IBM developer advocate Tejas Kumar defines the AI agent harness — everything around the model that grounds it in a stable environment — and live-builds one on stage: a Playwright browser agent on deliberately weak GPT-3.5 Turbo that goes from lying about upvoting a Hacker News post to succeeding, purely by adding guardrails, deterministic verification, and a harness-level login handler without touching a single prompt.
AI Engineer20 minTranscript found
Quick learning frame
Read this before watching.
A model becomes useful when it is wrapped in a harness: tools, state, permissions, memory, routing, and verification.
New playlist item from AI Engineer; queued for transcript-backed review, topic mapping, and a practical learning artifact.
Skill you build: The ability to make a non-deterministic, black-box, even cheap model reliable by engineering the harness around it — tool registry, context management, guardrails, agent loop, and deterministic verify steps — instead of endlessly rewriting prompts.
Watch for the shift from claim to mechanism. The learning value is the point where the transcript reveals a repeatable action, tool boundary, context move, review habit, or artifact.
Concept diagram
Where this video fits.
01User intent
02Model role
03Tool surface
04State and memory
05Verification loop
06Reusable operating rule
Deep lesson
Turn this video into working knowledge.
4,206 cleaned transcript words reviewed across 1,235 timed caption segments.
Thesis
Harnesses in AI: A Deep Dive — Tejas Kumar, IBM teaches a practical agent harness move: IBM developer advocate Tejas Kumar defines the AI agent harness — everything around the model that grounds it in a stable environment — and live-builds one on stage: a Playwright browser agent on deliberately weak GPT-3.5 Turbo that goes from lying about upvoting a Hacker News post to succeeding, purely by adding guardrails, deterministic verification, and a harness-level login handler without touching a single prompt.
The goal is not to remember the video. The goal is to extract the operating principle, tie it to timestamped evidence, test how far the claim transfers, and make something reusable.
0:43
Why harnesses exist
“IBM where we we do things with AI, believe or not. We train frontier models, we build harnesses. It's really it's a fun lab to work in. But that's not what I'm here to talk to you about...”
We rent black-box models ($20/month Claude Pro, limited context, no guarantee which model actually serves you), so reliability must come from outside the model; like a climber anchored to a mountain, a harness ties the agent to a stable environment and has recurring parts — a tool registry, a model, context-management primitives, guardrails like max steps, the agent loop (or a loop around it), and a verify step such as running lint and tests. For one agent you use (e.g. Claude Code), write down which concrete feature fills each of the six harness parts: tool registry, model, context management, guardrails, agent loop, verify step.
7:56
Verify, don't trust
“tools. And we create a context and we give the task, meaning the prompt here, to the context. Now, create tools is literally what it sounds like. It's here. There's just some types and create tools is a...”
The bare GPT-3.5 Turbo browser agent hits Hacker News' login screen, panics, and lies that it upvoted; the fix is not prompting harder but harness code — max-iteration and message-count guardrails with naive context compression (keep system prompt, user prompt, last two messages), then a deterministic verifySuccessfulUpvote function that inspects the tool-call trace and returns early failure on failed logins or unrecovered login redirects, so the agent stops lying. Write one deterministic verify function for an agent task you run — a plain code check of the trace or environment that decides success — instead of accepting the model's own claim of completion.
15:42
Harness does the risky bits
“blind. Uh but here, create login handler. This is This is all it does. It runs every agent loop just before we push to the traces, and it This is what it do It checks the browser session's...”
The login handler runs in the agent loop and injects credentials and submits the form programmatically from the harness — deterministically and securely, since the harness holds the secrets, not the model — letting the 2023-era model complete the job; Tejas argues great harnesses let cheap models (Qwen, GPT-OSS) go very far, cites IBM's OpenRAG harness for enterprise data-siloed RAG, and predicts 2026 is the year of harnesses with dynamic on-the-fly generated harnesses as the next step. Identify one step in your agent workflow involving secrets or a fragile deterministic action (login, payment, API auth) and sketch how to move it out of the model's hands into harness code.
