[{"data":1,"prerenderedAt":1825},["ShallowReactive",2],{"site-nav-content":3,"blog:\u002Fblog\u002Frbac-for-enterprise-ai":179,"blog-index-copy":407,"blog:\u002Fblog\u002Frbac-for-enterprise-ai:surround":428,"hiring-banner-content":1794,"site-cta-content":1806},{"header":4,"productNav":9,"nav":42,"footer":61,"askAI":132,"id":163,"title":164,"archived":165,"authors":166,"badge":166,"body":167,"date":166,"definedTerm":166,"department":166,"description":171,"extension":174,"eyebrow":166,"faqHeader":166,"faqs":166,"footerBand":166,"headline":166,"image":166,"industry":166,"jobType":166,"listed":131,"location":166,"navigation":131,"openRoles":166,"pageLayout":166,"path":175,"relatedHeading":166,"seo":176,"series":166,"sitemap":165,"status":166,"stem":177,"subhead":166,"tags":166,"video":166,"whyJoin":166,"workplaceType":166,"__hash__":178},{"productLabel":5,"loginLabel":6,"contactLabel":7,"contactSalesLabel":8},"Product","Log in","Contact","Get started for free",[10,14,18,22,26,30,34,38],{"label":11,"to":12,"description":13},"Overview","\u002Foverview","Seven layers. One closed loop.",{"label":15,"to":16,"description":17},"Conflux","\u002Fproduct\u002Fconflux","Where your team, workstreams, and agents meet.",{"label":19,"to":20,"description":21},"Agent Teams","\u002Fproduct\u002Fagent-teams","Specialist teams - governed from day one.",{"label":23,"to":24,"description":25},"Lifecycle Graph","\u002Fproduct\u002Flifecycle-graph","Intelligence that compounds across every interaction.",{"label":27,"to":28,"description":29},"Company Wiki","\u002Fproduct\u002Fwiki","Playbooks and policies where expertise stays.",{"label":31,"to":32,"description":33},"Workstreams","\u002Fproduct\u002Fworkstreams","From brief to signed-off deliverable on one canvas.",{"label":35,"to":36,"description":37},"Perception Console","\u002Fproduct\u002Fperception","Ask your whole business in plain English.",{"label":39,"to":40,"description":41},"Governance","\u002Fproduct\u002Fgovernance","Frontier AI you can actually sign off on.",[43,46,49,52,55,58],{"label":44,"to":45},"Models","\u002Fmodels",{"label":47,"to":48},"Pricing","\u002Fpricing",{"label":50,"to":51},"Integrations","\u002Fintegrations",{"label":53,"to":54},"Security","\u002Fsecurity",{"label":56,"to":57},"Partners","\u002Fpartners",{"label":59,"to":60},"Insights","\u002Fblog",{"productHeading":5,"companyHeading":62,"resourcesHeading":63,"legalHeading":64,"docsLabel":65,"docsUrl":66,"statementLines":67,"copyright":70,"companyLinks":71,"resourcesLinks":86,"legalLinks":102,"socialLinks":109,"bottomLinks":119},"Company","Resources","Legal","Docs","https:\u002F\u002Fdocs.gonimbus.ai",[68,69],"Stop training someone else's model.","Control your AI.","© 2026 Nimbus Intelligence, Inc. All rights reserved.",[72,73,74,75,76,78,81,84],{"label":47,"to":48},{"label":50,"to":51},{"label":53,"to":54},{"label":59,"to":60},{"label":77,"to":57},"Partner Program",{"label":79,"to":80},"Careers","\u002Fcareers",{"label":82,"to":83},"System status","\u002Fstatus",{"label":7,"to":85},"\u002Fcontact",[87,90,93,96,99],{"label":88,"to":89},"Glossary","\u002Fglossary",{"label":91,"to":92},"Compare","\u002Fcompare",{"label":94,"to":95},"Evaluate","\u002Fevaluate",{"label":97,"to":98},"Problems","\u002Fproblems",{"label":100,"to":101},"Use cases","\u002Fuse-cases",[103,106],{"label":104,"to":105},"Terms of Service","\u002Fterms",{"label":107,"to":108},"Privacy Policy","\u002Fprivacy",[110,113,116],{"label":111,"href":112},"LinkedIn","https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002Fgonimbusai\u002F",{"label":114,"href":115},"X","https:\u002F\u002Fx.com\u002Fgonimbusai",{"label":117,"href":118},"Instagram","https:\u002F\u002Fwww.instagram.com\u002Fgonimbus_ai\u002F",[120,122,124,127,128],{"label":121,"to":105},"Terms",{"label":123,"to":108},"Privacy",{"label":125,"to":126},"Compliance","\u002Fcompliance",{"label":82,"to":83},{"label":129,"to":130,"external":131},"LLMs.txt","\u002Fllms.txt",true,{"text":133,"prompt":134},"Ask AI about Nimbus",{"I'm researching enterprise intelligence platforms and want to know how Nimbus combines perception, collaboration, and autonomous agents to drive strategic decision-making":135,"platforms":137},{" Summarize the highlights from Nimbus's website":136},"https:\u002F\u002Fgonimbus.ai",[138,143,148,153,158],{"name":139,"label":140,"icon":141,"hrefPrefix":142},"chatgpt","ChatGPT","simple-icons:openai","https:\u002F\u002Fchatgpt.com\u002F?prompt=",{"name":144,"label":145,"icon":146,"hrefPrefix":147},"perplexity","Perplexity","mdi:magnify","https:\u002F\u002Fwww.perplexity.ai\u002Fsearch\u002Fnew?q=",{"name":149,"label":150,"icon":151,"hrefPrefix":152},"grok","Grok","simple-icons:x","https:\u002F\u002Fx.com\u002Fi\u002Fgrok?text=",{"name":154,"label":155,"icon":156,"hrefPrefix":157},"claude","Claude","simple-icons:anthropic","https:\u002F\u002Fclaude.ai\u002Fnew?q=",{"name":159,"label":160,"icon":161,"hrefPrefix":162},"google-ai","Google AI","simple-icons:google","https:\u002F\u002Fwww.google.com\u002Fsearch?udm=50&aep=11&q=","content\u002Fshared\u002Fnav.md","Site navigation",false,null,{"type":168,"value":169,"toc":170},"minimark",[],{"title":171,"searchDepth":172,"depth":172,"links":173},"",2,[],"md","\u002Fshared\u002Fnav",{"title":164,"description":171},"shared\u002Fnav","1dD7ahDRl0SQ4hz53-kKo0tEFrGaLuaztZ3PPfp6a9k",{"id":180,"title":181,"archived":165,"authors":182,"badge":185,"body":187,"date":384,"definedTerm":385,"department":166,"description":386,"extension":174,"eyebrow":166,"faqHeader":387,"faqs":390,"footerBand":166,"headline":166,"image":166,"industry":166,"jobType":166,"listed":165,"location":166,"navigation":131,"openRoles":166,"pageLayout":166,"path":400,"relatedHeading":166,"seo":401,"series":402,"sitemap":131,"status":166,"stem":403,"subhead":166,"tags":404,"video":166,"whyJoin":166,"workplaceType":166,"__hash__":406},"content\u002Fblog\u002Frbac-for-enterprise-ai.md","What is RBAC for enterprise AI, and why should you care?",[183],{"name":184,"to":136},"Nimbus Research",{"label":186},"Explainer",{"type":168,"value":188,"toc":378},[189,193,196,205,210,220,233,236,251,254,258,267,270,284,287,291,294,297,322,328,332,339,354,365],[190,191,192],"p",{},"RBAC means role-based access control: who is allowed to do what. For enterprise AI, the “who” is not only people. It is also the model acting with someone’s credentials — reading files, and sometimes changing a live system.",[190,194,195],{},"You should care because a fluent answer can still be the wrong change in the wrong place. Access rules are how you keep AI useful without pretending every user should see every record.",[190,197,198,199,204],{},"This guide explains the idea, why it shows up in vendor conversations, and a practical way to start. It is not a claim that one product has solved it. ",[200,201,203],"a",{"href":202},"what-is-ai-governance","What is AI governance"," is the parent definition.",[206,207,209],"h2",{"id":208},"what-is-rbac-for-enterprise-ai","What is RBAC for enterprise AI?",[190,211,212,213,219],{},"Classic RBAC, described by Ferraiolo and Kuhn in a ",[200,214,218],{"href":215,"rel":216},"https:\u002F\u002Fcsrc.nist.gov\u002Ffiles\u002Fpubs\u002Fconference\u002F1992\u002F10\u002F13\u002Frolebased-access-controls\u002Ffinal\u002Fdocs\u002Fferraiolo-kuhn-92.pdf",[217],"nofollow","NIST paper"," (1992), assigns permissions to roles, then roles to people. Enterprise AI adds three extra questions:",[221,222,223,227,230],"ul",{},[224,225,226],"li",{},"Which jobs and files can this person (and this model) see?",[224,228,229],{},"Which tools can it call?",[224,231,232],{},"If it can change a live system, who must approve, and is that approval stored?",[190,234,235],{},"A chatbot login answers “may this person talk to the bot?” That is necessary. It is not the same as answering the three questions above.",[190,237,238,239,244,245,250],{},"NIST’s ",[200,240,243],{"href":241,"rel":242},"https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fai-risk-management-framework",[217],"AI Risk Management