Salesforce is selling two ideas at once: ready-made agents that can do named jobs, and a control plane meant to govern agents built across different systems. The agents are the visible part. The rollout date for the shared harness is the detail buyers should read twice.
Salesforce announced its Enterprise AI Harness on September 11, 2026. A separate product release introduced new Agentforce agents for service, employee support, commerce, sales and back-office work.
The control plane is the real architecture story
Salesforce says its AI Control Plane will discover and register agents, establish identity and policy, manage lifecycle, evaluate performance, observe behavior and outcomes, and control cost. The scope includes Salesforce and third-party AI.
That is the right problem to attack. A company with ten agent products should not need ten incompatible permission models and ten separate audit exports.
The named agents map to jobs, not demos
| Work area | Agentforce direction | Buyer check |
|---|---|---|
| Service | Resolve and escalate customer work | Knowledge scope, handoff and correction path |
| Employee support | Handle HR and IT requests | Identity, sensitive fields and approval |
| Commerce | Guide shopper and merchant workflows | Catalog truth, pricing and checkout authority |
| Sales | Research, prospect and pursue goals over time | Outreach permission and account ownership |
| Back office | Coordinate operational work | System-of-record writes and segregation of duties |
Long-horizon work needs a stop authority
Salesforce describes a runtime with memory, durable execution and dynamic steering so an agent can pursue a goal for days or weeks. A salesperson could ask an agent to rescue at-risk deals and let it adapt as new information arrives.
The longer the job lasts, the more likely that permissions, ownership or data change underneath it. Every long-running plan needs a fresh authorization check before an external message, record update or financial action.
The availability sentence matters
Salesforce says many foundation technologies are available today. It also says new capabilities and the unified experience are planned to begin rolling out in early fiscal FY28. The company will publish more detail on availability, packaging, pricing and upgrade paths closer to general availability.
That means buyers should not treat the full diagram as one product they can deploy today. Salesforce itself tells customers to base purchasing decisions on products and services currently available.
A control-plane proof checklist
- List every agent, owner, model, environment and connected system.
- Show the effective identity and policy for one real user request.
- Pause an agent, revoke a credential and confirm the change propagates.
- Export one trace from trigger through model, tool call, approval and outcome.
- Set a cost ceiling and verify that enforcement stops work rather than only warning.
- Test a third-party agent so the demo is not limited to Salesforce-native paths.
Our ChatGPT Work Data Agent permission guide separates discover, read, export and write rights. The same layers belong in any control plane. Our agent cost-controls guide covers budget enforcement.
Company outcomes are evidence of customers, not your baseline
Salesforce lists customer results for named agents. Those figures are company-reported examples tied to particular deployments. They do not establish a general resolution or revenue rate for a new buyer.
The cleanest proof uses the same employee, the same restricted record and the same policy across two agents: one built in Salesforce and one supplied by a third party. Revoke the employee’s access, then repeat the request through both paths. A shared control plane should deny both attempts and produce traces that point to the same policy decision.
Run the same test with a cost ceiling and an emergency pause. If enforcement works only for the Salesforce-native agent, the product is a strong Salesforce console but not yet the cross-system control plane described in the announcement.
My take: buy the control, not the catalog
Job-ready agents can shorten implementation time, but catalogs age quickly. Identity, policy, observability, cost and lifecycle controls are the parts that should survive a model or vendor change.
I would pilot the control plane with one low-risk agent and one third-party agent. If the same revocation, trace and cost limit work for both, the architecture is earning its name.
Read the primary material
Checked September 12, 2026. Product scope, availability and customer outcomes come from Salesforce. Control tests are MustHave.ai analysis.