# Harness engineering — companion artifacts

Companion files for [Harness engineering for production AI agents](https://www.factualminds.com/blog/harness-engineering-production-ai-agents-2026/).

**Public URL prefix:** `https://www.factualminds.com/examples/architecture-blog-2026/harness-engineering/`

Checked **11 October 2026**. These files are a custom application policy and syntax-checkable sketches. They are not a deployed stack, not a client engagement, and not measured savings.

## Run the policy check

```bash
python3 -m py_compile harness_policy.py agentcore_invoke_sketch.py strands_harness_sketch.py
python3 harness_policy.py
DRY_RUN=1 python3 agentcore_invoke_sketch.py
```

`harness_policy.py` prints:

```text
task:codemod-retry-copy
approval:blocked
retry:reconcile_before_retry
verify_fail:missing_check:typecheck,path_outside_scope:package.json
verify_ok:pass
```

`agentcore_invoke_sketch.py` prints the `invoke_harness` payload and does not call AWS while `DRY_RUN` is `1` (the default). `strands_harness_sketch.py` imports `strands_harness` only inside `build_research_agent()`, so compiling it does not need the package.

## Layout

| File | What it is |
| --- | --- |
| `application-policy.yaml` | Custom application policy. Not an AgentCore or Strands schema |
| `enforcement-map.md` | Which system actually enforces each field |
| `harness_policy.py` | Task contract, approval gate, retry rule, deterministic verify |
| `agentcore_invoke_sketch.py` | `CreateHarness` / `InvokeHarness` shape from the AWS docs |
| `strands_harness_sketch.py` | `create_harness()` shape from the Strands docs. Separate API |
| `diagrams/` | Editable diagrams.net sources for the four article figures |
| `monday-checklist.md` | Ship checks that are not prompt text |

## Do not mix the two sketches

`agentcore_invoke_sketch.py` talks to `bedrock-agentcore-control` and `bedrock-agentcore`. `strands_harness_sketch.py` calls `strands_harness.create_harness`. Same word, different products. Hosting a Strands process on AgentCore Runtime still does not grant Gateway, Identity, or Policy.
