---
title: "Harvey builds its own agent security the week AWS gives it away and Goodfire cuts monitoring to $51"
description: "Harvey disclosed a policy engine on October 7 that checks every partner tool call its legal agents make, because the leaked files and the malpractice exposure belong to the law firm. The same week, AWS open-sourced an agent sandbox and Goodfire cut monitoring to $51 per 1,500 sessions from $10,000, the spread that asks whether agent governance is a market or a feature."
publisher: "The Inference"
section: "Safety"
published: 2026-10-08T23:12:11.386Z
modified: 2026-10-08T23:12:11.386Z
canonical: https://theinference.org/article/harvey-builds-its-own-agent-security-the-week-aws-gives-it-away-and-goodfire-cuts-monitoring-to-51
language: en
keywords: "AI Agents, Cybersecurity, Legal, Enterprise AI"
---

# Harvey builds its own agent security the week AWS gives it away and Goodfire cuts monitoring to $51

> Harvey disclosed a policy engine on October 7 that checks every partner tool call its legal agents make, because the leaked files and the malpractice exposure belong to the law firm. The same week, AWS open-sourced an agent sandbox and Goodfire cut monitoring to $51 per 1,500 sessions from $10,000, the spread that asks whether agent governance is a market or a feature.

## The same day: 500 lawyers and a security disclosure

On October 7, offshore law firm Ogier ended its pilot the committed way: [Harvey](https://theinference.org/markets/companies/harvey)'s agents now sit in front of [all 500 lawyers across 13 offices](https://www.ogier.com/news-and-insights/news/ogier-expands-its-ai-enabled-legal-service-offering-with-the-adoption-of-harvey/) [2]. The same day, Harvey's security team published a rarer artifact than a funding release: [a working account of how its own agents can be turned against the firms using them](https://www.harvey.ai/blog/building-harveys-mcp-policy-engine) [1].

## The product is the attack surface

The agents that carry the revenue and the agents that can carry the breach are the same agents. Connectors reach research platforms, document systems and communication tools through the Model Context Protocol, and the post names the failure modes: tools poisoned on arrival, tools changed after approval in a rug pull, trusted tools queried just wrong enough to send client data out [1]. It cites NSA guidance calling MCP "uneven and highly dependent on implementation discipline rather than protocol guarantees" [1]. The fix sits outside the model: Rego rules permit, deny or pause each proposed call, and deny by default when a check cannot complete [1]. The Tool Pinner, watching approved tools for later changes, "currently generates a substantial volume of alerts" [1].

## The price of governing agents just collapsed

The build decision landed the week governance got cheap. [AWS open-sourced Strands Box on October 7 under Apache 2.0](https://aws.amazon.com/blogs/opensource/introducing-strands-box-ai-agent-sandboxes-powered-by-dogwood/), with a broker that mediates every MCP tool call and policies that can deny an action based on what the agent already did [3]. Goodfire cut the other cost: probes reading a model's internal signals [monitored 1,500 agent sessions for about $51, against roughly $233 for a cheap model and about $10,000 for a top-tier one, while catching 94% of malicious hacking sessions](https://techcrunch.com/2026/10/08/goodfire-says-its-new-inside-out-monitors-catch-rogue-ai-agents-at-a-fraction-of-the-cost/) [4].

*Chart: **Watching 1,500 agent sessions fell from $10,000 to $51** Bar chart of monitoring cost per 1,500 agent sessions: about $51 with Goodfire's internal probes, about $233 with a cheaper model monitor, about $10,000 with a top-tier model monitor.*

*Goodfire-reported test costs on the open model Kimi K3, US dollars per 1,500 monitored agent sessions, published October 8, 2026. [4]*

