[{"data":1,"prerenderedAt":1977},["ShallowReactive",2],{"site-nav-content":3,"blog:\u002Fblog\u002Fwhat-auditors-are-asking-for":179,"blog-index-copy":450,"blog:\u002Fblog\u002Fwhat-auditors-are-asking-for:surround":471,"hiring-banner-content":1946,"site-cta-content":1958},{"header":4,"productNav":9,"nav":42,"footer":61,"askAI":132,"id":163,"title":164,"archived":165,"authors":166,"badge":166,"body":167,"date":166,"definedTerm":166,"department":166,"description":171,"extension":174,"eyebrow":166,"faqHeader":166,"faqs":166,"footerBand":166,"headline":166,"image":166,"industry":166,"jobType":166,"listed":131,"location":166,"navigation":131,"openRoles":166,"pageLayout":166,"path":175,"relatedHeading":166,"seo":176,"series":166,"sitemap":165,"status":166,"stem":177,"subhead":166,"tags":166,"video":166,"whyJoin":166,"workplaceType":166,"__hash__":178},{"productLabel":5,"loginLabel":6,"contactLabel":7,"contactSalesLabel":8},"Product","Log in","Contact","Get started for free",[10,14,18,22,26,30,34,38],{"label":11,"to":12,"description":13},"Overview","\u002Foverview","Seven layers. One closed loop.",{"label":15,"to":16,"description":17},"Conflux","\u002Fproduct\u002Fconflux","Where your team, workstreams, and agents meet.",{"label":19,"to":20,"description":21},"Agent Teams","\u002Fproduct\u002Fagent-teams","Specialist teams - governed from day one.",{"label":23,"to":24,"description":25},"Lifecycle Graph","\u002Fproduct\u002Flifecycle-graph","Intelligence that compounds across every interaction.",{"label":27,"to":28,"description":29},"Company Wiki","\u002Fproduct\u002Fwiki","Playbooks and policies where expertise stays.",{"label":31,"to":32,"description":33},"Workstreams","\u002Fproduct\u002Fworkstreams","From brief to signed-off deliverable on one canvas.",{"label":35,"to":36,"description":37},"Perception Console","\u002Fproduct\u002Fperception","Ask your whole business in plain English.",{"label":39,"to":40,"description":41},"Governance","\u002Fproduct\u002Fgovernance","Frontier AI you can actually sign off on.",[43,46,49,52,55,58],{"label":44,"to":45},"Models","\u002Fmodels",{"label":47,"to":48},"Pricing","\u002Fpricing",{"label":50,"to":51},"Integrations","\u002Fintegrations",{"label":53,"to":54},"Security","\u002Fsecurity",{"label":56,"to":57},"Partners","\u002Fpartners",{"label":59,"to":60},"Insights","\u002Fblog",{"productHeading":5,"companyHeading":62,"resourcesHeading":63,"legalHeading":64,"docsLabel":65,"docsUrl":66,"statementLines":67,"copyright":70,"companyLinks":71,"resourcesLinks":86,"legalLinks":102,"socialLinks":109,"bottomLinks":119},"Company","Resources","Legal","Docs","https:\u002F\u002Fdocs.gonimbus.ai",[68,69],"Stop training someone else's model.","Control your AI.","© 2026 Nimbus Intelligence, Inc. All rights reserved.",[72,73,74,75,76,78,81,84],{"label":47,"to":48},{"label":50,"to":51},{"label":53,"to":54},{"label":59,"to":60},{"label":77,"to":57},"Partner Program",{"label":79,"to":80},"Careers","\u002Fcareers",{"label":82,"to":83},"System status","\u002Fstatus",{"label":7,"to":85},"\u002Fcontact",[87,90,93,96,99],{"label":88,"to":89},"Glossary","\u002Fglossary",{"label":91,"to":92},"Compare","\u002Fcompare",{"label":94,"to":95},"Evaluate","\u002Fevaluate",{"label":97,"to":98},"Problems","\u002Fproblems",{"label":100,"to":101},"Use cases","\u002Fuse-cases",[103,106],{"label":104,"to":105},"Terms of Service","\u002Fterms",{"label":107,"to":108},"Privacy Policy","\u002Fprivacy",[110,113,116],{"label":111,"href":112},"LinkedIn","https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002Fgonimbusai\u002F",{"label":114,"href":115},"X","https:\u002F\u002Fx.com\u002Fgonimbusai",{"label":117,"href":118},"Instagram","https:\u002F\u002Fwww.instagram.com\u002Fgonimbus_ai\u002F",[120,122,124,127,128],{"label":121,"to":105},"Terms",{"label":123,"to":108},"Privacy",{"label":125,"to":126},"Compliance","\u002Fcompliance",{"label":82,"to":83},{"label":129,"to":130,"external":131},"LLMs.txt","\u002Fllms.txt",true,{"text":133,"prompt":134},"Ask AI about Nimbus",{"I'm researching enterprise intelligence platforms and want to know how Nimbus combines perception, collaboration, and autonomous agents to drive strategic decision-making":135,"platforms":137},{" Summarize the highlights from Nimbus's website":136},"https:\u002F\u002Fgonimbus.ai",[138,143,148,153,158],{"name":139,"label":140,"icon":141,"hrefPrefix":142},"chatgpt","ChatGPT","simple-icons:openai","https:\u002F\u002Fchatgpt.com\u002F?prompt=",{"name":144,"label":145,"icon":146,"hrefPrefix":147},"perplexity","Perplexity","mdi:magnify","https:\u002F\u002Fwww.perplexity.ai\u002Fsearch\u002Fnew?q=",{"name":149,"label":150,"icon":151,"hrefPrefix":152},"grok","Grok","simple-icons:x","https:\u002F\u002Fx.com\u002Fi\u002Fgrok?text=",{"name":154,"label":155,"icon":156,"hrefPrefix":157},"claude","Claude","simple-icons:anthropic","https:\u002F\u002Fclaude.ai\u002Fnew?q=",{"name":159,"label":160,"icon":161,"hrefPrefix":162},"google-ai","Google AI","simple-icons:google","https:\u002F\u002Fwww.google.com\u002Fsearch?udm=50&aep=11&q=","content\u002Fshared\u002Fnav.md","Site navigation",false,null,{"type":168,"value":169,"toc":170},"minimark",[],{"title":171,"searchDepth":172,"depth":172,"links":173},"",2,[],"md","\u002Fshared\u002Fnav",{"title":164,"description":171},"shared\u002Fnav","1dD7ahDRl0SQ4hz53-kKo0tEFrGaLuaztZ3PPfp6a9k",{"id":180,"title":181,"archived":165,"authors":182,"badge":185,"body":187,"date":424,"definedTerm":166,"department":166,"description":425,"extension":174,"eyebrow":166,"faqHeader":426,"faqs":429,"footerBand":166,"headline":166,"image":166,"industry":166,"jobType":166,"listed":165,"location":166,"navigation":131,"openRoles":166,"pageLayout":166,"path":442,"relatedHeading":166,"seo":443,"series":444,"sitemap":131,"status":166,"stem":445,"subhead":166,"tags":446,"video":166,"whyJoin":166,"workplaceType":166,"__hash__":449},"content\u002Fblog\u002Fwhat-auditors-are-asking-for.md","What are auditors asking for around AI?",[183],{"name":184,"to":136},"Nimbus Research",{"label":186},"Evaluation",{"type":168,"value":188,"toc":417},[189,193,196,215,219,222,229,235,238,241,244,251,254,258,261,270,279,287,296,304,307,311,314,317,320,339,342,345,348,356,360,363,383,390,393,396,400,403,406,409],[190,191,192],"p",{},"Auditors asking about AI usually want to follow one change: who decided, whether software could write without a person, and which rulebook you claim to follow. They pick a journal, a credit, a customer email, or a model connection, and they walk it from prompt to record.",[190,194,195],{},"This is showing up now because models sit on live systems, and existing control texts already care how a number became the number. You do not need every framework on day one. You need artefacts you can produce without asking anyone to remember.",[190,197,198,199,204,205,209,210,214],{},"This guide is a first evidence pack you can start this quarter. ",[200,201,203],"a",{"href":202},"what-is-ai-governance","What is AI governance"," is the rest of the access picture. ",[200,206,208],{"href":207},"rbac-for-enterprise-ai","RBAC for enterprise AI"," is who may see the job. ",[200,211,213],{"href":212},"what-is-write-back-governance","Write-back governance"," is the write checklist.",[216,217,181],"h2",{"id":218},"what-are-auditors-asking-for-around-ai",[190,220,221],{},"Two operational questions arrive first.",[190,223,224,228],{},[225,226,227],"strong",{},"Can you show who decided?"," A named person, on a clock the company trusts, bound to a quote that matches the write. “The team aligned” is not an answer. “The channel approved” is not an answer. “The bot user posted” is not an answer.",[190,230,231,234],{},[225,232,233],{},"Can you show the model did not write unchecked?"," Write-back means the AI changes a live system. Fail-closed means if nobody approves, nothing happens. A prompt that says “ask first” is not the gate. A weekly sampling of logs is not the gate if the write already landed.",[190,236,237],{},"Role-based access control (RBAC) means who is allowed to do what. It explains why that person, and not a guest, was offered the button. Auditors understand roles. They do not understand “the workspace.”",[190,239,240],{},"A payload is the exact change: fields, old and new values, target record — or the exact text and recipient for a message.",[190,242,243],{},"Then comes the mapping question: which framework applies to us? Not every company is under every text. Pretending otherwise produces a pile of mappings and no