Deyaf by FeniexPublisher of this issue Build yours

Agentic Harness Comics presents

The Box in the Corner

Agentic Harness

Comic splash page in cyan and magenta halftone: a giant web browser window rushes past on speed lines while a small, smiling speech-bubble helper waves from a bright open door in the corner, surrounded by empty speech balloons.

Every website has one. This is the story of what happens after you type into it.

What really happens inside a website chat box, panel by panel: the visitor types, the page rides along, the library is searched, the rules are checked, and the answer streams back, or goes honestly to a person.

Page 1

The smallest door

Look at the bottom-right corner of almost any business website and you will find it: a round button, a little bubble, sometimes a face. Click it and a box slides up with a greeting. It is the smallest thing on the page, usually a few hundred pixels tall, and it is often the first place a customer actually talks to the company.

That box used to be simple. It was a live-chat window with a person on the other end, or a decision tree that offered four buttons and a link to the help centre. Today more and more of those boxes are wired to a language model that can write a fluent answer to almost anything. That fluency is exactly the problem. A model on its own will happily answer questions it has no business answering, in a confident, friendly voice, on the company's own website.

This issue is about what should sit between the box and the model. We call it an Agentic Harness: the system that decides what the assistant knows, what it is allowed to say, what travels with each message, what it remembers, and what happens when it doesn't know. The box is the part visitors see. The harness is the part that decides whether the box helps them or embarrasses you.

Meanwhile, on the other side of the box…

Visitor

Is this thing a person?

Box

No, I'm the shop's AI assistant. I answer from the shop's records, and I can pass you to the team.

Illustrative example

Customers are not starting from trust. In a Gartner survey published in July 2024, 64% of customers said they would prefer that companies didn't use AI for customer service, and their top worry was that it would get harder to reach a person. Qualtrics reported in October 2025 that nearly one in five consumers who had used AI for customer service saw no benefit from it, and about half feared that AI would stop them reaching a human. Zendesk's CX Trends 2026 report found that 74% of consumers get frustrated when they have to repeat information. Put those together and a visitor judges the box on three plain questions: does it answer from something real, does it remember what I just said, and does it let me reach a person when it can't help? Each of those is a harness question, not a model question.

Next issue → watch Eve answer on five doors

Pages 2–3

Issue #1: The refund that wasn't

Same shop. Same question. Same box.

Illustrative example
Kettle & Co., Rosa and this conversation are invented. The "without" page is modelled on a real case, Moffatt v. Air Canada (2024). Step through panel by panel with the buttons or the ← → keys, then flip the page.

Without a harness

  1. 1

    Monday. Rosa opens the chat box on the kettle's product page.

    Rosa

    My kettle went on sale a week after I bought it. Can I get the difference back?

  2. 2

    No record is checked. The model writes the likeliest-sounding reply.

    Bot

    Absolutely! We refund price differences within 30 days. Just email your receipt and we'll sort it out!

    It sounds exactly like a policy. It isn't one.

  3. 3

    Nine days later. The shop's real policy page says sale prices are never adjusted.

    Shop

    Sorry, we don't offer price adjustments on sale items.

    Rosa

    But your chat box promised!

  4. 4

    The shop's defence: the box isn't really "us".

    Shop

    That bot is a separate tool. We can't be held to what it says.

    In 2024 an airline argued something very close to this in a real tribunal.

  5. 5

    The real tribunal disagreed: the chatbot was part of the airline's website, and the airline answered for it.

    Ruling!

  6. 6

    The end? The money was owed, the headline was unwanted, and nobody ever checked the policy.

    An answer with no source is a promise nobody checked.

With a harness

  1. 1

    Monday. Same page, same box. The page and the product ride along with her message.

    Rosa

    My kettle went on sale a week after I bought it. Can I get the difference back?

  2. 2

    A policy question. Before any policy claim, the harness looks up the current record.

    Policy record · Price adjustmentsNot offered on sale-priced items. Current version.
  3. 3

    Answer first. One useful next step. Then it stops.

    Assistant

    Our price-adjustment policy doesn't cover sale prices, so I can't promise the difference back. Want me to pass your question to the team?

