Your subject is not for rent

The hostage economy of the harness ecosystem: moving your knowledge out of the harness and into a hosted knowledge base doesn't free the subject — it changes its landlord. And the cost of leaving is spread exactly where it can't be added up.

Jesús Pérez
The harness post left a question open: if your project's knowledge lives inside the harness profile, switching harnesses means losing it. The market's answer — move it out to an external knowledge base — solves one coupling by introducing another. This post walks the harness layer by layer through the pairings nobody decides and everybody assumes, and proposes the change of regime: from renting to owning. No villain: every step of the enclosure is reasonable on its own, and that is exactly the problem.
Your subject is not for rent

The previous post ended on an uncomfortable observation: if your project’s knowledge lives inside the harness profile, switching harnesses means losing it. The literature admits this plainly and calls it a “coupling tension”.

The market already has its answer ready, and it is a good one: move the knowledge out to an external knowledge base. A memory service. A hosted graph. A managed RAG. It works, it solves the problem it says it solves, and the people building it know what they are doing.

There are also honest answers that charge no rent, and they deserve naming before we criticise the rest. The Open Knowledge Format is the cleanest of them: a directory of markdown where the file path is the concept’s identity and the links are the graph’s edges. No provider, no subscription, and nothing to export — because there was never anywhere to deposit it. It solves transport and claims nothing more: no types, no validation, no state. An excellent vehicle, and still not a subject.

The problem, then, is not that the knowledge sits outside. It is that it sits rented. And the answer offered by default today solves one coupling by introducing another: it looks like exile and it is a change of landlord.

The false exile

Taking the subject out of the harness does not free it if you move it into rented premises. The external knowledge base relieves you of coupling to the harness in exchange for coupling to the knowledge base provider: the subject as a service. And the price of admission is always the same one, the subscription. Look closely at what you are paying for: you are not paying for the knowledge — it is yours, you brought it — you are paying to keep having access to the place where you left it.

This is the pattern infrastructure has been teaching us for decades, and it is worth looking at plainly, because each step is reasonable on its own:

  1. The enclosure is justified by personalised attention, and the attention is real. “We know your data, we serve you better.” True. And that is exactly where it tightens: the better it serves you, the more expensive leaving becomes. Personalisation is a deposit you do not get back.
  2. Your data pays for the service and becomes raw material. What you hand over in exchange for convenience feeds an asset that is not yours. You pay to live in the ecosystem and you enrich it by inhabiting it.
  3. Dependency compounds. It started with a subscription, continued with the obvious integrations, and ends with your project unable to describe itself without a network call to a third party. A subject that needs permission to answer “what am I?” is not a subject: it is a tenant.

None of those three steps requires bad faith. That is the point.

Infrastructure is potential presence — and the harness is the same thing

It is worth saying what infrastructure is before arguing about who owns it. Infrastructure is not machines: it is power held in potential, the capacity to be present, to serve, to act when needed. Whoever holds up your infrastructure holds up your potential — not only what you do today, but what you could do tomorrow. That is why the business was never selling machines but administering other people’s potential, and charging rent for each one’s access to their own.

The harness is the same class of object one layer up: it is the infrastructure of your agency at agent speed. Which is why the commercial pattern repeats exactly, with two investments rather than one.

The first is the build. The provider invests in training the model the way a country builds public infrastructure: immense capital, sunk, unrepeatable — the dam, the power station, the grid. Then it gives you the means to use it for free (the free tier, the credits, the open-source harness) and charges you for usage like any other utility: electricity, water, the telephone. The decisive move is not the charging, which is legitimate; it is the normalisation of the need. Nobody argues about paying the electricity bill. The day working without an agent feels like working without electricity, nobody will argue about the fee. First the need is normalised, with it the fee, and with the fee the meter: your agency, billed by consumption on somebody else’s meter.

The second investment is in your learning. The tutorials, the templates, the popularisation of their harness: that is investment, not generosity, and saying so is not a reproach — it is reading the balance sheet. The harness is the door to the chain, and the chain bills you later, spread out where you cannot add it up. What you learned is not neutral either: you learned their way of working, and muscle memory is the moat. When the landlord funds your learning, what you learned is not portable knowledge — it is the ecosystem’s liturgy, and practising it elsewhere is worth nothing.

The two investments close over each other: the build makes the service possible, your learning makes the build necessary. The classic utility at least delivered a fungible good — a kilowatt is a kilowatt wherever it comes from. Here the good arrives wrapped in its ecosystem, so switching providers is not switching tariffs: it is relearning the liturgy and moving the subject. That is the difference between paying for electricity and paying a toll on being yourself.

Layer by layer: the pairings nobody decides

The canonical equation says agent = model + harness. The one that actually gets deployed is agent = model + harness + ecosystem, and the term nobody writes down is the one holding your data. Every layer arrives with a “natural” pairing that nobody chose and everybody assumes.

The right-hand column is the one that matters, because it is the one you can check:

Harness layerAssumed pairingWhat it camouflagesWhat changes when the subject is yours
Toolseditor ↔ agent (“your editor already ships one”)the default agent picks the default providerthe agent is swappable because the subject does not live inside it
Context and system promptvendor templates, ecosystem “best practices”your project’s voice, drafted by the landlordcontext is declared, versioned with you, and any agent can read it
Memory and statemanaged memory, the provider’s knowledge basethe whole subject, hosted elsewhere; exportable “in theory”typed files in your repository: “what am I?” makes no network call
Permissions and guardrailsthe platform as the authority on what is allowedyour security policy, delegated with no recordthe gate checks what you declared; deciding and enforcing stay yours
Verification and observabilitytelemetry and evaluation in the vendor’s dashboardthe criterion for “it works”, measured by whoever bills youa signed witness, checkable by a third party without asking you for anything

Three of those rows deserve elaboration, because they are the ones you do not see coming.