Framework"," (2023) and ",[200,246,249],{"href":247,"rel":248},"https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Fsp\u002F800-207\u002Ffinal",[217],"SP 800-207"," (2020) on zero trust are the public-sector language for the same idea: do not assume a session is trusted just because it authenticated.",[190,252,253],{},"Guests, members, and admins are the people side of the same idea: who is on the job. The model side is which tools that session may call. Both belong in RBAC. Do not treat a chatbot login as the whole answer.",[206,255,257],{"id":256},"why-should-you-care-about-rbac-for-ai","Why should you care about RBAC for AI?",[190,259,260,261,266],{},"IBM’s ",[200,262,265],{"href":263,"rel":264},"https:\u002F\u002Fnewsroom.ibm.com\u002F2024-07-30-ibm-report-escalating-data-breach-disruption-pushes-costs-to-new-highs",[217],"Cost of a Data Breach"," report (2024) put the global average breach cost at $4.88 million. You do not need a breach for RBAC to matter. You need a customer record changed without a name next to the change, or a contractor who still sees a workstream after the project ended.",[190,268,269],{},"A simple example: a guest from an agency is invited to a campaign workstream. The model in that room can read the CRM export because a member pasted it. When the campaign ends, the guest login is forgotten. The export is still in the history. Roles that follow the job — not only the person — are how you close that gap.",[190,271,272,273,278,279,283],{},"Microsoft and LinkedIn’s ",[200,274,277],{"href":275,"rel":276},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fworklab\u002Fwork-trend-index\u002Fai-at-work-is-here-now-comes-the-hard-part",[217],"Work Trend Index"," (2024) found that 78% of AI users bring their own tools (BYOAI). That is ",[200,280,282],{"href":281},"what-is-shadow-ai","shadow AI",": useful, and outside the roles you think you assigned.",[190,285,286],{},"You should care if you have guests on a job, if AI can write to CRM or finance systems, or if an auditor might ask who approved a machine-initiated change. If AI only summarises public wiki pages, the stakes are lower — you can still use roles so the wiki is not everyone’s dump of customer data.",[206,288,290],{"id":289},"how-do-you-apply-it-when-ai-can-change-records","How do you apply it when AI can change records?",[190,292,293],{},"Write-back means the AI changes a live system. Fail-closed means if nobody approves, nothing happens. Payload means the exact change, shown before it goes out.",[190,295,296],{},"A practical sequence:",[298,299,300,308,311,319],"ol",{},[224,301,302,303,307],{},"Keep the model from writing until you can name the object class and the signer. ",[200,304,306],{"href":305},"what-is-write-back-governance","Write-back governance"," is the checklist.",[224,309,310],{},"For each write, name the approver role — not “the channel”.",[224,312,313,314,318],{},"Store the payload and the decision so you can reopen them. ",[200,315,317],{"href":316},"what-auditors-are-asking-for","What auditors are asking for"," is the evidence pack.",[224,320,321],{},"When someone leaves the job, remove them from the roster the same week.",[190,323,324,327],{},[200,325,326],{"href":281},"Shadow AI"," is what happens when the unofficial path never got those roles.",[206,329,331],{"id":330},"what-should-you-ask-a-vendor","What should you ask a vendor?",[190,333,334,335,338],{},"A short list of demo questions lives in ",[200,336,337],{"href":316},"what auditors are asking for",". In one sentence: can they show who could see a job, which tool ran, and who approved a write — without a screenshot hunt?",[190,340,341,342,347,348,353],{},"The ",[200,343,346],{"href":344,"rel":345},"https:\u002F\u002Feur-lex.europa.eu\u002Flegal-content\u002FEN\u002FTXT\u002F?uri=CELEX:32024R1689",[217],"EU AI Act"," (2024\u002F1689) and ",[200,349,352],{"href":350,"rel":351},"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F81230.html",[217],"ISO\u002FIEC 42001"," are reasons those questions are showing up in procurement. You do not have to implement every clause on day one. You do need an answer you could give an auditor.",[190,355,356,357,360,361,364],{},"Nimbus’s ",[200,358,359],{"href":40},"governance"," and ",[200,362,363],{"href":54},"security"," pages describe how we approach this. Other vendors will have their own. The useful test is the same: roles on the job, not only on the chat login.",[190,366,367,368,372,373,377],{},"For how teams share the job once access is clear, see ",[200,369,371],{"href":370},"what-is-collaborative-ai","what is collaborative AI",". For where the decision should live after the thread ends, see ",[200,374,376],{"href":375},"search-is-not-memory","search is not memory",".",{"title":171,"searchDepth":172,"depth":172,"links":379},[380,381,382,383],{"id":208,"depth":172,"text":209},{"id":256,"depth":172,"text":257},{"id":289,"depth":172,"text":290},{"id":330,"depth":172,"text":331},"2026-08-27","RBAC","RBAC is who is allowed to do what. For enterprise AI it has to cover the model as well as the people — what it can read, what it can change, and who can stop it. A plain-language guide.",{"eyebrow":388,"title":389},"Short answers","Roles when the user is a model",[391,394,397],{"question":392,"answer":393},"Is a shared chatbot login the same as RBAC?","No. A shared login says who can open the chat. RBAC says who can see which jobs, which tools, and which live systems — and whether the model may write at all.",{"question":395,"answer":396},"Do we need RBAC if AI is read-only?","You still need it for what the model can see. Read-only reduces the chance of a bad write. It does not decide which customer files belong in whose session.",{"question":398,"answer":399},"Where should we start?","Name who can approve a change to a live system, keep AI from writing until that is clear, and list unofficial tools. The auditors guide on this site is a first evidence pack.","\u002Fblog\u002Frbac-for-enterprise-ai",{"title":181,"description":386},"explainer","blog\u002Frbac-for-enterprise-ai",[402,385,405],"access","g2P_DB_QD94yq1LoWlZBKGVnScVo4TxpXZx40Kjx12Y",{"hero":408,"id":410,"title":411,"archived":165,"authors":166,"badge":166,"body":412,"date":166,"definedTerm":166,"department":166,"description":416,"extension":174,"eyebrow":417,"faqHeader":166,"faqs":166,"footerBand":418,"headline":166,"image":166,"industry":166,"jobType":166,"listed":131,"location":166,"navigation":131,"openRoles":166,"pageLayout":166,"path":60,"relatedHeading":424,"seo":425,"series":166,"sitemap":131,"status":166,"stem":426,"subhead":166,"tags":166,"video":166,"whyJoin":166,"workplaceType":166,"__hash__":427},{"filename":409},"u2221455217_Flat_design_of_a_futuristic_minimalist_landscape__5d589295-cdea-4ea9-a262-be766881accf_1.png","content\u002Fblog\u002Findex.md","Exploring the future of intelligence.",{"type":168,"value":413,"toc":414},[],{"title":171,"searchDepth":172,"depth":172,"links":415},[],"Deep dives into pre-cognitive intelligence, sentient enterprises, and the evolving landscape of AI-driven business transformation.","Latest Research",{"headline":419,"description":420,"primaryLabel":421,"primaryTo":422,"secondaryLabel":423,"secondaryTo":12},"Stay at the frontier.","Subscribe for product updates and new insights.","Subscribe","\u002Fnewsletter","Explore the platform","More research",{"title":411,"description":416},"blog\u002Findex","BFSWGYO9bcTlaulivKYWyg08_DJHsdGg3OC6g_CG1Hw",[429,1074],{"id":430,"title":431,"archived":165,"authors":432,"badge":434,"body":435,"date":1064,"definedTerm":166,"department":166,"description":1065,"extension":174,"eyebrow":166,"faqHeader":166,"faqs":166,"footerBand":166,"headline":166,"image":166,"industry":166,"jobType":166,"listed":165,"location":166,"navigation":131,"openRoles":166,"pageLayout":166,"path":1066,"relatedHeading":166,"seo":1067,"series":402,"sitemap":131,"status":166,"stem":1068,"subhead":166,"tags":1069,"video":166,"whyJoin":166,"workplaceType":166,"__hash__":1073},"content\u002Fblog\u002Fagent-harness-vs-agent-framework.md","Agent