Short answer: Salesforce’s Trusted Enterprise AI Harness is a proposed composable foundation around enterprise AI, organized around six capabilities: Trusted Context, Trusted Agency, Trusted Action, Trusted Governance, Trusted Security and Trusted Models. Salesforce also announced an AI Control Plane for discovering, governing, evaluating and controlling AI. Many of the underlying technologies are available today, while the unified experience is planned to begin rolling out in early fiscal FY28. Pricing, packaging, upgrade paths and availability are not yet fully specified, so teams should evaluate the architecture and verify the currently purchasable pieces separately.
What Salesforce is announcing
Salesforce describes the Harness as a common layer that helps agents understand business context, reason and plan, act across systems and operate within enterprise controls. The announcement draws on technologies across Data 360, Informatica, MuleSoft and Agent Fabric, Tableau, Agentforce, Salesforce Guardian and the Salesforce Platform.
The important distinction is between an architecture description and a generally available product bundle. Salesforce says existing customers will have an upgrade path as new capabilities become available, but it also says that additional availability, packaging, pricing and upgrade details will be announced closer to general availability. A procurement decision should therefore name the exact product, edition, contract and region being evaluated.
The six capabilities in plain language
| Capability | Enterprise question | Marketing and operations check |
|---|---|---|
| Trusted Context | What customer, knowledge, metadata, semantics, memory and real-time signals can the agent use? | Are audience, consent, account and campaign definitions current and permissioned? |
| Trusted Agency | How does the agent reason, plan, remember, collaborate and orchestrate? | Which steps are flexible reasoning and which require deterministic approval? |
| Trusted Action | Which APIs, tools, workflows and business processes can the agent invoke? | Can an action change a lead, audience, offer or customer record, and who approves it? |
| Trusted Governance | How are lineage, quality, policies, guardrails and controls applied? | Can a team explain why a recommendation or automated action was allowed? |
| Trusted Security | Which identity, permissions, privacy and runtime controls apply? | Does the agent see only the data and perform only the actions its role permits? |
| Trusted Models | How can the organization route work to different models? | What accuracy, cost, latency, data-use and fallback rule selects a model? |
Why the AI Control Plane matters
Salesforce says the AI Control Plane gives businesses a common place to discover and register agents and AI capabilities, establish identity and policy, manage lifecycle, evaluate performance, observe behavior and outcomes, and control cost. That is an operating and governance proposition, not a guarantee that one console will expose every third-party system on day one.
Before adopting a control-plane workflow, ask for the object-level audit trail: agent identity, model and version, retrieved context, tool calls, policy decisions, human handoffs, outcome, latency and cost. A dashboard that only counts conversations or executions is not enough to review a consequential customer or marketing action.
Headless access changes the integration question
The announcement says the Harness is being built headlessly, with capabilities accessible through MCP, APIs, Skills and Plug-ins. Salesforce names Claude, Slack, Microsoft Teams, Agentforce and other AI experiences as possible surfaces. This can extend enterprise context and actions beyond a traditional CRM screen, but it also increases the number of integration and permission boundaries to test.
- List each external surface and the identity it uses.
- Define the minimum data and action scope for each skill, API or plug-in.
- Log failed, denied and escalated actions, not only successful completions.
- Keep a human approval path for irreversible customer, spend or compliance actions.
- Test prompt injection, stale context, duplicate actions and partial system failure.
Available now versus planned
Salesforce’s wording is deliberately conditional. The foundations are described as available today, but new capabilities and the unified experience are planned to begin rolling out in early fiscal FY28. The announcement does not provide a complete package matrix or universal customer timeline. Treat the following as a verification checklist:
- Which named capability is enabled in the current org?
- Which license, edition, Data 360 or Agentforce dependency applies?
- Is the capability generally available, pilot, preview or limited to a customer agreement?
- Which regions and data-residency options are supported?
- Which APIs, MCP tools, Skills or Plug-ins are documented and supported?
- How are evaluation, observability, retention and cost controls priced?
How marketers should evaluate it
A marketer should start with one bounded workflow, such as lead triage, campaign-brief preparation or customer-service handoff. Define the business outcome, allowed data, action authority, human review point and failure response before connecting a model. Measure qualified outcomes and operational quality; do not use model activity, generated text or agent count as a proxy for revenue.