artefact.",[190,245,246,250],{},[200,247,249],{"href":248},"collaborative-ai-for-legal-and-compliance-review","Collaborative AI for legal and compliance review"," still needs a signer when the review becomes a filing. Several departments on one job is not a shared identity.",[190,252,253],{},"If the decision was “we will not write,” that is still a decision. Store it. A read-only connector with a date and an owner is evidence.",[216,255,257],{"id":256},"why-is-this-showing-up-now","Why is this showing up now?",[190,259,260],{},"Models are in the path of records that already had auditors: financial reporting, customer commitments, legal filings, operational tickets.",[190,262,263,269],{},[200,264,268],{"href":265,"rel":266},"https:\u002F\u002Fwww.govinfo.gov\u002Fcontent\u002Fpkg\u002FPLAW-107publ204\u002Fhtml\u002FPLAW-107publ204.htm",[267],"nofollow","Sarbanes-Oxley"," (2002) is still the text many US-listed teams feel first. Internal control over financial reporting does not care that the proposer is a model. If AI can post, the control environment includes that path.",[190,271,272,273,278],{},"NIST’s ",[200,274,277],{"href":275,"rel":276},"https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fai-risk-management-framework",[267],"AI Risk Management Framework"," (2023) is organised as govern, map, measure, and manage. Measure, here, is the stored outcome, including the no. Govern is the roles and the owners. The framework will not click the refuse button for you.",[190,280,281,286],{},[200,282,285],{"href":283,"rel":284},"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F81230.html",[267],"ISO\u002FIEC 42001"," (2023) adds a management system for AI: policies, roles, risk assessment, documented processes, and evidence that those processes run. Useful if you will be asked for a certificate. Not a substitute for a payload screen.",[190,288,289,290,295],{},"The ",[200,291,294],{"href":292,"rel":293},"https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2024\u002F1689\u002Foj",[267],"EU AI Act"," (2024\u002F1689) is from 2024. A deployer is the organisation that uses an AI system under its authority, as the Act defines that role. You may also be a provider if you place a system on the market. Map the role with counsel. Human oversight that cannot refuse a write is not oversight.",[190,297,298,303],{},[200,299,302],{"href":300,"rel":301},"https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2022\u002F2554\u002Foj",[267],"DORA"," (2022) is about digital operational resilience for financial entities and their ICT third parties. If you are in that sector, the AI vendor is an ICT provider conversation, not only an innovation conversation.",[190,305,306],{},"Customers and boards ask for structure even when a text is voluntary. That is why the questions arrive before a regulator has written your company’s name.",[216,308,310],{"id":309},"how-do-you-prepare-evidence-without-a-huge-project","How do you prepare evidence without a huge project?",[190,312,313],{},"Do the one-change walk before anyone external does.",[190,315,316],{},"Pick a change a model proposed. Follow it from prompt to record. See whether you can produce a named person, a frozen payload, and a stored outcome without anyone’s memory.",[190,318,319],{},"Show:",[321,322,323,327,330,333,336],"ul",{},[324,325,326],"li",{},"A connector in read-only mode, and a failed write attempt.",[324,328,329],{},"One object class with a frozen payload and a named signer — or a dated decision that no class is enabled yet.",[324,331,332],{},"The live system’s own validation still firing, if a write ran.",[324,334,335],{},"A success and a rejection.",[324,337,338],{},"A person who was removed and could not sign the next day.",[190,340,341],{},"If you cannot show the failed attempt, assume an auditor will treat write as on.",[190,343,344],{},"Unchecked also includes send. A customer message is a write to the relationship. If mail can go out because the connector was on for retrieval, that is an unchecked write with no field names to screenshot.",[190,346,347],{},"Do not start with a coverage matrix against every clause. Breadth without a sample fails the first request. Depth on one change lets you map the same artefact twice if two texts apply.",[190,349,350,355],{},[200,351,354],{"href":352,"rel":353},"https:\u002F\u002Fwww.law.cornell.edu\u002Frules\u002Ffrcp\u002Frule_37",[267],"Federal Rule of Civil Procedure 37(e)"," (2015) is about preserving electronically stored information you should have kept. Chat retention sliders are not that programme. Put approvals where a new manager can find them.",[216,357,359],{"id":358},"what-is-a-reasonable-first-evidence-pack","What is a reasonable first evidence pack?",[190,361,362],{},"One page plus exports:",[321,364,365,368,371,374,377,380],{},[324,366,367],{},"Job name, system, connector mode, date, owner.",[324,369,370],{},"Roster: guest, member, admin, signer — or “signer not yet named; write off.”",[324,372,373],{},"One stored refusal (sandbox is fine).",[324,375,376],{},"One stored success if you have enabled a class; otherwise omit.",[324,378,379],{},"Clock and retention note: where the artefact lives, how long, who can export it without a vendor ticket.",[324,381,382],{},"Which texts you claim: SOX ICFR if you file; NIST AI RMF as structure; ISO 42001 if you are on that path; EU AI Act role if in scope; DORA if you are a financial entity.",[190,384,385,386,389],{},"Your ",[200,387,388],{"href":126},"compliance"," programme should hold that page.",[190,391,392],{},"ISO 42001, if you take it seriously, adds an owner for AI, a statement of which systems models may connect to and in which mode, a way to handle incidents and model or prompt changes that alter write behaviour, and records that last longer than a chat default. It does not add object-level tokens. You can be certified and still have an admin token on a model. Ask the auditor of that management system to sample a stored rejection from a live job.",[190,394,395],{},"For deployers under the EU AI Act, the operational match is: know you are using AI, use it as intended, monitor, keep required records, and ensure human oversight where the Act requires it. “The vendor is the provider” does not move your ERP posting into their audit file. Your token, your records, your signer. High-risk classification is legal work. This guide will not guess it.",[216,397,399],{"id":398},"how-do-you-start-this-quarter","How do you start this quarter?",[190,401,402],{},"This month: pick one real job. Run the one-change walk. Write the one-page pack. Fill blanks as findings, not as a reason to delay the page.",[190,404,405],{},"Next month: fix the first hole — usually the stored no, the read-only proof, or the named signer.",[190,407,408],{},"If you cannot complete the walk, keeping write off is the honest state of the control. Mapping will not replace it.",[190,410,411,413,414,416],{},[200,412,213],{"href":212}," and ",[200,415,208],{"href":207}," are the two product habits that make the pack easier to gather later.",{"title":171,"searchDepth":172,"depth":172,"links":418},[419,420,421,422,423],{"id":218,"depth":172,"text":181},{"id":256,"depth":172,"text":257},{"id":309,"depth":172,"text":310},{"id":358,"depth":172,"text":359},{"id":398,"depth":172,"text":399},"2026-09-06","Who decided, did the model write unchecked, and which rulebook applies. How to prepare a first evidence pack this quarter without a huge project.",{"eyebrow":427,"title":428},"Short answers","One change you can walk",[430,433,436,439],{"question":431,"answer":432},"If we are not in the EU, can we ignore the AI Act?","You can ignore it as a legal duty only if you are not in its scope. You should still answer the same operational questions — who decided, and did the model write unchecked — because auditors and customers will ask them in other words.",{"question":434,"answer":435},"Does ISO 42001 certification mean our CRM writes are governed?","No. Certification speaks to a management system. It does not replace a named person on a payload, a stored rejection, or a connector that can be read-only. Ask to see those artefacts in your product, not only the certificate.",{"question":437,"answer":438},"What is the smallest evidence pack that still helps?","One change a model proposed: named person, frozen payload, stored outcome including a no, plus the connector mode and the roster on that job. Map that pack to whichever texts apply. Do not start with a matrix of empty controls.",{"question":440,"answer":441},"Do we need this if AI is still read-only?","A dated decision to stay