Salesforce AI Harness: the Trusted Enterprise AI Harness explained

Rama Adi Nugraha
Written by

Rama Adi Nugraha

Katelin Teen
Reviewed by

Katelin Teen

Last edited September 11, 2026

Expert Verified
Illustration of the Salesforce Trusted Enterprise AI Harness wrapping an AI agent in six trust layers under an AI Control Plane

What Salesforce actually announced

Let me start with the thing itself, because the name is doing a lot of work. Salesforce is calling this the "Trusted Enterprise AI Harness," and it is not a single product you buy. It is a common, composable architecture meant to give agents everything they need to work reliably and securely, so companies do not have to build and manage those capabilities separately for every agent.

The pitch rests on one bet, stated plainly by Rohan Kumar, Salesforce's President and Chief Platform and Engineering Officer:

"The Agentic Enterprise won't be defined by which model a company chooses. Models will continue to change, and intelligence will increasingly be available everywhere. What will differentiate an enterprise is the trusted, proprietary context it brings to that intelligence, starting with the customer, and its ability to securely turn that context into action."

Salesforce frames the whole problem with one deceptively simple question: "Can we fulfill this order today?" No single system has the full answer. CRM knows the customer, ERP knows inventory, contracts hold the commitments, analytics defines the business terms, and policy sets what can actually be promised. The harness is meant to connect open-ended AI reasoning to the business rules and controls needed for a predictable answer.

If you have read Salesforce's Einstein Trust Layer material, this diagram will feel familiar. It shows how a prompt travels through security stages (secure data retrieval, grounding, masking, toxicity detection, audit trail) before and after it reaches a model. The harness is essentially this idea, scaled up from one prompt to every agent and action in the company.

Salesforce's Einstein Trust Layer workflow, showing a prompt moving from CRM apps through secure retrieval, grounding, masking and audit stages before reaching models, as taken from Salesforce
Salesforce's Einstein Trust Layer workflow, showing a prompt moving from CRM apps through secure retrieval, grounding, masking and audit stages before reaching models, as taken from Salesforce

The six trusted capabilities

Here is the core of it. Salesforce says trust is designed into each of the six capabilities from the start, and you can use them together as one system or take only the pieces you need. Picture them as six layers wrapping a single agent, with the Control Plane sitting on top.

The six trusted capabilities of the Salesforce AI Harness wrapping one AI agent, under the AI Control Plane
The six trusted capabilities of the Salesforce AI Harness wrapping one AI agent, under the AI Control Plane

Rather than paraphrase the marketing, here is what each one actually does, mapped to that "can we fulfill this order?" example.

CapabilityWhat it doesIn the order example
Trusted ContextBrings together data, metadata, semantics, knowledge, real-time signals, and memory into a shared understanding of the customer and businessKnows the customer, their contract and entitlements, and what "available" inventory means for them
Trusted AgencyReasoning, planning, state, memory, and orchestration, blending flexible AI with deterministic controlsDecides whether the order can be fulfilled and what happens next, following the rules that need certainty
Trusted ActionSecurely connects agents to apps, APIs, workflows, and business processes so they can executeReserves inventory, updates the order, triggers fulfillment, or hands off to a person
Trusted GovernanceGoverns the data, metadata, policies, and processes AI relies on, with lineage, quality, and guardrailsEnsures the answer is based on trusted information and the right handling policy
Trusted SecurityApplies identity, permissions, privacy, and runtime security to what agents can see and doEnsures the agent only sees authorized data and takes authorized actions
Trusted ModelsIntelligent model routing by accuracy, performance, cost, and business needRoutes the task to the right intelligence, and lets you swap models as tech evolves

Read down that list and you will notice something: these are the same concerns anyone who has put an agent on a live queue already worries about. Grounding it in real data. Letting it act, but only within limits. Making sure it cannot see what it should not. It is a genuinely coherent framework, and naming the pieces this cleanly is useful even if you never touch Salesforce's version of it.

The AI Control Plane

The newer idea, and the one I think matters most, is the AI Control Plane. As agents multiply across an organisation, you need a consistent way to know what AI is running, how it is performing, what it is allowed to do, and what it costs. The Control Plane is meant to be that single pane of glass.

