What should an enterprise build once and reuse across every AI agent?
Salesforce's Trusted Enterprise AI Harness names six shared capabilities and a control plane. The same layers show up at AWS, Microsoft and Google. Which ones you should own.
Listen to this article · 5 min
AI-generated narration of the full article.

The first AI agent in an enterprise is expensive. The second one should be cheaper, but often is not, because every team rebuilds the same foundations: how the agent gets business context, how it takes actions safely, how it is governed and how anyone can see what it did.
That is the problem Salesforce set out to name in September with its Trusted Enterprise AI Harness. The announcement is worth reading less as a Salesforce roadmap and more as a description of the reusable layers every enterprise will need, whichever vendors it uses.
What Salesforce announced
On September 13, Salesforce described an Enterprise AI Harness as “a trusted foundation around AI” that gives agents what they need to understand the business, reason, act and operate within enterprise controls, “without companies having to build and manage those capabilities separately for every agent.”
It names six capabilities: Trusted Context, Trusted Agency, Trusted Action, Trusted Governance, Trusted Security and Trusted Models. Alongside them, a new AI Control Plane is meant to let companies discover and register agents, establish identity and policy, manage lifecycle, evaluate performance, observe behavior and control cost, across Salesforce and third-party AI. Salesforce says the harness is being built “headlessly”, reachable through MCP, APIs, Skills and plug-ins, including from Claude, Slack and Microsoft Teams.
On timing, Salesforce is explicit: many of the foundation technologies are available today, while new capabilities and the unified experience are planned to begin rolling out in early fiscal year 2028, with packaging and pricing to be announced closer to general availability. Availability may vary by region.
The same layers, everywhere
Put Salesforce’s six capabilities next to the other September announcements and the overlap is hard to miss:
- Context: Salesforce’s Trusted Context, Microsoft’s work context and connectors, the data stores in Google’s Gemini Enterprise.
- Action: Salesforce’s Trusted Action, Google’s new actions in Microsoft 365, the MCP and skills support in AWS’s managed agents.
- Identity and security: an IAM role per agent at AWS, Entra identity in Microsoft’s Managed Runtime, resource-level IAM in Gemini Enterprise.
- Control and visibility: Salesforce’s AI Control Plane, the app inventory in the Microsoft 365 admin center, CloudTrail for AWS agents.
Every major platform now sells a harness. The question for an enterprise is not whether it needs one. It is how many it can afford to run.
- Runtime and orchestration
- Native connectors and actions
- Identity
- Business definitions
- Evaluation assets
- Audit and agent registry
- Rent per platform: Runtime and orchestration · Native connectors and actions
- Own once, across vendors: Identity · Business definitions · Evaluation assets · Audit and agent registry
Vendor-neutral layers worth owning
The trap: one harness per vendor
Each vendor’s harness is shared within its own ecosystem. A company that runs Salesforce for customers, Microsoft 365 for collaboration and AWS for data can end up with three harnesses: three identity mappings, three action catalogs, three control planes and three places to look during an incident.
Salesforce says its Control Plane will cover third-party AI as well. Other vendors make similar claims. Until those claims are proven in your environment, the practical answer is to decide which layers must stay enterprise-wide and vendor-neutral, and which can be platform-specific.
Worth owning once, across vendors:
- Identity: one identity provider and one way of expressing who an agent acts as.
- Business definitions: what “available”, “active customer” or “on-time” means. Salesforce is right that proprietary context compounds; it only compounds if it is defined once.
- Evaluation assets: test cases and acceptance criteria that do not depend on one platform.
- Audit aggregation: agent activity from every platform landing in one security and audit pipeline.
- An agent registry: every agent, its owner, purpose, scope and review date, regardless of where it runs.
Reasonable to rent per platform:
- The runtime and orchestration.
- Platform-native connectors and actions.
- Model routing within a platform.
What to do now
- Inventory your agents and pilots by platform. Most enterprises already have more harnesses than they realize.
- Pick the vendor-neutral layers above and give each one an owner.
- Evaluate control-plane claims against a real cross-vendor scenario before relying on them.
- Treat roadmap as roadmap. Plan with what is available today, and revisit when capabilities ship.
The harness idea is right. The risk is buying it several times over. For the full set of layers, see our 2026 stack guide.