Agent = Model + Harness is a good shorthand, and the underrated consequence is that most of the variance between a good agent and a bad one is harness variance rather than model variance. The recent results where the same model moved tens of points on configuration alone make that concrete.
For the enterprise-architecture angle you write from, the governance implication follows directly. If behaviour lives in the harness, then the harness is what needs versioning, change control and an audit trail, not just the model card.
What I see in practice is teams pinning the model version and then leaving retrieval settings, tool definitions and the system prompt free to change without review, which is exactly the part that actually moved.