
Three companies already ship an agent control tower. Salesforce announced one last Wednesday that arrives in February 2027 at the earliest, with two of its six capabilities admittedly unbuilt.
That's the headline everyone will run with this week. It's also the least interesting thing in the announcement.
Vernon Keenan did the real audit over at SalesforceDevops.net, scoring what Rohan Kumar promised him three weeks ago against what actually landed: three delivered, two partial, three open. Go read it. His closing line is the one that stuck with me and with half my feed. Roadmap to invoice is the real test, and there are no receipts yet.
I want to pick up his last point, because I think he buried the most important thing in the piece and then, to his credit, called it the hardest.
The short version
Salesforce's enterprise AI harness names six capabilities, Trusted Context, Agency, Action, Governance, Security, and Models, with an AI Control Plane above them, composable packaging, and consumption pricing with no number attached. Kumar volunteered on the press call that security and the FinOps piece still need building. The gap that matters isn't the February 2027 date, it's that context is the only layer in the harness captured at write time, by the person making the decision, at the moment they make it. Everything else can be bolted on later. Intent can't. That turns a 2027 procurement story into a decision you are already making this quarter, whether you know it or not: where your team's reasoning gets written down, and whether that record is structured enough for an agent to read.
What actually got named
Quick version. Six capabilities, one control plane, bring your own security vendor, pay for what you use. Kumar said plainly that security and the FinOps console still need building, which is an unusually honest thing for a platform chief to volunteer six days before Dreamforce.
Keenan catches the thing worth catching: that list is an inventory of assets Salesforce already owns, reorganized around agents. Catalog, semantic model, CDP, MuleSoft, identity, Guardian. It isn't a blank-sheet answer to what an agent actually needs. Which is fine, most platform announcements are inventories, and I said something similar last month about the company deciding to be the layer underneath when it put its CRM inside Claude.
I've been building the small version of this for a year. Heidi is a company brain: one memory layer, agents that run in team chat, long jobs that take hours, a guard layer around every action, a ledger of what happened. Multi-tenant, not an internal tool. So I've had to answer the same six questions on a much smaller budget, and the ordering Salesforce arrived at is not the ordering the problem forces on you.
Two things get left off that list every time.
Exhaust is not intent
Kumar's compounding loop is that action exhaust flows back and thickens the context layer. Right instinct. But exhaust records what happened, not what was meant, and the gap between those two is where agents go confidently wrong.
Your catalog holds the what. Twenty years of validation rules, flows, and Apex hold the how. Nothing in your stack holds the why. Why discount approval routes through finance in EMEA and not AMER. Why the last three architects killed the integration that keeps getting proposed. Why that one validation rule exists and which edge case it was written for. That knowledge lives in people's heads, in Slack threads, and in contractors who rolled off in 2023.
An agent that inherits the what and the how without the why follows the rule perfectly right up to the moment the rule shouldn't apply. And it has no way to know.
Here's the part that makes this urgent rather than philosophical. You cannot retrofit the why.
Context is the only layer in the harness that has to be captured at write time, at the moment of decision, by the person who made it. Everything else you can bolt on later. A control plane is a read of systems that already exist. Model routing is a config change. Even governance can be layered on top of running agents, badly, but it can be. Intent can't. If you weren't recording it in 2024, it's gone, and a console shipping in February 2027 will not go find it for you.
So the decision that actually locks in this budget cycle isn't which vendor you buy. It's where your decisions get written down and whether that record is structured enough for an agent to read. We've had a decision log template on the site for a while and I used to pitch it as a way to train judgment. It's also the cheapest context capture there is.
In Heidi this shows up as a boring rewrite I keep prioritizing over flashier work. Signals stop being a display layer and become derived, entity-keyed, and graded by how strong the evidence behind them is. Every act carries a receipt. Outcomes get labeled and closed back against the decision that produced them. None of it demos well. All of it compounds, and none of it can be bought in a year.
Metering is ten percent of FinOps
Keenan's other sharp observation, and the one Ian Gotts pulled out in the comments: a console that shows you what your agents cost is a meter. Anyone who has run cloud FinOps knows the meter is the small part of the job. The work is modeling cost before you commit, and pricing the tradeoffs.
For agents the levers are specific and they're architectural, not console features. Which model handles which step. How much context loads per call. How often an agent is allowed to act on its own. Where a deterministic rule can replace a reasoning step entirely.
That last one is the biggest lever in the building and nobody markets it, because "we made the agent think less" is a bad slide. It's also true. Every decision your system makes the same way every time should be a rule, not a token spend. We pushed a deterministic decision layer into our guard so the model gets called for judgment and not for lookups.
If you didn't design the levers in, the FinOps console gives you a bill and a shrug. Salesforce lists model routing as the built-in lever, which is real, and it only pays off if the console can predict the effect of a change before you make it. Predicting is much harder than metering. That's the gap between February 2027 and something a CFO will sign against an open-ended consumption commitment.
