From Prompts to Contracts: Harness Engineering for Auditable Enterprise LLM Agents
Quick Answer
This paper introduces a harness-engineering approach for enterprise LLM applications, ensuring auditable behavior through deterministic code and validation artifacts.
Quick Take
Evaluated on five Korean corporate groups, the method demonstrated 100% compliance across 270 runs, effectively blocking internal trace leakage while maintaining full utility.
Key Points
- Harness-engineering transforms prototypes into auditable applications with versioned artifacts.
- Achieved 100% compliance across 270 runs with three different hosted models.
- Internal trace leakage violations were entirely blocked by the harness.
- A bolt-on guardrail reduced utility to 88/120, while the harness maintained 120/120.
- The approach is validated on a public dataset from five Korean corporate groups.
Paper Resources
📖 Reader Mode
~2 min readAbstract:Enterprise large language model (LLM) applications often begin as prototypes whose behavior is carried by prompts and retrieval context. Productization adds requirements for source boundaries, entity routing, answer contracts, and reproducible traces. We present a harness-engineering approach that reconstructs this pattern into a traceable, auditable LLM-agent architecture: deterministic behavior moves into code, manifests, schemas, and validation artifacts around a replaceable composition boundary, while source-backed claims remain the authority for runtime answers. We instantiate it on a public-data slice of five Korean corporate groups (25 listed companies) and evaluate three research questions. (1) The harness preserves its source-grounding, entity-routing, trace, output-hygiene, and recommendation-language contracts across the fixed validation scenarios; a fault-injection control confirms the validators flag deliberately broken contracts. (2) The checks the harness enforces held under model substitution: across three hosted models, they passed on all 270 composition-boundary runs; failures were confined to the model-composed side and were caught and recorded. (3) The code-owned guarantees are load-bearing, not reproducible by prompting alone: holding the model fixed and varying only the enforcement layer, prompt instructions alone let recommendation-language and internal-trace-leakage violations reach the reader, which the harness blocks entirely. A bolt-on external guardrail prevents such violations too but over-refuses, dropping utility to 88/120 where the harness preserves full utility (120/120); in this ablation, only code-owned enforcement preserves both safety and utility. The result is a reusable engineering pattern for turning exploratory prototypes into auditable applications with versioned source, control, and validation artifacts.
| Comments: | 32 pages, 6 figures, 16 tables. Reference implementation and evaluation artifacts: this https URL (archived at this https URL) |
| Subjects: | Artificial Intelligence (cs.AI); Computation and Language (cs.CL); Software Engineering (cs.SE) |
| ACM classes: | I.2.11; D.2.4; D.2.5 |
| Cite as: | arXiv:2607.08028 [cs.AI] |
| (or arXiv:2607.08028v1 [cs.AI] for this version) | |
| https://doi.org/10.48550/arXiv.2607.08028 arXiv-issued DOI via DataCite (pending registration) |
Submission history
From: Joongho Ahn [view email]
[v1]
Thu, 9 Jul 2026 01:08:33 UTC (1,155 KB)
— Originally published at arxiv.org
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from arXiv cs.AI
See more →HOBA: Hierarchical On-Policy Bidding Agents for Adaptive Online Advertising
HOBA (Hierarchical On-policy Bidding Agents) is a novel hierarchical reinforcement learning framework that enhances online advertising bidding systems by improving adaptability and reducing hyperparameter tuning costs. It utilizes a for hyperparameter inference, a SARSA agent for expert model selection, and a dynamic expert pool for bid execution, achieving a +3.6% increase in target cost during large-scale deployment and outperforming state-of-the-art baselines on AuctionNet.