Salesforce’s AI Control Plane is a roadmap—not a shipped control surface
The six-part Enterprise AI Harness puts semantics, identity, policy, evaluation and cost in one architecture, but buyers still need a capability-by-capability availability map.
Salesforce has introduced a Trusted Enterprise AI Harness organized around six capabilities: context, agency, action, governance, security and models. Alongside it, the company is proposing an AI Control Plane for discovering agents, assigning identity and policy, managing lifecycle, evaluating performance, observing outcomes and controlling cost across Salesforce and third-party AI. That is a useful operating model for enterprise data agents—but the announcement is also explicit that the unified experience is not generally available today. Salesforce says rollout is planned to begin in early fiscal FY28, with packaging and pricing details to come later.
Why the architecture matters for data agents
The strongest part of the design is its separation of responsibilities. “Trusted Context” includes data, metadata, semantics, knowledge, real-time signals and memory. “Trusted Security” covers identity, permissions, privacy and runtime controls. “Trusted Governance” covers lineage, quality, policies and guardrails. For analytics teams, this is a reminder that natural-language access is not one feature: business meaning, access enforcement and evidence about how an answer was produced are different controls and should be tested separately. Salesforce describes those responsibilities as distinct capabilities in the same composable architecture.
The proposed Control Plane is broader than a model gateway. Salesforce says it should register agents and AI capabilities, manage identity and policy, evaluate performance, observe behavior and outcomes, and track cost across first- and third-party systems. The company also says the harness is being built headlessly, with access through MCP, APIs, Skills and plug-ins, and names Claude, Slack, Microsoft Teams and Agentforce as target experiences. Those cross-vendor and headless claims are part of the Sept. 10 announcement.
The buying question is availability
Teams should not convert the six labels directly into a procurement checklist marked “present.” Salesforce says many foundation technologies are available now, but new capabilities and the unified experience are planned for early FY28. It also says existing customers will be able to upgrade eligible investments as capabilities arrive, while availability, packaging, pricing and upgrade paths will be announced closer to general availability. The availability section makes those limits explicit.
A practical evaluation therefore needs a second column beside every architectural promise: what can an administrator configure and verify today? Ask which agents can already be discovered, where policy is enforced, whether identity follows each tool call, which evaluations run continuously, what outcome telemetry is retained and which costs can be attributed to an agent. Then ask for the dated rollout path for every gap.
Salesforce’s announcement is notable because it frames enterprise AI around shared context and control rather than around one model. Its immediate value, however, is architectural: it gives data and security teams a vocabulary for separating semantics, permissions, actions and oversight. Treat the future Control Plane as a roadmap until those controls can be demonstrated in the tenant. Salesforce itself advises customers to base purchasing decisions on products and services currently available.
sources
- Salesforce Introduces the Trusted Enterprise AI Harnesswww.salesforce.com
comments · 0