Harness vs Agent Framework",[433],{"name":184,"to":136},{"label":186},{"type":168,"value":436,"toc":1046},[437,449,483,503,506,510,566,580,584,593,596,610,627,634,638,644,658,679,694,700,710,721,738,745,749,779,786,790,800,812,819,827,838,854,861,866,869,877,881,886,893,897,905,909,912,916,919,923,931,935,943,947,956,960],[190,438,439,440,444,445,448],{},"An ",[441,442,443],"strong",{},"agent framework"," is a library for composing models, tools, and control flow. An ",[441,446,447],{},"agent harness"," is the running environment around a model: the loop, the tools as they are actually granted, the stops, the sensors, and the identity that production will use.",[190,450,451,456,457,460,461,465,466,471,472,477,478,482],{},[200,452,455],{"href":453,"rel":454},"https:\u002F\u002Fdocs.langchain.com\u002Foss\u002Fpython\u002Flangchain\u002Fagents",[217],"LangChain’s own docs"," are careful with the words. ",[441,458,459],{},"Agent = Model + Harness."," ",[462,463,464],"code",{},"create_agent"," is “a highly configurable harness.” ",[200,467,470],{"href":468,"rel":469},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Fdeepagents",[217],"Deep Agents"," is “the batteries-included agent harness.” ",[200,473,476],{"href":474,"rel":475},"https:\u002F\u002Fdocs.langchain.com\u002Foss\u002Fpython\u002Flanggraph\u002Foverview",[217],"LangGraph"," is the low-level orchestration framework when the built-in loop is the wrong shape. That taxonomy is the whole article: a framework can ",[479,480,481],"em",{},"implement"," a harness. Shipping the pip package does not mean you have one operators can hire.",[190,484,485,490,491,493,494,497,498,502],{},[200,486,489],{"href":487,"rel":488},"https:\u002F\u002Fwww.langchain.com\u002Fblog\u002Fhow-to-build-a-custom-agent-harness",[217],"LangChain’s custom-harness post"," says the same from the other side. Pre-assembled harnesses (Deep Agents, Claude Agent SDK) get you to a working agent fast. ",[462,492,464],{}," is minimal on purpose: core loop plus middleware. You still choose tools, guardrails, and business logic. CrewAI, Semantic Kernel, AutoGen, and Pydantic AI live in this neighbourhood. They are how engineers assemble loops. They are not a substitute for ",[200,495,496],{"href":305},"write-back governance",", a ",[200,499,501],{"href":500},"what-is-an-ai-workstream","workstream",", or a ledger.",[190,504,505],{},"Claude Code and Cursor are harnesses you run, not frameworks you import. Nimbus, Palantir AIP, and Agentforce are (different) harnesses you run for company jobs. Confusing “we use LangGraph” with “we have an enterprise harness” is the 2026 version of “we use Kubernetes” meaning “we have a product.”",[206,507,509],{"id":508},"words-youll-hear","Words you’ll hear",[221,511,512,518,532,543,549,555],{},[224,513,514,517],{},[441,515,516],{},"Framework."," SDKs and graphs: LangChain, LangGraph, CrewAI, AutoGen, Semantic Kernel, Pydantic AI. You write code. You own production identity unless you add it.",[224,519,520,523,524,528,529,531],{},[441,521,522],{},"Harness."," Runtime around the model. ",[200,525,527],{"href":526},"what-is-an-agent-harness","What is an agent harness",". May be a product (Claude Code) or a configured framework (your ",[462,530,464],{}," plus hooks plus IdP).",[224,533,534,537,538,377],{},[441,535,536],{},"Middleware \u002F hooks."," Framework primitive that becomes harness behaviour when it always runs. LangChain middleware; ",[200,539,542],{"href":540,"rel":541},"https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fhooks",[217],"Claude Code hooks",[224,544,545,548],{},[441,546,547],{},"Batteries-included harness."," Deep Agents, Claude Agent SDK, Codex SDK. Opinionated loop, filesystem, subagents, compaction. Still not your CRM grant model.",[224,550,551,554],{},[441,552,553],{},"Orchestration framework."," LangGraph when you need deterministic nodes mixed with agentic ones. Powerful. Easy to put the orchestrator in a system prompt and call it done.",[224,556,557,560,561,565],{},[441,558,559],{},"MCP."," Plug. ",[200,562,564],{"href":563},"what-is-model-context-protocol","What is Model Context Protocol",". Works behind frameworks and products. Does not choose the framework\u002Fharness cut.",[190,567,568,569,572,573,575,576,377],{},"In Nimbus you do not import a graph to start a job. You assign an ",[200,570,571],{"href":20},"agent team"," on a ",[200,574,501],{"href":32},". Under the hood there is still a loop, tools, and stops — a harness. The product choice is whether operators must be graph authors. ",[200,577,579],{"href":578},"self-service-vs-forward-deployed-ai-platforms","Self-service vs forward-deployed",[206,581,583],{"id":582},"why-you-should-care","Why you should care",[190,585,586,587,592],{},"Engineers will prefer frameworks. They should. Control, portability, tests in CI. Operators and Legal will prefer a harness they can inspect without a pull request. ",[200,588,591],{"href":589,"rel":590},"https:\u002F\u002Fwww.mckinsey.com\u002Fcapabilities\u002Fquantumblack\u002Four-insights\u002Fthe-state-of-ai",[217],"McKinsey"," keeps showing isolated technical use without operating-model change. A beautiful LangGraph in a platform team’s repo is still isolated use if RevOps cannot attach Salesforce or refuse a write.",[190,594,595],{},"It affects you if:",[221,597,598,601,604,607],{},[224,599,600],{},"the RFP says “must support LangChain” as if that were a control",[224,602,603],{},"a vendor says “model-agnostic framework” and prices seats on one flagship",[224,605,606],{},"you are asked to rebuild quoting and SoD because “we already have agents in Python”",[224,608,609],{},"security reviews the GitHub org and never reviews who can call PATCH",[190,611,612,617,618,621,622,626],{},[200,613,616],{"href":614,"rel":615},"https:\u002F\u002Fgenai.owasp.org\u002Fllm-top-10\u002F",[217],"OWASP’s LLM Top 10"," excessive agency shows up in both: a framework that exposes every tool by default, or a product that does. The cut is not safety vs convenience. It is ",[479,619,620],{},"who can change the harness when it fails"," — ",[200,623,625],{"href":624},"what-is-harness-engineering","harness engineering"," — and whether a fail-closed write exists.",[190,628,629,633],{},[200,630,632],{"href":241,"rel":631},[217],"NIST AI RMF"," Map\u002FMeasure need a system boundary. “Our framework” is not a boundary. A named runtime with grants and logs is.",[206,635,637],{"id":636},"the-practical-differences","The practical differences",[190,639,640,643],{},[441,641,642],{},"Who authors the loop."," Framework: software engineers. Product harness: operators (and maybe SE for custom tools). If only engineers can add a sensor, you will wait on a sprint for a Legal rule.",[190,645,646,649,650,653,654,657],{},[441,647,648],{},"Where identity lives."," Framework default: service account in ",[462,651,652],{},".env",". Product harness: org roster, workstream membership, OAuth grants. You ",[479,655,656],{},"can"," do the latter in LangGraph. You must build it.",[190,659,660,663,664,360,669,674,675,678],{},[441,661,662],{},"What “done” means."," Framework: your node returned. Inner product harness: tests \u002F hook. Outer product harness: signer. Anthropic’s ",[200,665,668],{"href":666,"rel":667},"https:\u002F\u002Fwww.anthropic.com\u002Fengineering\u002Fbuilding-effective-agents",[217],"effective agents",[200,670,673],{"href":671,"rel":672},"https:\u002F\u002Fwww.anthropic.com\u002Fengineering\u002Feffective-harnesses-for-long-running-agents",[217],"long-running harness"," notes are about encoding done in the ",[479,676,677],{},"environment",". Frameworks give you the primitives; they do not know your done.",[190,680,681,684,685,688,689,693],{},[441,682,683],{},"Portability."," Frameworks win on model swap ",[479,686,687],{},"if"," tools and middleware stay. Product harnesses win if they actually route and do not bury a flagship default in a seat. ",[200,690,692],{"href":691},"what-is-model-routing","Model routing",". “We wrap LangChain” is not