Structure Beats Magic
← All concepts
System architecture

The Model Proposes, the Harness Disposes

Give the model no direct external actions. It reasons and suggests; the surrounding layer validates, executes and records — that split is what makes an agent governable.

The Model Proposes, the Harness Disposes

The instinct when wiring an agent is to hand the model the tools and let it act. That single decision determines whether the system can be governed, because once the model executes directly there is no place left to stand between intention and effect. Every check becomes a request to the model to please behave.

The alternative is a hard architectural split: the model reasons, decides and generates a proposal — and holds no capability to reach the outside world. Around it sits the harness, which owns every call: guardrails on what may be attempted, budgets and retries, a sandbox for execution, routing, an evaluator on the result, observability and an audit trail. Around that sits governance, which gates the steps that need a human or an access decision.

This is what makes the difference between an agent that is constrained and one that is asked nicely. A model instructed not to delete production data may comply; a model with no delete capability cannot fail to. The first is a prompt, the second is an architecture — and only the second survives a prompt injection, a bad plan, or a model upgrade that quietly changes how instructions are weighted.

It also relocates the interesting engineering. If the model proposes and the harness disposes, then the quality of the system is set by the harness: what it validates, what it logs, when it escalates, how it recovers. That is unglamorous, buildable, testable work — and it is the part you own regardless of which model sits in the middle.

The neighbourhood

How this connects