Salesforce Trusted Enterprise AI Harness is a new enterprise architecture that combines six reusable capabilities with a central AI Control Plane. Salesforce previewed it on September 10 and says new capabilities and a unified experience are planned to begin rolling out in early fiscal 2028, so buyers should treat this as a roadmap announcement rather than a fully available product bundle.
- The six layers cover context, agency, action, governance, security and models.
- The AI Control Plane is intended to register agents, apply identity and policy, observe behaviour and manage cost.
- Existing Salesforce products supply much of the foundation, but packaging, pricing and regional availability remain undisclosed.
Everyone else is reporting the architecture; we are explaining the control boundary buyers need to verify before adoption.
What Salesforce Trusted Enterprise AI Harness includes
Salesforce describes the harness as a composable layer built from Data 360, Informatica, MuleSoft and Agent Fabric, Tableau, Agentforce, Salesforce Guardian and the Salesforce Platform. The aim is to let agents use the same governed customer context, business rules and actions instead of rebuilding those connections for every assistant or model.
The six capabilities divide the job clearly. Trusted Context assembles data, metadata, semantics, memory and business knowledge. Trusted Agency supplies planning and orchestration. Trusted Action connects agents to workflows and APIs. Governance and Security apply lineage, policies, permissions and runtime controls. Trusted Models routes work among models based on requirements such as accuracy, performance and cost.
| Launch fact | What Salesforce says | Buyer implication |
|---|---|---|
| Architecture | Six composable capabilities | Check which pieces are already licensed |
| Control layer | One AI Control Plane | Test coverage across third-party agents |
| Interfaces | MCP, APIs, skills and plug-ins | Verify permission propagation end to end |
| Availability | Rollout begins early fiscal 2028 | Do not plan against an undated feature |
Why the AI Control Plane is the important part
An agent that can answer questions is different from an agent that can reserve inventory, change a customer record or trigger fulfilment. Salesforce says the control plane will discover and register AI capabilities, establish identity and policy, manage lifecycle, evaluate performance, observe behaviour and control cost across Salesforce and third-party systems.
That is the product claim buyers should test. A useful pilot should trace one action from the user and agent identity through the invoked tool, data permissions, policy decision, execution log and final business record. If any step becomes invisible when a third-party model or MCP tool is used, the promised common control layer is incomplete for that workflow.
VentureBeat’s direct report also emphasised the roadmap timing and open architecture. Independent analysis from Engage Evolution focused on the same centralisation of policy, routing, evaluation and observability. Neither report supplies customer benchmarks, so there is no evidence yet for a productivity or cost saving claim.
Availability, limits and a practical evaluation
Salesforce says many underlying technologies are already available and eligible customers will be able to upgrade as new pieces arrive. It has not yet announced final packaging or pricing, and availability may vary by region. A procurement team should therefore map every needed capability to a presently orderable product rather than treating the harness name as a current SKU.
A controlled evaluation can begin with one reversible workflow. Teams should document the authoritative data source, allowed agent actions, human approval threshold, fallback model, retention settings and evidence required for an audit. They should also test how revoking a user or agent identity propagates across connected systems.
The pattern resembles other governed-agent launches covered by Lapaas Voice, including Klaviyo Headless opening CRM capabilities to agents and WRITER Enterprise Brain adding shared agent memory. The differentiator will be whether the control plane consistently governs actions outside Salesforce, not the breadth of a launch diagram.
Teams should also distinguish visibility from enforcement. A control plane may inventory an agent and display its activity without being able to stop an unauthorised action in every connected application. The pilot should deliberately attempt a forbidden operation, confirm that the policy blocks it, and verify that the denial appears in an audit record a security reviewer can understand.
Frequently asked questions
What is Salesforce Trusted Enterprise AI Harness?
It is a planned composable architecture that brings context, agency, actions, governance, security and model access together with a central AI Control Plane.
Is the complete harness available now?
No. Salesforce says existing technologies form its foundation, while new capabilities and the unified experience are planned to begin rolling out in early fiscal 2028.
Does it support third-party AI?
Salesforce says the design can work with third-party models, agents and systems through headless interfaces including MCP, APIs, skills and plug-ins. Buyers still need to verify actual control coverage in their own stack.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



