Artificer Digital The Artificer's Grimoire

The Artificer's Grimoire

Weekly intelligence on harness engineering for agentic systems — a practitioner's field guide, by Tim Schiller (Artificer Digital).

Latest Edition

Artificer's Grimoire — Edition 21 · July 19, 2026

The wrapper around the agent — control plane, spend caps, harness, discovery layer — showed several signs of becoming first-class product and practice this week: AWS shipped a self-hosted governance gateway (Anthropic introduced the same one a week earlier), QCon and a ThoughtWorks retreat each gave harness engineering its own session, and the cost and security incidents kept making the case for all of it.

ai-governance harness-engineering sdd coding-agents agent-security

Read edition →

Latest Scout

19 sources

Scout: The Enforcement Point Moves Out of the Agent's Reach — the July 2026 Agent-Authorization Research Wave

A cluster of July 2026 research moving the authorization decision for agent tool calls outside the agent's own context — an off-host signing gateway (aiAuthZ), a kernel-resident governance layer (Governed MCP), execution-integrity manifests (CXI), and an action-graded severity scale — read as one practitioner map, alongside MCP Enterprise-Managed Authorization reaching stable

Teams running agents against real tools and data need to decide where the authorization decision for a consequential action lives. The July research converges on one answer — outside the agent's context, where attacker-writable input can't reach it — and the products are starting to ship it. Knowing which of these to adopt now (out-of-agent tool-call authorization, default-deny gateways, severity-graded evaluation) versus watch (cryptographic per-message receipts, kernel-resident governance) is the useful work.

Previous Editions