Chapters
Try It For Free
July 21, 2026

Securing the Agent DLC | Harness Blog

Traditional security was built for software that sits still. Agents don't. 

Agentic applications break the assumptions traditional security was built on. The traditional SDLC assumes artifacts are static once deployed, attack surfaces are known and inventoried, humans control every decision and gate, and supply chain risk ends at code and dependencies. Agents violate all four. They reason and act at runtime in ways no static scan can fully anticipate. They dynamically discover and connect to tools, MCP servers, and APIs, expanding the attack surface continuously. They spawn sub-agents and chain across systems without a human in the loop. And they inherit trust from every model, tool, and API they connect to, making supply chain risk exponentially wider and harder to contain.

Security tools built for the traditional SDLC weren’t designed for any of this.

Agent Security: A New Discipline 

Securing agents requires a fundamentally different approach than securing traditional software. Not a new tool bolted onto existing practice, but a new discipline built around how agents actually work - one that shifts left to constrain what agents can do before they're deployed, and shields right to enforce policy and maintain visibility while they run.

Today, Harness announced the availability of the industry's first DevSecOps platform for the Agent Development Lifecycle (Agent DLC) - purpose-built for both developing and operating agents securely.

Shift-Left for secure agent development

You can't predict everything an agent will do once deployed. But what an agent does at runtime isn't random. The skills you expose, the tools you wire up, the models you select, and the prompts you write all shape it. Shift-left for agent development isn't about catching every runtime risk before it happens; it's about limiting what agents can do once they're live.

Primitive Scanning analyzes the new design-time decisions that agents introduce, helping catch exposure and misconfiguration before any agent is built or deployed. It extends Harness SAST with skill and prompt scanning, and Harness Security Testing Orchestration with model scanning.

AIBOM with Harness Supply Chain Security gives you a complete inventory of every model, tool, and dependency used to build an agent, expanding the traditional SBOM to cover the full AI supply chain.

AI Testing tells you whether agents are safe by testing them for adversarial inputs, unexpected behaviors, and policy violations across the OWASP Top 10 LLM and Agentic AI risks.

AIBOM inventories the AI components used to build an agent, including models, libraries, frameworks, datasets, prompts, skills, tools, and services.

Shield-Right for secure agent runtime 

Shift-left narrows what agents can do, but once deployed, agents operate in an open world. They encounter inputs, tool responses, and chain behaviors that no pre-deployment check can fully anticipate. Protecting agents in production requires continuous visibility into what agents are running and what they're doing.

Agent Discovery expands AI Discovery beyond individual AI assets by introducing an agent SPM capability to the platform that continuously surfaces agents as they spin up, maps how AI assets connect and chain, and assesses their posture across your organization. Where shift-left defines the boundaries, Agent Discovery tells you what's operating within them.

AI Firewall protects all AI assets, including agents at runtime, enforcing policy continuously against prompt injection, tool misuse, and data exfiltration through agentic chains - after the agent is live and as long as it runs.

AgentTrace brings observability throughout the entire agent activity session, providing a full audit trail across prompts, reasoning, tool calls, and outputs. This is especially important for agentic operations to have confidence that the non-deterministic systems are acting as expected. 

Agent Discovery continuously identifies active AI agents, maps their dependencies and interactions, and surfaces associated risk and sensitive-data exposure.

The Agent DLC Needs Dedicated Security

Blindly applying traditional AppSec to agent development doesn't work. The assumptions don't hold, the tools don't reach, and the attack surface keeps moving. What's needed isn't a patch on existing practice; it's a purpose-built approach that secures agents at every stage of how they're actually built and run.

That's what Harness offers. Shift-left to define the boundaries. Shield-right to hold them. A single platform that treats agent security not as an afterthought, but as a first-class discipline across the full Agent DLC.

Agents are already in production. The question is whether your security posture is built for them.

Talk to our team to see how Harness secures the Agent DLC.

Rahul Sood

Rahul Sood is the General Manager for Application Security at Harness, where he leads the company's AppSec portfolio. He is focused on building security for the AI era, integrated directly into modern DevOps workflows. Before joining Harness, Rahul was Chief Product Officer at Pindrop.

Similar Blogs

Harness Platform