Salesforce introduces a Trusted Enterprise AI Harness and AI Control Plane

Salesforce’s new architecture combines business context, agent action, identity, policy, model choice, observability, and cost control for enterprise AI.

Salesforce introduced its Trusted Enterprise AI Harness on September 11, 2026, in response to enterprise agents moving from answering questions to taking actions across systems. Salesforce describes the harness as a trusted foundation that helps agents understand the business, reason and plan, act, and operate within enterprise controls, without each agent or AI surface needing a separate foundation.

The architecture is organized around six capabilities: Trusted Context, Trusted Agency, Trusted Action, Trusted Governance, Trusted Security, and Trusted Models. Salesforce presents them as a common, composable architecture. Customers can use the capabilities together or select parts, combining Salesforce technology with existing systems, third-party models, and other agents. This is a vendor product position; the actual availability depends on deployment versions and customer agreements.

Salesforce uses a simple order question to show why a harness is needed: can an order be fulfilled today? The answer may be split across CRM relationship data, ERP inventory, contract commitments, analytics definitions, policies, and prior interactions. An agent must understand that context for the customer at that moment, decide what can be promised, and act within permissions. Connecting systems is not the same as connecting their meaning and rules.

Trusted Context brings data, metadata, semantics, knowledge, real-time signals, and memory into a shared context. Trusted Agency handles reasoning, planning, state, collaboration, and orchestration. Trusted Action connects applications, APIs, workflows, tools, and business processes. For the order example, an agent could reserve inventory, update an order, trigger fulfillment, or escalate to a person within a controlled boundary, with the outcome flowing back into context.

Governance and security are central rather than optional add-ons. Salesforce describes Trusted Governance as handling lineage, quality, guardrails, and policies. Trusted Security covers identity, permissions, privacy, data protection, and runtime security. Trusted Models lets an enterprise connect or switch models based on accuracy, performance, cost, and business requirements. The model is therefore only one control point; identity, policy, and action boundaries turn open-ended reasoning into predictable execution.

Salesforce is also introducing an AI Control Plane where businesses can discover and register agents, establish identity and policy, manage lifecycle, evaluate performance, observe behavior and outcomes, and control cost. Its value is a common management view across Salesforce and third-party AI. Organizations still need to define what counts as an agent, which outcomes are comparable, and who can approve, pause, or retire one.

The architecture is headless from the ground up, with capabilities available through MCP, APIs, Skills, and Plug-ins. Salesforce says it can extend into Claude, Slack, Microsoft Teams, Agentforce, and other AI experiences. That creates composability, but it also creates responsibility for connector scope, identity propagation, data boundaries, and version compatibility. Reaching more surfaces should not imply that every surface receives the same write permissions.

Salesforce says some underlying technologies are available today, while new capabilities and the unified experience are planned to begin rolling out in early fiscal FY28. Pricing, packaging, and upgrade paths will be detailed closer to general availability. Enterprises should therefore treat the announcement as an architecture direction, not a finished delivery. A sensible evaluation starts with one cross-system workflow and tests context, policy, escalation, traceability, and cost before expanding.

MODULE.002 //

More insights

Ideas on websites, AI automation, digital marketing, AI news, and VMTS updates.