Salesforce Previews an AI Harness to Govern Agents Across Enterprise Stacks

The planned architecture combines data context, agent controls and model routing rather than asking companies to standardize on one AI stack. Its price and final commercial model remain unknown.

By 3 min read
Salesforce Previews an AI Harness to Govern Agents Across Enterprise Stacks
Salesforce Previews an AI Harness to Govern Agents Across Enterprise Stacks

Listen to this story

The audio brief

About 1:44
0:001:44
Read transcript
Salesforce is previewing a cross-stack AI harness that could let enterprises govern agents without standardizing on one model vendor or orchestration platform. Its proposed Trusted Enterprise AI Harness combines business context, permissions, actions, security, evaluation, cost controls and model routing, with an AI Control Plane at the center. The control plane is meant to let administrators register agents, assign identities and policies, manage their lifecycles, observe behavior and outcomes, and evaluate performance—even when those agents come from third parties. Salesforce says companies could use the full architecture or connect individual pieces to existing systems through MCP, APIs, Skills and Plug-ins. That flexibility targets a fragmented market. A VentureBeat survey of 107 organizations found that 85 percent used at least two agent-orchestration platforms, with an average of 3.1 platforms per enterprise. Salesforce is positioning its proposal alongside Microsoft Agent 365 and AWS Bedrock AgentCore Harness, though AWS is more focused on runtime orchestration, context, tools and failure recovery. There is also a technical reason the surrounding harness matters. In a Salesforce preprint, optimizing the harness around a smaller Qwen model lifted success across seven enterprise-agent benchmarks from 29.2 percent to 78 percent without changing the model weights. A targeted on-policy approach reached 79.7 percent, while imitation achieved 63.1 percent. Customer availability is expected in early 2027, but pricing and licensing remain unknown. The key question is whether this composable layer can stay portable as the models and agents underneath it change.

Story brief

3 key points

Salesforce has previewed a cross-stack governance architecture that could let enterprises register, secure, evaluate and cost-manage internal and third-party agents through one AI Control Plane. The broader Trusted Enterprise AI Harness combines six layers spanning context, actions, permissions, security and model routing, with components exposed through MCP, APIs, Skills and Plug-ins. Availability is targeted for...

  1. 01

    Customer availability is expected in early 2027; packaging, usage or per-user rates, minimum commitments and licensing remain undisclosed.

  2. 02

    Salesforce says the control plane will cover third-party AI, including agent registration, identities, policies, lifecycle, evaluation, observability and cost controls.

  3. 03

    A VentureBeat survey found 85% of 107 organizations used at least two orchestration platforms, averaging 3.1 per enterprise.

Salesforce is betting that the hard part of enterprise AI is no longer picking a model. Its newly previewed Trusted Enterprise AI Harness is designed to give companies a shared layer for the business data, permissions, actions, governance and cost controls that sit around agents running across different systems.

The company previewed the architecture ahead of Dreamforce, with broad customer availability expected in early 2027. Salesforce has not disclosed its specific product packages, usage or per-user rates, minimum commitments, or final licensing model—leaving the buying decision well behind the product pitch.

A harness that reaches beyond the runtime

In the conventional sense, a harness is the surrounding software that gives a language model instructions, tools, context and an environment in which to operate. Salesforce is using the term for a wider architecture: six connected capabilities called Trusted Context, Trusted Agency, Trusted Action, Trusted Governance, Trusted Security and Trusted Models.

What Salesforce says the layers cover

  • Context: customer and enterprise data, metadata, business meaning, knowledge, real-time signals and memory.
  • Agency and action: planning, orchestration and connections to applications, APIs, workflows and tools.
  • Governance and security: data lineage, policies, permissions, privacy, data protection and runtime security.
  • Models: routing work among models based on factors including accuracy, performance, cost and business requirements.

The control-plane contest

The accompanying AI Control Plane is the operational center of Salesforce’s proposal. It is intended to let administrators discover and register agents, set identities and policies, manage lifecycles, evaluate performance, observe behavior and outcomes, and control costs—even for third-party AI.

That puts Salesforce alongside Microsoft Agent 365, which is positioned to observe, govern and secure agents beyond Microsoft’s own ecosystem, and AWS’s Bedrock AgentCore Harness. AWS’s product sits closer to the narrower definition, managing an agent’s orchestration loop, tools, context window, persistent state and failure recovery while being surrounded by identity, memory, gateways, observability, evaluations and policy controls.

Salesforce’s distinction is that it wants to fold the control-plane and runtime jobs into a broader system that also defines the context agents consume and the actions they can take. The company says customers can use the full stack or combine individual components with their existing and third-party systems, exposing capabilities through MCP, APIs, Skills and Plug-ins.

Openness is the promise—and the test

The multi-vendor posture addresses a real deployment pattern, though the available survey is directional rather than a market-share estimate. In a July VentureBeat Intelligence survey of 107 organizations with at least 100 employees, 85% said they ran at least two agent-orchestration platforms, averaging 3.1 per enterprise; 53% expected their primary control plane to be hybrid by the end of 2026.

Salesforce’s own preprint offers a reason to take the layer around a model seriously, but also a warning about easy portability. Researchers reported that optimizing a technical harness around a smaller Qwen model lifted average success across seven enterprise-agent benchmarks from 29.2% to 78.0% without changing model weights. Yet fine-tuning that model to imitate a stronger model’s trajectories reduced success to 63.1%; a targeted on-policy approach reached 79.7%.

That study is a preprint, not a production evaluation of this new product, and it examines a much narrower kind of harness. Still, it underlines the question Salesforce must answer before launch: can a supposedly composable layer govern a changing mix of models and agents without needing substantial retuning whenever the intelligence beneath it changes?

Sources

  1. venturebeat.comMany models, many agents, many tasks: Salesforce’s new Enterprise AI Harness seeks to ground all in your shared business context
  2. venturebeat.comSalesforce unveils Trusted Enterprise AI Harness | VentureBeat

Loading discussion...