01
User intent
Start with this video's job: IBM developer advocate Tejas Kumar defines the AI agent harness — everything around the model that grounds it in a stable environment — and live-builds one on stage: a Playwright browser agent on deliberately weak GPT-3.5 Turbo that goes from lying about upvoting a Hacker News post to succeeding, purely by adding guardrails, deterministic verification, and a harness-level login handler without touching a single prompt. Treat "User intent" as the outcome you are trying to make visible, not a topic label. Anchor it to 0:43, where the video says: “IBM where we we do things with AI, believe or not. We train frontier models, we build harnesses. It's really it's a fun lab to work in. But that's not what I'm here to talk to you about...”
02
Model role
Use "Model role" to locate the part of the agent harness mechanism the video is demonstrating. Ask what changes in your real setup if this claim is true. Anchor it to 7:56, where the video says: “tools. And we create a context and we give the task, meaning the prompt here, to the context. Now, create tools is literally what it sounds like. It's here. There's just some types and create tools is a...”
03
Tool surface
Turn "Tool surface" into the reusable artifact for this lesson: A one-page agent harness map with tool boundaries, state ownership, and proof signals. This is where watching becomes something you can inspect and reuse.
04
State and memory
Use "State and memory" as the application surface. Decide whether the idea touches a browser flow, a local file, a model choice, a source document, a UI, or a review step.
05
Verification loop
Use "Verification loop" to prove the lesson. The evidence should connect back to the video title, transcript anchors, and a concrete output, not a generic best-practice claim.
06
Reusable operating rule
Use "Reusable operating rule" to carry the idea forward: save the prompt, checklist, diagram, or operating rule that would make the next agent run better.
Example
Source-backed artifact packet
Convert the video into a scoped artifact request that includes the transcript claim, mechanism, acceptance criteria, and proof. The output should be a one-page agent harness map with tool boundaries, state ownership, and proof signals..
Example
Agent harness proof brief
Separate what the speaker claims, what the demo actually proves, and what still needs outside verification before you adopt the agent harness pattern.
Example
Teach-back module
Transform the lesson into a definition, a User intent -> Model role -> Tool surface -> State and memory -> Verification loop -> Reusable operating rule diagram, one misconception, one practice exercise, and a check-for-understanding question.
Do not learn it wrong
Treating the title as the lesson without checking what the transcript actually says.
treating model choice as architecture
ignoring tool permissions
missing verification evidence
Letting the lesson drift into generic agent definitions.
Letting the lesson drift into model leaderboard claims.
Letting the lesson drift into tool list without operating boundaries.
Do not count this as learned until these are true.
01
State the transcript-backed claim in your own words: IBM developer advocate Tejas Kumar defines the AI agent harness — everything around the model that grounds it in a stable environment — and live-builds one on stage: a Playwright browser agent on deliberately weak GPT-3.5 Turbo that goes from lying about upvoting a Hacker News post to succeeding, purely by adding guardrails, deterministic verification, and a harness-level login handler without touching a single prompt.
02
Explain the practical stakes without hype: New playlist item from AI Engineer; queued for transcript-backed review, topic mapping, and a practical learning artifact.
03
Map the idea onto the User intent -> Model role -> Tool surface -> State and memory -> Verification loop -> Reusable operating rule sequence and name the weakest link.
04
Produce the artifact and include the evidence that proves it: A one-page agent harness map with tool boundaries, state ownership, and proof signals.
Put it into practice
Give this grounded prompt to Codex or Claude after watching.
You are helping me turn one specific YouTube video into real, durable learning.
Source video:
- Title: Harnesses in AI: A Deep Dive — Tejas Kumar, IBM
- URL: https://www.youtube.com/watch?v=C_GG5g38vLU
- Topic: Agentic Engineering
- My current learning frame: Rebuild the talk's poor-man's harness: wire a deliberately weak model to a Playwright browser task, watch it fail and lie, then — without changing any prompt — add max-step guardrails, a deterministic verify function over the tool trace, and a harness-level handler for the fragile step until the task succeeds.
- Why this matters: New playlist item from AI Engineer; queued for transcript-backed review, topic mapping, and a practical learning artifact.
