Salesforce AI Agent Governance for Regulated Businesses
Salesforce AI agent governance is about knowing what every agent in your business can do, what it actually did, and who is accountable for it. Launching an agent takes days. Explaining its decisions to an auditor or regulator can take much longer. In September 2026 Salesforce introduced the Enterprise AI Harness and a new AI Control Plane to address this. This article explains both, what you can use today, and a practical governance plan for regulated businesses that do not want to wait until 2027.
What Is the Salesforce Enterprise AI Harness
The Enterprise AI Harness is a framework, not a single product. Salesforce describes it as a trusted foundation that gives agents what they need to understand the business, reason, take action and stay within enterprise controls, without each agent having to build those pieces separately.
It draws on products many customers already own, including Data 360, Informatica, MuleSoft and Agent Fabric, Tableau, Agentforce, Salesforce Guardian and the core Salesforce Platform. You can use all of it or only the parts you need, including with third-party models and agents.
The Six Capabilities of the Harness
| Capability | What it covers |
|---|---|
| Trusted Context | Customer data, metadata, knowledge and real-time signals that give AI a shared understanding of the business |
| Trusted Agency | Reasoning, planning, memory and orchestration, combined with deterministic controls |
| Trusted Action | Secure connections to applications, APIs and workflows so agents can carry out decisions |
| Trusted Governance | Data lineage, quality checks, policies and guardrails for compliance |
| Trusted Security | Identity, permissions, privacy protection and runtime security for what AI can access and do |
| Trusted Models | Routing work to the right model by accuracy, performance, cost and business need |
What the AI Control Plane Adds
The AI Control Plane is the part most compliance and IT teams will care about. Salesforce says it will let organisations discover and register agents, establish identity and policy, manage each agent's lifecycle, evaluate performance, observe behaviour and outcomes, and control cost. In short, one place to answer "which agents are running, what are they allowed to do, and what are they costing us?"
Why Governance Matters for Regulated Businesses
Banks, insurers, healthcare providers and government-linked organisations already work under strict rules on personal data and audit trails. Data protection laws such as the UAE's Personal Data Protection Law and India's Digital Personal Data Protection Act apply to data an agent reads and changes, just as they apply to data a person handles.
For every agent, a regulated business should be able to answer three questions quickly:
- What data did the agent use to reach its decision?
- What action did it take, and in which system?
- Who approved the agent's level of access, and when?
If those answers depend on someone digging through logs across several systems, you have a governance gap.
What Is Available Today and What Comes Later
Salesforce says many of the underlying technologies are available now. The new capabilities and the unified experience, including the AI Control Plane, are planned to start rolling out in early fiscal FY28. Salesforce's fiscal year begins in February, so that means February 2027 at the earliest. Pricing has not been announced.
Our recommendation is not to wait. The controls below use features that exist today, and they will make adopting the Control Plane much simpler when it arrives.
A Governance Plan You Can Start Now
- Keep an agent register. List every agent, its business owner, its purpose, the objects it can read and change, and its model.
- Give each agent least-privilege access. Use a dedicated permission set per agent. Never reuse an admin or integration profile.
- Switch on audit trails. Use Field History Tracking, Setup Audit Trail and, where licensed, Event Monitoring for the objects agents change.
- Define human approval points. Refunds above a threshold, contract changes and anything regulated should need a person's sign-off.
- Test agents on a schedule. Re-run a fixed set of test scenarios every month and after every change to prompts, actions or models.
- Review cost and outcomes monthly with the business owner and IT together.
Common Governance Mistakes
- Treating agents as features rather than workers. An agent that takes action needs an owner, access rules and reviews, just like a new employee.
- One shared identity for every agent. It makes auditing almost impossible.
- Governance written after launch. Rules added later are rarely enforced.
- Assuming the vendor handles compliance. Salesforce provides controls. Using them correctly is your responsibility.
How Alu Cloud Consulting Can Help
We help regulated organisations design agent governance on Salesforce: permission models, audit configuration, approval flows and a practical agent register. We have delivered compliance-focused Salesforce work for financial services, and we apply the same discipline to AI. For the wider picture of this year's launches, read our Dreamforce 2026 summary.
Need an AI governance plan your compliance team will sign off? Talk to us.
Ready to talk about your Salesforce project?
Every engagement starts with a free discovery call. No pressure, just an honest conversation about where you are and what you are trying to build.
Frequently Asked Questions
What is the Salesforce Enterprise AI Harness?
It is Salesforce's framework for running AI safely across a business. It combines six capabilities, covering context, agency, action, governance, security and models, built from products such as Data 360, MuleSoft, Tableau, Agentforce and Salesforce Guardian. An AI Control Plane sits on top to register, monitor and control agents.
When will the AI Control Plane be available?
Salesforce says the new capabilities and unified experience will begin rolling out in early fiscal FY28. Salesforce's fiscal year starts in February, so that means February 2027 at the earliest. Many underlying technologies are available today, and pricing will be announced closer to general availability.
How do we govern AI agents in Salesforce today?
Keep a register of every agent with its owner, purpose and access. Give each agent its own least-privilege permission set, switch on Field History Tracking and Setup Audit Trail, add human approval for high-risk actions, and re-run a fixed set of test scenarios every month and after every change.
Do data protection laws apply to AI agents?
Yes. Laws such as the UAE's Personal Data Protection Law and India's Digital Personal Data Protection Act apply to personal data an agent reads or changes, just as they apply to data handled by people. Regulated businesses should be able to show what data an agent used and what it did.
Is the Enterprise AI Harness the same as the Einstein Trust Layer?
No. The Einstein Trust Layer focuses on securing individual AI requests, with controls such as data masking. The Enterprise AI Harness is broader. It covers the full set of agents and AI capabilities across a business, including context, actions, governance, security, model choice and cost.