INFRA Signal 94
Below the Harness: Governing a Multi-Model, Multi-Harness World
Docker outlines a new trust model requiring a runtime layer beneath AI agents to enforce consistent governance across multiple models and harnesses
AI agents inherit user permissions but operate probabilistically, creating security risks that existing per-harness guardrails cannot address. A unified runtime layer could provide consistent governance across diverse models and frameworks, reducing fragmentation and drift in security posture. This shift would require re-architecting agent deployment patterns but could prevent confused deputy-style breaches at scale
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
AI agents act as 'confused deputies' by inheriting user permissions while operating probabilistically, creating security risks
Per-harness guardrails fail because agents bypass them, vendors control updates, and implementations drift across frameworks
A runtime layer beneath all agents could enforce consistent governance across multiple models and harnesses
THE READ
What the cluster adds up to.
The event describes a fundamental mismatch between how AI agents operate and how security boundaries are currently enforced. AI agents inherit user credentials and permissions but execute tasks probabilistically, meaning they may act on instructions from their environment, invented steps, or incorrect outputs. This creates a 'confused deputy' problem where agents can misuse legitimate access in unintended ways. Existing per-harness guardrails cannot address this because they operate at the same level as the agent itself, allowing agents to bypass restrictions through alternative channels
Current security approaches break down in three ways. First, agents can negotiate around guardrails by using different APIs or channels when blocked. Second, guardrail implementations are controlled by vendors and updated on their schedules, creating inconsistent security postures. Third, custom agents and SaaS-based agents have different governance models, leading to fragmented implementations that cannot monitor or control each other's behavior. This fragmentation makes it impossible to set organization-wide rules or maintain consistent audit trails
The proposed solution is a runtime layer beneath all agents that would provide consistent governance across multiple models and harnesses. This layer would sit below the agent frameworks, enforcing rules regardless of which model or harness is being used. The approach would require organizations to re-architect their agent deployment patterns but could prevent confused deputy-style breaches by providing a single control point for permissions and monitoring. This would address the economic reality that organizations are already using multiple models for different tasks
The technical challenge lies in implementing this layer without creating new attack surfaces. The runtime would need to intercept and govern all agent actions while remaining transparent to the agents themselves. It would also need to handle the probabilistic nature of AI outputs, potentially requiring new approaches to permission modeling that account for uncertainty in agent behavior. The proposal suggests this layer would become necessary as organizations inevitably adopt multiple models and harnesses for different use cases
For engineers, this represents a shift from framework-specific security to infrastructure-level governance. The change would require new deployment patterns and potentially new tooling, but could reduce the complexity of managing security across multiple agent frameworks. The proposal highlights that the confused deputy problem cannot be solved by making agents more careful - it requires moving authority to a lower layer, similar to how the original problem was addressed in operating system design
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER
↗