Toolspublished

Salesforce Pushes Agents Into CRM Workflows as NIST Turns to Identity Controls

The shift is not just from answering questions to taking actions across business systems. It puts permissions, audit trails, change control and traffic capacity ahead of model choice for teams trying to move beyond pilots.

By 3 min read
Salesforce Pushes Agents Into CRM Workflows as NIST Turns to Identity Controls
Salesforce Pushes Agents Into CRM Workflows as NIST Turns to Identity Controls

Listen to this story

The audio brief

About 1:35
0:001:35
Read transcript
Salesforce is moving AI agents from answering questions to carrying out CRM work: qualifying sales leads, resolving service cases, booking appointments, and even underwriting risk. Its Winter ’27 release says those agents can use governed customer data while operating across Slack, Microsoft Teams, voice systems, and older enterprise software. That turns an agent into a connected workload, not just a chat window. Salesforce says its Adaptive Experiences and Dynamic Plans capability is already in production with four customers, including PowerSchool, where more than 550 users are involved. The important shift is toward control. NIST’s Center for AI Standards and Innovation has started an AI Agent Standards Initiative, with early work focused on security, and on identity and authorization for software and AI agents. In practical terms, every agent needs a recognizable identity, narrowly scoped permissions, and records that show what it did and why. If an agent changes as it learns from production activity, operators also need evaluations and regression gates before new behavior reaches sensitive workflows. Scale adds another constraint. Cloudflare reported a 1,700 percent rise in daily agent requests on its network, while Cisco tests found agents could generate up to 450 percent more traffic per task than humans. Plume also measured a roughly 2,000 percent year-over-year increase in large-language-model data volume among participating homes with regular traffic. The question ahead is whether identity controls, testing, observability, bandwidth, and latency can mature as quickly as agent deployment.

Story brief

3 key points

Salesforce’s Winter ’27 release expands agents from conversational assistants into governed CRM operations, while NIST’s new AI Agent Standards Initiative focuses on identity, authorization and security. The shift raises practical deployment requirements: distinct agent identities, auditable actions and regression testing for systems that may learn from production. Infrastructure is another constraint: Cloudflare...

  1. 01

    NIST’s early work includes an AI-agent security request for information and a draft paper on software and agent identity and authorization.

  2. 02

    Salesforce says Adaptive Experiences & Dynamic Plans is live at four customers, including PowerSchool with more than 550 users.

  3. 03

    CoreWeave claims Serverless RL cuts costs up to 40% and improves training speed 1.4×; the figures are company-supplied.

Salesforce’s Winter ’27 release positions AI agents to qualify sales pipelines, resolve service cases, book appointments and underwrite risk. Once software can carry a workflow across CRM, collaboration tools, voice and older enterprise systems, the hard question is no longer only whether its model can reason: it is what the agent is allowed to do, on whose authority, and how its actions are checked.

Salesforce says its agents can use governed CRM data while operating through Slack, Microsoft Teams, voice and legacy systems. That design turns an agent from a chat interface into a connected workload: it can draw context from a system of record and act through multiple channels. Salesforce also reported that its Adaptive Experiences & Dynamic Plans capability is in production at four customers, including PowerSchool with more than 550 users.

The control plane moves alongside the agent

NIST’s Center for AI Standards and Innovation has announced an AI Agent Standards Initiative intended to support trust and interoperability. Its early work is security-heavy: a request for information on AI-agent security sits alongside a draft concept paper on software and AI-agent identity and authorization.

The mechanism is straightforward. A workflow agent needs an identity that connected systems can recognize, permissions that limit its actions, and records that let operators reconstruct what happened. NIST’s focus does not settle how those controls will work, but it signals where emerging standards work is concentrating as vendors push autonomy deeper into business software.

Traffic is becoming an operating constraint
1,700%Growth in daily AI-agent requests

Cloudflare reported that daily AI-agent requests on its network increased 1,700% between June 2025 and May 2026. It also estimated that more than half of internet traffic is non-human.

Up to 450%More traffic per task in Cisco tests

Cisco testing cited by Cablefax found that agents can generate up to 450% more total traffic per task than humans.

Learning in production changes the release process

CoreWeave has launched unified agentic AI capabilities that connect training, inference, observability and reinforcement learning in a production feedback loop. Observability is the ability to trace and inspect what a system did. In this model, it is not merely a diagnostic tool: it is part of the proposed route for finding failures and preventing regressions as agent workflows change.

CoreWeave says its Serverless RL approach can cut costs by up to 40% and increase training speed by about 1.4 times without sacrificing quality. Those are company-supplied performance claims, rather than an independent measure of reliability in enterprise deployments. The more consequential operational implication is that a system designed to improve while handling production work needs explicit tests and gates before altered behavior reaches sensitive workflows.

Automation also becomes a network load

The infrastructure signal is broader than Salesforce’s product release. Plume found that 22% of active Plume-enabled homes had regular large-language-model traffic in April, up from 19% a year earlier. Among homes with that traffic, it measured roughly 2,000% year-over-year growth in associated data volume and a 364% increase in time connected.

Three questions for a workflow-agent rollout

  • Can each agent receive a distinct identity and narrowly scoped permissions across the CRM, ticketing and scheduling systems it can reach?
  • If the vendor continuously tunes or learns from production activity, what traces, evaluations and regression gates identify changed behavior before it affects a live workflow?
  • For voice, contact-center and remote-user deployments, how much upstream bandwidth and latency headroom is needed if automated tasks create more sustained traffic?

Sources

  1. marketscale.comAI agents are moving from chatbots to running workflows, and ops will feel it first