read-only, with an owner and the connector name, is evidence. You need the full write pack before the first production write class.","\u002Fblog\u002Fwhat-auditors-are-asking-for",{"title":181,"description":425},"evaluation","blog\u002Fwhat-auditors-are-asking-for",[444,447,448,294,388],"audit","ISO 42001","EfFv_YZ08TZJm4MDym8B05aD4MGOwabpfOQ5EtWvDxw",{"hero":451,"id":453,"title":454,"archived":165,"authors":166,"badge":166,"body":455,"date":166,"definedTerm":166,"department":166,"description":459,"extension":174,"eyebrow":460,"faqHeader":166,"faqs":166,"footerBand":461,"headline":166,"image":166,"industry":166,"jobType":166,"listed":131,"location":166,"navigation":131,"openRoles":166,"pageLayout":166,"path":60,"relatedHeading":467,"seo":468,"series":166,"sitemap":131,"status":166,"stem":469,"subhead":166,"tags":166,"video":166,"whyJoin":166,"workplaceType":166,"__hash__":470},{"filename":452},"u2221455217_Flat_design_of_a_futuristic_minimalist_landscape__5d589295-cdea-4ea9-a262-be766881accf_1.png","content\u002Fblog\u002Findex.md","Exploring the future of intelligence.",{"type":168,"value":456,"toc":457},[],{"title":171,"searchDepth":172,"depth":172,"links":458},[],"Deep dives into pre-cognitive intelligence, sentient enterprises, and the evolving landscape of AI-driven business transformation.","Latest Research",{"headline":462,"description":463,"primaryLabel":464,"primaryTo":465,"secondaryLabel":466,"secondaryTo":12},"Stay at the frontier.","Subscribe for product updates and new insights.","Subscribe","\u002Fnewsletter","Explore the platform","More research",{"title":454,"description":459},"blog\u002Findex","BFSWGYO9bcTlaulivKYWyg08_DJHsdGg3OC6g_CG1Hw",[472,1223],{"id":473,"title":474,"archived":165,"authors":475,"badge":477,"body":478,"date":1213,"definedTerm":166,"department":166,"description":1214,"extension":174,"eyebrow":166,"faqHeader":166,"faqs":166,"footerBand":166,"headline":166,"image":166,"industry":166,"jobType":166,"listed":165,"location":166,"navigation":131,"openRoles":166,"pageLayout":166,"path":1215,"relatedHeading":166,"seo":1216,"series":444,"sitemap":131,"status":166,"stem":1217,"subhead":166,"tags":1218,"video":166,"whyJoin":166,"workplaceType":166,"__hash__":1222},"content\u002Fblog\u002Fhow-to-choose-between-a-coding-harness-and-an-enterprise-harness.md","How to Choose Between a Coding Harness and an Enterprise Harness",[476],{"name":184,"to":136},{"label":186},{"type":168,"value":479,"toc":1195},[480,497,515,535,543,547,629,646,650,653,665,684,690,696,709,713,719,725,735,747,761,775,779,785,791,801,811,817,824,828,880,894,908,912,923,932,948,960,969,972,980,995,1002,1005,1025,1029,1034,1037,1041,1052,1056,1059,1063,1066,1070,1082,1086,1095,1099],[190,481,482,483,486,487,490,491,496],{},"Choosing between a ",[225,484,485],{},"coding harness"," and an ",[225,488,489],{},"enterprise harness"," is choosing the workspace. A coding harness (Claude Code, Cursor, Codex, open shells) wraps a model for a developer and a repository. An enterprise harness wraps a model for operators and systems of record. Same equation — ",[200,492,495],{"href":493,"rel":494},"https:\u002F\u002Fdocs.langchain.com\u002Foss\u002Fpython\u002Flangchain\u002Fagents",[267],"Agent = Model + Harness"," — different loop.",[190,498,499,500,504,505,509,510,514],{},"This is the buying companion to ",[200,501,503],{"href":502},"inner-vs-outer-agent-harness","inner vs outer agent harness",". It sits beside ",[200,506,508],{"href":507},"how-to-choose-between-a-copilot-and-a-work-os","how to choose between a copilot and a work OS",": copilots are personal assistants; coding harnesses are ",[511,512,513],"em",{},"agentic"," inner loops with tools and tests; enterprise harnesses are outer loops with grants and signers. Do not collapse all three into “we need ChatGPT.”",[190,516,517,522,523,528,529,534],{},[200,518,521],{"href":519,"rel":520},"https:\u002F\u002Fmartinfowler.com\u002Farticles\u002Fharness-engineering.html",[267],"Böckeler"," documents how coding-agent users add guides and sensors. ",[200,524,527],{"href":525,"rel":526},"https:\u002F\u002Faddyosmani.com\u002Fblog\u002Fown-the-outer-loop\u002F",[267],"Osmani"," tells engineers to own verify-and-release. ",[200,530,533],{"href":531,"rel":532},"https:\u002F\u002Fwww.thoughtworks.com\u002Finsights\u002Farticles\u002Foperating-system-enterprise-ai",[267],"Thoughtworks"," argues the organisational layer is still the gap. The purchase mistake is using one budget line for all three layers.",[190,536,537,542],{},[200,538,541],{"href":539,"rel":540},"https:\u002F\u002Fwww.mckinsey.com\u002Fcapabilities\u002Fquantumblack\u002Four-insights\u002Fthe-state-of-ai",[267],"McKinsey’s 2025 State of AI"," is the organisational backdrop: usage is easy; scale is redesign. A Cursor rollout can scale pull requests. It will not, by itself, scale governed CRM writes. An OS-class rollout can scale those writes. It will annoy engineers if you force “rewrite this function” through a Critical gate.",[216,544,546],{"id":545},"words-youll-hear","Words you’ll hear",[321,548,549,576,587,609,619],{},[324,550,551,554,555,559,560,563,564,569,570,575],{},[225,552,553],{},"Coding \u002F inner harness."," Repo workspace, sandbox, ",[556,557,558],"code",{},"AGENTS.md"," \u002F ",[556,561,562],{},"CLAUDE.md",", hooks, CI. Eval: ",[200,565,568],{"href":566,"rel":567},"https:\u002F\u002Fwww.swebench.com\u002F",[267],"SWE-bench",", ",[200,571,574],{"href":572,"rel":573},"https:\u002F\u002Farxiv.org\u002Fabs\u002F2601.11868",[267],"Terminal-Bench",", your tests.",[324,577,578,581,582,586],{},[225,579,580],{},"Enterprise \u002F outer harness."," Job workspace, connectors, roster, write quotes, ledger. Eval: signed payload vs SoR. ",[200,583,585],{"href":584},"what-is-an-enterprise-agent-harness","What is an enterprise agent harness",".",[324,588,589,592,593,569,598,569,603,608],{},[225,590,591],{},"Copilot."," Personal completion surface. Often no repo loop. ",[200,594,597],{"href":595,"rel":596},"https:\u002F\u002Fopenai.com\u002Fbusiness\u002Fchatgpt-enterprise\u002F",[267],"ChatGPT Enterprise",[200,599,602],{"href":600,"rel":601},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fmicrosoft-365\u002Fcopilot",[267],"Microsoft 365 Copilot",[200,604,607],{"href":605,"rel":606},"https:\u002F\u002Fwww.anthropic.com\u002Fnews\u002Fclaude-for-work",[267],"Claude for Work",". Keep for mail. Do not hand it the NetSuite token.",[324,610,611,614,615,586],{},[225,612,613],{},"Framework."," How you assemble a loop in code. Not a purchase of a company workspace. ",[200,616,618],{"href":617},"agent-harness-vs-agent-framework","Harness vs framework",[324,620,621,624,625,586],{},[225,622,623],{},"MCP."," Plug into either. Dangerous when both share a production write server. ",[200,626,628],{"href":627},"mcp-for-enterprise-integrations","MCP for enterprise",[190,630,631,632,569,635,569,638,641,642,586],{},"Nimbus is an enterprise \u002F outer option: ",[200,633,634],{"href":32},"workstreams",[200,636,637],{"href":20},"teams",[200,639,640],{"href":40},"governance",". Claude Code is a coding \u002F inner option. The rational stack is both, with a hard rule: no unsigned SoR writes from the inner harness. ",[200,643,645],{"href":644},"how-to-solve-unapproved-crm-writes-from-ai","How to solve unapproved CRM writes",[216,647,649],{"id":648},"why-the-choice-is-usually-both","Why the choice is usually “both”",[190,651,652],{},"The tools look similar in a first meeting. Both stream tokens. Both call tools. Both have “agents” on the website. The evaluation is what happens after the answer.",[190,654,655,658,659,664],{},[225,656,657],{},"Buy a coding harness when"," the artefact is code in a repo you already trust with CI: features, refactors, tests, developer docs, infra-as-code that merges through the same gates humans use. ",[200,660,663],{"href":661,"rel":662},"https:\u002F\u002Fwww.anthropic.com\u002Fengineering\u002Feffective-harnesses-for-long-running-agents",[267],"Anthropic’s long-running harness"," is this world: git, progress files, end-to-end checks.",[190,666,667,670,671,674,675,674,679,683],{},[225,668,669],{},"Buy an enterprise harness when"," the artefact is a change to Salesforce, NetSuite, a policy commitment, or a cross-department decision that must be replayed. ",[200,672,673],{"href":212},"Write-back",". ",[200,676,678],{"href":677},"what-is-human-in-the-loop-ai","HITL",[200,680,682],{"href":275,"rel":681},[267],"NIST RMF"," context of use is operations, not a checkout.",[190,685,686,689],{},[225,687,688],{},"Keep a copilot