## Harvey builds and buys as the market decides

Harvey also buys. Its [$550 million round at a $15.5 billion valuation on September 9](https://www.reuters.com/legal/government/legal-ai-startup-harvey-reaches-155-billion-valuation-new-funding-round-2026-09-09/) came with Guardrails AI, an agent-security startup and its fourth acquisition this year [5]. The growth is company-claimed and fast: [over $100 million of ARR added in Q3, past $400 million total](https://digg.com/ai/2qm8zxq1), 97% gross revenue retention, 80% of the 100 highest-grossing US firms [5][6], more than 3,000 customers in over 70 countries [7]. SailPoint, the listed identity vendor, [shipped agent governance and a kill switch into IdentityIQ 9.0](https://www.channelinsider.com/security/tools-and-platforms/sailpoint-ai-identity-security-identityiq-9/) the same day [8]. Apps building these controls in, and clouds giving them away, is [the bear case for selling them separately](https://theinference.org/article/almost-nobody-has-bought-agent-security-yet-the-market-is-paying-as-if-everyone-has).

## The tell is the alert queue

[Anthropic](https://theinference.org/markets/companies/anthropic), the model supplier, [has sold the same workflows directly since May under Claude for Legal](https://inc42.com/resources/selling-intelligence-was-the-warm-up-for-ai-owning-vertical-markets-may-be-the-play/) [9], which leaves governance as the layer this disclosure actually evidences. The number to watch is unwritten: how fast flagged tool changes outrun the humans reviewing them. A control that drowns its reviewers is a support tier, not a moat.

## Takeaway

Harvey built its own MCP policy engine days after AWS open-sourced an agent sandbox and Goodfire cut session monitoring to $51 per 1,500 sessions, the price spread that will decide whether agent governance is a product or a feature every platform absorbs.

## Sources

1. [Harvey blog, Building Harvey's MCP Policy Engine, 7 October 2026](https://www.harvey.ai/blog/building-harveys-mcp-policy-engine)
2. [Ogier, Ogier expands its AI-enabled legal service offering with the adoption of Harvey, 7 October 2026](https://www.ogier.com/news-and-insights/news/ogier-expands-its-ai-enabled-legal-service-offering-with-the-adoption-of-harvey/)
3. [AWS Open Source Blog, Introducing Strands Box: AI agent sandboxes powered by Dogwood, 7 October 2026](https://aws.amazon.com/blogs/opensource/introducing-strands-box-ai-agent-sandboxes-powered-by-dogwood/)
4. [TechCrunch, Goodfire says its new 'inside-out' monitors catch rogue AI agents at a fraction of the cost, 8 October 2026](https://techcrunch.com/2026/10/08/goodfire-says-its-new-inside-out-monitors-catch-rogue-ai-agents-at-a-fraction-of-the-cost/)
5. [Reuters, Legal AI startup Harvey reaches $15.5 billion valuation in new funding round, 9 September 2026](https://www.reuters.com/legal/government/legal-ai-startup-harvey-reaches-155-billion-valuation-new-funding-round-2026-09-09/)
6. [Digg, Harvey's Q3 recap puts annual recurring revenue above $400 million, 7 October 2026](https://digg.com/ai/2qm8zxq1)
7. [Blockchain.news, Harvey Develops MCP Policy Engine to Enhance AI Security, 7 October 2026](https://blockchain.news/news/harvey-mcp-policy-engine-security)
8. [Channel Insider, SailPoint Expands AI Identity Security, Launches IdentityIQ 9.0, 7 October 2026](https://www.channelinsider.com/security/tools-and-platforms/sailpoint-ai-identity-security-identityiq-9/)
9. [Inc42, Selling Intelligence Was the Warm-Up For AI. Owning Vertical Markets May Be The Play, October 2026](https://inc42.com/resources/selling-intelligence-was-the-warm-up-for-ai-owning-vertical-markets-may-be-the-play/)


---

Harvey builds its own agent security the week AWS gives it away and Goodfire cuts monitoring to $51 — The Inference. Canonical: https://theinference.org/article/harvey-builds-its-own-agent-security-the-week-aws-gives-it-away-and-goodfire-cuts-monitoring-to-51
