Salesforce introduced its Trusted Enterprise AI Harness on Thursday, Sept. 10, making a strategic bid to become the control layer for artificial intelligence agents operating across corporate systems. The architecture brings together business context, agent orchestration, actions, governance, security and model access, with a new AI Control Plane intended to give companies one place to see and manage agents from Salesforce and other vendors.

The announcement arrives as large organizations move from isolated AI experiments to systems that can read data, call software tools and complete work. That transition raises a harder problem than choosing a model: companies need to decide which agents exist, what information each one can reach, which actions it may take, how its performance is evaluated and what it costs.

Salesforce’s answer is to package those requirements around the customer data, metadata, workflows and permissions already inside its ecosystem. Many of the underlying technologies are available now, the company said, but new capabilities and the unified experience are scheduled to begin rolling out in early fiscal 2028. Packaging and pricing remain undisclosed.

Salesforce is moving the contest above the model layer

The Enterprise AI Harness groups six capabilities: context, agency, action, governance, security and models. Together, they are meant to supply agents with business definitions and memory, let them plan work, connect them to applications and workflows, enforce policies and route tasks to different models.

That structure reflects an important change in enterprise AI. Foundation models are becoming interchangeable for some tasks, but a company’s operational context is not. An agent answering whether an order can ship today may need customer history from CRM, inventory from an enterprise resource planning system, contract terms, internal policies and permission to update fulfillment. The value sits in connecting those sources without allowing open-ended reasoning to become uncontrolled execution.

Salesforce is drawing on Data 360, Informatica, MuleSoft, Tableau, Agentforce, Salesforce Guardian and its core platform. That gives the company a large installed base and a deep pool of business metadata. It also means the Harness is partly an integration of products customers may already own, rather than an entirely new system available as a finished product today.

The control plane is the strategic center

The most consequential component is the AI Control Plane. Salesforce says it will discover and register agents, establish identity and policy, manage lifecycles, evaluate performance, observe behavior and outcomes, and monitor cost across Salesforce and third-party AI.

That is a bid to govern agent sprawl. VentureBeat reported that a July survey of 107 qualified respondents at organizations with at least 100 employees found an average of 3.1 agent-orchestration platforms per enterprise. The sample was self-selected and skewed toward large technology organizations, so the result should be treated as directional. Even so, it supports the practical problem behind Salesforce’s pitch: companies are unlikely to standardize every AI workload on one vendor.

Salesforce is not alone. TechTarget noted competing control-layer products from ServiceNow, Genesys and Amazon Web Services, along with offerings from startups. The emerging platform battle resembles earlier cloud-management contests: each vendor wants to be the system that defines policy across a heterogeneous estate.

Winning that position would create commercial leverage. The vendor operating the control plane can influence how agents are approved, which models receive work, which data services are invoked and how usage is measured. Governance may look like a risk function, but it can become the distribution layer for the rest of the AI stack.

Openness will be tested in implementation

Salesforce describes the Harness as open and composable. It says customers will be able to use all six capabilities together or select individual components, including with third-party models, agents and systems. The headless architecture is expected to expose capabilities through APIs, Model Context Protocol connections, skills and plug-ins, reaching interfaces such as Claude, Slack, Microsoft Teams and Agentforce.

Those commitments matter because a multivendor control plane is useful only if it can govern systems it does not own with comparable depth. Discovery, identity, policy enforcement, logs and cost controls need to work consistently across vendors. If third-party agents receive weaker visibility or require proprietary adapters, the open architecture could still produce practical lock-in.

Enterprises should also distinguish portability from neutrality. A system may connect to several models while still making Salesforce data and workflows easiest to use. That can be a legitimate product advantage, but buyers need to understand where convenience ends and dependency begins.

CIOs should buy against evidence, not architecture diagrams

The Harness gives technology leaders a useful framework for evaluating agent readiness, but it is still a roadmap. Salesforce says many foundational technologies are available, while the unified experience and additional capabilities will arrive later. Customers should not assume every advertised control is deployable across their present environment or included in existing contracts.

Before committing, CIOs should inventory active agents, data connections and credentials; define who owns agent approval and retirement; require logs that connect decisions to actions; test whether policies follow an agent across applications; and measure cost at the task level. Procurement teams should ask which capabilities are generally available, which require upgrades, how third-party systems are licensed and how data can be exported if the control layer changes.

Salesforce’s strategic premise is persuasive: enterprise AI needs a durable operating layer around fast-changing models. The unresolved question is whether that layer becomes an open management plane or another suite boundary. The answer will be determined by interoperability, implementation and pricing—not by how many products appear beneath a single new name.