Augments LabsAugments ADK

Agent Harness vs Agent Governance

The Core Distinction

The difference is not about scale or automation. It is about mindset.

Agent harness is reactive. It assumes agents will misbehave and the developer's job is to catch it. Every guardrail, every HITL gate, every usage limit is a response to a potential failure. The question is always: what can go wrong, and how do I stop it?

Agent governance is proactive. It defines how things should work and makes the correct behavior the default β€” or the only option. The question is: here is exactly how we do things here.

The difference is subtle but changes everything:

Harness (Reactive)Governance (Proactive)
Mindset"What you can't do""Here is how we do things here"
MechanismCatch violations after they happenMake violations impossible by design
ScalingLinear β€” more agents = more things to watchSublinear β€” define policy once, all agents comply
Developer burdenExhausting β€” constant monitoringSustainable β€” system enforces correctness
AnalogySecurity guard checking every personBuilding codes that make unsafe construction impossible

The Kubernetes Lesson

Kubernetes scales insanely well because of one principle: declarative desired state with automatic reconciliation.

You never say "start 3 pods." You say "I want 3 replicas of this service." The system continuously reconciles actual state to desired state. You sleep at night because the SYSTEM governs, not you.

K8s ConceptWhat it doesAgent Governance Equivalent
Deployment specDeclares desired stateAgent policy β€” "this agent responds in under 200 words, cites sources, uses professional tone"
ControllerWatches actual state, reconciles to desiredRunner β€” observes agent behavior, enforces policy
ResourceQuotaMakes overspending impossibleBudget β€” sub-agent can use max 10K tokens
LimitRangeDefault resource bounds for all podsFleet defaults β€” every sub-agent gets 30s timeout
NetworkPolicyDefines which pods can communicateDelegation policy β€” which agents can delegate to which
Admission ControllerShapes requests before they enter the systemPolicy injection β€” not catching bad output, but shaping correct input
Labels + SelectorsGrouping and targetingAgent metadata β€” description, tags, routing

The key insight: K8s ResourceQuota doesn't catch overspending β€” it makes overspending impossible. K8s NetworkPolicy doesn't monitor unauthorized traffic β€” it prevents it from being routed. This is governance by design, not governance by detection.


How the ADK Provides Both

The Augments Agents ADK supports both harness and governance. Both are needed β€” governance is the primary mechanism, harness is the safety net. Like Kubernetes has both admission controllers (proactive) and liveness probes (reactive).

Governance Features (Proactive)

These define the correct behavior upfront. Agents follow them by design.

PrimitiveWhereWhat it prescribes
SystemPrompt / DynamicSystemPromptAgent.system_promptAgent behavior, tone, constraints, operating procedures. The primary governance mechanism.
Agent.descriptionAgent.descriptionWhat this agent does β€” flows to as_tool() and handoffs. Tells the supervisor LLM exactly when to delegate.
Agent.output_schemaAgent.output_schemaDefines what correct output looks like. Not a validation β€” a structural requirement. The LLM produces this shape or nothing.
ToolUseBehaviorAgent.tool_use_behaviorDefines what happens after tool execution. "stop_on_first_tool" means the tool result IS the output β€” no LLM rewrite.
HandoffConfig.strategyHandoff.configDefines exactly what context flows to the next agent. "intent_only" means the target gets only the intent, not the full conversation.
as_tool(budget=...)Agent.as_tool()Resource allocation per delegation. Not a limit that catches overspending β€” a budget that makes overspending impossible.
as_tool(timeout=...)Agent.as_tool()Time allocation per delegation. The sub-agent run is bounded by asyncio.wait_for().

Harness Features (Reactive)

These catch problems that slip past governance. The safety net, not the primary mechanism.

PrimitiveWhereWhat it catches
AgentInputGuardrailAgent.input_guardrailsBad input that the system prompt alone can't prevent. PII leaks, jailbreaks, off-topic requests.
AgentOutputGuardrailAgent.output_guardrailsBad output that the output schema can't enforce. Content policy violations, hallucinated data.
requires_approvalFunctionToolDangerous tool calls that need human judgment. A reactive gate β€” the agent already decided to act.
LLMUsageLimitsRunConfig.usage_limitsToken/request overspend. A hard cap when budget-by-design isn't sufficient.
max_turns / max_total_turnsRunner / RunConfigInfinite loops. A circuit breaker when the agent can't converge.
FunctionTool.max_retriesFunctionToolBroken tools. Removes a failing tool from the LLM's view after N failures.
RunHooksRunner.arun(hooks=...)Observability β€” what agents are doing, when, at what cost. Needed when governance isn't enough and you need to debug.

Why Both Matter

Governance without harness is naive β€” even well-designed systems have edge cases. System prompts can be circumvented. Output schemas can be satisfied with garbage. Budgets can be consumed on useless work.

Harness without governance is exhausting β€” you're constantly reacting to problems instead of preventing them. Every new agent means more guardrails to write, more HITL gates to configure, more dashboards to watch.

The right architecture: Governance handles the 95% case by making correct behavior the default. Harness handles the 5% where governance alone isn't sufficient.


Feature Classification

Every ADK primitive classified by its role:

ADK PrimitiveGovernance (Proactive)Harness (Reactive)Notes
SystemPromptYesPrimary governance. Defines behavior, tone, SOPs.
DynamicSystemPromptYesContext-aware governance. Runtime policy adaptation.
Agent.descriptionYesRouting signal for supervisor LLMs.
Agent.output_schemaYesStructural output requirement.
ToolUseBehaviorYesPost-tool execution policy.
HandoffConfigYesContext transfer policy.
as_tool(budget=...)YesResource allocation per delegation.
as_tool(timeout=...)YesTime allocation per delegation.
FunctionTool.max_result_tokensYesOutput size policy.
AgentInputGuardrailYesCatches bad input.
AgentOutputGuardrailYesCatches bad output.
requires_approval (HITL)YesHuman gate on dangerous actions.
LLMUsageLimitsYesHard cap on token spend.
max_turns / max_total_turnsYesLoop circuit breaker.
FunctionTool.max_retriesYesBroken tool circuit breaker.
RunHooksYesObservability for debugging.
Context compactionYesReactive context overflow management.
can_use_toolYesYesBoth: defines access policy (governance) and enforces it (harness).

Summary

LayerQuestionScalesWhen to use
Governance"How should this agent behave?"SublinearlyAlways. The primary mechanism.
Harness"What if governance isn't enough?"LinearlyWhen you need a safety net for edge cases.

Start with governance. Add harness where governance alone is insufficient. Never rely on harness alone β€” it is exhausting at scale and assumes failure rather than preventing it.