Salesforce — “Salesforce Introduces the Trusted Enterprise AI Harness” (10 September 2026)
Tag: S-2026-09-10-salesforce-enterprise-ai-harness-control-plane Type: article (vendor newsroom “story”, salesforce.com/news, 10 Sep 2026; fetched in full) Author(s): Salesforce (quotes: Rohan Kumar, President, Chief Platform and Engineering Officer; Shawn Malhotra, CTO, Rocket Mortgage) Date of source: 2026-09-10 Date ingested: 2026-09-17 Authority weight: medium — dated primary from a listed vendor describing its own pre-release architecture; specific component and capability lists, but no shipped product, no pricing, no regulation or standard, one non-bank customer endorsement of the concept only Raw file: /_raw_sources/S-2026-09-10-salesforce-enterprise-ai-harness-control-plane.md
What it claims
Five days before Dreamforce (15–17 Sep 2026), Salesforce announced an “Enterprise AI Harness” — “a trusted foundation around AI that brings together what agents need to understand the business, reason and plan, take action, and operate within enterprise controls, without companies having to build and manage those capabilities separately for every agent or AI experience”. It comprises six “trusted capabilities” — Trusted Context (data, metadata, semantics, knowledge, signals, memory), Trusted Agency (reasoning, planning, state, memory, orchestration “combining flexible AI reasoning with deterministic controls where certainty is required”), Trusted Action (secure connection to applications, APIs, workflows, tools), Trusted Governance (“govern the data, metadata, policies, and processes AI relies on, with lineage, quality, guardrails, and controls”), Trusted Security (“identity, permissions, privacy, data protection, and runtime security to what AI can access and what agents are allowed to do”) and Trusted Models (model routing on accuracy, performance, cost) — drawn from Data 360, Informatica, MuleSoft and Agent Fabric, Tableau, Agentforce, Salesforce Guardian and the Salesforce Platform. Customers “can use the six together as one system or take only what they need … including third-party models, agents, and systems”.
Alongside it Salesforce introduces a new “AI Control Plane”: “a common place to see, manage, and control agents and AI across the enterprise”, enabling companies to “discover and register agents and AI capabilities, establish identity and policy, manage lifecycle, evaluate performance, observe behavior and outcomes, and control cost — across Salesforce and third-party AI”. The harness is “being built headlessly from the ground up” (MCP, APIs, Skills, Plug-ins) so its capabilities surface in Claude, Slack, Microsoft Teams and Agentforce, under the “AIforce” strategy. A “unified, modern experience” is promised with role-specific views (context/governance for data leaders, identity/policy for security leaders, agents/models/actions for builders).
The argument for the harness is that AI reasoning “can be open-ended, but enterprise execution often cannot be”, and that proprietary context, not model choice, is the durable differentiator (Kumar quote). Rocket Mortgage’s CTO endorses composability: “We don’t want to bet our future on one closed stack”.
Availability: “Many of the technologies that form the foundation … are available today, with new capabilities and the unified experience planned to begin rolling out in early fiscal FY28”; packaging, pricing and upgrade paths “will be announced closer to general availability”; “Customers should base purchasing decisions on products and services currently available.”
Notable quotes
- “Alongside those capabilities, a new AI Control Plane gives businesses one place to see, manage, and control agents and AI as they spread across the enterprise.” (para 3)
- “It enables companies to discover and register agents and AI capabilities, establish identity and policy, manage lifecycle, evaluate performance, observe behavior and outcomes, and control cost — across Salesforce and third-party AI.” (AI Control Plane section)
- “AI reasoning can be open-ended, but enterprise execution often cannot be.” (Why an Enterprise AI Harness Matters)
- “Customers should base purchasing decisions on products and services currently available.” (Availability footnote)
What’s speculative vs. asserted
Asserted (reliable as event facts): the announcement date; the six-pillar naming; the component products named; the headless/MCP design intent; the Rocket Mortgage quote; the FY28 rollout language and the forward-looking disclaimer.
Vendor-asserted / forward-looking (unverified): every capability of the AI Control Plane (discovery, registration, identity, policy, lifecycle, evaluation, observation, cost) — none is shown shipped; “across … third-party AI” scope; “deterministic controls where certainty is required”; “runtime security”.
Not stated (gaps): any regulation, standard, regulator or certification (no EU AI Act, ISO/IEC 42001, NIST AI RMF, DORA, SS1/23); any live customer deployment of the Control Plane; how the Control Plane’s agent register relates to the AWS AgentCore, Microsoft, Okta, IBM, Broadcom, Dataiku, Archer and WSO2 registers already in the vault; data-residency or EU-sovereignty specifics; pricing.
Vault inference (not a source claim): this is a CRM/application-platform vendor entering the cross-vendor “agent control plane” race; the “system of record for the AI-system register” question this vault has tracked since the 15 Sep scan now has one more contender, with the longest stated lead time (rollout from ~Feb 2027).
Topics this feeds
- AI Governance Platforms — adds an application-platform vendor (Salesforce) to the standalone agent-control-plane cluster (Okta, IBM, Broadcom, Dataiku, Archer, WSO2), with an explicit “third-party AI” scope claim, a headless/MCP delivery model and a 2027 rollout horizon; reinforces the “which inventory is the system of record” open question.
- Salesforce — company page created 2026-09-17 (third Salesforce-authored source in the vault).
Open questions raised
- Which components of the AI Control Plane exist today versus FY28, and will the agent register be exposed for import into a GRC or AI-governance system of record (or claim that role itself)?
- No regulation or standard is named: will “Trusted Governance” carry EU AI Act / ISO/IEC 42001 mappings, or remain a product-pillar label?
- Is Rocket Mortgage (or any EU/UK regulated firm) a live deployment, or an endorsement of the architecture only?
- How does the Salesforce Control Plane interoperate with the hyperscaler registers (AgentCore, Foundry, Vertex) it will run alongside — and, under DORA, is Salesforce then an ICT third party for agent governance itself?