Memory and state. This is the row that gives the post its title. When the project’s memory lives in the service, what sits out of your reach is not a file: it is the answer to what you are. Export exists, almost always — but exporting hands you a dump, not a subject: without the types, without the decisions and their reasons, without the state and its transition condition, what you recover is archaeology. The alternative is not a better export format. It is that one should never have been needed: if the subject is typed NCL — configuration files with contracts that get checked, in your repository and nobody else’s — you already have it, and it keeps answering with the network down.

Context and system prompt. The quietest layer. You adopt the provider’s templates because they are well made and carry months of tuning inside them — the right decision on day one. Some time later, the way your project presents itself to an agent was written by someone who does not work here, and you no longer know which of your conventions are yours and which came in the box. Declared context reverses the direction: you write it, it lives with the code, and the agent consults it as data instead of arriving wearing it.

Verification and observability. The sharpest one, and the one almost nobody looks at. When the dashboard that tells you whether something works is served by whoever bills you for it working, the criterion of success has changed hands with nothing signed. You do not have to assume manipulation: it is enough that the provider chooses what gets measured. A signed witness does the opposite — anyone can check a slice of your model without holding the whole, without your hosting and without your permission.

And a note on costs: they are offset along the chain. Each layer subsidises the next — the editor is free, the model is discounted if you use their provider, memory is included in the team plan — so that no layer has a price of its own, and therefore no decision to leave has a calculable price. That is not a discount: it is fog. Where you cannot calculate the cost of leaving, you have already stayed.

Here is where I would like to give you the number: what it costs on average to migrate between agent ecosystems. There isn’t one, or at least not one that survives serious reading, and if there were I would cite it. Its absence is not a gap in the market — it is the market’s shape: the number cannot be calculated because the costs are spread where they do not add up.

The counter-model: the subject as property

ontoref’s answer to coupling is not “move it somewhere else”, but change its regime: from renting to owning.

  • Typed files in your repository. Ontology, decisions, state and tensions are NCL versioned alongside you. There is no network call in “what am I?”.
  • Addressable without cloning, verifiable without trusting. Another project, another team or another agent check your model by witness. They need neither your hosting, nor your plan, nor your API key.
  • Local first. The daemon is a cache, not a condition of existence. With no network, the subject keeps answering.
  • A protocol, not a runtime. You can leave with everything because everything was yours from the start. Portability is not an export function: it is the absence of an import.

Decentralisation exercised, not granted

There is a distinction here that the usual decentralisation talk skips. Nobody decentralises you from the outside; decentralisation offered as a service is centralisation with better presentation. It is only viable when exercisedmotu proprio, as subject and holder, not as the beneficiary of somebody else’s architecture. ontoref does not “give” decentralisation: it gives the condition that makes it exercisable, a subject that is yours, verifiable by anyone, dependent on no one.

And the result of exercising it is not merely less dependency. It is resilience, and the difference matters: less dependency is a balance, you owe less; resilience is a capacity, you keep answering. When the provider changes prices, retires an interface, gets acquired, goes down or disappears, the project whose subject is its own still knows what it is, what it decided and where it was heading. With no network, no plan and no permission. Your potential was never deposited in the ecosystem.

With the books open

Here is the part where this text has to accept the same scrutiny it applies, because a critique of enclosure written by someone who hides their own compensation model is marketing with a grudge.

ontoref needs to sustain itself too. The difference between a price and taking hostages is not that one charges and the other doesn’t: it is that the price is declared and the exit is cheap. So the model is published as queryable data, not as a pricing page: the viability paths live inside the positioning surface itself, typed, each declaring whether its compensation is direct or indirect, and you consult them with the same tool I am offering you. You can audit the one lecturing you about auditing.

Decentralisation does not stay a principle either: this project’s constellation practises it on itself — its own forge as canonical, the public copy as a one-way mirror, an optional sovereign peer, and the private vault that is replicated nowhere.

The exit bill

What I can give you is the number that is mine to give: what it costs to leave me.

You delete the .ontoref/ directory and your system keeps running. There is no uninstall to undo, no runtime to pull out of the critical path, no data to reclaim: the files were already in your repository, in typed plain text, versioned by you. There is no export because there never was an import.

And the honest counterpart, in the same breath: what you lose by leaving is the checking, not the data. You stop having anyone verify that what you declared is still true. That is exactly what you were sold, and it is all you were sold. A broader blanket of guarantees would be easier to advertise and would leave you owing more.

Closing

A rented subject answers to its landlord before it answers to its project.

The honest boundary, in its economic version: I do not promise you that leaving is free — I guarantee you that leaving is yours. What you own stays with you and you check it yourself. What you rent stays with the landlord, and the landlord is not going to tell you.

Was this useful? Rate it
Got something to add? Tell me what you think, what you'd suggest, or whether we should keep exploring this topic.
· reads

We use cookies to help this site function, understand service usage, and support marketing efforts. Cookie Policy for more info.