Rational RootToronto

Fundamentals

What is a harness?

Why the same underlying intelligence behaves completely differently in different products — and why that difference, not the model, is what your governance actually cares about.

Reading

6 min
For anyone choosing AI tools

The model is not the product

Every AI product you can install is really two things. Underneath sits the model — the engine that reads, reasons and writes. Around it sits the harness — the application built around that engine: the window you type into, the sign-in it uses, the files and systems it is allowed to touch, the tools it can operate, and the guardrails and audit trail wrapped around all of it.

Harness is the industry's word for that outer layer, and it is where most of the real product competition is currently happening.

The engine and car analogy holds up well. Several manufacturers buy comparable engines, but the vehicles built around them differ enormously — and the vehicle is what you actually drive, insure, and let onto your property.

The four things a harness decides

IdentityWhose account the AI is signed in as.
AccessWhich files and systems it may see.
ToolsWhat it can actually do, from drafting a document to running a multi-step job.
AuditWhat your governance can review afterwards.
When two AI products seem to have different capabilities, it is almost never a difference in intelligence. It is a difference in what the harness permits.

The harnesses you will hear about

Microsoft 365 CopilotTenant-native. Lives inside Word, Excel, Outlook and Teams, grounded in your Microsoft 365 tenant through Graph. It sees exactly what the signed-in account sees and no more, which gives it the strongest built-in governance story. The trade-off is that it is bound to one tenant per sign-in.
ClaudeConnector-first and agentic. Chat and projects alongside genuine work on real files and folders. Connects to Microsoft 365 through Entra app registrations with admin-consented, scoped permissions, and can hold connections to more than one tenant side by side.
ChatGPTChat-first. A polished chat and voice application with connectors and agent features of its own. Its account model is built around one organization at a time, which becomes brittle in multi-entity setups.

Why this is a governance question

If you take one thing from this: the question can our AI reach that folder is not a question about how clever the model is. It is a question about identity and consent — which account it runs as, and what an administrator has permitted that account to do.

That makes harness selection a policy decision with a technical implementation, rather than a technical decision with policy consequences. It belongs in the same conversation as your access standards, not in a separate one about tooling.

Start here

One hour. Five hundred dollars.

The smallest commitment that still leaves you with something durable — whether or not there is ever a second conversation.