when"," the job is a paragraph in a mailbox. Do not scale it into an approval architecture.",[190,691,692,695],{},[225,693,694],{},"Build on a framework when"," engineers own a unique loop and will maintain grants. That is a programme, not a seat.",[190,697,698,703,704,708],{},[200,699,702],{"href":700,"rel":701},"https:\u002F\u002Fhai.stanford.edu\u002Fai-index\u002F2025-ai-index-report",[267],"Stanford HAI’s 2025 AI Index"," charts the explosion of coding-agent tooling. Procurement that only reads that chart will under-buy the outer layer. Procurement that only reads ",[200,705,448],{"href":706,"rel":707},"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F42001",[267]," will over-process inner loops and lose developers.",[216,710,712],{"id":711},"decision-tests","Decision tests",[190,714,715,718],{},[225,716,717],{},"1. What is the system of record for the outcome?"," Git: inner. CRM\u002FERP\u002Fcustomer commitment: outer. Both: two harnesses, one write plane (the outer quotes).",[190,720,721,724],{},[225,722,723],{},"2. Who is the signer?"," The author of the PR (inner, plus CODEOWNERS). A named RevOps\u002FFinance\u002FLegal role (outer). If you cannot name the role, you are not ready to buy the outer write path — buy read-only first.",[190,726,727,730,731,586],{},[225,728,729],{},"3. What is the independent sensor?"," Pytest \u002F tsc \u002F CI (inner). Payload schema + SoR read-back (outer). “The model said it was fine” is neither. ",[200,732,734],{"href":733},"eval-loops-for-enterprise-agent-harnesses","Eval loops",[190,736,737,740,741,746],{},[225,738,739],{},"4. What identity should the tools use?"," Developer sandbox and repo token (inner). Workstream-scoped OAuth (outer). A shared MCP god account fails both ",[200,742,745],{"href":743,"rel":744},"https:\u002F\u002Fgenai.owasp.org\u002Fllm-top-10\u002F",[267],"OWASP"," and SoD.",[190,748,749,752,753,755,756,760],{},[225,750,751],{},"5. How will you ratchet failures?"," Inner: ",[556,754,558],{}," + hooks + tests (",[200,757,759],{"href":758},"what-is-harness-engineering","harness engineering","). Outer: wiki revision + gate tier + graph. If your plan is “we’ll prompt better,” you have not chosen a harness. You have chosen hope.",[190,762,763,766,767,674,771,586],{},[225,764,765],{},"6. Time-to-value and staffing."," Cursor can be a week for a team that already has CI. AIP can be a programme. Nimbus-style self-service claims a product week for a standard write — verify with a ",[200,768,770],{"href":769},"how-to-run-an-enterprise-ai-proof-of-value","PoV",[200,772,774],{"href":773},"self-service-vs-forward-deployed-ai-platforms","Self-service vs FDE",[216,776,778],{"id":777},"anti-patterns","Anti-patterns",[190,780,781,784],{},[225,782,783],{},"Cursor for Salesforce."," MCP connected to production. Tests on fixtures. Amount changes. No signer in the ledger. Inner loop on an outer record.",[190,786,787,790],{},[225,788,789],{},"Work OS for a one-line refactor."," Critical gate, three departments. Engineers route around. Outer loop on an inner job.",[190,792,793,796,797,586],{},[225,794,795],{},"One mesh to rule them."," IDE, chatbot, and OS all write through the same server. Two writers. ",[200,798,800],{"href":799},"multi-agent-ai-architecture","Multi-agent architecture",[190,802,803,806,807,586],{},[225,804,805],{},"Benchmark shopping."," Buying Agentforce because of a coding leaderboard, or buying Claude Code because of a governance white paper. Wrong evidence. ",[200,808,810],{"href":809},"how-to-evaluate-an-agent-harness","How to evaluate an agent harness",[190,812,813,816],{},[225,814,815],{},"Banning inner harnesses until the OS ships."," Usually slows software and does not stop paste-into-CRM. Ban the write path; allow the compile path.",[190,818,819,820,823],{},"Nimbus should lose the inner job on purpose. If a vendor tries to replace Claude Code for application engineering, ask for sandbox, hooks, and merge sensors — ",[200,821,822],{"href":809},"evaluate the harness"," — and expect to keep a coding tool anyway. If a coding-tool vendor tries to replace the OS for NetSuite journals, ask for quoted GL lines and a Finance signer.",[216,825,827],{"id":826},"a-simple-portfolio","A simple portfolio",[829,830,831,844],"table",{},[832,833,834],"thead",{},[835,836,837,841],"tr",{},[838,839,840],"th",{},"Job",[838,842,843],{},"Buy",[845,846,847,856,864,872],"tbody",{},[835,848,849,853],{},[850,851,852],"td",{},"Mail, slides, one-off Q&A",[850,854,855],{},"Copilot",[835,857,858,861],{},[850,859,860],{},"Application and infra repos",[850,862,863],{},"Coding harness",[835,865,866,869],{},[850,867,868],{},"Cross-department SoR writes",[850,870,871],{},"Enterprise harness",[835,873,874,877],{},[850,875,876],{},"Unique simulation \u002F exotic tools",[850,878,879],{},"Framework + your grants",[190,881,882,883,886,887,889,890,893],{},"Most enterprises tick all four rows. Budget them separately. Share policy ",[511,884,885],{},"intent"," (discount cap) via wiki and via ",[556,888,558],{}," where relevant; share ",[511,891,892],{},"enforcement"," only on the plane that can execute the write.",[190,895,896,897,899,900,903,904,907],{},"See ",[200,898,11],{"href":12}," for how Nimbus maps to the third row, ",[200,901,902],{"href":45},"models"," for routing, ",[200,905,906],{"href":51},"integrations"," for connectors. See Claude Code \u002F Cursor docs for the second. Do not let a single SOW blur the rows.",[216,909,911],{"id":910},"procurement-sequence-that-does-not-waste-a-quarter","Procurement sequence that does not waste a quarter",[190,913,914,917,918,922],{},[225,915,916],{},"Week 1 — inventory loops, not vendors."," List jobs that already have a finish line. Tag each: git artefact, SoR artefact, mailbox artefact, unique research. You now have four shopping lists. ",[200,919,921],{"href":539,"rel":920},[267],"McKinsey"," programmes that skip this step buy one platform and force every row into it.",[190,924,925,928,929,586],{},[225,926,927],{},"Week 2 — freeze the write rule."," Unsigned SoR writes are impossible from copilots, coding agents, frameworks, and the OS. That rule is cheaper than any bake-off. It also tells Security what to revoke this month (god MCP servers). ",[200,930,931],{"href":644},"Unapproved CRM writes",[190,933,934,937,938,943,944,947],{},[225,935,936],{},"Week 3 — inner bake-off only if you lack a coding harness."," Hooks, sandbox, CI independence, model swap on the same tools. Terminal-Bench and SWE-bench as vendor quality, not as Legal’s control. ",[200,939,942],{"href":940,"rel":941},"https:\u002F\u002Fcode.claude.com\u002Fdocs\u002Fen\u002Fhooks",[267],"Anthropic hooks"," vs Cursor rules vs Codex — pick for ",[511,945,946],{},"your"," repos.",[190,949,950,953,954,957,958,586],{},[225,951,952],{},"Week 4 — outer bake-off only for SoR jobs."," Run the refuse\u002Freplay script from ",[200,955,956],{"href":809},"how to evaluate an agent harness",". Include Nimbus, AIP, Agentforce, or a LangGraph programme as fits the staffing model. ",[200,959,774],{"href":773},[190,961,962,965,966,968],{},[225,963,964],{},"Do not"," hold week 3 until week 4 ships. Engineers will adopt inner tools anyway; you will only lose the chance to standardise hooks. ",[225,967,964],{}," skip week 4 because week 3’s coding agent “can also call Salesforce.” That is the anti-pattern.",[190,970,971],{},"Budget: copilot seats (predictable, personal); coding harness seats or usage (developer count); enterprise harness by work, not by mailbox count if you care about routing. Mixing all three into one “AI budget” is how flagship models burn on classify and how CRM writes go unquoted to save a line item.",[190,973,974,975,979],{},"Thoughtworks’ ",[200,976,978],{"href":531,"rel":977},[267],"organisational harness"," is the steering cadence after purchase: incidents become controls across both inner and outer. Buy tools that allow that ratchet. A coding harness that forbids custom hooks, or an OS that forbids adding a gate without FDE, will stall week 5.",[190,981,982,983,986,987,990,991,994],{},"Expect political arguments that are actually workspace arguments. Engineering will say the OS is slow. They are right for a one-line refactor. RevOps will say Cursor is unsafe. They are right for a production Opportunity. The CISO will say “one approved agent.” Translate: one ",[511,984,985],{},"write rule",", many loops. ",[200,988,294],{"href":292,"rel":989},[267]," oversight can be satisfied per system of use, not per brand. ",[200,992,682],{"href":275,"rel":993},[267]," Map is the same