Declarative does not mean complete.
Google's AX repository describes three v1alpha1 resources: Task, Workspace, and Model. The task requests work. The workspace can pre-wire Git repositories, Model Context Protocol servers, and skill packages. The model resource holds the platform model configuration.[1]
That split is useful. It also stops before the agent loop. AX says its task runner starts the workspace and runs the agent command. The repository warns that its core concepts, protocols, and specifications can change before a stable release.[1]
The harness owns behavior.
Strands draws the next line. Its SDK runs in the application process and owns turn limits, token budgets, cancellation, stop reasons, tools, memory, sessions, tracing, and evaluations.[3] Those settings decide whether the agent stops, what it may call, and what evidence survives the run.
Scheduling starts the job. The harness decides how the job behaves after ignition.
A manifest that names a model but omits the harness version and loop policy cannot reproduce behavior. Record both. If the harness offers assembled defaults, export the resolved configuration rather than citing the package name alone.
The runtime owns containment and state.
AX runs on Agent Substrate. Substrate describes itself as an execution runtime, not an agent SDK. It maps stateful actors onto workers and manages creation, destruction, suspension, resumption, assignment, and routing.[2]
Substrate also says it is pre-1.0 and makes no backward-compatibility guarantee. Its published density and resume numbers are project claims tied to its own design and demos. They are not measurements of your cluster, workload, or security policy.[2]
Proof needs its own layer.
AX exposes task status and condition transitions through a watch call. Its design stores task state in Redis and sends work to horizontally scaled controllers, which drive tasks toward the requested state through Substrate.[4] A desired state and a live phase are operational facts. They do not prove that the code change was correct.
Keep a separate receipt with the manifest hash, harness version, resolved policy, sandbox image, network policy, task events, revision, test command, and test output. That receipt links what operators requested to what the agent did and what the repository accepted.
Use the four-boundary handoff.
- Declare the goal, workspace revision, model route, limits, and stop authority.
- Pin the harness package and save its resolved loop, tool, memory, and cancellation policy.
- Pin the runtime image and record isolation, network, credentials, state, lease, and cleanup rules.
- Attach task events, changed revision, tests, outputs, reviewer, and disposition.