Agent Harness vs Agent Framework vs MCP: Which Layer Owns the Loop, State, Tools, Permissions, and Recovery

| Source: MarkTechPost

Tags: MCP, Model Context Protocol, agent harness, LangGraph, Claude Code, agentic AI, OpenAI Agents SDK

A structured breakdown of three confusingly-conflated AI agent architecture layers: the harness (owns loop, sandboxing, permissions), the framework (provides composable primitives), and MCP (a wire protocol only). Includes an ownership matrix mapping six responsibilities across all three layers.

Details

The article addresses a persistent confusion in agent architecture discussions: harness, framework, and MCP are used interchangeably but occupy distinct layers with different ownership responsibilities. An agent harness — as defined by OpenAI's August 2026 Codex post and Anthropic's Claude Code docs — is an opinionated, product-grade execution system. It owns the full loop, manages conversation state across turns, enforces sandboxing, and handles checkpoint/resume. Anthropic explicitly states the Claude Agent SDK exposes 'the same tools, agent loop, and context management that power Claude Code.' Agent frameworks (LangGraph, OpenAI Agents SDK, Microsoft Agent Framework — which reached 1.0 GA in April 2026) provide composable primitives: model clients, tool abstractions, graph orchestration, memory interfaces. They own the loop skeleton but leave policy — turn limits, approval gates, handoffs — to the developer. MCP (Model Context Protocol) is purely a wire protocol using JSON-RPC 2.0 between hosts, clients, and servers. Governed by the Linux Foundation's Agentic AI Foundation since December 2025, it standardizes how an LLM application discovers and calls tools, but owns no loop logic or agent state whatsoever. The article maps six responsibilities (execution loop, state/memory, tool transport, permissions, recovery, sandboxing) across all three layers. Key insight: only the harness enforces permissions and recovery — the protocol layer cannot.