advice.",[190,996,997,998,1001],{},"If budget forces a single purchase this half, buy the loop that matches the ",[511,999,1000],{},"highest-harm"," unfinished job. Ungoverned CRM writes usually outrank “we could use a better coding agent” — paste already exists; unsigned APIs are new blast radius. If the highest-harm job is shipping software and SoR writes are still human, buy the coding harness and freeze the write rule until the outer product lands. Either way, write the rule down before the PO.",[190,1003,1004],{},"Nimbus should win the outer row on self-service quoting and graph export, and should lose the inner row on purpose. If a bake-off ranks us against Claude Code on SWE-bench, the scorecard is wrong. If it ranks us against a copilot on mail quality, also wrong. Rank us against AIP and Agentforce on the refuse\u002Freplay script, and against “we’ll build LangGraph” on time-to-first-governed-write.",[190,1006,1007,1008,1011,1012,1015,1016,1019,1020,1024],{},"The copilot row still matters. People will keep ",[200,1009,597],{"href":595,"rel":1010},[267]," for drafts. That is healthy if the write path is the easy official one. Banning unofficial ",[511,1013,1014],{},"drafts"," usually fails; making unofficial ",[511,1017,1018],{},"writes"," fail-closed usually works. ",[200,1021,1023],{"href":1022},"what-is-shadow-ai","Shadow AI"," is often a write-path problem wearing a chat-policy costume.",[216,1026,1028],{"id":1027},"questions-people-actually-ask","Questions people actually ask",[1030,1031,1033],"h3",{"id":1032},"we-already-paid-for-github-copilot","We already paid for GitHub Copilot.",[190,1035,1036],{},"That is often a completion copilot, not a full coding harness. You may still want Claude Code or Cursor for agentic repo work. Evaluate hooks and tests, not the seat.",[1030,1038,1040],{"id":1039},"can-the-enterprise-harness-include-a-coding-specialist","Can the enterprise harness include a coding specialist?",[190,1042,1043,1044,1047,1048,586],{},"Yes, as a ",[511,1045,1046],{},"bounded tool"," that opens a draft PR. The SoR write still quotes in the outer harness. Specialists are hands. ",[200,1049,1051],{"href":1050},"agent-team-architecture","Agent teams",[1030,1053,1055],{"id":1054},"what-if-legal-wants-one-vendor","What if Legal wants one vendor?",[190,1057,1058],{},"One vendor for identity and logging is reasonable. One vendor for repo loop and CRM loop is how you get a mediocre both. Prefer two harnesses and one interceptor rule: unsigned SoR writes are impossible everywhere.",[1030,1060,1062],{"id":1061},"how-do-we-score-nimbus-vs-claude-code-in-a-bake-off","How do we score Nimbus vs Claude Code in a bake-off?",[190,1064,1065],{},"Different jobs. Run inner tests on a repo. Run outer tests on a quoted CRM write. A combined “winner” is a category error unless you only have one job.",[1030,1067,1069],{"id":1068},"what-should-i-read-next","What should I read next?",[190,1071,1072,1075,1076,1078,1079,1081],{},[200,1073,1074],{"href":502},"Inner vs outer"," for architecture. ",[200,1077,810],{"href":809}," for the live tests. ",[200,1080,585],{"href":584}," for the outer object.",[216,1083,1085],{"id":1084},"related-reading","Related reading",[190,1087,1088,413,1091,586],{},[200,1089,1090],{"href":507},"How to choose between a copilot and a work OS",[200,1092,1094],{"href":1093},"build-vs-buy-an-enterprise-ai-os","Build vs buy an enterprise AI OS",[216,1096,1098],{"id":1097},"sources","Sources",[321,1100,1101,1107,1113,1119,1125,1131,1137,1143,1148,1153,1159,1165,1171,1177,1182,1188],{},[324,1102,1103],{},[200,1104,1106],{"href":493,"rel":1105},[267],"LangChain, Agents",[324,1108,1109],{},[200,1110,1112],{"href":519,"rel":1111},[267],"Böckeler, Harness engineering for coding agent users",[324,1114,1115],{},[200,1116,1118],{"href":525,"rel":1117},[267],"Addy Osmani, Own the outer loop",[324,1120,1121],{},[200,1122,1124],{"href":531,"rel":1123},[267],"Thoughtworks, The operating system for enterprise AI",[324,1126,1127],{},[200,1128,1130],{"href":661,"rel":1129},[267],"Anthropic, Effective harnesses for long-running agents",[324,1132,1133],{},[200,1134,1136],{"href":605,"rel":1135},[267],"Anthropic, Claude for Work",[324,1138,1139],{},[200,1140,1142],{"href":595,"rel":1141},[267],"OpenAI, ChatGPT Enterprise",[324,1144,1145],{},[200,1146,602],{"href":600,"rel":1147},[267],[324,1149,1150],{},[200,1151,568],{"href":566,"rel":1152},[267],[324,1154,1155],{},[200,1156,1158],{"href":572,"rel":1157},[267],"Terminal-Bench (arXiv:2601.11868)",[324,1160,1161],{},[200,1162,1164],{"href":539,"rel":1163},[267],"McKinsey, The state of AI in 2025",[324,1166,1167],{},[200,1168,1170],{"href":700,"rel":1169},[267],"Stanford HAI, 2025 AI Index",[324,1172,1173],{},[200,1174,1176],{"href":275,"rel":1175},[267],"NIST AI RMF",[324,1178,1179],{},[200,1180,285],{"href":706,"rel":1181},[267],[324,1183,1184],{},[200,1185,1187],{"href":743,"rel":1186},[267],"OWASP Top 10 for LLM applications",[324,1189,1190],{},[200,1191,1194],{"href":1192,"rel":1193},"https:\u002F\u002Fmodelcontextprotocol.io\u002Fspecification\u002F2025-11-25\u002Findex",[267],"Model Context Protocol specification",{"title":171,"searchDepth":172,"depth":172,"links":1196},[1197,1198,1199,1200,1201,1202,1203,1211,1212],{"id":545,"depth":172,"text":546},{"id":648,"depth":172,"text":649},{"id":711,"depth":172,"text":712},{"id":777,"depth":172,"text":778},{"id":826,"depth":172,"text":827},{"id":910,"depth":172,"text":911},{"id":1027,"depth":172,"text":1028,"children":1204},[1205,1207,1208,1209,1210],{"id":1032,"depth":1206,"text":1033},3,{"id":1039,"depth":1206,"text":1040},{"id":1054,"depth":1206,"text":1055},{"id":1061,"depth":1206,"text":1062},{"id":1068,"depth":1206,"text":1069},{"id":1084,"depth":172,"text":1085},{"id":1097,"depth":172,"text":1098},"2026-08-24","A coding harness runs a repository — Claude Code, Cursor, Codex. An enterprise harness runs company jobs with connectors and signers. Most organisations need both; they are not substitutes.","\u002Fblog\u002Fhow-to-choose-between-a-coding-harness-and-an-enterprise-harness",{"title":474,"description":1214},"blog\u002Fhow-to-choose-between-a-coding-harness-and-an-enterprise-harness",[444,1219,1220,1221],"agent-harness","coding-agents","enterprise-ai","zypj0rFuSxQgNAtRx0gY8CyrewpGlXGHc6zrzz32V4g",{"id":1224,"title":1225,"archived":165,"authors":1226,"badge":1228,"body":1229,"date":1920,"definedTerm":166,"department":166,"description":1921,"extension":174,"eyebrow":166,"faqHeader":1922,"faqs":1925,"footerBand":166,"headline":166,"image":166,"industry":166,"jobType":166,"listed":165,"location":166,"navigation":131,"openRoles":166,"pageLayout":166,"path":1938,"relatedHeading":166,"seo":1939,"series":444,"sitemap":131,"status":166,"stem":1940,"subhead":166,"tags":1941,"video":166,"whyJoin":166,"workplaceType":166,"__hash__":1945},"content\u002Fblog\u002Fhow-to-evaluate-loop-engineering.md","How to Evaluate Loop Engineering",[1227],{"name":184,"to":136},{"label":186},{"type":168,"value":1230,"toc":1902},[1231,1247,1250,1253,1299,1306,1310,1313,1334,1352,1355,1375,1383,1387,1390,1422,1426,1437,1443,1446,1449,1452,1456,1459,1462,1465,1468,1471,1475,1482,1493,1496,1499,1502,1506,1513,1520,1523,1526,1529,1533,1550,1553,1556,1559,1562,1566,1569,1580,1583,1586,1589,1593,1598,1601,1604,1607,1610,1614,1620,1633,1636,1639,1642,1646,1649,1679,1685,1689,1692,1698,1704,1710,1716,1719,1723,1810,1823,1830,1834,1837,1847,1857,1866,1881,1885,1895,1898],[190,1232,1233,1234,1237,1238,1241,1242,1246],{},"Evaluating ",[225,1235,1236],{},"loop engineering"," means testing whether a vendor can run ",[225,1239,1240],{},"standing orders"," the way operators actually work — skip when nothing changed, record quiet outcomes, reuse recipes, notify a named roster — not whether a demo chat looked fluent. ",[200,1243,1245],{"href":275,"rel":1244},[267],"NIST’s AI Risk Management Framework"," Measure and Manage functions assume you can observe outcomes and tighten controls after harm. A loop without a run page is not observable. It is email archaeology.",[190,1248,1249],{},"This sheet is vendor-agnostic. Paste it into an RFP. Run it on an incumbent automation suite, a new “agentic” platform, or a homegrown scheduler. The object under test is the standing order: a compiled recipe that starts on a signal and leaves a record. If the vendor cannot show that object, stop scoring adjectives.",[190,1251,1252],{},"Three nouns vendors conflate on slide one:",[321,1254,1255,1269,1278],{},[324,1256,1257,1260,1261,413,1265,586],{},[225,1258,1259],{},"Loop."," A