Six trusted capabilities and a new AI Control Plane, built for an open and composable AI ecosystem
The Agentic Enterprise is changing how work gets done — and the role every person plays in it. As agents become part of how people work across every function of the business, they are taking on more complex work: understanding what is happening, deciding what to do next, taking action across systems, and working alongside people and other agents. That creates a new enterprise challenge: how do you give agents what they need to do that work reliably, securely, and at scale?
That’s the role of an Enterprise AI Harness, and it’s what Salesforce is building: a trusted foundation around AI that brings together what agents need to understand the business, reason and plan, take action, and operate within enterprise controls, without companies having to build and manage those capabilities separately for every agent or AI experience.
Salesforce’s Enterprise AI Harness brings together six capabilities spanning context, agency, action, governance, security, and models, delivered through a common, composable architecture and built on the customer relationships, processes, and controls already running the business. Alongside those capabilities, a new AI Control Plane gives businesses one place to see, manage, and control agents and AI as they spread across the enterprise. Customers can use the six together as one system or take only what they need, with Salesforce technology, their existing technology, or both, including third-party models, agents, and systems.
Why an Enterprise AI Harness Matters
Consider a seemingly simple customer question: “Can we fulfill this order today?”
No single system has the complete answer. CRM knows the customer and the relationship. ERP knows inventory and fulfillment. Contracts contain commitments and entitlements. Analytics provides business definitions. Policies determine what can be promised. Previous interactions provide critical memory. And business processes determine how the work should actually get done.
The challenge isn’t simply connecting those systems. An agent needs to understand all of that information in the context of this customer, at this moment — then determine the right action, securely take it, and operate within the policies and controls of the business. AI reasoning can be open-ended, but enterprise execution often cannot be. The Enterprise AI Harness connects that reasoning to the business rules, policies, and controls required for predictable execution.
An Enterprise AI Harness makes these capabilities reusable across the enterprise. Context can be shared across agents and models. Actions and workflows can be securely invoked wherever they’re needed. And governance and security can be applied consistently as AI moves across the business.
As people and agents work together, every interaction and action can also create new signals, outcomes, and memory that enrich the context available to what comes next — creating a compounding intelligence loop over time.
Models will continue to improve and become more broadly available. But an enterprise’s proprietary context is uniquely its own — its customers, knowledge, semantics, memory, processes, relationships, and history. As the underlying intelligence changes, that proprietary context compounds and becomes a durable source of differentiation.
Salesforce’s Enterprise AI Harness
This is the architecture enterprises need for the AI era — and it’s the architecture Salesforce has been building toward for decades. The trusted customer data, metadata, semantics, business logic, workflows, permissions, security, and governance that companies already rely on to run their businesses can now become the foundation for how AI understands, reasons, and acts.
Salesforce is drawing on the core technologies from across Data 360, Informatica, MuleSoft and Agent Fabric, Tableau, Agentforce, Salesforce Guardian and the Salesforce Platform through a common, composable architecture and unified experience for its Enterprise AI Harness. For existing Salesforce customers, the technologies they already use provide the foundation for this expansion, with an upgrade path to unlock new capabilities as they become available.
The Six Trusted Capabilities
Trust is designed into each of the six capabilities from the start. Together, they give AI what it needs to understand the business, determine what to do, take action, and operate within enterprise controls. For a question like “Can we fulfill this order today?”, each plays a different role.
Trusted Context brings together customer context with data, metadata, semantics, knowledge, real-time signals, memory, and an understanding of how work gets done across the enterprise. Grounded in governed enterprise data, it gives AI a shared understanding of the customer and the business around them. For the order, it means understanding the customer, their contract and entitlements, available inventory, and what “available” means for them.
Trusted Agency gives agents the reasoning, planning, state, memory, collaboration, and orchestration they need to pursue complex business outcomes — combining flexible AI reasoning with deterministic controls where certainty is required. It helps determine whether the order can be fulfilled and what needs to happen next, while following the business rules that require certainty.
Trusted Action securely connects AI to applications, APIs, workflows, tools, and business processes so agents can move from understanding what needs to happen to getting it done. It allows the agent to reserve inventory, update the order, trigger fulfillment, or engage a person when needed. The outcomes of those actions can then flow back into Trusted Context.
Trusted Governance helps enterprises govern the data, metadata, policies, and processes AI relies on, with lineage, quality, guardrails, and controls. It helps ensure the answer is based on trusted information and that the agent follows the policies governing how the order should be handled.
Trusted Security applies identity, permissions, privacy, data protection, and runtime security to what AI can access and what agents are allowed to do. It helps to ensure that the agent can only see the customer information and take the actions it is authorized to access.
Trusted Models gives enterprises the flexibility to securely connect the right model for each job, with intelligent model routing based on accuracy, performance, cost, and business requirements. It helps to ensure that the work can be routed to the right intelligence for the task, while giving the business flexibility to change models as technology evolves.
“The Agentic Enterprise won’t be defined by which model a company chooses. Models will continue to change, and intelligence will increasingly be available everywhere. What will differentiate an enterprise is the trusted, proprietary context it brings to that intelligence — starting with the customer — and its ability to securely turn that context into action,” said Rohan Kumar, President, Chief Platform and Engineering Officer. “That’s what we’re building with Salesforce’s Enterprise AI Harness: a system where every interaction and action can create new context and intelligence, making the enterprise’s context richer over time while operating with the security, governance, and control businesses need to trust AI at scale.”
A New AI Control Plane for the Enterprise
As agents and AI spread across the enterprise, businesses need a consistent way to know what AI is operating across their organization, how it is performing, what it is allowed to do, and how much it costs.
Salesforce is introducing a new AI Control Plane to give businesses a common place to see, manage, and control agents and AI across the enterprise. It enables companies to discover and register agents and AI capabilities, establish identity and policy, manage lifecycle, evaluate performance, observe behavior and outcomes, and control cost — across Salesforce and third-party AI.
This gives enterprises a consistent layer of visibility and control as AI expands across teams, applications, models, and systems — without requiring every agent or AI experience to be managed separately.
Built for Choice and Openness
Salesforce’s Enterprise AI Harness is designed to meet customers wherever and however they choose to build and use AI.
A new unified, modern experience will make it easier for different teams to work with the capabilities most relevant to them — from context and governance for data leaders, to identity and policy for security leaders, to agents, models, and actions for builders.
The Enterprise AI Harness is also being built headlessly from the ground up, with capabilities accessible through technologies including MCP, APIs, Skills and Plug-ins. This allows Salesforce capabilities to extend beyond traditional Salesforce applications and into the AI experiences where people already work — including Claude, Slack, Microsoft Teams, Agentforce, and other AI experiences — advancing the broader AIforce strategy to bring Salesforce to any AI, agent, app, or surface.
“AI is moving faster than any technology we’ve seen — which is exactly why composability matters so much to us. We don’t want to bet our future on one closed stack; we want the freedom to adapt as the landscape shifts. That’s what resonated with us about Salesforce’s new Enterprise AI Harness,” said Shawn Malhotra, CTO, Rocket Mortgage.
Availability
Many of the technologies that form the foundation of Salesforce’s Trusted Enterprise AI Harness are available today, with new capabilities and the unified experience planned to begin rolling out in early fiscal FY28.
Existing customers will be able to upgrade eligible Salesforce investments to unlock new capabilities as they become available.
Additional details on availability, packaging, pricing, and upgrade paths will be announced closer to general availability.
Pricing and packaging are subject to change. Availability may vary by region and is governed by customer agreements. Customers should base purchasing decisions on products and services currently available.