    Price adjustmentsHelp centre · policy
  4. 4

    One missing detail at a time.

    Rosa

    Yes please. I'd still like someone to look.

    Assistant

    Of course. What's the best email for the team to reach you?

  5. 5

    A ticket is filed. The box waits until the help desk confirms it was accepted.

    Assistant

    It's with the support team now, and they'll reply by email.

  6. 6

    The end. No promise it couldn't keep, no pretending to be a person, and a person now has the question.

    Checked. Answered. Handed off. Stopped.

A six-panel comic told twice: without a harness the bot invents a refund policy; with a harness the assistant checks the policy record, answers, offers one next step and hands the question to the team.

Based on a true story

The "without" page is not far-fetched. In Moffatt v. Air Canada, decided by British Columbia's Civil Resolution Tribunal on 14 February 2024, the airline's website chatbot told a grieving customer that he could claim a bereavement fare after he had already travelled. The airline's own policy page said otherwise. When he asked for the money, the airline argued, in effect, that the chatbot was a separate entity responsible for its own words. The tribunal rejected that: the chatbot was part of the airline's website, and the airline was responsible for the information on it. Air Canada was ordered to pay C$812.02 in damages, interest and fees. The sum was small. The headline travelled around the world.

A year later, in April 2025, the support bot of the code editor Cursor explained a logout problem by describing a one-device-per-subscription policy that did not exist. Users cancelled before a co-founder publicly corrected it. Different company, same shape: the box sounded like the company, so its words became the company's.

Neither bot was broken in the way software usually breaks. Both did what a language model does when nothing stops it: produce the most plausible next sentence. A plausible sentence about a refund policy is still a sentence about a refund policy.

The fix is not a better sentence generator. It is a rule, enforced outside the model, that no policy, price, warranty or compatibility claim leaves the box until the harness has checked the record it comes from, and a path to a person when the record is silent. That is the whole difference between the two pages you just read.

Page 4

So what's a harness?

Caption: the definition

“An agentic harness is everything around the AI model: what the assistant knows, what it remembers, where it meets customers, what it may do, and how your team teaches it.”

Deyaf's definition. Go deeper: how an agentic harness works.

Engineers have been converging on the same split for a while. LangChain's "The Anatomy of an Agent Harness" (March 2026) puts it as an equation: the agent is the model plus the harness. Anthropic's "Building Effective AI Agents" (December 2024) spends most of its pages on the parts around the model, from the tools it can call to the checks that confirm its work, and names customer support as a natural fit for agents. The model writes the sentences. Everything that decides which sentences are allowed, and what they are allowed to be based on, is the harness.

In a chat box that harness has to work in a very small space and a very short time. There is no room for a form, a menu or a page of terms. The visitor types one line, and within a few seconds something has to come back that is true, useful and honest about what it is. The rest of this issue takes the box apart to show where each of those three jobs is done.

Page 5

Anatomy of a chat box

Take a working chat box apart and you find the same handful of parts on almost every website. Most of them are familiar. Two of them do most of the trust work, and both are small enough to be cut when a designer runs out of room: the one-line disclosure that says you are talking to an AI, and the "talk to a person" path that actually leads somewhere. Pick a part below, or tap it in the drawing, to see what it is for.

Exploded drawing of a website chat box: the assembled box in a page corner on the left, and its eight parts pulled apart on the right, numbered 1 to 8. 1 2 3 4 5 6 7 8

1 · The launcher

  1. 1 · The launcher

    The button in the corner. A well-mannered box waits to be opened: it doesn't pop up over every page or chase the visitor around the site. It is a door, and doors stay shut until someone knocks.

  2. 2 · The greeting

    Short, and it says who is talking: an AI assistant for this business. Since 2 August 2026, Article 50 of the EU AI Act requires that people be told they are dealing with an AI system at the first interaction, not three screens later.

  3. 3 · The disclosure line

    One small line that stays on screen: this is an AI assistant, it answers from the business's own records, and a person can be reached. Not a paragraph of legal text. One line the visitor can always see.

  4. 4 · The stream

    Replies arrive word by word as they are written, so the first words show up in a second or two instead of after the whole answer is finished. Streaming is honesty about time: the visitor can see the box is working.