compiled standing order with triggers and a run page. See ",[200,1262,1264],{"href":1263},"what-is-loop-engineering","what is loop engineering",[200,1266,1268],{"href":1267},"six-things-that-start-a-loop","six things that start a loop",[324,1270,1271,1274,1275,586],{},[225,1272,1273],{},"Eval loop."," Independent verification that a job finished — tests, read-back, signer — not a trigger. See ",[200,1276,1277],{"href":733},"eval loops for enterprise agent harnesses",[324,1279,1280,1283,1284,1288,1289,674,1291,1294,1295,1298],{},[225,1281,1282],{},"Agentic workflow."," A designed interactive sequence with stops. See ",[200,1285,1287],{"href":1286},"what-is-an-agentic-workflow","what is an agentic workflow",". Score it with ",[200,1290,956],{"href":809},[225,1292,1293],{},"That"," sheet scores the interactive harness. ",[225,1296,1297],{},"This"," sheet scores repeat automation.",[190,1300,1301,1302,1305],{},"If your RFP only asks context-window size, you will buy a model for a Monday cron job. ",[200,1303,285],{"href":283,"rel":1304},[267]," wants named actors and records around AI systems. “The bot ran” is not a record. “The assistant said it was done” is not a record.",[216,1307,1309],{"id":1308},"why-loop-evaluation-fails","Why loop evaluation fails",[190,1311,1312],{},"Teams reuse copilot scorecards because those cards are already in the drawer. They fail in predictable ways:",[1314,1315,1316,1322,1328],"ol",{},[324,1317,1318,1321],{},[225,1319,1320],{},"The demo pass."," A model summarises a file beautifully. No trigger, no skip, no version. You have scored reading, not standing orders.",[324,1323,1324,1327],{},[225,1325,1326],{},"The integration pass."," “We connect to Salesforce.” No run page, no quiet outcome, no roster. You have scored a connector, not an operating object.",[324,1329,1330,1333],{},[225,1331,1332],{},"The personal-automation pass."," A chain fires. Outcomes scatter across personal inboxes. No organisational recipe. You have scored glue, not loop engineering.",[190,1335,1336,1339,1340,1343,1344,1347,1348,1351],{},[200,1337,541],{"href":539,"rel":1338},[267]," reports wide experimentation and narrower scale. Loop engineering is how repeat work scales: ",[225,1341,1342],{},"compile"," what worked, ",[225,1345,1346],{},"trigger"," it reliably, ",[225,1349,1350],{},"record"," what happened. High-performing organisations in that survey are more likely to redesign workflows, not merely sprinkle assistants on the current process. This RFP is a redesign test.",[190,1353,1354],{},"Red flags you can mark in the room:",[321,1356,1357,1360,1363,1366,1369,1372],{},[324,1358,1359],{},"Outcomes live only in chat transcripts",[324,1361,1362],{},"“Success” when there was nothing to do — but Finance still got paged",[324,1364,1365],{},"Reuse means “find Sarah’s Slack thread from Q2”",[324,1367,1368],{},"Every write goes through a model — even fixed journal templates",[324,1370,1371],{},"No pause — cancel kills state without a resumable run",[324,1373,1374],{},"Notifications go to channels, not to a roster attached to the job",[190,1376,1377,1382],{},[200,1378,1381],{"href":1379,"rel":1380},"https:\u002F\u002Faiindex.stanford.edu\u002F",[267],"Stanford HAI’s AI Index"," is a useful external reminder that capability is not the scarce input. You are not scoring whether the model can write a polite email. You are scoring whether Tuesday’s job exists when the author is on leave.",[216,1384,1386],{"id":1385},"the-rfp-sheet-eight-tests","The RFP sheet — eight tests",[190,1388,1389],{},"Each test has a why, a when, a thing to do, and a thing to refuse. Run them in order if you are short on time: skip semantics first, then run page, then reuse. A fluent demo that fails test 1 is not a standing order.",[1391,1392,1396],"pre",{"className":1393,"code":1394,"language":1395,"meta":171,"style":171},"language-mermaid shiki shiki-themes github-light github-dark","flowchart LR\n  skipTest[\"Can it skip quietly?\"] --> pageTest[\"Is there a run page?\"]\n  pageTest --> reuseTest[\"Can another team reuse it?\"]\n  reuseTest --> refuseTest[\"Can someone refuse a write?\"]\n","mermaid",[556,1397,1398,1406,1411,1416],{"__ignoreMap":171},[1399,1400,1403],"span",{"class":1401,"line":1402},"line",1,[1399,1404,1405],{},"flowchart LR\n",[1399,1407,1408],{"class":1401,"line":172},[1399,1409,1410],{},"  skipTest[\"Can it skip quietly?\"] --> pageTest[\"Is there a run page?\"]\n",[1399,1412,1413],{"class":1401,"line":1206},[1399,1414,1415],{},"  pageTest --> reuseTest[\"Can another team reuse it?\"]\n",[1399,1417,1419],{"class":1401,"line":1418},4,[1399,1420,1421],{},"  reuseTest --> refuseTest[\"Can someone refuse a write?\"]\n",[1030,1423,1425],{"id":1424},"_1-can-it-skip-when-nothing-changed","1. Can it skip when nothing changed?",[190,1427,1428,1429,1432,1433,1436],{},"Run the loop on unchanged inputs. The run page should say ",[225,1430,1431],{},"skipped"," or ",[225,1434,1435],{},"no op"," — with timestamp and recipe version — not green-check spam.",[190,1438,1439,1440,1442],{},"Why it matters: month-end with zero exceptions is success. Bots that “succeed” on empty tables train operators to ignore alerts. See ",[200,1441,1268],{"href":1267}," for triggers that should dedupe.",[190,1444,1445],{},"When to insist: any scheduled or event-driven job that will run in unattended hours.",[190,1447,1448],{},"What to do: show ten consecutive skipped runs. Show alert volume — ideally zero.",[190,1450,1451],{},"What to refuse: a “success” email on an empty extract, or a skip that exists only as the absence of mail. Absence is not a record.",[1030,1453,1455],{"id":1454},"_2-can-it-record-quiet-outcomes","2. Can it record quiet outcomes?",[190,1457,1458],{},"Quiet success is a first-class outcome: ran, nothing to write, roster optionally notified at digest frequency.",[190,1460,1461],{},"Why it matters: auditors and controllers ask what happened on the twelfth — including days nothing moved. Silence without a record is indistinguishable from failure. NIST’s Measure function is not optional because the week was quiet.",[190,1463,1464],{},"When to insist: regulated work, shared-service work, anything a second person will reconstruct.",[190,1466,1467],{},"What to do: export skipped runs for a month without vendor engineering.",[190,1469,1470],{},"What to refuse: a professional-services quote to produce last month’s quiet days. If export is a project, observation is not a product feature.",[1030,1472,1474],{"id":1473},"_3-can-you-parameterise-a-write-without-a-model","3. Can you parameterise a write without a model?",[190,1476,1477,1478,1481],{},"Show a loop that posts or quotes a ",[225,1479,1480],{},"fixed-shape"," payload — accounts, amounts, CRM fields — from structured input, with no language model in the path.",[190,1483,1484,1485,413,1489,586],{},"Why it matters: many operational writes are templates, not essays. If the vendor routes everything through chat, you are paying inference tax on deterministic work and importing non-determinism into close. Compare ",[200,1486,1488],{"href":1487},"loop-vs-workflow-vs-agent","loop vs workflow vs agent",[200,1490,1492],{"href":1491},"a-loop-is-not-an-agent","a loop is not an agent",[190,1494,1495],{},"When to insist: journals, stage updates, status writes, any payload a controller could have typed from a spreadsheet.",[190,1497,1498],{},"What to do: disable the model. Does the loop still quote the write and wait on sign?",[190,1500,1501],{},"What to refuse: “the model is more flexible” as an answer to a fixed schema. Flexibility on a journal line is a defect.",[1030,1503,1505],{"id":1504},"_4-can-it-pause-and-resume-cleanly","4. Can it pause and resume cleanly?",[190,1507,1508,1509,1512],{},"A loop waiting on a file, a signer, or an external system should ",[225,1510,1511],{},"pause"," with visible state — not vanish into a thread.",[190,1514,1515,1516,1519],{},"Why it matters: close week spans days. Operations must distinguish “waiting on a person” from “broken.” ",[200,1517,1518],{"href":677},"What is human-in-the-loop AI"," applies to standing orders too.",[190,1521,1522],{},"When to insist: any recipe that crosses a night, a weekend, or a named approver.",[190,1524,1525],{},"What to do: pause mid-run. Attach the missing file. Resume without restarting from scratch unless you choose to. Keep the same run identifier.",[190,1527,1528],{},"What to refuse: cancel-as-pause. If state dies, you do not have a pause. You have a restart with extra steps.",[1030,1530,1532],{"id":1531},"_5-can-it-notify-the-roster-not-a-copied-channel","5. Can