An agent harness is everything around the model that makes it act. The model only reads text and writes text. The harness is the program that takes what the model asks for, does it, and hands back the result.
What a harness does
A model can say "run this search" or "edit this file," but it cannot do either on its own. The harness:
- Runs the loop. It sends the model its instructions and the story so far, reads the reply, carries out any action, adds the result, and calls the model again until the task is done or stopped.
- Executes tools. Browsers, code runners, file access and outside services are all connected through the harness, often using a standard such as the Model Context Protocol.
- Manages context. It decides what stays in the context window, what gets summarized and what is saved as memory.
- Enforces limits. Permissions, spending caps, approval steps and logs live here.
A common shorthand is agent = model + harness. Some writers say "scaffold" for the same idea, and the exact boundary varies from source to source.
An analogy
Think of the model as a very capable contractor who can only talk. The harness is the site manager who passes along the instructions, hands over the tools, writes down what was done and can pull the plug. Swap the contractor and the site manager still works. Fire the site manager and nothing gets built.
Why it matters to you
Two agents running the same model can behave very differently because their harnesses differ. Much of what people call an agent's quality is harness quality: how well it recovers from errors, how much it remembers and how it checks its own work.
The harness is also where safety belongs. A rule written in a prompt is a request. A rule enforced in the harness, such as a blocked domain, a spending cap or a required human approval, holds even if the model misbehaves. That is why careful builders keep permissions and logs somewhere the model cannot edit, often inside an agent sandbox.
How it relates to neighboring terms
An AI agent is the combined system. The harness is its non-model half. AI guardrails are checks that usually run inside or beside the harness. A framework is a library of parts for building harnesses, while an orchestrator manages several agents, each with a harness of its own.
What to look for when you choose one
Ask what the harness lets the agent do without asking you, where its logs go, whether you can stop a task mid-step, and which of its limits depend on the model behaving. If you can answer those four, you understand your agent better than most people running one.