Why CIOs should invest in agent harnesses
As AI agents access data and take autonomous actions, agent harnesses provide essential security and governance controls, enabling CIOs to scale AI safely across the enterprise.
AI agents promise to take on an expanding range of tasks across the enterprise, from automating routine processes to helping employees work across complex systems. But as agents gain the ability to access sensitive information and take actions on their own, giving them too much freedom can create new security and governance risks.
An agent harness provides the security, governance and observability layer around an AI agent. This helps an organization control what it can access, what actions it can take and how it behaves.
As enterprises begin to deploy agents at scale knowing how to govern safely is key.
The growing need for agent governance
In today’s enterprise, AI agents pose many of the same security and access risks as human employees.
That makes the question of what an agent can access -- and what it is allowed to do -- increasingly important. Employees typically receive training, operate under defined permissions and are granted access to sensitive information on a need-to-know basis. AI agents need similar boundaries.
“All of this is fairly new, in the scope of IT and how AI fits into any enterprise’s operation. A lot of people are running fast with scissors at this point,” said Joe DiFonzo, CIO at Sabre.
Data from the Cloud Security Alliance suggests that organizations are struggling to put key boundaries in place. The survey found that 53% of organizations said their AI agents occasionally or sometimes exceeded their intended permissions, while 47% reported a security incident involving an AI agent.
For Sandip Patel, senior cloud solution architect at Microsoft, the answer is to apply the same fundamental principles of access to AI agents as organizations already apply to employees.
“Agents have access to your systems, your sensitive data. So it’s important to treat an agent like you would a human,” Patel said.
Patel’s point speaks to a broader shift: as agents embed themselves further into the fabric of the workplace, governance is no longer a nice-to-have, and the systems we have to ensure employees engage with data safely make for a good blueprint for AI agents.
“All of the principles you had for human access to anything now also apply to all these agents,” DiFonzo said. “We have identity and access management infrastructure in the company that controls what systems employees can go into, what privileges they have access to and what data they can access. The same thing applies here.”
How does an agent harness work?
An agent harness is essentially a layer of scaffolding that surrounds an AI agent, bringing together the security, governance and operational controls needed to ensure it behaves within defined boundaries. The key components of a successful agent harness include:
- Audit trails and logging.
- Human oversight and intervention.
- Identity and access management.
- Observability and monitoring.
- Secure guardrails and permissions.
As an agent harness manages the above, organizations are given a way to manage agents much like they manage other actors within the enterprise. From limiting access to visibility, organizations have a much better grasp over how an AI agent is operating, especially when agents are used at scale.
As businesses deploy multiple agents to work together, agent harnesses provide visibility into the complex chains of interactions between them. This is increasingly important as agents take on more specialized roles.
“How do you organize your agents into a coherent mix of experts that are linked together in the right way to deliver the output at the end of a very long chain of interaction?” asks DiFonzo.
For DiFonzo, questions like this underscore the importance of controls. While it may sound like an extensive list of controls could become roadblocks to innovation and agent autonomy, they are in fact drivers of innovation. For CIOs grappling with the pace of AI adoption, putting these controls in place may be less about slowing innovation than creating a safe way to accelerate it.
Governance as an enabler of AI innovation
For leaders concerned that greater governance will inevitably slow innovation, the temptation to put the brakes on AI adoption can be strong.
Taking a more restrictive approach can create its own risks, according to Cindi Howson, chief data & AI strategy officer at ThoughtSpot. As employees find ways to use AI regardless of corporate policy, organizations can end up with less visibility and control over how the technology is being used.
“When innovation moves so quickly it’s almost easier for a CIO to say 'no, we’re going to turn everything off.' This gives rise to shadow IT and shadow AI,” said Howson. “You can’t just turn things off, because employees will circumvent it.”
Rather than restricting AI altogether, organizations need governance frameworks that allow employees to experiment within clearly defined boundaries, Howson said. This is where an agent harness can play a role, providing the controls needed to let businesses move quickly without leaving AI activity unchecked.
“Innovation in a large enterprise actually requires this kind of a platform,” said DiFonzo.
For innovation and growth to exist, there must be a level of governance to give businesses the confidence to experiment, deploy and scale AI without exposing the organisation to unnecessary risk.
A well-governed agent environment can allow organizations to:
- Experiment safely.
- Increase visibility of AI tools.
- Reduce shadow AI.
- Respond to risk quickly.
- Scale quickly and safely.
Advice for CIOs
As businesses continue to adopt AI agents, the case for agent harnesses is growing. For CIOs, investing in the right infrastructure is only part of the challenge. As agents become more deeply embedded in the enterprise, leaders will also need to rethink how AI is governed, owned and scaled.
Make AI governance a cross-functional responsibility
Governance doesn’t only belong to the CIO, it should be cross-functional, involving CIOs as well as the line of business, said Howson.
“The line of business will set the policy around acceptable risk and the pace at which they want to run at. The CIO will set the policy around reducing risk and budget,” she said. “AI governance really is a team sport.”
Prioritize safe, sustainable scale over the number of agents
When it comes to AI governance and agent harnesses, success comes from sustainable pacing and shouldn’t be considered a race to the finish line.
“The organizations that succeed with AI won't be the ones that deploy the most agents. They will be the ones that can safely govern, secure and continuously improve them,” said Patel.
Don't wait for the technology to mature
The time to embrace agent harnesses and agentic AI governance is now, according to DiFonzo.
“Move faster because you really need to get up to speed on this technology. It is the key to industrial scale AI,” he said.
The challenge is not choosing between governance and innovation, but building the foundations that allow both to happen at scale. Agent harnesses can provide that foundation, giving organizations the control they need to move faster with confidence.