
Why a Harness, Not Just Another AI Model?
Imagine a customer asking, “Can we fulfil this order today?” The CRM knows who the customer is. Inventory sits in an ERP system. Contract terms, service commitments and approval policies may live elsewhere. A model can produce a plausible sentence; a dependable enterprise answer requires current context, an authorised decision and an action that follows the rules.
Salesforce's Enterprise AI Harness announcement describes an architecture for making those capabilities reusable across agents rather than rebuilding them for each new use case. It draws on Data 360, Informatica, MuleSoft and Agent Fabric, Tableau, Agentforce, Guardian and the Salesforce Platform. Salesforce says customers can use the capabilities together or take only what they need alongside existing technology.
The important shift: the differentiator is not merely which model answers. It is how an organisation's proprietary customer context, business processes and controls become available to AI without surrendering governance.
The Six Trusted Capabilities
Salesforce presents these as complementary parts of one open, composable architecture, not six separate products every customer must buy.
Trusted Context
Unites customer data with metadata, business meaning, knowledge, real-time signals and memory. An agent can understand the customer, their contract and the current situation rather than answer from a document in isolation.
Trusted Agency
Combines reasoning, planning, state and orchestration with deterministic rules when an outcome must be predictable. An agent can decide the next step without improvising around a firm business constraint.
Trusted Action
Connects agents to applications, APIs, workflows and tools so an approved decision can become an actual business action — such as reserving inventory or escalating to a person.
Trusted Governance
Applies quality, lineage, policies and guardrails to the information and processes agents rely on. It addresses whether the answer and the action follow the organisation’s rules.
Trusted Security
Applies identity, permissions, privacy, data protection and runtime security. Agents should access only the records and operations they are authorised to use.
Trusted Models
Supports the choice and routing of models according to accuracy, speed, cost and business requirements, so the organisation is not tied to one model for every task.
The AI Control Plane: One View Across Agents
Salesforce is also introducing an AI Control Plane: a proposed common place to discover and register AI capabilities, assign identity and policy, manage lifecycles, evaluate performance, observe behaviour and outcomes, and watch costs. The ambition extends to third-party AI, not just agents running in Salesforce.
This is distinct from the six capabilities. Those help AI understand, decide, act and stay within controls; the Control Plane is intended to help teams see and manage the growing estate. Its precise feature availability should be checked against Salesforce's current product documentation before a rollout is planned.
How Is It Different from Agentforce, AIforce or a Chatbot?
A standalone AI model or chatbot
Generates responses from a prompt and available context.
Connects models to shared enterprise context, governed actions, security and operational controls.
Agentforce
The platform for building and running Salesforce AI agents.
The broader architecture of reusable capabilities around agents, including third-party agents and models; Agentforce is part of that foundation.
AIforce
Salesforce's strategy to make its platform capabilities available to AI experiences beyond Salesforce's own screens.
The underlying context, agency, action, governance, security and model capabilities that help make that openness useful and controlled.
AI Control Plane
The proposed common place to discover, register, observe and manage agents and AI.
The full architecture; the Control Plane is its cross-enterprise management layer, not a seventh trusted capability.
Salesforce says the architecture is being designed for headless access through MCP, APIs, Skills and Plug-ins, so its capabilities can extend into experiences such as Claude, Slack, Microsoft Teams and other AI surfaces. These are architectural intentions, not a promise that every integration is generally available today.
Benefits That Matter to Customers
Reuse instead of duplication. Shared context, actions and guardrails can reduce the need to build a separate integration and policy layer for every agent. The potential benefit is architectural; the effort still depends on the state of your existing data and processes.
More reliable execution. Pairing flexible reasoning with deterministic policy checks and authorised actions is better suited to workflows where a wrong promise or write-back has consequences.
Choice without losing control. A composable approach can support existing systems and different models, while a common management layer aims to make identity, observability and cost visible across AI experiences.
Build on current investments. Customers already using Salesforce data, metadata, workflows and permissions may be able to extend those foundations as eligible new capabilities arrive, rather than replace everything at once.
KVP View: Start with the Business, Not the Architecture Diagram
Our experience across Salesforce implementations and agentic AI planning points to the same recurring issue: the quality of customer data, definitions and permissions decides whether an AI use case is viable. The harness is a compelling way to reuse those foundations, but it cannot make inconsistent data or unclear ownership disappear.
For customers, we recommend choosing one consequential question — for example, whether a service request can be resolved or an order can be fulfilled — and mapping every source, decision rule, permitted action and escalation path. Evaluate the capabilities against that workflow, not as an all-at-once platform purchase.
For developers, we recommend keeping agent actions small and testable, expressing hard business rules outside open-ended prompts, applying least-privilege access, and instrumenting both successful and denied actions. Treat model selection as replaceable; version the business definitions, policies and integrations that make the result trustworthy.
How we plan to work with it: KVP intends to start with existing Salesforce foundations, assess where Data 360 and integrations can improve shared context, build one bounded Agentforce workflow with human escalation, and review emerging Control Plane capabilities as they become available. That is our proposed approach, not a claim of a completed harness deployment or measured customer outcome.
Five Practical Steps to Get Started
Choose a bounded workflow
Name the customer question, what a correct result looks like, and when a person must take over.
Map context and ownership
Locate the records, definitions, policies and real-time signals the workflow needs; correct quality gaps before connecting an agent.
Define safe actions
Expose only the necessary APIs and workflows; require explicit permissions and test denied as well as approved paths.
Make outcomes observable
Record what context was used, what the agent attempted, what it actually changed and the cost of each run.
Check current eligibility
Inventory existing Salesforce investments and confirm which harness and Control Plane capabilities are available in your region and edition before committing budget.
Official Salesforce Sources and Availability
As of September 2026, Salesforce says many foundational technologies are available now, while new capabilities and the unified experience are planned to begin rolling out in early Salesforce fiscal FY28. Pricing, packaging, eligibility, upgrade paths and regional availability have not all been announced. Base purchasing decisions on currently available products and confirm specifics with Salesforce.