Salesforce Previews an AI Harness to Govern Agents Across Enterprise Stacks
The planned architecture combines data context, agent controls and model routing rather than asking companies to standardize on one AI stack. Its price and final commercial model remain unknown.
Listen to this story
The audio brief
Story brief
3 key pointsSalesforce has previewed a cross-stack governance architecture that could let enterprises register, secure, evaluate and cost-manage internal and third-party agents through one AI Control Plane. The broader Trusted Enterprise AI Harness combines six layers spanning context, actions, permissions, security and model routing, with components exposed through MCP, APIs, Skills and Plug-ins. Availability is targeted for...
- 01
Customer availability is expected in early 2027; packaging, usage or per-user rates, minimum commitments and licensing remain undisclosed.
- 02
Salesforce says the control plane will cover third-party AI, including agent registration, identities, policies, lifecycle, evaluation, observability and cost controls.
- 03
A VentureBeat survey found 85% of 107 organizations used at least two orchestration platforms, averaging 3.1 per enterprise.
Salesforce is betting that the hard part of enterprise AI is no longer picking a model. Its newly previewed Trusted Enterprise AI Harness is designed to give companies a shared layer for the business data, permissions, actions, governance and cost controls that sit around agents running across different systems.
The company previewed the architecture ahead of Dreamforce, with broad customer availability expected in early 2027. Salesforce has not disclosed its specific product packages, usage or per-user rates, minimum commitments, or final licensing model—leaving the buying decision well behind the product pitch.
A harness that reaches beyond the runtime
In the conventional sense, a harness is the surrounding software that gives a language model instructions, tools, context and an environment in which to operate. Salesforce is using the term for a wider architecture: six connected capabilities called Trusted Context, Trusted Agency, Trusted Action, Trusted Governance, Trusted Security and Trusted Models.
What Salesforce says the layers cover
- Context: customer and enterprise data, metadata, business meaning, knowledge, real-time signals and memory.
- Agency and action: planning, orchestration and connections to applications, APIs, workflows and tools.
- Governance and security: data lineage, policies, permissions, privacy, data protection and runtime security.
- Models: routing work among models based on factors including accuracy, performance, cost and business requirements.
The control-plane contest
The accompanying AI Control Plane is the operational center of Salesforce’s proposal. It is intended to let administrators discover and register agents, set identities and policies, manage lifecycles, evaluate performance, observe behavior and outcomes, and control costs—even for third-party AI.
That puts Salesforce alongside Microsoft Agent 365, which is positioned to observe, govern and secure agents beyond Microsoft’s own ecosystem, and AWS’s Bedrock AgentCore Harness. AWS’s product sits closer to the narrower definition, managing an agent’s orchestration loop, tools, context window, persistent state and failure recovery while being surrounded by identity, memory, gateways, observability, evaluations and policy controls.
Salesforce’s distinction is that it wants to fold the control-plane and runtime jobs into a broader system that also defines the context agents consume and the actions they can take. The company says customers can use the full stack or combine individual components with their existing and third-party systems, exposing capabilities through MCP, APIs, Skills and Plug-ins.
Openness is the promise—and the test
The multi-vendor posture addresses a real deployment pattern, though the available survey is directional rather than a market-share estimate. In a July VentureBeat Intelligence survey of 107 organizations with at least 100 employees, 85% said they ran at least two agent-orchestration platforms, averaging 3.1 per enterprise; 53% expected their primary control plane to be hybrid by the end of 2026.
Salesforce’s own preprint offers a reason to take the layer around a model seriously, but also a warning about easy portability. Researchers reported that optimizing a technical harness around a smaller Qwen model lifted average success across seven enterprise-agent benchmarks from 29.2% to 78.0% without changing model weights. Yet fine-tuning that model to imitate a stronger model’s trajectories reduced success to 63.1%; a targeted on-policy approach reached 79.7%.
That study is a preprint, not a production evaluation of this new product, and it examines a much narrower kind of harness. Still, it underlines the question Salesforce must answer before launch: can a supposedly composable layer govern a changing mix of models and agents without needing substantial retuning whenever the intelligence beneath it changes?
Sources
- venturebeat.comMany models, many agents, many tasks: Salesforce’s new Enterprise AI Harness seeks to ground all in your shared business context
- venturebeat.comSalesforce unveils Trusted Enterprise AI Harness | VentureBeat
Loading discussion...
Reader comments
Newest comments first. Replies stay oldest first.