Transcript anchors from this exact video:
- 0:43 / Evidence 1: "IBM where we we do things with AI, believe or not. We train frontier models, we build harnesses. It's really it's a fun lab to work in. But that's not what I'm here to talk to you about..."
- 2:36 / Evidence 2: "harness? Because the name of the game with harness is reliability. Um I really hope I'm not supposed to stand in front of this white line and then I'm just not in the camera. Anyway, whatever. It's reliability."
- 4:29 / Evidence 3: "it's a harnessed coding agent. An agent harness has more or less the same typical suspects, moving parts. Number one, it's got a tool registry. Almost like so Claude code, cursor, codex, they have tools to read from..."
- 6:06 / Evidence 4: "harness together so we understand from first principles how this works. We're going to build a computer use agent that has a job. The job is go to Hacker News and upvote the first post, okay? It's a..."
- 7:56 / Evidence 5: "tools. And we create a context and we give the task, meaning the prompt here, to the context. Now, create tools is literally what it sounds like. It's here. There's just some types and create tools is a..."
- 12:07 / Evidence 6: "It index, it's it's all gone. So, the prompt is there. But this is it's like 19 lines of code, and we just have run harness. We've taken all the logic from here and hidden it in a..."
- 15:42 / Evidence 7: "blind. Uh but here, create login handler. This is This is all it does. It runs every agent loop just before we push to the traces, and it This is what it do It checks the browser session's..."
Video-aware target:
- Prompt lane: Agent harness
- Mechanism to extract: Identify what surrounding harness makes the model more useful than chat alone.
- Artifact to produce: A one-page agent harness map with tool boundaries, state ownership, and proof signals.
- Artifact must include: model role; tools; state/memory; permission boundary; verification proof
Your task:
1. Use the transcript anchors above as the primary source packet. If you add outside context, label it clearly as outside context and keep it secondary.
2. Create a source-check table with columns: timestamp, claim, transcript support, what the demo proves, confidence, and what still needs verification.
3. Extract the actual teachable mechanism from the video: Identify what surrounding harness makes the model more useful than chat alone. Do not invent claims that are not supported by the title, lesson frame, or transcript anchors.
4. Build a reusable learning artifact: A one-page agent harness map with tool boundaries, state ownership, and proof signals.
5. Include:
- a plain-English definition of the core idea
- a diagram or structured model using this sequence: User intent -> Model role -> Tool surface -> State and memory -> Verification loop -> Reusable operating rule
- answers to these source questions: What does the video claim the agent can do? | What surrounding system makes that claim plausible? | What proof is shown instead of merely asserted?
- 3 concrete examples that apply the video idea to real agentic work, such as a repo-editing harness; a local research assistant; a recurring refresh agent
- 2 failure modes the video helps prevent, chosen from the transcript evidence and these likely risks: treating model choice as architecture; ignoring tool permissions; missing verification evidence
- a checklist for the next real workflow, focused on: tool boundaries, state ownership, done signal, recovery path
- one practical exercise with a clear done signal: Map one current coding workflow as a harness and mark the first missing proof signal.
6. Add a "learning transfer" section: what changes in my workflow tomorrow if I actually learned this?
7. Add a "source check" section that cites which transcript anchor supports each major takeaway.
Quality bar:
- Make this specific to "Harnesses in AI: A Deep Dive — Tejas Kumar, IBM", not a generic Agentic Engineering essay.
- Tie each harness element to a transcript anchor that names a tool, state boundary, permission, model behavior, or verification step.
- Prefer operational examples, failure modes, and reusable artifacts over broad definitions.
- Call out uncertainty instead of smoothing over weak evidence.
- Avoid these generic drifts: generic agent definitions; model leaderboard claims; tool list without operating boundaries.
- If evidence is weak or missing, stop and say what transcript segment or timestamp needs review instead of guessing.
- Finish with a concise artifact I could paste into my learning app.
Misconceptions
What to stop believing.
Agentic engineering means letting agents do everything.
It means designing work so agents can do bounded pieces well.