The Agent Harness: The new architecture layer between AI and Action
CIOREVIEW >> Artificial Intelligence >> NEWS

Weston Wood Solutions

Jyoti Chopra, Director of Information Technology

The Agent Harness: The new architecture layer between AI and Action

Jyoti Chopra, Director of Information Technology
Jyoti Chopra, Director of Information Technology, Weston Wood Solutions

Jyoti Chopra

Intelligent Systems Strategist

Redefining AI's Role in the Enterprise

This is not the age of co-pilots that can assist with emails and summaries anymore. AI is now doing things. It is pulling information, generating tickets, updating systems and interfacing with workflows within ERP, CRM and service applications. This is where things become not just fascinating but risky. The potential is evident. But the control paradigm is not. And this is what most organizations are running into now. What lies between AI capability and actual execution is what we refer to as the agent harness.

This does not pertain to any products or tools. Instead, it is the layer that enables AI to “do anything” other than acting on its own. These controls provide answers to some of the very basic but important questions: Which type of data can be seen by the agent? Which permissions can it use? Which systems can it interact with? What is permitted vs. suggested? What gets recorded and what doesn’t? When and how does it end its process and handover the process to the human agent?

Currently, most of the conversation is taking place around models. However, in enterprise settings, the model is not the hard part. The tough part is everything else around it.

The place where traditional architecture fails

Most of the systems are designed to be predictable. We describe the process, we give the permission, and we know what the result will be. If anything happens, we notice it. There is an error, there is a log, and there is an alert. But AI works differently. It interprets. It predicts. It completes things. And sometimes it makes mistakes, and these mistakes look perfectly fine.

Consider a simple example in the banking industry. An AI agent assesses a client’s exposure but overlooks a critical position. It is not the failure of the system. It is the incorrect output. Your monitoring system will not detect it. This is the shift. We’re not just running systems anymore. We’re running decision layers inside systems.

Rethinking the Design Approach

Begin with Contextual Control. The easiest way to get into trouble is to give AI too much access. Just because the data is available does not mean that the agent should have access to it. It needs to be considered carefully. What sources are approved? Who owns them? How updated and reliable they are

For instance, in healthcare, allowing an agent to use any clinical practice guidelines may be acceptable, but allowing it to take patients’ data without proper control would be totally unacceptable. Most issues we’ve seen in the industry come back to this. Not the model but the context.

 

  ​The easiest way to get into trouble is to give AI too much access.”   

 

Treat Agents as Real Identities. Anything that is capable of taking actions must possess an identity. This fact is not new. What’s new is that the “anything” is not a human being. Service accounts are no longer enough, and this is a potential problem lying just around the corner. Agents must have well defined scope, explicit ownership, restricted access rights and traceability.

Think of retail. It makes sense that an inventory management agent would have access to restocking only for the particular geographic area that he is responsible for. But that same agent, having access across the entire supply chain, doesn’t.  The problem is to contain the access.

Be deliberate with system access. Once an agent has the ability to invoke an API or modify records, then it's part of your system. It’s a different kind of responsibility.

Within manufacturing, a suggestion from an agent to make an adjustment would be great. Allowing that agent to make changes to schedules unvalidated is another thing. Hence, it requires a structure of approved integrations, ownership of connections, allowed actions and logging of all actions. This is where organizations tend to underestimate the difficulty of this challenge.

Think and act separately. This is probably the single most important principle. Don’t have AI take actions based on its interpretation. Have AI interpret only. It means AI will be able to understand the command or request and suggest what needs to be done. But the execution part must go through a system that puts controls.

For example, when using a service desk, an agent can recommend resetting access or opening a ticket. This request needs to be validated and processed by the system, nonetheless. It sounds simple, but it marks the difference between order and chaos.

Know how it works. To have trust in any of these tools, you must be able to explain them. This means not on a theoretical level but on a practical one. You must be able to describe the following: what request was made? What data was used? What decision was made? What action was done?

This is critical in financial services because if there is any AI-based recommendation that concerns any compliance matters, you must be able to trace everything. If not, you won't trust it; no one else will either.

Beyond an IT Challenge

One misconception is that this is purely an IT concern. This is not true. Architecture determines the pattern. Security controls access. The data owners dictate usability. Application management determines integrations. Business management owns the solution.

Ultimately, IT must hold it all together. The agents must be managed like any other digital employee. They need to be on-boarded, tested, monitored, and eventually retired. Otherwise, it starts to fall apart.

The Future of AI in the Enterprise Space

The rapid deployment of AI in the enterprise space is a known quantity at this point. What may be less well-known is that the coming wave is not one of model improvement, but of better control over the use of those models. Organizations that master this phase will not only deploy AI, but they’ll also architect it to be controllable.

This is what an agent harness is. It’s not a feature. It’s not a tool. It’s the layer on top of AI that allows large-scale usability. And it shifts the paradigm. Because now the discussion is not about what AI can do, but about what you’re comfortable letting it do.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.