The Salesforce AI Control Plane and the six jobs it does: discover and register agents, set identity and policy, manage lifecycle, evaluate performance, observe behaviour, and control cost
The Salesforce AI Control Plane and the six jobs it does: discover and register agents, set identity and policy, manage lifecycle, evaluate performance, observe behaviour, and control cost

Concretely, the Control Plane lets you discover and register agents, establish identity and policy, manage lifecycle, evaluate performance, observe behaviour and outcomes, and control cost. The interesting part is that it is meant to span both Salesforce and third-party AI, so a company running several agent platforms could, in theory, govern all of them from one place.

That ambition is grounded in a real pain. Per VentureBeat's launch analysis, enterprises already run an average of 3.1 agent platforms, with 85% running two or more. If you have watched that sprawl happen, a neutral control layer over all of it sounds like exactly what you want.

Why the framing lands: trust is the real bottleneck

The reason this announcement is more than repackaging is that it targets the actual thing stopping agents from reaching production. It is not model quality anymore. It is trust. Rebecca Wettemann, CEO and principal analyst at Valoir, put it well:

"We've really moved from AI FOMO to AI FOMU, fear of messing up. People worry that autonomous agents will run amok unharnessed and either do something deleterious to the business or run up a million-dollar token bill. It's the vendors that succeed with governance and trust that will succeed in getting customers from interesting AI pilots to AI in production."

That fear is the whole ballgame. I have watched confident-sounding bots quietly hand out wrong answers, which is why every rollout should be tested against real history before it touches a customer. A named enterprise customer, Rocket Mortgage's CTO Shawn Malhotra, echoed the openness angle Salesforce is selling. He told Forkast his team does not want to bet its future on one closed stack, and wants the freedom to swap models as the landscape shifts.

The honest read: what is real, what is still roadmap

Here is where a fair post has to slow down. The vision is strong, but this is a launch, not a shipping product, and the coverage picked up several real gaps worth knowing before you build a plan around it.

First, the timeline. The unified experience does not begin rolling out until early fiscal FY28. In AI terms, that is glacial, and VentureBeat's Carl Franzen made the obvious point: customers are unlikely to sit and wait for a branded harness while they are already building elsewhere, so it will need to be especially compelling on price, ease, or capability to pull them back.

Second, the pieces are not all built. To Salesforce's credit, Rohan Kumar said so directly:

"I wouldn't say we have all the capabilities, just to be fair, because some of these things, especially when it comes to trusted security and the FinOps piece, there are things that we need to go build."

Third, the messaging is not fully settled. diginomica's Stuart Lauchlan noticed that cost control appears in two places at once (folded into Trusted Governance in the briefing, but sitting inside the Control Plane in the written announcement), a small tell that the framework is fresh.

Then there is the definition fight. The rest of the industry uses "agent harness" to mean the tool, memory, and context scaffolding around one model. Salesforce stretched it to cover context and governance across the whole enterprise, and Kumar conceded the classic definition is "very limited" in his view. Whether that is visionary or a buzzword expansion over Data 360 plus MuleSoft plus Tableau plus Agentforce is a fair debate.

And finally, the lock-in question that the whole "open and composable" pitch invites. Forkast's Dana Ellison named it cleanly:

"The challenge for decision-makers is balancing this promise of composability against the risk of vendor lock-in. If you centralize your agent governance on a single platform, you are effectively betting on that platform's ability to remain neutral and interoperable as the market evolves."

None of this makes the harness a bad idea. It makes it an early one. The category-defining ambition is real, and Lauchlan even reads it as the start of a two-year "sea change" where every big vendor races to claim it does context and trust better. Just do not confuse a compelling architecture diagram with something you can deploy this quarter.

Do you actually need a harness?

This is the question I would actually sit with, because the answer splits cleanly by who you are.

If you are a large enterprise running many agents across many systems, and your real problem is governance at scale (who is allowed to do what, how do I see it all, how do I not get a surprise token bill), then a control plane like this is aimed squarely at you, and it is worth tracking through FY28.

But a lot of people searching for "Salesforce AI harness" do not have that problem yet. They have a narrower one: I need one AI agent on my support queue that is safe to turn on. For that job, an entire enterprise harness is a heavier answer than the question needs. This is the classic "this is infrastructure, but I wanted an employee" gap. The harness is the scaffolding; you still have to assemble it, connect your data, and wait for the parts.

