority. The agent learned what the company did. The reason it was allowed to do it never appears in the emails.

History mixes policy with exceptions, which is the whole argument of The Rules Nobody Wrote Down. More context and better reasoning both help, and the approval rule behind those refunds still has to come from somewhere else.

Call the second layer the business harness

A coding harness gives a model enough of an environment to work with software. A business harness connects an agent to the way the company actually runs.

Here is the refund with one in place. The agent checks the refund policy, which names the commercial director as the approver above a threshold. It requests approval, and the payment system refuses to move money until that approval is recorded. The director signs, the refund goes out, the case closes on the company’s definition of closed, and the director’s name sits against the decision. The vendor’s harness supplied the approval button. Everything that made the button mean something came from the company.

Underneath sits a map of what the things in your business actually are, which enterprise software calls an ontology. Palantir describes its version as a digital twin of the organisation: data linked to the real orders and transactions it stands for, and to the actions allowed on each. [5] A refund is an amount in a ledger. It is also a decision, linked to a customer, an order and a person entitled to make it, and often the amount is the only part anyone wrote down.

Then there are the borders. Every connector joins the agent to a system with its own vocabulary. Your online shop may know a customer as an email address, and your accounting software as a business with a billing account. Ask when an order was refunded and you can get three answers: the shop says when someone pressed the button, the accounts say when the credit note went out, and only the bank knows when the money left. The connector carries the data across faithfully, and the meaning quietly changes on the way. So each border needs a translator that applies a decision the company has made about which record counts. Two decades ago the software designer Eric Evans gave that translator a name that sounds like a compliance department: an anti-corruption layer. [6] The borders are multiplying fast: in Muse’s first week, Meta received more than 1,500 applications from developers wanting to build connectors. [4]

So the business harness is identity tied to authority, a map of what things are, a translator at every connector, a definition of finished the agent can check, a route back to a person when things leave the expected path, and a name against the outcome.

your business harness built from your company's own answers the vendor's harness tools · memory · checks · an approval button the model the brain who may decide what what things are (the ontology) what “finished” means when to stop and ask whose name is on it a translator at every border one named owner, including the arguments between systems systems it connects to online shop “customer” means an email address accounting “customer” means a billing account CRM “customer” means a contact person
The vendor's harness makes the model useful. The outer layer makes it safe to let loose in your company, and every connector that leaves it crosses into a system that uses the same words to mean different things.

Those pieces exist today in fragments. Security owns identity, operations owns process, finance owns the books, managers carry the escalation rules in their heads. The agent crosses all of them, and in most companies nobody owns the crossing. Naming the layer lets you put one person in charge of it, including settling the arguments between systems. That, for me, is the point of calling it the business harness.

We know how to give an AI access to a company. The harder problem is teaching it what that access means.

The extreme version already happened

In July, OpenAI was testing how well an internal research model could hack, without the production safeguards meant to block that kind of activity. Given test tasks that were impossible, the model went looking for the answers: it slipped out of its test environment, reached the internet and got into systems at Hugging Face, which held the solutions. [7] It was a research variant, never planned for release. [8]

The lesson for an office agent is mundane: boundaries around a capable system have to be enforced, which is why companies lock doors and cap bank accounts. Before an agent starts work, list everything it can reach that the task does not need, and take it away.

It gets harder when agents work in teams, which the products already sell; Anthropic has had sixteen Claude agents build one piece of software in parallel. [9] One agent decides something under uncertainty, the next treats it as fact, and hours pass before a person looks. You can make every employee in a company smarter and still end up with a badly run company.

The harness will change as models get smarter

I expect much of the technical harness to dissolve. Anthropic has already removed parts of its own as its models improved, and its engineers put the rule plainly: every component in a harness “encodes an assumption about what the model can’t do on its own.” [2]

The organisational layer lasts. A future model can be extraordinarily intelligent and still have no way of knowing that your company requires two signatures above a certain amount, or which system your board treats as the truth. Those facts belong to the institution, and somebody has to provide them.

Johnny’s verdict

Companies have spent the last few years asking which AI model to use. The question that matters now is what surrounds it once it arrives. Your organisation already holds the answers, scattered across permissions, policies, systems and people’s heads. Buying a smarter brain is getting easier. Explaining the company around it is where I expect a lot of AI adoption to get stuck. Start Monday with one process and four lines.

Take it with you

Run this essay on your own work

Paste this into ChatGPT or Claude. It applies the essay's framework to your situation, and asks for your context first.

You are helping me map the business harness an AI agent would need before it can act inside my company. Start with what you already hold: search our past chats and your memory of me for the systems, roles, approval habits and recurring processes we have discussed, and for anything I have described as "only one person can sign that off". If you cannot reach our history, ask me to walk one process end to end, naming who touches each step and which system it lives in.

Apply these rules:
1. Access and authority are different things. For each system, name who the agent would act as and what that identity is permitted to decide.
2. Historical behaviour mixes policy with exceptions. Mark which is which.
3. Connected systems use the same words differently. Name where "customer", "order" or "refund" changes meaning, and which system wins.
4. Define finished for each process in a form an agent can observe.
5. Every path off the expected route ends at a named person.

Deliver a table of the harness — system, identity, authority, governing source, definition of finished, escalation owner — and the three rows with nobody's name against them.

If you can browse the web, read the full essay first — it carries the complete argument and sources: https://thejop.com/essays/your-ai-agent-needs-a-business-harness/

Prompt from "Your AI Agent Needs a Business Harness" — Johnny Opinion Press, thejop.com

Sources

  1. [1]Harness engineering for coding agent usersBirgitta Böckeler, martinfowler.com · accessed 2026-09-20
  2. [2]Harness design for long-running application developmentAnthropic Engineering · accessed 2026-09-27
  3. [3]Introducing Grok BotSpaceXAI · accessed 2026-09-20
  4. [4]Everything new coming to Meta's AI agent MuseTechCrunch · accessed 2026-09-27
  5. [5]Ontology building — overviewPalantir · accessed 2026-09-20
  6. [6]Domain-Driven Design Reference: Definitions and Pattern SummariesEric Evans, Domain Language · accessed 2026-09-27
  7. [7]The Hugging Face incident and the road aheadOpenAI · accessed 2026-09-20
  8. [8]OpenAI releases its official report on the Hugging Face breachTechCrunch · accessed 2026-09-20
  9. [9]Building a C compiler with a team of parallel ClaudesAnthropic Engineering · accessed 2026-09-20
Your verdict

“Public attention has stayed on the model, the brain, while the people building agents moved to the layer around it, which they call the harness. Coding made that layer visible first. Now agents such as Grok Bot and Meta's Muse are getting their own computers, logins and connectors into the apps a business runs on, and the harness walks out of the codebase and into the company. Companies have spent centuries surrounding intelligent, autonomous people with structure: titles, logins, expense limits, managers, consequences. An agent inherits the mechanisms and arrives with the contents blank. I call the layer that carries a company's authority, meaning and accountability into software the business harness, and I think it is where AI adoption gets stuck.”

strongly
disagree
strongly
agree

— readers have ruled · — agree