
What Salesforce actually announced
Let me start with the thing itself, because the name is doing a lot of work. Salesforce is calling this the "Trusted Enterprise AI Harness," and it is not a single product you buy. It is a common, composable architecture meant to give agents everything they need to work reliably and securely, so companies do not have to build and manage those capabilities separately for every agent.
The pitch rests on one bet, stated plainly by Rohan Kumar, Salesforce's President and Chief Platform and Engineering Officer:
"The Agentic Enterprise won't be defined by which model a company chooses. Models will continue to change, and intelligence will increasingly be available everywhere. What will differentiate an enterprise is the trusted, proprietary context it brings to that intelligence, starting with the customer, and its ability to securely turn that context into action."
Salesforce frames the whole problem with one deceptively simple question: "Can we fulfill this order today?" No single system has the full answer. CRM knows the customer, ERP knows inventory, contracts hold the commitments, analytics defines the business terms, and policy sets what can actually be promised. The harness is meant to connect open-ended AI reasoning to the business rules and controls needed for a predictable answer.
If you have read Salesforce's Einstein Trust Layer material, this diagram will feel familiar. It shows how a prompt travels through security stages (secure data retrieval, grounding, masking, toxicity detection, audit trail) before and after it reaches a model. The harness is essentially this idea, scaled up from one prompt to every agent and action in the company.

The six trusted capabilities
Here is the core of it. Salesforce says trust is designed into each of the six capabilities from the start, and you can use them together as one system or take only the pieces you need. Picture them as six layers wrapping a single agent, with the Control Plane sitting on top.

Rather than paraphrase the marketing, here is what each one actually does, mapped to that "can we fulfill this order?" example.
| Capability | What it does | In the order example |
|---|---|---|
| Trusted Context | Brings together data, metadata, semantics, knowledge, real-time signals, and memory into a shared understanding of the customer and business | Knows the customer, their contract and entitlements, and what "available" inventory means for them |
| Trusted Agency | Reasoning, planning, state, memory, and orchestration, blending flexible AI with deterministic controls | Decides whether the order can be fulfilled and what happens next, following the rules that need certainty |
| Trusted Action | Securely connects agents to apps, APIs, workflows, and business processes so they can execute | Reserves inventory, updates the order, triggers fulfillment, or hands off to a person |
| Trusted Governance | Governs the data, metadata, policies, and processes AI relies on, with lineage, quality, and guardrails | Ensures the answer is based on trusted information and the right handling policy |
| Trusted Security | Applies identity, permissions, privacy, and runtime security to what agents can see and do | Ensures the agent only sees authorized data and takes authorized actions |
| Trusted Models | Intelligent model routing by accuracy, performance, cost, and business need | Routes the task to the right intelligence, and lets you swap models as tech evolves |
Read down that list and you will notice something: these are the same concerns anyone who has put an agent on a live queue already worries about. Grounding it in real data. Letting it act, but only within limits. Making sure it cannot see what it should not. It is a genuinely coherent framework, and naming the pieces this cleanly is useful even if you never touch Salesforce's version of it.
The AI Control Plane
The newer idea, and the one I think matters most, is the AI Control Plane. As agents multiply across an organisation, you need a consistent way to know what AI is running, how it is performing, what it is allowed to do, and what it costs. The Control Plane is meant to be that single pane of glass.