For broader agent architecture context, see the site’s agent harness framework. For commercial decision context, keep the separate Salesforce pricing and buying checklist distinct; this article does not estimate Harness pricing.
Turn the architecture into a bounded pilot
A capability map is useful only when it changes an operating decision. Choose one workflow with a clear owner and a reversible scope. A campaign-brief assistant, for example, might retrieve approved product facts and audience definitions, propose a brief and route it to a human. It should not publish an offer, change a bid or send a customer message until the organization has defined an approval boundary.
Write the pilot contract before connecting data:
- Input boundary: list the objects, documents, fields and real-time signals the workflow may read.
- Reasoning boundary: state where the model may summarize or propose, and where deterministic rules must decide.
- Action boundary: list every write, API call, message or workflow invocation, with an approval owner.
- Evidence boundary: require citations, source timestamps or record identifiers when an operator needs to verify the output.
- Stop boundary: define the conditions that force a human handoff, rollback or disablement.
This structure connects the six capabilities to a real control loop. Context determines what the agent can see; agency determines how it reasons; action determines what it can do; governance and security determine whether the step is allowed; and model routing determines which intelligence is suitable for the task.
Questions for data, security and marketing owners
Different teams will evaluate the Harness from different risk positions. Data owners should ask how semantics, lineage, freshness and conflicting records are represented. Security owners should ask how identity, permissions, data residency, encryption and runtime isolation are enforced. Marketing owners should ask whether the context includes the approved audience, offer, consent and measurement definitions rather than only a convenient CRM snapshot.
Ask for a demonstrable audit trail, not just a feature list. For a single test run, a reviewer should be able to identify the agent, model, retrieved context, instructions, tool calls, policy checks, human interventions, outcome, latency and cost. If the platform cannot expose a field, name that limitation in the operating procedure. A control plane that hides uncertainty can create more risk than a smaller workflow with explicit manual checks.
Headless access makes this more important. MCP servers, APIs, Skills and Plug-ins can place an action in a surface that is not the Salesforce UI. Keep the same identity and policy model across Claude, Slack, Microsoft Teams, Agentforce and other surfaces; do not assume that an action is safe because it was initiated from a familiar chat window.
How to measure an enterprise AI workflow
Measure the workflow at three levels. First, measure operational quality: task completion, factual error, escalation, latency, failure recovery and human rework. Second, measure control quality: unauthorized-action attempts, policy denials, sensitive-data exposure, audit completeness and rollback success. Third, measure the business outcome that the workflow was designed to influence, such as qualified opportunities, resolved cases or time to approved campaign launch.
Keep activity metrics separate from outcomes. Number of prompts, generated briefs or agent executions can describe adoption, but they do not prove productivity or revenue. Compare against a defined baseline or holdout where appropriate, record the measurement window and note other changes to pricing, staffing, media or process. This keeps a vendor architecture claim from becoming an unsupported ROI claim.
Implementation sequence
- Inventory the current data, tools, agents, permissions and business owners.
- Select one workflow with low blast radius and a measurable outcome.
- Configure read access first; test stale, contradictory and missing context.
- Add one reversible action with explicit approval and logging.
- Run adversarial tests for prompt injection, privilege escalation, duplicate writes and partial outage.
- Review quality, controls, cost and human workload before expanding scope.
This sequence is compatible with a composable architecture, but it is not a Salesforce product requirement. The implementation still depends on the exact products, contracts, connectors and data model available to the customer.
Frequently asked questions
Is the Trusted Enterprise AI Harness one product?
Salesforce presents it as a composable architecture and unified experience in development. The exact product bundle and purchase path remain subject to later availability and packaging details.
Does it replace Agentforce?
The announcement positions the Harness as a foundation that includes Agentforce technologies among other Salesforce capabilities. It does not say that Agentforce is replaced.
Can I buy it today?
Some underlying technologies may be available today, but Salesforce says pricing, packaging, availability and upgrade details will be announced closer to general availability. Verify the exact offer with Salesforce and the applicable customer agreement.
Bottom line: the announcement is significant because it frames enterprise AI as a reusable context, action, governance, security and model layer. The practical buying decision still depends on the currently available product surface, contract, region, permissions, auditability and total cost of the workflow.