The gate isn't confidence, it's reversibility
One more thing missing from the six.
Trusted Action is broken out as its own capability because action is where the CISO says no. Correct. But the practical question at runtime is never "is the model confident enough." It's "how bad is this if it's wrong, and can I take it back."
We gate on three axes: confidence, reversibility, and the strength of the evidence behind the signal that triggered the act. Draft an email, fully reversible, let it run. Update the CRM record, reversible with a receipt and an undo, let it run with a trail. Send money or touch the general ledger, not reversible, a human confirms.
That taxonomy is a product decision and it has to exist before the governance layer has anything to enforce. Security in the Salesforce list is identity, permissions, and data protection, which is who may act. Reversibility is what happens when they act wrong. Different question, and it's the one that decides how much autonomy you can actually ship. I wrote the design version of this argument in Undo Is a Design Primitive and The Receipt and the Work, and I'd hold to both.
Small detail with a long tail, and I keep coming back to it. The announcement names data leaders, security leaders, and builders. Keenan checked for the word Trailblazer. It isn't there.
Somebody has to curate the semantic model, register the agents, and run the tower. In most Salesforce shops that person is a declarative admin, and the harness was written as if they don't exist. Same shape as the collapse I keep writing about on the PM side, where the job stops being spec writing and becomes building the system the agents run inside. The admin who learns to curate context and set autonomy gates is the most valuable person in the org in eighteen months. Nobody is training them, and the vendor that figures out that training owns the rollout.
What I'd do this week
Don't wait for February 2027 to make a decision you're already making.
Pick one recurring decision your team makes. A pricing exception, an approval route, an escalation. Go look at where the reasoning behind it is currently written down. Not the outcome. The reasoning.
If the answer is a Slack thread, a meeting nobody recorded, or somebody's head, you've found the layer the harness can't sell you.
Start writing it somewhere an agent can read. That's the whole move. Everything else on the slide will still be for sale next year.
Sources: Vernon Keenan, SalesforceDevops.net, on the Salesforce enterprise AI harness and Rohan Kumar's scorecard · Salesforce
Frequently asked
What is the Salesforce enterprise AI harness?+
It is Salesforce's name for the full stack an enterprise agent needs to run safely: six capabilities, Trusted Context, Trusted Agency, Trusted Action, Governance, Security, and Models, with an AI Control Plane sitting above them. Packaging is composable, you can bring your own security vendor, and you pay for what you use. No price was given. Rohan Kumar said on the press call that the security piece and the FinOps piece still need building, and the window for the full thing is February 2027 at the earliest.
Why can't you retrofit context the way you can retrofit a control plane?+
Because context is the only layer captured at write time. A control plane is a read of systems that already exist, so it can be built later over anything. Model routing is a config change. Governance can be layered on top of agents that are already running. But the reason a decision was made only exists at the moment someone makes it, and only that person can record it. If it wasn't written down then, it is not recoverable from logs, schemas, or code. It is gone.
Isn't action exhaust enough to rebuild the why?+
No. Exhaust records what happened, not what was meant, and the gap between those two is exactly where agents go confidently wrong. You can reconstruct that a discount was approved. You cannot reconstruct that it was approved because a named customer had an open escalation that quarter and the VP wanted the renewal clean. An agent that inherits the what and the how without the why follows the rule perfectly right up to the moment the rule shouldn't apply.
Why is an agent FinOps console only part of the job?+
A console that shows what your agents cost is a meter, and metering is the small part of cloud FinOps. The work is modeling cost before you commit and pricing the tradeoffs. For agents the levers are architectural, not console features: which model handles which step, how much context loads per call, how often an agent may act on its own, and where a deterministic rule can replace a reasoning step. If those levers weren't designed in, the console gives you a bill and a shrug.
What should gate an autonomous agent action, confidence or reversibility?+
Reversibility, mostly. Confidence tells you how sure the model is, which is the wrong question at runtime. The right one is how bad this is if it's wrong and whether you can take it back. Draft an email, fully reversible, let it run. Update a CRM record, reversible with a receipt and an undo, let it run with a trail. Send money or touch the general ledger, not reversible, a human confirms. Security answers who may act. Reversibility answers what happens when they act wrong.
Who actually operates the harness inside a Salesforce shop?+
Nobody named in the announcement. It addresses data leaders, security leaders, and builders. The word Trailblazer does not appear. But somebody has to curate the semantic model, register the agents, and run the tower, and in most orgs that person is a declarative admin. The admin who learns to curate context and set autonomy gates is the most valuable person in the org in eighteen months, and nobody is training them yet.

Comments (0)
Sign in with LinkedIn to leave a comment.
Sign in with LinkedIn