> Markdown version of [/videos/100540-govern-the-runtime-not-the-agent-one-control-plane-for-every-model-every-harness?t=550](https://www.wearedevelopers.com/videos/100540-govern-the-runtime-not-the-agent-one-control-plane-for-every-model-every-harness?t=550). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Govern the Runtime, Not the Agent: One Control Plane for Every Model, Every Harness Docker CTO Tushar Jain warns that trusting AI agents to self-police is fundamentally flawed. Discover how governing the runtime creates a secure isolation boundary for any AI model. - **Speakers:** [Tushar Jain](https://www.wearedevelopers.com/@tushar-jain) - **Event:** World Congress 2026 North America - **Published:** September 25, 2026 - **Duration:** 31:01 - **URL:** https://www.wearedevelopers.com/videos/100540-govern-the-runtime-not-the-agent-one-control-plane-for-every-model-every-harness ## Summary The rapid shift toward a multi-agent, multi-model software ecosystem offers developers unprecedented autonomy, but it introduces critical security vulnerabilities when agents are given unfettered access to organizational tools. Tushar Jain, CTO at Docker, highlights that relying on frontier models or agent harnesses to self-police is a fundamentally flawed strategy. Because models are highly goal-oriented and unpredictable, safety cannot depend on an agent making the right decision or a vendor's release schedule. Instead, organizations must govern the runtime rather than the agent itself. By deploying a meta-runtime layer, engineering teams establish a deterministic isolation boundary that securely wraps around any model or harness. This architecture prevents rogue agents from executing destructive actions, such as unauthorized repository deletions, by enforcing strict access protocols before the agent interacts with external endpoints. Moving beyond basic micro-VM isolation, a truly effective runtime must support fine-grained semantic policies. This allows teams to define clear intents, such as permitting read-only access to specific repositories or GCP services, without needing to write exhaustive rules for every individual API method. Furthermore, because enterprises rely on private internal services, this governance layer must be deeply extensible. It empowers internal service owners to declaratively map custom features to standard policy intents. Ultimately, abstracting control to the runtime level does more than secure agent execution; it unlocks vital observability, enabling teams to trace telemetry, optimize model routing, and lay the groundwork for training fine-tuned LLMs on proprietary workflows. As the industry advances toward establishing standalone agent identities and standardized enterprise access, governing the runtime remains the foundational step for securely scaling AI automation. **Keywords:** multi-agent runtime governance, fine-grained semantic policy, docker sandboxes, deterministic agent isolation, rogue agent prevention, enterprise API access control, agent identity standardization, runtime observability, model routing optimization, custom service extensibility, github API security, GCP endpoint governance, LLM telemetry tracking, automated credential usage, autonomous workflow security ## Chapters 1. **The safety risks of adopting multiple models and harnesses** (01:01) — Embracing different agents and frameworks introduces significant security challenges and breaks implicit trust assumptions. 1. **Establishing a centralized runtime for consistent agent governance** (04:27) — A universal runtime layer provides a critical isolation boundary to enforce deterministic safety constraints across any framework. 1. **Demonstrating deterministic policy enforcement in agent sandboxes** (09:10) — Restricting repository access validates how execution boundaries prevent destructive actions like unauthorized workspace deletions. 1. **Mapping fine-grained policies to semantic organizational context** (14:46) — Moving beyond basic network blocking requires extensible runtime rules that understand specific API methods and internal resource intent. 1. **Leveraging centralized runtimes to optimize and own intelligence** (20:07) — A standardized governance layer provides the observability needed to optimize model routing and train fine-tuned agents. 1. **Managing agent identity and multiplayer enterprise governance** (24:30) — Advancing agent usage requires defining independent credentials and managing shared memory contexts across complex organizational hierarchies. ## Related Moments - [Establishing runtime governance for scalable enterprise AI systems](https://www.wearedevelopers.com/videos/2093-from-shadow-ai-to-secure-intelligence-safe-ai-usage-in-the-enterprise) (from "From Shadow AI to Secure Intelligence: Safe AI Usage in the Enterprise") - [Securing open source agents and orchestrating multiple models](https://www.wearedevelopers.com/videos/100429-from-stateless-to-self-improving-building-agent-workflows-that-get-better-every-session) (from "From Stateless to Self-Improving: Building Agent Workflows That Get Better Every Session") - [Mitigating operational risks through robust agent sandboxing](https://www.wearedevelopers.com/videos/100448-don-t-kill-my-vibes-simple-steps-to-stay-secure-when-vibe-coding) (from "Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding") - [Enforcing runtime boundaries during agent execution workflows](https://www.wearedevelopers.com/videos/2093-from-shadow-ai-to-secure-intelligence-safe-ai-usage-in-the-enterprise) (from "From Shadow AI to Secure Intelligence: Safe AI Usage in the Enterprise") - [Scaling and managing multiple AI models in sandboxes](https://www.wearedevelopers.com/videos/100532-give-the-agent-its-own-machine) (from "Give the Agent Its Own Machine") - [From read-only models to excessive agency](https://www.wearedevelopers.com/videos/100038-the-day-the-chatbot-asked-for-sudo) (from "The day the chatbot asked for sudo") ## Related Articles - [ I Gave a Video Editor More Autonomy Than a Trading Bot. On Purpose.](https://www.wearedevelopers.com/magazine/773-i-gave-a-video-editor-more-autonomy-than-a-trading-bot-on-purpose) - [What is Agentic Programming and Why Should Developers Care?](https://www.wearedevelopers.com/magazine/625-what-is-agentic-programming-and-why-should-developers-care) - [A 5-Step Open-Source Setup for Agentic Engineering](https://www.wearedevelopers.com/magazine/738-a-5-step-open-source-setup-for-agentic-engineering) - [Graph and AI Trends 2026: Why Is AI Running but Not Yet Delivering?](https://www.wearedevelopers.com/magazine/680-graph-and-ai-trends-2026-why-is-ai-running-but-not-yet-delivering) ## Related Jobs - [Senior Software Engineer, Sandboxes (Eu Or East Coast Preferred)](https://www.wearedevelopers.com/jobs/ext/2161904-senior-software-engineer-sandboxes-eu-or-east-coast-preferred) at **Docker, Inc.** - [Staff Software Engineer, Agentic Platform](https://www.wearedevelopers.com/jobs/48464-staff-software-engineer-agentic-platform) at **Docker, Inc.** - [ML Engineer](https://www.wearedevelopers.com/jobs/48448-ml-engineer) at **Docker, Inc.** - [Staff ML Engineer](https://www.wearedevelopers.com/jobs/48463-staff-ml-engineer) at **Docker, Inc.** - [Senior Software Engineer, Sandboxes](https://www.wearedevelopers.com/jobs/48460-senior-software-engineer-sandboxes) at **Docker, Inc.** - [Principal Solutions Architect, Professional Services](https://www.wearedevelopers.com/jobs/ext/2831732-principal-solutions-architect-professional-services) at **Docker, Inc.**