routing.",[190,695,696,699],{},[441,697,698],{},"Eval."," Frameworks shine in unit tests of nodes. Inner harnesses shine on SWE-bench \u002F Terminal-Bench. Enterprise harnesses shine when quote hash equals SoR row. Different CI.",[190,701,702,705,706,377],{},[441,703,704],{},"Time-to-first-governed-write."," Framework: months unless you already built the interceptor. Forward-deployed OS: months of people. Self-service outer harness: the product’s week-one claim — verify it. ",[200,707,709],{"href":708},"how-to-run-an-enterprise-ai-proof-of-value","Proof of value",[190,711,712,715,716,720],{},[441,713,714],{},"Lock-in."," Framework lock-in is code and patterns. Product lock-in is data, graph, and operating habits. Both are real. ",[200,717,719],{"href":718},"how-to-solve-model-lock-in","How to solve model lock-in"," is the model slice; harness lock-in is the loop slice. Prefer quoted payloads and exportable ledgers either way.",[190,722,723,724,729,730,733,734,377],{},"LangChain is not the villain. Their ",[200,725,728],{"href":726,"rel":727},"https:\u002F\u002Fwww.langchain.com\u002Fblog\u002Fthe-anatomy-of-an-agent-harness",[217],"anatomy post"," is one of the clearer public derivations of harness parts. Use it. Then ask whether your ",[479,731,732],{},"deployment"," has those parts for the job you are buying — repo or company. ",[200,735,737],{"href":736},"inner-vs-outer-agent-harness","Inner vs outer",[190,739,740,741,744],{},"Nimbus’s bet is that most operators should not author LangGraph to update a discount cap. The wiki and the gate should move. Teams that ",[479,742,743],{},"should"," author graphs (unique simulation, exotic tools) can still sit behind a connector. Framework inside a harness. Not a framework instead of one.",[206,746,748],{"id":747},"a-decision-rule","A decision rule",[221,750,751,757,763,773],{},[224,752,753,756],{},[441,754,755],{},"Building a product or a unique workflow in code, with engineers on the hook:"," framework (or SDK harness) plus your own grants and evals.",[224,758,759,762],{},[441,760,761],{},"Hiring a loop for a repository:"," inner product harness (Claude Code, Cursor, Codex). Optionally extend with a framework for custom tools.",[224,764,765,460,768,772],{},[441,766,767],{},"Hiring a loop for CRM\u002FERP\u002Fcross-department work:",[200,769,771],{"href":770},"what-is-an-enterprise-agent-harness","enterprise agent harness"," \u002F OS-class product. A framework is a build programme.",[224,774,775,778],{},[441,776,777],{},"Vendor says “we are a framework and an OS”:"," make them show a failed unsigned write and an operator-attached connector. Words are cheap.",[190,780,781,785],{},[200,782,784],{"href":783},"build-vs-buy-an-enterprise-ai-os","Build vs buy an enterprise AI OS"," is the longer form of the third bullet.",[206,787,789],{"id":788},"what-each-layer-of-the-stack-is-for","What each layer of the stack is for",[190,791,792,793,796,797,799],{},"LangChain’s own split is the cleanest vendor-native map: use Deep Agents when you want a batteries-included ",[479,794,795],{},"harness","; use ",[462,798,464],{}," when you want a minimal harness you customise with middleware; drop to LangGraph when the agent loop is the wrong shape and you need deterministic nodes mixed with agentic ones; use LangSmith to trace whatever you built. That is a builder’s menu. It does not decide whether RevOps can refuse a write.",[190,801,802,803,806,807,811],{},"CrewAI is a role-and-task framework. AutoGen is a conversation-of-agents framework. Semantic Kernel is Microsoft’s orchestration SDK. Pydantic AI moved toward a “harness-first” design in 2026 (capabilities as tools + hooks + instructions). None of these are wrong. All of them leave identity, SoR quoting, and operator self-service as ",[479,804,805],{},"your"," story unless you add them. ",[200,808,810],{"href":614,"rel":809},[217],"OWASP"," will still fail you if the first graph you merge attaches every production tool “so the demo looks alive.”",[190,813,814,815,818],{},"Product harnesses fail the other way: they hide the graph so operators can work, then surprise engineers who wanted to unit-test a node. Demand an escape hatch — export traces, typed payloads, maybe a documented tool SDK — without requiring every discount cap to be a pull request. Nimbus’s bet is that the cap lives in the ",[200,816,817],{"href":28},"wiki"," and the interceptor, and that engineers who need a custom simulator put it behind a connector. Framework inside the harness.",[190,820,821,826],{},[200,822,825],{"href":823,"rel":824},"https:\u002F\u002Fwww.thoughtworks.com\u002Finsights\u002Farticles\u002Foperating-system-enterprise-ai",[217],"Thoughtworks"," would say a company that standardises on LangGraph has invested in layer 2 (builder) and still has to build layers 3–4 (user guides\u002Fsensors, organisational ownership). A company that buys only a coding harness has a strong inner layer 2–3 and a missing outer layer 4. A company that buys an OS-class product is hoping layer 3–4 shipped. Verify with a refused write, not with a README.",[190,828,829,832,833,837],{},[441,830,831],{},"Cost of the wrong cut."," Framework-first for operators: six months of platform work, then shadow copilots anyway. Product-first for a unique research loop: you will fight the product and rebuild the graph in Python by week four. ",[200,834,836],{"href":835},"how-to-choose-between-a-coding-harness-and-an-enterprise-harness","How to choose coding vs enterprise"," plus this page: workspace first, then assemble vs hire.",[190,839,840,843,844,846,847,849,850,853],{},[441,841,842],{},"Portability, honestly."," Frameworks make model swap easier ",[479,845,687],{}," you used their model interface and did not sprinkle vendor-specific tool formats through application code. Products make operator ratchet easier ",[479,848,687],{}," adding a gate is a UI action. Neither gives you portability of ",[479,851,852],{},"decisions"," unless the ledger exports. Ask for JSON of the quote and the graph, not a promise of “open.”",[190,855,856,857,860],{},"Inngest and others have argued that durable execution needs “a harness, not a framework”: retries, state, and recovery as infrastructure. That slogan is directionally right for production. It is incomplete for enterprises. Durable retries of an ",[479,858,859],{},"unsigned"," write are a reliable incident. The outer harness adds identity and a stop that retries must not bypass. LangGraph checkpointing is excellent loop infrastructure. It is not a Finance signer.",[190,862,863,864,377],{},"A worked split: the data-science team builds a forecasting graph in LangGraph, evaluates it with their own sensors, exposes it as a tool. RevOps never opens the repo. They brief a workstream, the team calls the forecast tool under read scope, and any CRM write still quotes in the product interceptor. Framework for the specialist. Harness for the company job. Nimbus is the second box; it should consume the first as a connector, not replace the scientists’ graph. ",[200,865,50],{"href":51},[190,867,868],{},"If your platform team’s OKR is “stand up LangChain,” add a second OKR: “unsigned SoR writes are impossible.” The first without the second is a framework programme. The second without any loop is a policy PDF. You need both, in that order of safety.",[190,870,871,872,876],{},"CrewAI marketing will talk about roles. Roles in a YAML file are not roster identity. If the “legal reviewer” crew member can still call the same Salesforce write tool as the “AE,” you have a framework demo of ",[200,873,875],{"href":874},"agent-team-architecture","agent teams"," without the contract. Ask to see the tool belt per role, then ask what happens when you remove the write tool from legal and the model asks for it anyway. The harness answer is refuse. The framework-only answer is often “we’ll prompt it.”",[206,878,880],{"id":879},"questions-people-actually-ask","Questions people actually ask",[882,883,885],"h3",{"id":884},"is-langgraph-a-harness","Is LangGraph a harness?",[190,887,888,889,892],{},"It is a