The takeaway
As agent deployments multiply, the control layer around identity, context, actions, and auditability becomes as important as the model itself.
Why it matters for builders
Builders should test whether identities, permissions, policy decisions, tool calls, model routing, and costs remain traceable across every connected agent workflow.
Salesforce Builds a Control Plane for Enterprise AI Agents
Salesforce is moving the enterprise AI conversation from individual copilots to the control layer that governs many agents, models, and tools at once. The company has previewed a Trusted Enterprise AI Harness and a central AI Control Plane ahead of Dreamforce.
Six layers around every agent
The harness groups six capabilities: Trusted Context, Trusted Agency, Trusted Action, Trusted Governance, Trusted Security, and Trusted Models. Together, they describe a shared operating layer for agents that need to understand business data, plan work, call systems, and operate within permissions.
Trusted Context is the foundation. It combines customer data, metadata, semantics, knowledge, real-time signals, memory, and business processes. Trusted Agency covers reasoning, planning, state, collaboration, and orchestration. Trusted Action connects agents to applications, APIs, workflows, and tools. Governance and Security add lineage, quality, policies, identity, privacy, and runtime controls. The Models layer is designed to route work based on accuracy, performance, cost, and business requirements.
According to AI Weekly’s report, Salesforce says the architecture is open and composable, with support for third-party models, agents, and systems.
A control plane for agent sprawl
The companion AI Control Plane is the more consequential piece for technical teams. Salesforce says it will provide a registry for agents and AI capabilities, identity and policy controls, lifecycle management, performance evaluation, behavioral observability, and cost control across Salesforce and external systems.
That is a direct response to a practical production problem: organizations are accumulating agents faster than they are building ways to inventory, audit, and shut them down. A central view is useful only if it follows identity and permissions through every model call, MCP server, API, and workflow. Otherwise, it becomes another dashboard that reports activity without controlling it.
What builders should watch
Salesforce says many underlying technologies are already available, while new capabilities and the unified experience are planned to begin rolling out in early fiscal 2028. Packaging, pricing, and upgrade paths are still to be announced.
For automation teams, the signal is clear: the durable asset is not just the model. It is the governed context and action layer around the model. When evaluating an enterprise harness, test whether a revoked identity stops downstream tool calls, whether every action is traceable to a policy decision, and whether model routing preserves the same audit trail.
Salesforce is betting that enterprise AI will be won by the platform that makes agents trustworthy across systems, not merely by the model with the best benchmark score.

The Automation Brief
Read 5 AI stories instead of 50.
The essential moves in AI agents, models, automation and infrastructure — filtered for builders and operators, with the part that actually matters.
No noise. Unsubscribe anytime.
Editorial notes
Stefan Trbojevic
n8n Lab Editorial
12 September 2026
12 September 2026
AI disclosure: AI assisted with research and drafting. Factual claims are reviewed by an editor.