Two approaches side by side: building the six-layer Salesforce harness (GA early FY28, assemble yourself) versus hiring a ready-to-work eesel AI teammate that goes live in about 30 minutes
Two approaches side by side: building the six-layer Salesforce harness (GA early FY28, assemble yourself) versus hiring a ready-to-work eesel AI teammate that goes live in about 30 minutes

The interesting thing is that the guardrails Salesforce is bundling into a six-layer architecture are, for a support agent, already table stakes elsewhere. This is where I would reach for a ready-to-work teammate instead of a platform to build on. At eesel, the same concerns show up as defaults, not layers you assemble:

  • Trust before go-live: instead of a governance framework, you run a simulation over hundreds of your real past tickets. It replays them and scores the agent's answers against what your team actually sent, so you see the gaps before a customer does. That directly answers the "will it run amok" fear.
  • Scoped action and approvals: you decide exactly which tickets it handles and which actions it can take, with a human-in-the-loop approval step for anything sensitive.
  • Observability out of the box: every run is logged with its status and outcome, so "observe behaviour" is a screen you open, not a capability you provision.
The eesel activity log showing agent runs with approved, rejected, pending and resolved statuses across Zendesk tickets and chats
The eesel activity log showing agent runs with approved, rejected, pending and resolved statuses across Zendesk tickets and chats

There is one more piece worth naming, because the harness makes a big deal of being built headlessly and reachable through MCP, APIs, and plug-ins, including into Claude and Slack. That agent-friendly, programmable surface is a genuinely good instinct, and eesel took the same one. eesel ships a real CLI (@eesel/cli) plus an MCP server for every workspace, so the same teammate you configure in the dashboard can be driven from a terminal or a script. You can connect an integration, edit its standing instructions, list and approve human-in-the-loop actions (eesel approvals), and read its run history (eesel activity) entirely from the command line, and a coding agent like Claude Code or Cursor can do the same. It is the same "govern the agent as code" idea the Control Plane is reaching for, available today for one teammate rather than in FY28 for the whole fleet. The eesel CLI docs go deep if you want the full command set.

Try eesel on your Salesforce queue

If your goal is a safe, working AI agent on Salesforce Service Cloud rather than a multi-year platform bet, this is where eesel fits. It joins your existing queue as a teammate: it reads your help center and past tickets, drafts or auto-sends replies on the cases you choose, and keeps every action scoped, approved, and logged. Because it connects to Service Cloud Cases directly, you can simulate it on your own history this afternoon and see the numbers before anything goes live, no FY28 rollout required.

The eesel onboarding flow showing an AI teammate being connected to a helpdesk, Slack, and a shareable chat link
The eesel onboarding flow showing an AI teammate being connected to a helpdesk, Slack, and a shareable chat link

It is usage-based, billed per ticket handled rather than per seat, with a free trial that needs no credit card, which is a very different commitment than "wait for pricing to be announced closer to GA." If you are weighing the broader Salesforce AI stack, my Agentforce pricing breakdown and roundup of Agentforce alternatives are the natural next reads. And if you want the deeper "how does AI actually work on a support queue" version, start with AI for customer service or the difference between an AI agent and a rule-based chatbot.

The Trusted Enterprise AI Harness is a serious, well-argued vision for governing agents at enterprise scale, and I will be genuinely curious to see it ship. But for the specific job of getting one trustworthy support agent live, you do not have to build the harness first. You can just hire the teammate.

Frequently Asked Questions

What is the Salesforce AI Harness?
The Salesforce Trusted Enterprise AI Harness is a composable architecture, announced at Dreamforce on 10 September 2026, that gives AI agents shared business context and lets them act on it safely. It bundles six trusted capabilities (context, agency, action, governance, security, models) plus a new AI Control Plane for managing agents across the enterprise. It sits around Agentforce, not inside it.
When is the Salesforce AI Harness available and how much does it cost?
Many of the foundational technologies are available today, but the new capabilities and the unified experience begin rolling out in early fiscal FY28 (early 2027). Salesforce has not disclosed pricing or packaging yet; those details come closer to general availability. For a sense of current Salesforce AI costs, see the Agentforce pricing breakdown.
How is the AI Harness different from Agentforce or Einstein?
Agentforce is the agent platform that builds and runs the agents; the harness is the trust-and-infrastructure layer around them. It draws on Data 360, MuleSoft, Tableau, the Einstein Trust Layer, and Agentforce rather than replacing them, and its AI Control Plane can also govern non-Salesforce agents.
What is an AI harness in general?
Salesforce's own explainer defines an agent harness as the software infrastructure wrapped around an AI model to manage its lifecycle, context, tools, memory, and safety limits: "not the brain that does the thinking" but the environment it operates in. Salesforce's Enterprise AI Harness stretches that definition to cover context and governance across the whole company.
Do I need the Salesforce AI Harness to run a safe support agent?
Not necessarily. A full enterprise harness makes sense if you are governing dozens of agents across many systems. If your job is a safe, working support agent, a ready-to-work teammate like eesel ships the guardrails as defaults: it simulates on your past tickets, scopes what it can do, keeps human approvals, and logs every action, and it connects to Salesforce Service Cloud in minutes.

