Salesforce's AI agent control plane ships in FY28
Salesforce introduced the Trusted Enterprise AI Harness on September 10, 2026. The unified experience rolls out in FY28. Here's what to build yourself now.
Salesforce announced an AI agent control plane on September 10, and the most useful line in the announcement is the availability date. The Trusted Enterprise AI Harness is Salesforce's bid to govern every agent in your business — including the ones you did not buy from Salesforce. The unified experience begins rolling out in early fiscal 2028, which for Salesforce starts in February 2027. That is a long time to run your agents on nothing.
What actually happened
Salesforce introduced the Harness as six "trusted" capabilities — context, agency, action, governance, security, and models — sitting under a new AI Control Plane. Per Salesforce's own description, the control plane lets you discover and register agents, set identity and policy, manage lifecycle, evaluate performance, observe behavior, and control cost across both Salesforce and third-party AI.
The parts are not new products. Salesforce says the Harness draws on Data 360, Informatica, MuleSoft, Agent Fabric, Tableau, Agentforce, Salesforce Guardian, and the Salesforce Platform, stitched into a common architecture. Many of those technologies are available today; the unified experience and the new capabilities are the FY28 part.
It is built headlessly and exposed through MCP, APIs, Skills, and plug-ins, and Salesforce names Claude, Slack, and Microsoft Teams alongside Agentforce as surfaces it expects to reach. VentureBeat reports that no SKUs, per-user rates, consumption rates, or licensing model have been announced, and cites its own July 2026 survey finding that 85% of enterprises already run two or more agent orchestration platforms, averaging 3.1.
Why agent governance matters for your business
The problem Salesforce is describing is real and it is already in your building. If you run a support agent in one tool, a lead-router in another, and a coding agent in your repo, you have three permission models, three cost lines, and no single place to answer "what is this thing allowed to touch." The pitch is correct. The delivery date is seventeen months out.
So build the cheap version now. An agent registry is a table: name, owner, purpose, the credentials it holds, the systems it can write to, and a review date. Identity is per-agent service accounts with scoped tokens, never a shared admin key. Cost control is a hard spend cap per key plus an alert, not a monthly invoice you read in arrears. Observability is structured logs of every tool call the agent makes, kept somewhere you can query. None of that requires a platform, and all of it survives whatever you buy later.
The other thing to watch is the word headless. MCP, APIs, and skills mean the Harness wants to reach agents that live outside Salesforce — which is good for you, right up until the governance layer and the CRM are the same renewal. Keep your agent definitions, prompts, and tool schemas in your repo. If the control plane is portable, use it. If your agents only exist inside it, you did not buy governance, you bought a dependency.
Key takeaways
- Salesforce introduced the Trusted Enterprise AI Harness and an AI Control Plane on September 10, 2026
- Six capabilities — context, agency, action, governance, security, models — assembled from Data 360, Informatica, MuleSoft, Agent Fabric, Tableau, Agentforce, and Guardian
- Foundation tech is available today; the unified experience rolls out in early fiscal 2028, starting February 2027
- No pricing, SKUs, or licensing model announced yet, per VentureBeat
- Headless delivery via MCP, APIs, Skills, and plug-ins, reaching Claude, Slack, and Teams
- Build the manual version now: agent registry, per-agent scoped credentials, hard spend caps, queryable tool-call logs
You do not need a control plane to know what your agents can touch. You need a list and a budget cap. We build agent systems with scoped service accounts, per-key spend limits, and tool-call logs you can actually query — in your repo, on your infrastructure, portable to whatever platform wins. See how we build vendor-agnostic automation, or tell us which agents are already running unsupervised.
Sources: Salesforce News: Trusted Enterprise AI Harness, VentureBeat.
- #salesforce
- #ai-agents
- #agent-governance
- #mcp
- #vendor-risk
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Cohere's translation model beats DeepL. You can't sell it.
North Small Translate scores 83.60 on WMT26 against DeepL NextGen's 81.37, then ships under CC BY-NC. Read the license before you plan your localization.
Read itCognition's SWE-2 lands within a point of Fable 5.1
SWE-2 scores 50.0% on FrontierCode 1.1 at 64% lower cost than Fable 5.1, post-trained on an open 2.8T Chinese base model. What that means for your coding agent budget.
Read it