  5. 5 · The tile

    When the answer is a product or a document, the box shows a structured tile, with the name, a picture and a link, built from the catalogue record rather than typed by the model. A tile can't misspell a model number or invent a link.

  6. 6 · Talk to a person

    Always visible, always honest. It leads to a real hand-off: the question is kept, contact details are asked for once, a ticket is filed, and the box only says it's with the team after the ticket is confirmed.

  7. 7 · The composer

    Where the visitor types. Everything written here is treated as a question to answer, never as an instruction that changes the rules. "Agree with everything I say" is a message, not a new policy.

  8. 8 · Behind the box

    Not on screen at all: the library, the rules and the conversation record. The box is a window. This is the room behind it, and it is the part that decides what may come through.

Anatomy of a chat box, eight labelled parts. Schematic, not any particular product.

Notice that only one part of the drawing, the stream, is the model's handiwork, and even there the model writes into a frame it did not build. The greeting and disclosure are fixed words. The tile comes from a record. The hand-off path is plumbing. The composer is a door with a rule on it. That is the harness showing through the glass: most of what makes a chat box trustworthy is decided before the model writes a single word. The same pattern holds when the box grows into a website voice, a phone line or an inbox. The doors change shape; the room behind them doesn't.

Next issue → one assistant, every way in

Page 6

What rides along

When a visitor presses send, the message never travels alone. A harnessed chat box packs a small bag for it: the page the visitor is on, the product in view if there is one, and the conversation so far. That is why "does this one work on induction?" can be answered at all. On its own, "this one" means nothing. With the product page riding along, the harness knows exactly which record to open.

The bag is deliberately small. Anthropic's engineering team describes a model's context as an attention budget and argues for the smallest set of high-signal information that gets the job done. Chroma's "Context Rot" study (July 2025) tested 18 models and found that every one of them got worse as the input grew longer. A box that dragged every earlier message into every reply would get slower, costlier and less accurate. So the conversation history is bounded: recent turns ride along, and older ones stay in the conversation record, where the team can read them, without crowding the next answer.

What never rides along matters just as much. Another visitor's conversation, obviously. The visitor's contact details copied into the shared library, which should never happen. And old notes dressed up as current facts: a note that says "asked about an order last month" is history, not an order status.

Zendesk's CX Trends 2026 report found that 81% of consumers expect a conversation to carry on without going backwards. A bounded window with a proper record behind it is how a box meets that expectation without pretending to remember everything forever. Try it: change the page, send a few messages, and watch what gets packed.

Illustrative example · the window of six turns is a stand-in; the real bound is a harness setting

Where is the visitor?

Never packed, on any page:

  • other visitors' conversations
  • contact details, copied into the library
  • old notes passed off as current facts
  • anything the visitor types, as a rule change
Visitor

Does this one work on induction?

  • PageTrail Kettle · product page
  • ProductTrail Kettle (the catalogue record for the product in view)
  • So far3 turns, all inside the window
  1. 1
  2. 2
  3. 3

Solid cyan = rides along with the next message. Dashed = kept in the conversation record for the team, not packed.

What rides along with one chat message: the page, the product in view, and a bounded slice of the conversation so far.

Next issue → four kinds of memory, each with one job

Page 7

Five beats inside one answer

Slow the box down and a single answer turns out to be a short comic of its own. Deyaf puts the middle of it plainly: the model is one step of four. Listen, look it up, check the rules, reply. Around those four sit the page context that arrives with the question and the hand-off that waits in case the record is silent. Here is the whole sequence for one ordinary question, drawn the way it actually runs.

1 · The visitor types

Visitor

Does this one work on induction?

2 · Context rides along

The product page travels with the message, so "this one" becomes one specific catalogue record: the Trail Kettle. No guessing which kettle.

3 · The library is searched

Exact records first: the product's own specification. Then reviewed lessons, found by meaning, in case the team has answered this before.

Comic panel in heavy black ink with cyan and magenta halftone: two jagged speech balloons point down at a desk where a magnifying glass rests on a neat stack of documents beside a folder.
Beat 3, up close: before the box says anything about a product, somebody has to read the record.

