Guide

Regulated Agent Harness Architecture

A practical architecture for agent authority, tool and data scope, pre-action policy, validation, human escalation, monitoring and evidence.

For financial-services platform architects, AI risk leads and security teams.

Last updated: Sep 7, 2026 · Version v1.0 · Not legal advice.

Short answer

A regulated-agent harness connects an agent’s proposed action to explicit authority, bounded access, policy evaluation, validation and human escalation, then records the execution outcome. KLA’s reference architecture organizes that work into seven controls.

Architecture

The action path

Business owner grants authority → agent proposes action → identity and scope checks → pre-action policy → validation or human decision where required → controlled execution → outcome and evidence.

Apply the sequence to each consequential action. Establish network and credential boundaries around it, and send operational failures to the monitoring and remediation process.

Control map

Seven controls and their owners

KLA’s product mapping below describes relevant surfaces. The acceptance column is a deployment test to perform; it does not assert estate-wide enforcement or completed customer verification.

ControlKLA mappingAccountable ownerAcceptance test
AuthorityAgent Registry; governed request identityPlatform and business ownerUnrecognized or out-of-scope agent cannot perform the action
Tool and data scopeTool Catalog; Data BoundariesPlatform and data ownerRestricted tool, record and tenant requests are rejected
Pre-action policyPolicy Builder; KLA Policy EnginePolicy ownerExercise allow, warn, require_approval and block on the integrated path
ValidationSimulation; workflow-specific checksIndependent reviewerInvalid output and unsafe state transitions fail before release
Human escalationDecision DeskAuthorized decision ownerRejection and expiry prevent the approved-action path from executing
MonitoringAssurance Center; Lineage ExplorerOperations and securityA control failure becomes an owned finding with a response
EvidenceAudit Trail; Evidence RoomEvidence and records ownerReconstruct request, decision, human review and actual execution outcome
Integration

Define the enforcement boundary

List every tool endpoint, credential, data source and delegated agent that can cause the selected action. Route the governed action through the checkpoint and test alternate paths. Record any path that remains outside enforcement.

The host environment owns sandboxing, network isolation and production access. An approval must apply to the concrete action and remain valid at execution; specify behavior when parameters, policy or authority change.

Acceptance

Review one case end to end

Use a synthetic case with a permitted read, an action requiring approval and a blocked operation. Check downstream state after approval, rejection, expiry and retry. Record identifiers, policy version, reviewer identity and result.

For sealed exports, also run the independent verifier and retain its result. A visible record and a successfully verified bundle provide different evidence; label each accurately.

Context

Source and interpretation

This is KLA’s architecture proposal, informed by the Bank of England’s harness note. Its seven controls are KLA’s grouping. The accompanying article explains the Bank’s six themes and the note’s scope.

FAQ

Questions buyers should resolve

Does a harness replace model evaluation?

Model evaluation remains part of system validation. A harness also needs tests of authority, access, action execution, human decisions and operating failures.

What does KLA control in this architecture?

KLA contributes policy, human decisions and evidence for configured governed paths. Verify integration coverage and separately assign hosting, network, credential and system-level assessment responsibilities.

Links

Related links

AI Act standards: agent control mapping

/guides/ai-act-standards-agent-control-mapping

Open

Bank of England harness engineering analysis

/blog/bank-of-england-ai-harness-engineering

Open

Preparing agent controls for EU AI Act standards

/blog/eu-ai-act-standards-agent-controls

Open

SAFR runtime framework

/blog/safr-mas-framework-explained

Open

Discuss your agent control architecture

/book-demo

Open
Regulated Agent Harness Architecture | KLA