Agent = Model + Harness is a good way to frame it, and the RBAC and sandboxing points are the right ones to lead with. One thing I'd push back on a little is the model-swap claim -- in practice, swapping the model behind a harness isn't quite unplug and replug, the tool-call schemas and prompt structure that worked well for one model often need retuning for the next, especially anything relying on a specific function-calling format. The harness abstracts the plumbing but not the model's particular quirks.