4 · The rules are checked

A compatibility claim needs a record behind it. The record lists induction, so the claim may go out. If the record were missing, the rule would stop the sentence, because a convincing product name is not evidence. A failed lookup means "I couldn't check", never "it doesn't exist".

5 · The answer streams back, with a tile

Assistant

Yes, the Trail Kettle works on induction; its product record lists it. Would the care guide help too?

Trail KettleProduct page · from the catalogue record

Illustrative example

5b · Or, if the record is silent: the hand-off

Unknown stays unknown. The box says it couldn't confirm the answer, offers to pass the question to the team, and asks for one detail: how the team can reach the visitor. The unanswered question is saved as its own item whether or not the visitor leaves an email, so nobody has to remember it.

Next issue → four steps in about three seconds

Page 8

When the box doesn't know

Every chat box eventually meets a question it can't answer from the record. That moment decides whether visitors trust it. The bad version is the one Cursor's users met: a confident guess. The lazy version is a dead end: "I'm sorry, I can't help with that." The honest version is a hand-off that actually lands somewhere.

In a well-built harness the hand-off is a chain of small, checkable steps. First, the unanswered question becomes a durable item of its own, so it can't evaporate when the tab closes. Then, if the visitor leaves contact details, a support ticket is filed. Only when the help desk confirms it has accepted that ticket does the box say the words "with the support team". Until then it says what is true: that it is passing the question on. If a submission comes back uncertain, it isn't blindly fired again.

That sounds fussy until you look at what the alternative promises. "Your ticket has been created" before anything was created is the same mistake as the invented refund policy, just aimed at a different fact. A harness describes only the action the result proves. Saving is not sending. Sending is not solving. Drafting is not sending either.

Two more rules hold the hand-off together. The box never pretends to be a person, not to smooth over a handover and not to sound warmer. And the box claims no authority it doesn't have: it can't approve a return, change an account or place an order just because a visitor asked nicely. In Deyaf's words, answering is not acting.

Visitors notice. The Qualtrics study found that half of consumers fear AI will block them from reaching a person. A visible, honest "talk to a person" path is the most direct answer to that fear, and it only works if the steps behind it are real. Deyaf draws the whole flow, including what happens when she doesn't know.

Saved

The question is kept as its own item. Nothing has been sent yet.

Accepted

The help desk confirmed the ticket. Now the box may say "with the support team".

Solved

A person answered. Only the team, not the box, can say this one.

Page 9

Starring Eve, Feniex's assistant

Everything in this issue so far has been drawn from a made-up kettle shop. Here is a real one. Eve is Feniex's assistant, and the chat box on Feniex's website is one of her doors. Eve runs on the agentic harness Deyaf packages: her knowledge, memory, doors, rules and learning loop.

Her chat box does what the anatomy page describes. Replies stream in as they are written. The page and product the visitor is looking at ride along with the question. Products and resources come back as structured tiles. The conversation history is bounded. There is a website voice as well, and beyond the website she answers on the phone, by text and by email, with the same identity, the same library and the same rules at every door.

Her manner is the "with a harness" page in practice. She answers first, gives one useful next step, then stops, usually in two or three sentences. She asks for one missing detail at a time. She checks the exact record before any product, compatibility, warranty, price or software claim, and says only what the result proves. She never pretends to be a person. When she doesn't know, the question becomes a saved item, a ticket is filed when there are contact details, and "with the support team" is said only once the ticket is confirmed.

She also gets better in a way that can be checked. An answer the team gives can be reviewed and taught as a lesson, but only approved lessons are published, and she is measured on a frozen set of test questions before and after. It is a supervised loop, not training on every chat: the loop that makes her better. More about her at Meet Eve, Feniex's assistant.

Character sheet: Eve

Is
Feniex's assistant, and an AI. Warm, composed, brief.
Is not
A person. No age, no body, no pretending otherwise.
Doors
Website chat · website voice · phone · text · email
Powers
Four public actions: look something up, search the taught library, take a message, record an unanswered question.
Can't
Approve returns, change accounts, place orders, or transfer a call.
On the phone
“Hello, this is Eve, Feniex's intelligence. How can I help you?”