Concretely, the Control Plane lets you discover and register agents, establish identity and policy, manage lifecycle, evaluate performance, observe behaviour and outcomes, and control cost. The interesting part is that it is meant to span both Salesforce and third-party AI, so a company running several agent platforms could, in theory, govern all of them from one place.
That ambition is grounded in a real pain. Per VentureBeat's launch analysis, enterprises already run an average of 3.1 agent platforms, with 85% running two or more. If you have watched that sprawl happen, a neutral control layer over all of it sounds like exactly what you want.
Why the framing lands: trust is the real bottleneck
The reason this announcement is more than repackaging is that it targets the actual thing stopping agents from reaching production. It is not model quality anymore. It is trust. Rebecca Wettemann, CEO and principal analyst at Valoir, put it well:
"We've really moved from AI FOMO to AI FOMU, fear of messing up. People worry that autonomous agents will run amok unharnessed and either do something deleterious to the business or run up a million-dollar token bill. It's the vendors that succeed with governance and trust that will succeed in getting customers from interesting AI pilots to AI in production."
That fear is the whole ballgame. I have watched confident-sounding bots quietly hand out wrong answers, which is why every rollout should be tested against real history before it touches a customer. A named enterprise customer, Rocket Mortgage's CTO Shawn Malhotra, echoed the openness angle Salesforce is selling. He told Forkast his team does not want to bet its future on one closed stack, and wants the freedom to swap models as the landscape shifts.
The honest read: what is real, what is still roadmap
Here is where a fair post has to slow down. The vision is strong, but this is a launch, not a shipping product, and the coverage picked up several real gaps worth knowing before you build a plan around it.
First, the timeline. The unified experience does not begin rolling out until early fiscal FY28. In AI terms, that is glacial, and VentureBeat's Carl Franzen made the obvious point: customers are unlikely to sit and wait for a branded harness while they are already building elsewhere, so it will need to be especially compelling on price, ease, or capability to pull them back.
Second, the pieces are not all built. To Salesforce's credit, Rohan Kumar said so directly:
"I wouldn't say we have all the capabilities, just to be fair, because some of these things, especially when it comes to trusted security and the FinOps piece, there are things that we need to go build."
Third, the messaging is not fully settled. diginomica's Stuart Lauchlan noticed that cost control appears in two places at once (folded into Trusted Governance in the briefing, but sitting inside the Control Plane in the written announcement), a small tell that the framework is fresh.
Then there is the definition fight. The rest of the industry uses "agent harness" to mean the tool, memory, and context scaffolding around one model. Salesforce stretched it to cover context and governance across the whole enterprise, and Kumar conceded the classic definition is "very limited" in his view. Whether that is visionary or a buzzword expansion over Data 360 plus MuleSoft plus Tableau plus Agentforce is a fair debate.
And finally, the lock-in question that the whole "open and composable" pitch invites. Forkast's Dana Ellison named it cleanly:
"The challenge for decision-makers is balancing this promise of composability against the risk of vendor lock-in. If you centralize your agent governance on a single platform, you are effectively betting on that platform's ability to remain neutral and interoperable as the market evolves."
None of this makes the harness a bad idea. It makes it an early one. The category-defining ambition is real, and Lauchlan even reads it as the start of a two-year "sea change" where every big vendor races to claim it does context and trust better. Just do not confuse a compelling architecture diagram with something you can deploy this quarter.
Do you actually need a harness?
This is the question I would actually sit with, because the answer splits cleanly by who you are.
If you are a large enterprise running many agents across many systems, and your real problem is governance at scale (who is allowed to do what, how do I see it all, how do I not get a surprise token bill), then a control plane like this is aimed squarely at you, and it is worth tracking through FY28.
But a lot of people searching for "Salesforce AI harness" do not have that problem yet. They have a narrower one: I need one AI agent on my support queue that is safe to turn on. For that job, an entire enterprise harness is a heavier answer than the question needs. This is the classic "this is infrastructure, but I wanted an employee" gap. The harness is the scaffolding; you still have to assemble it, connect your data, and wait for the parts.

The interesting thing is that the guardrails Salesforce is bundling into a six-layer architecture are, for a support agent, already table stakes elsewhere. This is where I would reach for a ready-to-work teammate instead of a platform to build on. At eesel, the same concerns show up as defaults, not layers you assemble:
- Trust before go-live: instead of a governance framework, you run a simulation over hundreds of your real past tickets. It replays them and scores the agent's answers against what your team actually sent, so you see the gaps before a customer does. That directly answers the "will it run amok" fear.
- Scoped action and approvals: you decide exactly which tickets it handles and which actions it can take, with a human-in-the-loop approval step for anything sensitive.
- Observability out of the box: every run is logged with its status and outcome, so "observe behaviour" is a screen you open, not a capability you provision.

There is one more piece worth naming, because the harness makes a big deal of being built headlessly and reachable through MCP, APIs, and plug-ins, including into Claude and Slack. That agent-friendly, programmable surface is a genuinely good instinct, and eesel took the same one. eesel ships a real CLI (@eesel/cli) plus an MCP server for every workspace, so the same teammate you configure in the dashboard can be driven from a terminal or a script. You can connect an integration, edit its standing instructions, list and approve human-in-the-loop actions (eesel approvals), and read its run history (eesel activity) entirely from the command line, and a coding agent like Claude Code or Cursor can do the same. It is the same "govern the agent as code" idea the Control Plane is reaching for, available today for one teammate rather than in FY28 for the whole fleet. The eesel CLI docs go deep if you want the full command set.
Try eesel on your Salesforce queue
If your goal is a safe, working AI agent on Salesforce Service Cloud rather than a multi-year platform bet, this is where eesel fits. It joins your existing queue as a teammate: it reads your help center and past tickets, drafts or auto-sends replies on the cases you choose, and keeps every action scoped, approved, and logged. Because it connects to Service Cloud Cases directly, you can simulate it on your own history this afternoon and see the numbers before anything goes live, no FY28 rollout required.

It is usage-based, billed per ticket handled rather than per seat, with a free trial that needs no credit card, which is a very different commitment than "wait for pricing to be announced closer to GA." If you are weighing the broader Salesforce AI stack, my Agentforce pricing breakdown and roundup of Agentforce alternatives are the natural next reads. And if you want the deeper "how does AI actually work on a support queue" version, start with AI for customer service or the difference between an AI agent and a rule-based chatbot.
The Trusted Enterprise AI Harness is a serious, well-argued vision for governing agents at enterprise scale, and I will be genuinely curious to see it ship. But for the specific job of getting one trustworthy support agent live, you do not have to build the harness first. You can just hire the teammate.
Frequently Asked Questions
What is the Salesforce AI Harness?
When is the Salesforce AI Harness available and how much does it cost?
How is the AI Harness different from Agentforce or Einstein?
What is an AI harness in general?
Do I need the Salesforce AI Harness to run a safe support agent?

Article by
Rama Adi Nugraha
Rama is a software engineer at eesel AI with two years of experience writing about B2B SaaS, AI tools, and customer support technology. Based in Bali, Indonesia, he brings a developer's perspective to product comparisons — cutting through marketing copy to what the integrations and APIs actually do.