Share this article

Rama Adi Nugraha

Article by

Rama Adi Nugraha

Rama is a software engineer at eesel AI with two years of experience writing about B2B SaaS, AI tools, and customer support technology. Based in Bali, Indonesia, he brings a developer's perspective to product comparisons — cutting through marketing copy to what the integrations and APIs actually do.

Related Posts

All posts →
Illustration of a satellite orbiting the Moon, feeding stacked crater, ice and volcanic data layers into a foundation model that two scientists study
Trending

NASA-IBM Lunar Foundation Model: the open-source Moon AI, explained

NASA and IBM just open-sourced a foundation model trained only on Moon data. It beats a bigger generic model at finding ice and craters. Here is what it is, and the lesson underneath it.

Alicia Kirana UtomoAlicia Kirana UtomoSep 11, 2026
Illustration of a self-hosted AI agent runtime running as a single binary
Trending

ZeroClaw review: the open-source AI agent runtime, honestly tested

An honest ZeroClaw review: what the open-source, Rust-based AI agent runtime does brilliantly, where its security story wobbles, and who should skip it.

Rama Adi NugrahaRama Adi NugrahaJul 19, 2026
Illustrated hero banner for a hands-on review of Paperclip, the open-source AI agent control plane
Trending

Paperclip review: the open-source AI agent runtime, tested

An honest Paperclip review: what the open-source control plane for running a company of AI agents does brilliantly, where its support story falls short, and who should actually run it.

Rama Adi NugrahaRama Adi NugrahaJul 20, 2026
Illustrated hero banner for a hands-on review of NemoClaw, NVIDIA's governed AI agent runtime
Trending

NemoClaw review: NVIDIA's governed AI agent runtime, tested

An honest NemoClaw review: what NVIDIA's open-source governed agent runtime does brilliantly, where its alpha-stage security story wobbles, and who should actually run it.

Alicia Kirana UtomoAlicia Kirana UtomoJul 20, 2026
Shadow, the AI interface for Mac, review cover illustration
Trending

Shadow review (2026): the AI interface for Mac

My hands-on Shadow review: the bot-free AI interface for Mac that transcribes meetings on-device, runs custom Skills from a shortcut, and costs $8 a month.

Alicia Kirana UtomoAlicia Kirana UtomoJul 8, 2026
Two people having a natural conversation with an AI voice assistant, sound waves flowing between them
Trending

GPT-Live-1: OpenAI's full-duplex voice model, explained

What GPT-Live-1 actually is: OpenAI's full-duplex voice model that listens and speaks at once, now in ChatGPT and the API at $0.05 per minute.

Alicia Kirana UtomoAlicia Kirana UtomoSep 11, 2026
Illustration of Meta Muse, a personal AI agent, running errands inside a secure cloud computer
Trending

What is Meta Muse? Meta's personal AI agent, explained

Meta Muse is a personal AI agent that shops, books, and emails for you inside its own Secure VM. Here is what it does, how it works, and where it fits.

Alicia Kirana UtomoAlicia Kirana UtomoSep 9, 2026
Wonderful AI pricing breakdown illustration in deep electric blue
Trending

Wonderful AI pricing in 2026: what an enterprise AI OS really costs

Wonderful AI pricing is quote-only, with one public number: a $2.5M/year AWS listing. Here is what that buys, what it hides, and when to skip it.

Rama Adi NugrahaRama Adi NugrahaSep 9, 2026
Wonderful AI enterprise AI OS explainer hero banner
Trending

What is Wonderful AI? Inside the $5B enterprise AI OS

Wonderful AI is an enterprise 'AI OS' that runs agents across voice, chat and legacy systems. Here is what it does, who it is for, and what it costs.

Alicia Kirana UtomoAlicia Kirana UtomoSep 9, 2026

Ready to hire your AI teammate?

Set up in minutes. No credit card required.

Get started free