it notify the roster — not a copied channel?",[190,1534,1535,1536,1539,1540,1544,1545,1549],{},"Notifications should target the people on the job — controller, RevOps, counsel — with a link to the ",[225,1537,1538],{},"run page",". See ",[200,1541,1543],{"href":1542},"what-is-an-ai-workstream","what is an AI workstream"," for the job-object idea, and ",[200,1546,1548],{"href":1547},"how-to-evaluate-collaborative-ai","how to evaluate collaborative AI"," for the roster questions.",[190,1551,1552],{},"Why it matters: Slack channels rot when people leave. Rosters follow the job. A copied channel is how a departed contractor keeps getting close packs, and how the new controller never does.",[190,1554,1555],{},"When to insist: any loop that another department will act on.",[190,1557,1558],{},"What to do: remove one person from the roster. Prove they stop receiving loop notifications without creating a new automation.",[190,1560,1561],{},"What to refuse: “we’ll update the webhook.” If membership is not data, notification is folklore.",[1030,1563,1565],{"id":1564},"_6-can-you-reuse-a-recipe-without-copying-the-old-slack-channel","6. Can you reuse a recipe without copying the old Slack channel?",[190,1567,1568],{},"Clone the loop — triggers, steps, gates, notify rules — into a new team or region without re-prompting from memory.",[190,1570,1571,1572,1574,1575,1579],{},"Why it matters: ",[200,1573,1236],{"href":1263}," is an organisational capability, not hero prompts. If reuse requires export to JSON and a services quote, note the tax. ",[200,1576,1578],{"href":531,"rel":1577},[267],"Thoughtworks’ operating-system framing"," is useful here: ownership and durable state belong to the job, not to the person who first described it.",[190,1581,1582],{},"When to insist: any recipe you will need in a second business unit within a year.",[190,1584,1585],{},"What to do: stand up the same loop for a second team in under one hour — operator-led.",[190,1587,1588],{},"What to refuse: a clone that copies the prompt but drops the skip rules, the signer, or the run-page contract. That is a new folklore, not reuse.",[1030,1590,1592],{"id":1591},"_7-does-every-trigger-land-on-the-same-run-page","7. Does every trigger land on the same run page?",[190,1594,1595,1596,586],{},"Schedule, file, data change, drop, ping, run now — several doors, one outcome surface. See ",[200,1597,1268],{"href":1267},[190,1599,1600],{},"Why it matters: operators should not learn six UIs. Audit should not merge six log formats. If the scheduled close and the emergency rerun do not look like the same object, you will get two classes of evidence.",[190,1602,1603],{},"When to insist: as soon as a team has more than one start condition for the same recipe.",[190,1605,1606],{},"What to do: fire two different triggers against the same recipe. Show both run pages side by side.",[190,1608,1609],{},"What to refuse: a “manual” path that writes with weaker gates than the scheduled path. Urgency is not a policy exception.",[1030,1611,1613],{"id":1612},"_8-can-you-refuse-a-write-and-prove-the-system-of-record-unchanged","8. Can you refuse a write and prove the system of record unchanged?",[190,1615,1616,1617,586],{},"Even loops that only draft should demonstrate fail-closed behaviour when signers reject. Loops that write must show quote → sign → execute → read-back. See ",[200,1618,1619],{"href":212},"what is write-back governance",[190,1621,1622,1623,1625,1626,1629,1630,1632],{},"Why it matters: this is where loop evaluation meets harness evaluation. ",[200,1624,810],{"href":809}," test one — ",[225,1627,1628],{},"stop an action"," — applies to automated writes too. ",[200,1631,203],{"href":202}," is the category language.",[190,1634,1635],{},"When to insist: before any production write, including “just a status field.”",[190,1637,1638],{},"What to do: show a rejected payload. Show the CRM or ERP unchanged. Show the rejection on the run page, with who rejected and which policy version applied.",[190,1640,1641],{},"What to refuse: a write that cannot be shown in a quoted form. A paragraph the model later “applies” is not a payload.",[216,1643,1645],{"id":1644},"rfp-questions-paste-these","RFP questions — paste these",[190,1647,1648],{},"These are the short versions you can drop into a vendor questionnaire. They are not vendor-specific. They are not even AI-specific. They are standing-order tests.",[1314,1650,1651,1654,1661,1664,1667,1670,1673,1676],{},[324,1652,1653],{},"Show ten skipped runs with timestamps and recipe version.",[324,1655,1656,1657,1660],{},"Show a write path with ",[225,1658,1659],{},"no model call"," — structured in, quoted out.",[324,1662,1663],{},"Pause a run for 48 hours; resume; show a continuous run identifier.",[324,1665,1666],{},"Clone a loop to a second team without re-entering prompts.",[324,1668,1669],{},"Trigger the same recipe via schedule and via file drop; compare run pages.",[324,1671,1672],{},"Remove a roster member; prove notifications stop.",[324,1674,1675],{},"Reject a quoted write; prove the system of record unchanged; show who rejected.",[324,1677,1678],{},"Where do outputs live if email is down — still on the run page?",[190,1680,1681,1682,1684],{},"Add the harness sheet when loops call agents or share connectors with interactive work. Add ",[200,1683,1548],{"href":1547}," when the output is a signed pack rather than a silent write.",[216,1686,1688],{"id":1687},"proof-of-value-one-week","Proof of value — one week",[190,1690,1691],{},"Do not spend the week watching a prepared demo. Spend it on one real job.",[190,1693,1694,1697],{},[225,1695,1696],{},"Day 1–2:"," Pick one repeat job — weekly pipeline summary, bank file intake, redline folder watch. Name the trigger your team already watches. Write the skip condition in a sentence a controller would accept.",[190,1699,1700,1703],{},[225,1701,1702],{},"Day 3:"," Run ten times with empty or stale inputs. Demand skipped run pages. If you cannot get them, the rest of the week is theatre.",[190,1705,1706,1709],{},[225,1707,1708],{},"Day 4:"," Run once with a real change. Confirm roster notification links to the run — not a pasted screenshot. Confirm an independent reader can open the run without the author.",[190,1711,1712,1715],{},[225,1713,1714],{},"Day 5:"," Clone to a second roster or region. Time it. Attempt a refused write. Confirm the system of record did not move.",[190,1717,1718],{},"Pass criteria: skip semantics, run page, roster notify, reuse, and one refused or unsigned write that did not land. Fail any one and you do not have loop engineering. You have a demo that will not survive the first quiet week.",[216,1720,1722],{"id":1721},"how-this-differs-from-harness-evaluation","How this differs from harness evaluation",[829,1724,1725,1742],{},[832,1726,1727],{},[835,1728,1729,1732,1735],{},[838,1730,1731],{},"Topic",[838,1733,1734],{},"Loop engineering (this page)",[838,1736,1737,1738,1741],{},"Agent harness (",[200,1739,1740],{"href":809},"sibling sheet",")",[845,1743,1744,1755,1766,1777,1788,1799],{},[835,1745,1746,1749,1752],{},[850,1747,1748],{},"Unit of buy",[850,1750,1751],{},"Standing order \u002F recipe",[850,1753,1754],{},"Interactive runtime",[835,1756,1757,1760,1763],{},[850,1758,1759],{},"Hero metric",[850,1761,1762],{},"Skipped vs processed runs",[850,1764,1765],{},"Refused writes \u002F replay",[835,1767,1768,1771,1774],{},[850,1769,1770],{},"Trigger surface",[850,1772,1773],{},"Several signal types",[850,1775,1776],{},"User goal \u002F chat",[835,1778,1779,1782,1785],{},[850,1780,1781],{},"Quiet success",[850,1783,1784],{},"No op recorded",[850,1786,1787],{},"Waiting on signer",[835,1789,1790,1793,1796],{},[850,1791,1792],{},"Reuse",[850,1794,1795],{},"Recipe library",[850,1797,1798],{},"Versioned harness + tools",[835,1800,1801,1804,1807],{},[850,1802,1803],{},"Model role",[850,1805,1806],{},"Optional, bounded step",[850,1808,1809],{},"Often central",[190,1811,1812,1813,1817,1818,1822],{},"You need both sheets if ",[200,1814,1816],{"href":1815},"four-pillars-of-an-enterprise-ai-platform","the four pillars"," describe your stack — Automate (loops) plus Collaboration (agents on workstreams) under governance. ",[200,1819,1821],{"href":1820},"loop-engineering-vs-harness-engineering","Loop engineering vs harness engineering"," explains the crafts. This page and the harness page are how you buy them separately.",[190,1824,1825,1829],{},[200,1826,1828],{"href":1827},"loop-vs-rpa","Loop vs RPA"," is the adjacent comparison if incumbents sell bots. Do not let an RPA