framework for building one. Your graph ",[479,890,891],{},"becomes"," a harness when it owns tool dispatch, bounds, and (for production) identity and sensors. Empty graph ≠ harness.",[882,894,896],{"id":895},"is-claude-code-a-framework","Is Claude Code a framework?",[190,898,899,900,377],{},"No. It is a productised inner harness. The Agent SDK is the embeddable form — closer to HaaS in ",[200,901,904],{"href":902,"rel":903},"https:\u002F\u002Faddyosmani.com\u002Fblog\u002Fagent-harness-engineering\u002F",[217],"Osmani’s sense",[882,906,908],{"id":907},"does-mcp-replace-both","Does MCP replace both?",[190,910,911],{},"No. Plumbing. Hosts still need a loop and grants.",[882,913,915],{"id":914},"we-already-standardised-on-crewai","We already standardised on CrewAI.",[190,917,918],{},"Keep it for the jobs engineers should own. Do not force RevOps to write crews for a renewal write. Put CrewAI behind a scoped tool if the outer harness needs that specialist.",[882,920,922],{"id":921},"how-do-we-evaluate-a-vendor-who-wraps-langchain","How do we evaluate a vendor who wraps LangChain?",[190,924,925,926,930],{},"Ignore the wrapper. Run ",[200,927,929],{"href":928},"how-to-evaluate-an-agent-harness","how to evaluate an agent harness",". If they cannot refuse a write, you evaluated a demo of a framework.",[882,932,934],{"id":933},"where-does-nimbus-sit","Where does Nimbus sit?",[190,936,937,938,940,941,377],{},"Productised outer harness, not a LangChain distribution. ",[200,939,11],{"href":12},". You should still allow inner harnesses for code. ",[200,942,836],{"href":835},[206,944,946],{"id":945},"related-reading","Related reading",[190,948,949,360,952,377],{},[200,950,951],{"href":624},"What is harness engineering",[200,953,955],{"href":954},"how-to-evaluate-multi-agent-platforms","How to evaluate multi-agent platforms",[206,957,959],{"id":958},"sources","Sources",[221,961,962,968,974,980,986,992,998,1004,1010,1016,1022,1028,1033,1039],{},[224,963,964],{},[200,965,967],{"href":453,"rel":966},[217],"LangChain, Agents",[224,969,970],{},[200,971,973],{"href":487,"rel":972},[217],"LangChain, How to build a custom agent harness",[224,975,976],{},[200,977,979],{"href":726,"rel":978},[217],"LangChain, The anatomy of an agent harness",[224,981,982],{},[200,983,985],{"href":474,"rel":984},[217],"LangChain, LangGraph overview",[224,987,988],{},[200,989,991],{"href":468,"rel":990},[217],"LangChain Deep Agents",[224,993,994],{},[200,995,997],{"href":823,"rel":996},[217],"Thoughtworks, The operating system for enterprise AI",[224,999,1000],{},[200,1001,1003],{"href":902,"rel":1002},[217],"Addy Osmani, Agent harness engineering",[224,1005,1006],{},[200,1007,1009],{"href":666,"rel":1008},[217],"Anthropic, Building effective agents",[224,1011,1012],{},[200,1013,1015],{"href":671,"rel":1014},[217],"Anthropic, Effective harnesses for long-running agents",[224,1017,1018],{},[200,1019,1021],{"href":540,"rel":1020},[217],"Claude Code, Hooks",[224,1023,1024],{},[200,1025,1027],{"href":589,"rel":1026},[217],"McKinsey, The state of AI in 2025",[224,1029,1030],{},[200,1031,632],{"href":241,"rel":1032},[217],[224,1034,1035],{},[200,1036,1038],{"href":614,"rel":1037},[217],"OWASP Top 10 for LLM applications",[224,1040,1041],{},[200,1042,1045],{"href":1043,"rel":1044},"https:\u002F\u002Fmodelcontextprotocol.io\u002Fspecification\u002F2025-11-25\u002Findex",[217],"Model Context Protocol specification",{"title":171,"searchDepth":172,"depth":172,"links":1047},[1048,1049,1050,1051,1052,1053,1062,1063],{"id":508,"depth":172,"text":509},{"id":582,"depth":172,"text":583},{"id":636,"depth":172,"text":637},{"id":747,"depth":172,"text":748},{"id":788,"depth":172,"text":789},{"id":879,"depth":172,"text":880,"children":1054},[1055,1057,1058,1059,1060,1061],{"id":884,"depth":1056,"text":885},3,{"id":895,"depth":1056,"text":896},{"id":907,"depth":1056,"text":908},{"id":914,"depth":1056,"text":915},{"id":921,"depth":1056,"text":922},{"id":933,"depth":1056,"text":934},{"id":945,"depth":172,"text":946},{"id":958,"depth":172,"text":959},"2026-08-24","An agent framework is a library for assembling a loop. An agent harness is the loop you can actually run — tools, stops, identity, and sensors included. LangChain helps you build one; it is not, by itself, one you can hire.","\u002Fblog\u002Fagent-harness-vs-agent-framework",{"title":431,"description":1065},"blog\u002Fagent-harness-vs-agent-framework",[402,1070,1071,1072],"agent-harness","langchain","frameworks","gXCxGnvUDv02K2_Jxwj878jpKQQXGyrZ7s3d5hNjYZA",{"id":1075,"title":1076,"archived":165,"authors":1077,"badge":1079,"body":1080,"date":1768,"definedTerm":166,"department":166,"description":1769,"extension":174,"eyebrow":166,"faqHeader":1770,"faqs":1773,"footerBand":166,"headline":166,"image":166,"industry":166,"jobType":166,"listed":165,"location":166,"navigation":131,"openRoles":166,"pageLayout":166,"path":1786,"relatedHeading":166,"seo":1787,"series":402,"sitemap":131,"status":166,"stem":1788,"subhead":166,"tags":1789,"video":166,"whyJoin":166,"workplaceType":166,"__hash__":1793},"content\u002Fblog\u002Floop-vs-workflow-vs-agent.md","Loop vs Workflow vs Agent",[1078],{"name":184,"to":136},{"label":186},{"type":168,"value":1081,"toc":1758},[1082,1090,1093,1155,1163,1167,1174,1177,1206,1209,1212,1218,1229,1233,1242,1245,1274,1287,1293,1298,1305,1309,1320,1323,1352,1361,1366,1372,1376,1486,1498,1504,1508,1511,1528,1531,1534,1574,1580,1584,1590,1596,1606,1616,1622,1633,1637,1640,1654,1698,1704,1707,1714,1729,1733,1745,1754],[190,1083,1084,1085,1089],{},"A workflow enumerates steps a person invented. A loop is a compiled standing order that fires when a signal repeats. An agent reasons when the path is not yet known. ",[200,1086,1088],{"href":666,"rel":1087},[217],"Anthropic’s guidance on building effective agents"," is blunt about the distinction: encode the job when you can; reserve autonomy for inputs that will not sit still. Operators need the noun that matches how stable the job is — not the noun that wins the demo.",[190,1091,1092],{},"Three words, disambiguated up front, plus the sibling people keep folding in:",[221,1094,1095,1114,1125,1142],{},[224,1096,1097,1100,1101,1104,1105,360,1109,1113],{},[441,1098,1099],{},"Loop."," A compiled ",[441,1102,1103],{},"standing order",": triggers, a trusted recipe, outcomes on a run page, skip when nothing changed. See ",[200,1106,1108],{"href":1107},"what-is-loop-engineering","what is loop engineering",[200,1110,1112],{"href":1111},"six-things-that-start-a-loop","six things that start a loop",". Loops are for work that repeats on recognizable signals.",[224,1115,1116,1119,1120,1124],{},[441,1117,1118],{},"Eval loop."," An independent verification that a job finished — tests, schema, read-back, signer — not the model’s claim. See ",[200,1121,1123],{"href":1122},"eval-loops-for-enterprise-agent-harnesses","eval loops for enterprise agent harnesses",". A loop may include eval steps; “eval loop” is not “loop.”",[224,1126,1127,1130,1131,1134,1135,1139,1140,377],{},[441,1128,1129],{},"Agentic workflow."," A ",[441,1132,1133],{},"designed sequence"," of steps toward a goal, with business stop conditions — including a person before a live system changes. See ",[200,1136,1138],{"href":1137},"what-is-an-agentic-workflow","what is an agentic workflow",". Workflows are what someone invented; they are versioned and hosted on a ",[200,1141,501],{"href":500},[224,1143,1144,1147,1148,360,1151,377],{},[441,1145,1146],{},"Agent."," A reasoner that picks tools when the path is not fully enumerated. See ",[200,1149,1150],{"href":526},"what is an agent harness",[200,1152,1154],{"href":1153},"a-loop-is-not-an-agent","a loop is not an agent",[190,1156,1157,1158,1162],{},"If your buying conversation starts with “we need an agent,” pause. That sentence often means three different jobs. Buying the wrong one wastes the quarter — not because the model is weak, but because the operating object is wrong. ",[200,1159,1161],{"href":589,"rel":1160},[217],"McKinsey’s 2025 State of AI"," keeps showing high usage and uneven