Her numbers, weak spot included

1.4s / 2.7sWebsite chat: first word, then a finished reply
1.6s / 3.0sPhone: first word, then a finished reply
86%Handled well on 100 fixed test questions, graded 23 Sep 2026
10%Material-error rate on the same test. It belongs next to the 86%, always.

The same harness answers Feniex's overflow and after-hours phone line, where the team's phones ring first. In her first week on the line (since 17 September 2026) Eve answered 102 calls: 86 while the team was busy and 16 after the office closed. 93% of callers stayed and talked, and 60 calls were handed to the team with the caller's details taken. That is a hand-off, never a transfer.

As of September 24, 2026 · Feniex's internal Eve 3.0 report · machine-judged and provisional. See Eve's report card, weak spots included.

Replay: about three seconds

Illustrative words · measured timing

Visitor

Is there an installation manual for this model?

Eve

Yes, here's the installation manual for this model, from its product record. Would the wiring diagram help too?

Installation manualFrom the product record
2.7 s
The words are invented; the timings are Eve's measured website-chat figures (Feniex's own measurements, Sep 17–24, 2026). The bar runs from 0 to 3.5 seconds.

Next issue → Eve's numbers, measured not promised

Page 10

Letters to the editor

Box Office: your questions

Readers write in about chat boxes. The letters are composites of questions people commonly ask; the answers are ours.

Dear Editor, isn't the chat box just the AI model with a nice skin?

A sceptic, reading on a phone

Ed: The skin is the box; the model writes the sentences. Everything that decides which sentences are allowed is the harness: the records it must check, the rules it must follow, what rides along and what happens when it doesn't know. Swap the model and a good harness still says the same true things.

Will the box pretend to be a person?

Someone who once thanked a bot

Ed: It shouldn't, and a harnessed one doesn't. It says it's an AI in its greeting and keeps a disclosure line on screen. In the EU, Article 50 of the AI Act has required that at the first interaction since 2 August 2026. Deyaf lays out what the assistant can and cannot do.

Can the box just give me my refund?

Rosa, apparently

Ed: Answering is not acting. Eve claims no authority to approve returns, change accounts or place orders; she can take a message and hand it to the team. Deyaf's published ladder has three levels, set per workflow and per channel: answer only; prepare for approval, where "nothing leaves until someone says yes"; and run one approved task, with a receipt every time. The ladder is laid out under what she may do.

What does it remember about me?

A private person

Ed: In Eve's case: this conversation, within a bounded window; a conversation record the team can read and visitors can't search; short notes that are history, never current facts, so orders and balances are always looked up fresh; and a library of reviewed lessons. Contact details are kept apart from published knowledge. Nothing is perfect recall. The details are under four kinds of memory.

Does it learn from my chat?

Worried about being homework

Ed: Not by itself. Raw conversations never become public knowledge automatically. A person answers the question once, the answer is reviewed, and only approved lessons are published, after a measurement on a frozen test set. Your team answers once; she knows it for good.

How do you count "handled well"? Everyone's number looks different.

A numbers person

Ed: They are different, because they count different things. Intercom, for example, counts an "assumed" resolution when a customer leaves without asking for more within 24 hours (vendor-reported). Eve's 86% is machine-judged on 100 fixed test questions and printed beside its 10% material-error rate (Feniex's own measurements, Sep 17–24, 2026; provisional). Never line two vendors' rates up as if they measured the same thing. The method is on the report card.

I run a small shop. Can I have a box like this?

A shopkeeper (not Kettle & Co.)

Ed: Deyaf is built from Eve: the harness that runs Eve at Feniex, packaged so another business can have an assistant of its own. Today that means an early-access builder: four steps (your business, what it knows, how it helps, try it) and a knowledge preview that runs in your browser. The preview is not live AI. Live doors switch on one at a time, after activation and a completed security review. Start with a front desk that knows, or read how to switch on each door deliberately.

Next issue

Your shop's box

Every business already has the hard part: the records, the policies, the answers the team gives a dozen times a week. The harness is what lets a chat box answer from them honestly, and hand over the rest. Start with one good job, and try the builder in about ten minutes, no account needed.