success-email farm satisfy test 1. “The script finished” is not a skipped run.",[216,1831,1833],{"id":1832},"department-lenses","Department lenses",[190,1835,1836],{},"Use the same eight tests. Change the job you bring to the POV.",[190,1838,1839,1842,1843,586],{},[225,1840,1841],{},"Finance"," — scheduled close packs, parameterised journals, controller on the roster. Skip on a week with no exceptions. See ",[200,1844,1846],{"href":1845},"loops-for-finance-and-planning","loops for finance and planning",[190,1848,1849,1852,1853,586],{},[225,1850,1851],{},"RevOps"," — stage-triggered hygiene, skip when fields are unchanged, notify the people who own the stage definition. See ",[200,1854,1856],{"href":1855},"loops-for-revenue-operations","loops for revenue operations",[190,1858,1859,1861,1862,586],{},[225,1860,64],{}," — inbound redlines, notify counsel, no send without a workflow gate. The loop starts the job; the workflow owns the stop. See ",[200,1863,1865],{"href":1864},"loops-for-legal-and-compliance","loops for legal and compliance",[190,1867,1868,1869,569,1873,1875,1876,1880],{},"Related reading: ",[200,1870,1872],{"href":1871},"what-is-collaborative-ai","what is collaborative AI",[200,1874,1492],{"href":1491},", and ",[200,1877,1879],{"href":1878},"what-is-an-enterprise-ai-operating-system","what is an enterprise AI operating system"," when you need the kernel metaphor rather than the RFP sheet.",[216,1882,1884],{"id":1883},"how-this-shows-up-in-nimbus","How this shows up in Nimbus",[190,1886,1887,1888,1890,1891,1894],{},"Nimbus Loops are one implementation of the standing-order object this sheet scores: triggers, recipes, run pages, roster notify, and ",[200,1889,640],{"href":40}," gates on a ",[200,1892,1893],{"href":32},"workstream",". You can run the eight tests there. You should also run them on whoever else claims “unattended agents” or “intelligent automation.”",[190,1896,1897],{},"Nimbus is not loop engineering. Loop engineering is whether your organisation can compile repeat work, skip quietly, and leave a record a second person can open. The product should make those tests boring. If a Nimbus demo — or any demo — cannot show ten skipped runs and one refused write, treat it as a copilot evaluation and score it on the harness sheet instead.",[1899,1900,1901],"style",{},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":171,"searchDepth":172,"depth":172,"links":1903},[1904,1905,1915,1916,1917,1918,1919],{"id":1308,"depth":172,"text":1309},{"id":1385,"depth":172,"text":1386,"children":1906},[1907,1908,1909,1910,1911,1912,1913,1914],{"id":1424,"depth":1206,"text":1425},{"id":1454,"depth":1206,"text":1455},{"id":1473,"depth":1206,"text":1474},{"id":1504,"depth":1206,"text":1505},{"id":1531,"depth":1206,"text":1532},{"id":1564,"depth":1206,"text":1565},{"id":1591,"depth":1206,"text":1592},{"id":1612,"depth":1206,"text":1613},{"id":1644,"depth":172,"text":1645},{"id":1687,"depth":172,"text":1688},{"id":1721,"depth":172,"text":1722},{"id":1832,"depth":172,"text":1833},{"id":1883,"depth":172,"text":1884},"2026-09-12","Evaluating loop engineering means asking whether standing orders can skip quietly, record outcomes on a run page, parameterise a write without a model, pause, notify the roster, and reuse a recipe without copying the old Slack channel.",{"eyebrow":1923,"title":1924},"Common questions","RFP tests for standing orders",[1926,1929,1932,1935],{"question":1927,"answer":1928},"Is this the same checklist as evaluating an agent harness?","Sibling, not duplicate, and scoring them on one sheet is how you buy a model for a Monday cron job. [How to evaluate an agent harness](how-to-evaluate-an-agent-harness) scores the interactive runtime — stops, replay, sensors around agents. This page scores standing orders — triggers, skip semantics, run pages, recipe reuse. Use both if you run agents and loops on the same roster. Use only this page if the job is unattended repeat work with a known path. Refuse a vendor that answers harness questions with a skipped-run demo, or loop questions with a fluent chat. They are different objects and they fail differently.",{"question":1930,"answer":1931},"What is the fastest proof-of-value test?","Run the same standing order ten times with empty or unchanged inputs. You should get ten run pages marked skipped — and zero spurious writes or alert storms. Then run once with a real change and confirm the roster was notified with a link to the run, not a pasted screenshot. Do this on a job the team already watches, not on a synthetic demo the vendor prepared. Refuse a POV that only shows a beautiful summary of a file. That is a copilot test. It tells you nothing about whether Tuesday’s close exists as an object when the author is out.",{"question":1933,"answer":1934},"Do we need a model in every loop?","No, and a vendor that cannot show a loop without one is selling inference, not loop engineering. Many standing orders are deterministic — compare, route, notify, quote a write for sign. Ask for a parameterised write path that does not call a model. If everything routes through chat, you are scoring a copilot. Use a model step when the input is messy and the rest of the recipe is known. Refuse a design that puts a language model in the path of a fixed journal template. You will pay twice: tokens, and the day the model invents an account code.",{"question":1936,"answer":1937},"What should we refuse even if the demo is fluent?","Refuse outcomes that live only in transcripts, and refuse “success” on empty inputs that still pages Finance. Refuse reuse that means finding last quarter’s thread, and refuse a write that cannot be shown with the model disabled. Refuse a pause that kills state, and refuse notifications that go to a copied channel rather than a roster you can edit. NIST’s AI Risk Management Framework assumes you can observe outcomes and then manage them. If you cannot export a month of skipped runs without a professional-services ticket, you cannot Measure — and you should not buy.","\u002Fblog\u002Fhow-to-evaluate-loop-engineering",{"title":1225,"description":1921},"blog\u002Fhow-to-evaluate-loop-engineering",[1942,444,1943,1944],"loops","RFP","automation","0qwQuy9uhlMrnUTMza--HZ1qmoRcv2zODPJJZ7ggXZE",{"enabled":165,"message":1947,"linkLabel":79,"linkHref":80,"id":1948,"title":1949,"archived":165,"authors":166,"badge":166,"body":1950,"date":166,"definedTerm":166,"department":166,"description":171,"extension":174,"eyebrow":166,"faqHeader":166,"faqs":166,"footerBand":166,"headline":166,"image":166,"industry":166,"jobType":166,"listed":131,"location":166,"navigation":131,"openRoles":166,"pageLayout":166,"path":1954,"relatedHeading":166,"seo":1955,"series":166,"sitemap":165,"status":166,"stem":1956,"subhead":166,"tags":166,"video":166,"whyJoin":166,"workplaceType":166,"__hash__":1957},"We're hiring! Join the team building the Sentient Enterprise.","content\u002Fshared\u002Fhiring.md","Hiring banner",{"type":168,"value":1951,"toc":1952},[],{"title":171,"searchDepth":172,"depth":172,"links":1953},[],"\u002Fshared\u002Fhiring",{"title":1949,"description":171},"shared\u002Fhiring","1zs3boivKda1e-b-hAyuNcmZSKjZUAXmecnwHVgcHzk",{"fold":1959,"id":1963,"title":1964,"archived":165,"authors":166,"badge":166,"body":1965,"date":166,"definedTerm":166,"department":166,"description":171,"extension":174,"eyebrow":166,"faqHeader":166,"faqs":166,"footerBand":1969,"headline":166,"image":166,"industry":166,"jobType":166,"listed":131,"location":166,"navigation":131,"openRoles":166,"pageLayout":166,"path":1973,"relatedHeading":166,"seo":1974,"series":166,"sitemap":165,"status":166,"stem":1975,"subhead":166,"tags":166,"video":166,"whyJoin":166,"workplaceType":166,"__hash__":1976},{"headline":1960,"description":1961,"primaryLabel":8,"primaryTo":1962,"secondaryLabel":466,"secondaryTo":12},"Run frontier AI your business actually owns.","Governed agent swarms, 2,000+ integrations, and a knowledge graph that stays inside your walls. Start on Free.","\u002Fsignup?plan=free","content\u002Fshared\u002Fcta.md","Site CTAs",{"type":168,"value":1966,"toc":1967},[],{"title":171,"searchDepth":172,"depth":172,"links":1968},[],{"headline":1970,"description":1971,"primaryLabel":8,"primaryTo":1962,"secondaryLabel":1972,"secondaryTo":85},"See what governed AI looks like on your stack.","Connect your tools, run a workstream, and keep every decision on your ledger. Start on Free.","Talk to our team","\u002Fshared\u002Fcta",{"title":1964,"description":171},"shared\u002Fcta","PS2VPJsszmUpMBZT6nEp8cWXCdeiN6zDRl-p8d0uY2k",1790215701468]