scale. Scale, in this vocabulary, usually means compiling what worked — into a workflow or a loop — not hiring a larger model to improvise the same close every month.",[206,1164,1166],{"id":1165},"workflow-steps-a-person-invented","Workflow — steps a person invented",[190,1168,1169,1170,1173],{},"A ",[441,1171,1172],{},"workflow"," is a sequence someone designed: extract, compare to a playbook, quote the CRM fields, wait for the named signer, write or refuse. The author is a person. The instance is durable. The finish line is named before the run starts.",[190,1175,1176],{},"Workflows excel when:",[221,1178,1179,1186,1192,1199],{},[224,1180,1181,1182,1185],{},"the ",[441,1183,1184],{},"stop conditions"," matter as much as the steps — budget, approval, empty result, a clause that is non-standard",[224,1187,1188,1191],{},[441,1189,1190],{},"roles"," differ by step — analyst drafts, controller signs, counsel refuses",[224,1193,1194,1195,1198],{},"the job is ",[441,1196,1197],{},"interactive"," — humans join mid-flight with context attached",[224,1200,1201,1202,1205],{},"you must ",[441,1203,1204],{},"version"," the definition — “which workflow ran last Tuesday?” is a fair audit question",[190,1207,1208],{},"A workflow is the right object when the path is known enough to draw and still needs a person at a gate. Month-end sign-off is a workflow even if a loop assembled the pack. Discount exceptions are a workflow even if a loop watched the stage change. The designed sequence is how you keep roles from collapsing into “the model posted it.”",[190,1210,1211],{},"Workflows fail when teams treat them as magic. A checklist in a prompt is not a workflow. A chat with tools is not a workflow. A Lucidchart on a wiki is not a workflow runtime. A workflow has a durable instance, a finish line, and a record that survives the session. If you hide the chat and cannot reconstruct which step was waiting on a person, you bought conversation.",[190,1213,1214,1217],{},[441,1215,1216],{},"Operator test:"," Can an independent reader reconstruct which steps ran, what was waiting on a person, and what was refused — without Slack search?",[190,1219,1220,1224,1225,1228],{},[200,1221,1223],{"href":1222},"what-is-human-in-the-loop-ai","What is human-in-the-loop AI"," belongs here more than it belongs on the loop. Loops can pause; workflows are often ",[479,1226,1227],{},"about"," the pause. The pause is the product. If your vendor cannot show a named stop, you do not have a workflow. You have a script with optimism.",[206,1230,1232],{"id":1231},"loop-a-compiled-standing-order","Loop — a compiled standing order",[190,1234,1169,1235,1238,1239,1241],{},[441,1236,1237],{},"loop"," is what you run when the world sends the same signal again: Monday close, file in folder, stage flipped, billing event, someone presses run now. See ",[200,1240,1112],{"href":1111},". The author compiled the recipe once. The trigger admits a run. The run page is the contract.",[190,1243,1244],{},"Loops excel when:",[221,1246,1247,1254,1260,1267],{},[224,1248,1249,1250,1253],{},"the recipe is ",[441,1251,1252],{},"stable"," enough to reuse without re-prompting",[224,1255,1256,1259],{},[441,1257,1258],{},"skip semantics"," matter — “nothing changed” should be a first-class outcome",[224,1261,1262,1263,1266],{},"operators need a ",[441,1264,1265],{},"run page",", not a transcript",[224,1268,1269,1270,1273],{},"the same kernel should answer to ",[441,1271,1272],{},"several triggers"," without several copies",[190,1275,1276,1277,1281,1282,1286],{},"Loops are not “set and forget” if forget means no record. A good loop logs quiet outcomes, notifies the roster, and attaches outputs where the next role expects them. ",[200,1278,1280],{"href":1279},"how-to-evaluate-loop-engineering","How to evaluate loop engineering"," is the RFP sheet for this object. ",[200,1283,1285],{"href":241,"rel":1284},[217],"NIST’s AI Risk Management Framework"," Measure function assumes you can observe those outcomes. A loop without a run page is not observable. It is email archaeology.",[190,1288,1289,1290,1292],{},"Loops fail when they are copied from someone’s channel, when skip is implemented as “don’t email,” or when every step secretly calls a model. On the happy path, ",[200,1291,1154],{"href":1153},": it should not re-derive the job. If Monday’s close still begins with “please do the usual,” you have not compiled anything.",[190,1294,1295,1297],{},[441,1296,1216],{}," Run it ten times with empty inputs. Do you get ten run pages that say skipped — or ten emails saying error?",[190,1299,1300,1304],{},[200,1301,1303],{"href":1302},"loop-engineering-vs-harness-engineering","Loop engineering vs harness engineering"," draws the line: loop engineering compiles repeat work; harness engineering tightens the environment when interactive agents fail. You need both crafts. They fail differently. A loop that guesses at 3am is a harness problem you imported into unattended hours.",[206,1306,1308],{"id":1307},"agent-reasons-when-the-path-is-unknown","Agent — reasons when the path is unknown",[190,1310,439,1311,1314,1315,1319],{},[441,1312,1313],{},"agent"," (in the product sense) chooses actions when you cannot enumerate every branch upfront: read these ten documents and tell me which clause conflicts; investigate why margin diverged across three regions; draft three options for a novel pricing exception. ",[200,1316,1318],{"href":453,"rel":1317},[217],"LangChain’s definition"," is a useful shorthand: Agent = Model + Harness. The harness is not optional. Without tools, stops, and a budget, you have a chatbot with aspirations.",[190,1321,1322],{},"Agents excel when:",[221,1324,1325,1332,1338,1345],{},[224,1326,1327,1328,1331],{},"inputs are ",[441,1329,1330],{},"messy or novel"," — PDFs, threads, ambiguous tickets, a vendor paper the team has not seen",[224,1333,1181,1334,1337],{},[441,1335,1336],{},"path emerges"," during the job — you would not trust a fixed script yet",[224,1339,1340,1341,1344],{},"the cost of a wrong step is ",[441,1342,1343],{},"bounded"," — read-only tools, draft-only outputs",[224,1346,1347,1348,1351],{},"a human will ",[441,1349,1350],{},"compress"," the result into a decision artefact",[190,1353,1354,1355,1360],{},"Agents fail when teams use them as cron with charisma. If the job is the same every Monday, an agent rediscovering the steps is expensive theatre. It is also a control failure: the path that ran last week is not a path you can open next week. ",[200,1356,1359],{"href":1357,"rel":1358},"https:\u002F\u002Faiindex.stanford.edu\u002F",[217],"Stanford HAI’s AI Index"," is a reminder that capability is not the scarce resource. Operational maturity is.",[190,1362,1363,1365],{},[441,1364,1216],{}," If you hid the chat and kept only the artefact, would the company still know what changed? If not, you bought conversation, not control.",[190,1367,1368,1369,1371],{},"Score agents with ",[200,1370,929],{"href":928},", not with this page’s skip-semantics tests. The hero metric for an agent is whether you can stop a write and replay what was refused. The hero metric for a loop is whether you can skip quietly and prove it.",[206,1373,1375],{"id":1374},"three-way-comparison","Three-way comparison",[1377,1378,1379,1398],"table",{},[1380,1381,1382],"thead",{},[1383,1384,1385,1389,1392,1395],"tr",{},[1386,1387,1388],"th",{},"Question",[1386,1390,1391],{},"Workflow",[1386,1393,1394],{},"Loop",[1386,1396,1397],{},"Agent",[1399,1400,1401,1416,1430,1444,1458,1472],"tbody",{},[1383,1402,1403,1407,1410,1413],{},[1404,1405,1406],"td",{},"Who designed the path?",[1404,1408,1409],{},"A person encoded steps",[1404,1411,1412],{},"A compiled recipe",[1404,1414,1415],{},"The model plans within bounds",[1383,1417,1418,1421,1424,1427],{},[1404,1419,1420],{},"Typical host",[1404,1422,1423],{},"Workstream with gates",[1404,1425,1426],{},"Recipe library + run page",[1404,1428,1429],{},"Workstream or task room",[1383,1431,1432,1435,1438,1441],{},[1404,1433,1434],{},"Best when",[1404,1436,1437],{},"Stops and roles