No single control layer
Guardrails differ from agent to agent, so every review starts from scratch.
AI Harness
AI Harness is the governance, risk, compliance and operations layer for AI agents. Every agent is registered, risk-tiered, gated, controlled and audited, and a person stays accountable for every regulated decision.
When each agent carries its own compliance, accountability is unclear and audit evidence gets assembled after the fact. In regulated work, that is the gap that stops agents reaching production.
Guardrails differ from agent to agent, so every review starts from scratch.
It is hard to say who is accountable for what an agent does.
Audit records are pieced together later instead of written as things happen.
Harness puts the same four governance steps around every agent, whatever it does and whoever built it.
Each agent gets a named accountable owner and a risk tier, set by how much regulated data it touches and how independently it acts.
Policy and sensitive-data checks, agreements covering every model and connector that touches regulated data, and human sign-off before an agent goes live.
Guardrails run on every call. Regulated outcomes wait for a person to approve.
Continuous monitoring, escalation on low confidence, a written audit record and scheduled recertification.
Not every agent needs the same scrutiny. Harness assigns one of three tiers and applies the matching controls.
Monitor and log. For agents working on internal or non-sensitive data with a person closely involved.
Configured guardrails and sampled human review. For agents that touch sensitive data or act with more independence.
Mandatory human approval and a full audit trail. For agents that handle identifiable personal or health data and can affect a significant outcome for a person.
Agents do not own compliance. Harness does, through a single pipeline every call passes through.
Every agent call passes through one pipeline before it reaches a model, a knowledge base or a tool.
Patient and personal identifiers are removed before anything reaches a model, using self-hosted detection.
Incoming text such as clinical notes and user messages is checked for injection attempts first.
Each call is logged with who, which model and what outcome, at the moment it happens. Never backfilled.
Controls are mapped to clauses of the AI management system standard, so a security review has a framework to check against.
Agents move from prototype to pilot to production only through named gates, each with a recorded human sign-off.
Harness is designed around the obligations that apply to healthcare and life sciences.
HIPAA privacy and security and business associate agreements, with a person reviewing high-impact outputs and a record of who approved what.
Data-integrity principles (ALCOA+) and computerized-system expectations such as 21 CFR Part 11, with provenance for every output.
Harness supports your compliance programme. It does not replace your own legal and compliance review.
Set policy once and see every agent against it.
Control model and connector access, and review guardrail configuration.
Know the tier, the gates and the evidence each agent needs.
Read-only access to the registry, approvals and audit record.
Harness governs agents wherever they run. AI Foundry is the design environment that connects to Harness while an agent is being built, so compliance is part of the design rather than a review at the end.
Explore AI FoundryHarness is designed to run on AWS, Azure and Google Cloud, with your regulated data staying in your own environment.
Tell us about the agents you are building or running, and we will show you how Harness fits.