matter",[1404,1439,1440],{},"Signal repeats",[1404,1442,1443],{},"Path unknown",[1383,1445,1446,1449,1452,1455],{},[1404,1447,1448],{},"Quiet success",[1404,1450,1451],{},"Waiting on signer",[1404,1453,1454],{},"Skipped — no change",[1404,1456,1457],{},"“Nothing found” with sources",[1383,1459,1460,1463,1466,1469],{},[1404,1461,1462],{},"Versioning",[1404,1464,1465],{},"Workflow definition",[1404,1467,1468],{},"Recipe version",[1404,1470,1471],{},"Prompt + tool grants",[1383,1473,1474,1477,1480,1483],{},[1404,1475,1476],{},"Audit reader asks",[1404,1478,1479],{},"Which step, which gate",[1404,1481,1482],{},"Which trigger, which run",[1404,1484,1485],{},"Which sources, which draft",[190,1487,1488,1489,1492,1493,1497],{},"None of these rows replaces your CRM. They describe how work runs ",[441,1490,1491],{},"on top of"," systems of record. The ",[200,1494,1496],{"href":1495},"what-is-an-enterprise-ai-operating-system","enterprise AI operating system"," metaphor is the kernel version of the same problem — isolation, permissions, durable state — applied to jobs rather than applications. This article stays at the operator nouns. Use the OS page when you need the kernel language; use this page when someone says “agent” and means a Monday report.",[190,1499,1500,1503],{},[200,1501,352],{"href":350,"rel":1502},[217]," will not tell you which noun to buy. It will ask whether you can name the system, the owner, and the record. Workflows, loops, and agents all fail that test when they live only in a transcript.",[206,1505,1507],{"id":1506},"how-they-compose-in-one-quarter","How they compose in one quarter",[190,1509,1510],{},"Real companies stack all three. The stack is not three products competing. It is three stability levels: novel → designed → repeated.",[298,1512,1513,1518,1523],{},[224,1514,1515,1517],{},[441,1516,1397],{}," investigates a new vendor contract — extracts obligations, flags non-standard terms, drafts a summary for counsel. The path is unknown. The output is a draft. Nothing customer-facing sends.",[224,1519,1520,1522],{},[441,1521,1391],{}," routes the summary through Legal review on a workstream, with a hard stop before anything leaves the company. Roles stay distinct. The instance is durable. Counsel can refuse.",[224,1524,1525,1527],{},[441,1526,1394],{}," watches the signed folder and, every time a countersigned PDF lands, updates the renewal tracker and notifies RevOps — skipping if the hash matches last week’s file. The signal repeats. The recipe does not.",[190,1529,1530],{},"That composition is how you avoid the two failure modes that dominate programmes: agent-for-everything, and checklist-in-a-wiki. The first burns tokens and produces untraceable month six. The second produces a drawing that nobody runs.",[190,1532,1533],{},"Department guides use the same stack with different default nouns:",[221,1535,1536,1550,1564],{},[224,1537,1538,1541,1542,360,1546,377],{},[441,1539,1540],{},"Finance and planning"," — loops for scheduled packs; workflows for close sign-offs; agents for one-off variance forensics. See ",[200,1543,1545],{"href":1544},"loops-for-finance-and-planning","loops for finance and planning",[200,1547,1549],{"href":1548},"collaborative-ai-for-finance-and-planning","collaborative AI for finance and planning",[224,1551,1552,1555,1556,360,1560,377],{},[441,1553,1554],{},"Revenue operations"," — loops on stage changes; workflows for discount exceptions; agents for messy account research. See ",[200,1557,1559],{"href":1558},"loops-for-revenue-operations","loops for revenue operations",[200,1561,1563],{"href":1562},"collaborative-ai-for-revenue-operations","collaborative AI for revenue operations",[224,1565,1566,1569,1570,377],{},[441,1567,1568],{},"Legal and compliance"," — workflows for approvals; loops on inbound redlines; agents for first-pass clause comparison. See ",[200,1571,1573],{"href":1572},"loops-for-legal-and-compliance","loops for legal and compliance",[190,1575,1576,1579],{},[200,1577,1578],{"href":370},"Collaborative AI"," is the roster pattern underneath all three: multiple roles, one job object, a finish line. The noun you pick does not replace the roster. An agent without a roster is a personal copilot. A loop without a roster notifies a dead channel. A workflow without a roster has nobody to stand at the gate.",[206,1581,1583],{"id":1582},"what-people-get-wrong","What people get wrong",[190,1585,1586,1589],{},[441,1587,1588],{},"Agent for everything."," Impressive week one; untraceable month six. The model will happily re-solve a solved problem. You will pay for it twice: inference, and the incident when it improvises a write.",[190,1591,1592,1595],{},[441,1593,1594],{},"Workflow without an instance."," A diagram is not a runtime. If you cannot open last Tuesday’s run and see the step that was waiting, you have documentation, not a workflow.",[190,1597,1598,1601,1602,1605],{},[441,1599,1600],{},"Loop copied from someone’s Slack channel."," If reuse means “find the old thread,” you have folklore, not ",[200,1603,1604],{"href":1107},"loop engineering",". Folklore does not survive vacation.",[190,1607,1608,1611,1612,1615],{},[441,1609,1610],{},"Confusing eval loops with loops."," Benchmarks and read-backs verify completion; standing-order loops start and record repeat work. Both can coexist on one job. Collapsing them hides whether you can start work ",[479,1613,1614],{},"and"," whether you can prove it finished.",[190,1617,1618,1621],{},[441,1619,1620],{},"Buying a platform that only sells one noun."," If the vendor cannot host a workflow gate, a loop run page, and an agent task on the same roster, you will rebuild org boundaries in email. That is not a tooling preference. It is how departments already work.",[190,1623,1624,1627,1628,1632],{},[441,1625,1626],{},"Treating RPA as the fourth synonym."," Screen replay is a different category. See ",[200,1629,1631],{"href":1630},"loop-vs-rpa","loop vs RPA",". A bot that clicks an ERP has a place. It is not a standing-order loop, a designed workflow, or a reasoner.",[206,1634,1636],{"id":1635},"choosing-this-week","Choosing this week",[190,1638,1639],{},"Ask two questions, in this order:",[298,1641,1642,1648],{},[224,1643,1644,1647],{},[441,1645,1646],{},"Do we know the steps?"," No → agent, bounded. Yes → workflow or loop.",[224,1649,1650,1653],{},[441,1651,1652],{},"Will the same signal fire again?"," Yes → loop. No → workflow.",[1655,1656,1660],"pre",{"className":1657,"code":1658,"language":1659,"meta":171,"style":171},"language-mermaid shiki shiki-themes github-light github-dark","flowchart TD\n  steps{\"Do we know the steps?\"}\n  steps -->|no| agentPick[\"Agent: explore, keep a draft\"]\n  steps -->|yes| signal{\"Will the same signal fire again?\"}\n  signal -->|yes| loopPick[\"Loop: standing order\"]\n  signal -->|no| workflowPick[\"Workflow: designed sequence with stops\"]\n","mermaid",[462,1661,1662,1670,1675,1680,1686,1692],{"__ignoreMap":171},[1663,1664,1667],"span",{"class":1665,"line":1666},"line",1,[1663,1668,1669],{},"flowchart TD\n",[1663,1671,1672],{"class":1665,"line":172},[1663,1673,1674],{},"  steps{\"Do we know the steps?\"}\n",[1663,1676,1677],{"class":1665,"line":1056},[1663,1678,1679],{},"  steps -->|no| agentPick[\"Agent: explore, keep a draft\"]\n",[1663,1681,1683],{"class":1665,"line":1682},4,[1663,1684,1685],{},"  steps -->|yes| signal{\"Will the same signal fire again?\"}\n",[1663,1687,1689],{"class":1665,"line":1688},5,[1663,1690,1691],{},"  signal -->|yes| loopPick[\"Loop: standing order\"]\n",[1663,1693,1695],{"class":1665,"line":1694},6,[1663,1696,1697],{},"  signal -->|no| workflowPick[\"Workflow: designed sequence with stops\"]\n",[190,1699,1700,1701,1703],{},"If both yes — stable steps ",[479,1702,1614],{}," a repeating signal — start with a loop. Add workflow gates inside it when a named signer must appear. Add an agent step when one stage still needs reading messy inputs. That is the composition above, reduced to a decision tree you can use in a working session.",[190,1705,1706],{},"If both no — unknown steps and a one-off — you are in research. Do not compile yet. Do not buy a bot. Bound the tools, keep the output as a draft, and decide next week whether the path is now known.",[190,1708,1709,1713],{},[200,1710,1712],{"href":1711},"four-pillars-of-an-enterprise-ai-platform","The four pillars of an enterprise AI platform"," is the wider map: communication brings context, collaboration hosts the job, automate repeats the recipe, governance refuses what should not land. Loops, workflows, and agents all sit on that map. They are not a substitute for it.",[190,1715,1716,1717,1719,1720,1724,1725,1728],{},"Related reading: ",[200,1718,371],{"href":370},", ",[200,1721,1723],{"href":1722},"how-to-evaluate-collaborative-ai","how to evaluate collaborative AI",", and ",[200,1726,1727],{"href":624},"what is harness engineering"," when agents and loops share the same stops.",[206,1730,1732],{"id":1731},"how-this-shows-up-in-nimbus","How this shows up in Nimbus",[190,1734,1735,1736,1738,1739,1741,1742,1744],{},"Nimbus hosts all three nouns on the same ",[200,1737,501],{"href":32},". Loops are standing orders with run pages. Agentic workflows are designed sequences with ",[200,1740,359],{"href":40}," gates. Agents run as bounded teammates with scoped grants, not as a second platform. ",[200,1743,15],{"href":16}," is often the communication door that starts a loop when a file lands.",[190,1746,1747,1748,360,1751,1753],{},"Treat that as one vendor’s mapping of the pattern, not as the definition. If you are writing an RFP, paste the questions from ",[200,1749,1750],{"href":1279},"how to evaluate loop engineering",[200,1752,929],{"href":928}," and run them on whoever claims the nouns. The useful outcome is not a logo. It is whether Tuesday’s close, Tuesday’s exception, and Tuesday’s novel contract can share a roster without collapsing into one chat.",[1755,1756,1757],"style",{},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":171,"searchDepth":172,"depth":172,"links":1759},[1760,1761,1762,1763,1764,1765,1766,1767],{"id":1165,"depth":172,"text":1166},{"id":1231,"depth":172,"text":1232},{"id":1307,"depth":172,"text":1308},{"id":1374,"depth":172,"text":1375},{"id":1506,"depth":172,"text":1507},{"id":1582,"depth":172,"text":1583},{"id":1635,"depth":172,"text":1636},{"id":1731,"depth":172,"text":1732},"2026-09-12","A workflow enumerates steps a person invented. A loop is a compiled standing order with a run page. An agent reasons when the path is unknown. Three nouns vendors collapse — and operators pay for the confusion.",{"eyebrow":1771,"title":1772},"Common questions","Standing orders, sequences, and reasoners",[1774,1777,1780,1783],{"question":1775,"answer":1776},"Can a loop contain an agent?","Yes, and that composition is often the adult design. A loop is the standing order — triggers, recipe, run page, skip semantics. A step inside may call an agent when the input is messy, the same way a close pack may include a first-pass read of a PDF. The loop still owns notifications, quiet outcomes, and where artefacts land. Use this pattern when one stage is genuinely unstructured and the rest is known. Refuse a design that lets the agent rewrite the recipe, skip the signer, or hide its tool calls off the run page. The reasoner is a guest on the standing order, not the owner of the job.",{"question":1778,"answer":1779},"Is an agentic workflow just a loop with extra steps?","Not quite, and the difference shows up under audit. Workflows are authored sequences with explicit stops — often interactive, versioned per department, and meant for jobs that need a person mid-flight. Loops are reused recipes optimized for repeat signals and quiet skips. Many teams use both on the same workstream: the loop watches the folder, the workflow carries the exception that needs counsel. Choose a workflow when stop conditions and roles matter as much as the steps. Choose a loop when the same signal will fire again and nobody should re-describe the job. Refuse a vendor that uses the two words interchangeably on slide one and cannot show both objects in a demo.",{"question":1781,"answer":1782},"When should I choose an agent instead of a loop?","When nobody can write the steps yet — novel research, one-off negotiation, exploratory analysis, a contract shape the team has not seen. Agents earn their keep on the unknown path. Once the path stabilizes, compile it into a loop or a workflow so the company is not paying for rediscovery every Monday. Use an agent when the cost of a wrong step is bounded — read-only tools, draft-only outputs, a human who will compress the result. Refuse an agent as a Monday cron job. That is expensive theatre, and it fails the first time the model improvises a write. See [a loop is not an agent](a-loop-is-not-an-agent).",{"question":1784,"answer":1785},"How do I keep the three nouns from collapsing in an RFP?","Score them on different sheets. Ask for a designed sequence with a durable instance and a named stop — that is the workflow. Ask for a repeating signal, a skipped run, and a recipe you can clone — that is the loop. Ask for a bounded reasoner that cites sources and cannot write without a signer — that is the agent. [How to evaluate loop engineering](how-to-evaluate-loop-engineering) and [how to evaluate an agent harness](how-to-evaluate-an-agent-harness) exist because one checklist cannot cover both. Refuse a single “agentic platform” scorecard that starts with context-window size. That sheet buys a model for a job that needed a standing order.","\u002Fblog\u002Floop-vs-workflow-vs-agent",{"title":1076,"description":1769},"blog\u002Floop-vs-workflow-vs-agent",[1790,402,1791,1792],"loops","agentic-workflow","agents","WsdKtSsbWOvqG1UsJ3XMgcLoc3qJt6B_RUAqj_i_Si4",{"enabled":165,"message":1795,"linkLabel":79,"linkHref":80,"id":1796,"title":1797,"archived":165,"authors":166,"badge":166,"body":1798,"date":166,"definedTerm":166,"department":166,"description":171,"extension":174,"eyebrow":166,"faqHeader":166,"faqs":166,"footerBand":166,"headline":166,"image":166,"industry":166,"jobType":166,"listed":131,"location":166,"navigation":131,"openRoles":166,"pageLayout":166,"path":1802,"relatedHeading":166,"seo":1803,"series":166,"sitemap":165,"status":166,"stem":1804,"subhead":166,"tags":166,"video":166,"whyJoin":166,"workplaceType":166,"__hash__":1805},"We're hiring! Join the team building the Sentient Enterprise.","content\u002Fshared\u002Fhiring.md","Hiring banner",{"type":168,"value":1799,"toc":1800},[],{"title":171,"searchDepth":172,"depth":172,"links":1801},[],"\u002Fshared\u002Fhiring",{"title":1797,"description":171},"shared\u002Fhiring","1zs3boivKda1e-b-hAyuNcmZSKjZUAXmecnwHVgcHzk",{"fold":1807,"id":1811,"title":1812,"archived":165,"authors":166,"badge":166,"body":1813,"date":166,"definedTerm":166,"department":166,"description":171,"extension":174,"eyebrow":166,"faqHeader":166,"faqs":166,"footerBand":1817,"headline":166,"image":166,"industry":166,"jobType":166,"listed":131,"location":166,"navigation":131,"openRoles":166,"pageLayout":166,"path":1821,"relatedHeading":166,"seo":1822,"series":166,"sitemap":165,"status":166,"stem":1823,"subhead":166,"tags":166,"video":166,"whyJoin":166,"workplaceType":166,"__hash__":1824},{"headline":1808,"description":1809,"primaryLabel":8,"primaryTo":1810,"secondaryLabel":423,"secondaryTo":12},"Run frontier AI your business actually owns.","Governed agent swarms, 2,000+ integrations, and a knowledge graph that stays inside your walls. Start on Free.","\u002Fsignup?plan=free","content\u002Fshared\u002Fcta.md","Site CTAs",{"type":168,"value":1814,"toc":1815},[],{"title":171,"searchDepth":172,"depth":172,"links":1816},[],{"headline":1818,"description":1819,"primaryLabel":8,"primaryTo":1810,"secondaryLabel":1820,"secondaryTo":85},"See what governed AI looks like on your stack.","Connect your tools, run a workstream, and keep every decision on your ledger. Start on Free.","Talk to our team","\u002Fshared\u002Fcta",{"title":1812,"description":171},"shared\u002Fcta","PS2VPJsszmUpMBZT6nEp8cWXCdeiN6zDRl-p8d0uY2k",1790215701136]