The short version
- A real governance layer exists today: the Einstein Trust Layer, open-sourced Agent Script guardrails, Testing Center with custom scoring evals, Session Tracing into Data 360, and Agent Fabric's cross-vendor registry and broker, most of it generally available.
- Guardian is not a new agent watchdog: it is Salesforce's existing suite of security add-ons (Shield, Security Center, Privacy Center and more), repositioned at Dreamforce for agent identity and rogue-agent detection, with no dates published for those additions.
- The Enterprise AI Harness, announced September 10, names six trusted capabilities, but its AI Control Plane, the piece that would govern all your agents in one place, is planned for early fiscal 2028, which means February 2027 at the earliest.
- The sharpest open questions come from analysts, not the keynote: agents inheriting user permissions at machine scale, drift controls that rely on agents self-reporting, and what happens to permissions after the second handoff.
The Question Nobody Answered at the Keynote
2026 was the year agents got jobs: seven of them, with names, plus every custom agent teams are shipping themselves. The governance question follows immediately, and it is not hypothetical. In a VentureBeat survey (their own, and directional), 85% of enterprises already run agents on two or more platforms, averaging 3.1. Gartner has predicted that over 40% of agentic AI projects will be cancelled by the end of 2027, largely on cost and risk-control grounds. And analysts frame this whole product cycle as a response to what one called a stunning lack of adequate guardrails attached to agent activity.
Salesforce's answer spans products announced years apart, some real today and some dated 2027. This post sorts them honestly into three piles: what you can turn on now, what Guardian actually is, and what waits for the AI Control Plane.
Pile One: What You Can Turn On Today
The unglamorous truth is that most of Salesforce's working governance shipped before the keynote language arrived:
- The Einstein Trust Layer still does the quiet work: data masking, toxicity detection, contractually enforced zero data retention with approved model providers, and an audit trail of AI interactions. (One press snippet called Guardian its replacement; Salesforce's own docs say otherwise, and the Trust Layer remains live.)
- Agent Script, open-sourced with spec, parser, and compiler on GitHub, is where guardrails become code: typed rules, explicit transitions, and a declared boundary between deterministic behavior and LLM reasoning.
- Testing Center, generally available since May 2026, runs custom scoring evals against brand voice, compliance, and resolution quality, including multi-turn and voice simulation. Custom scorers on live production sessions are GA via API, beta in the UI; A/B testing of agent versions is in pilot.
- Session Tracing and observability: every input, response, reasoning step, LLM call, and guardrail check lands in a session data model inside Data 360, with Agent Analytics and Agent Health Monitoring generally available, and OpenTelemetry export of full traces in beta.
- Shield Event Monitoring and Transaction Security audit agent activity and can block abnormal access in real time, the same controls your org already uses for humans.
- Security Mesh, announced September 14 and GA for core integrations, pulls security telemetry (including Okta, CrowdStrike, and DigitSec feeds) into one OCSF-normalized view, delivered through the Security Center add-on with Data 360. Its companion, MCP Risk Scores, will scan MCP servers at registration for prompt injection, tool poisoning, and rug-pull attacks with continuous re-scoring, but carries no published GA date yet.
Agent Fabric: The Cross-Vendor Layer That Already Exists
The most underappreciated piece predates the hype: MuleSoft's Agent Fabric launched in September 2025, a year before Dreamforce made agent governance fashionable, and has been expanding since. The registry catalogs your agents wherever they live; automated scanners discover them across Agentforce, Amazon Bedrock, Vertex AI, and Copilot Studio (GA since January 2026, with Microsoft Foundry and MCP-server scanning added through spring). The Agent Broker routes work between them with what MuleSoft calls guided determinism, Agent Script rules wrapped around LLM reasoning, generally available since June 2026.
Two details matter for architects. First, A2A bridging: Flex Gateway translates protocols so non-A2A agents present as A2A-compliant without code changes, and policy is enforced on every agent-to-agent and agent-to-tool interaction. Second, the observability view already shows lineage, latency, error rates, policy violations, and cost per agent. The gap: registering bespoke agents by URL slipped to early fiscal 2027, so fully custom agents outside the scanned platforms still wait.
Guardian, Sorted Out
You will read that Salesforce announced Guardian at Dreamforce as its agent watchdog. The accurate version is less dramatic. Guardian has existed since at least March 2026 as the umbrella name for Salesforce's security add-on suite: Shield (Event Monitoring, Platform Encryption, Transaction Security), Security Center, Privacy Center, Data Mask, Backup and Recover, and related products, each separately priced.
What Dreamforce added is a repositioning for the agent era, with two promised focus areas: agent identity, constraining agents beyond the permissions they inherit from users, and detection of agents behaving outside expected boundaries. Neither carries a published date, and notably, Guardian appears in press coverage of the keynote but not in Salesforce's own Dreamforce announcement blogs. Our read: treat Guardian as the security suite you may already license, and treat the agent-identity additions as roadmap until Salesforce dates them.
The Harness and the FY28 Control Plane
The Enterprise AI Harness, announced September 10, is the strategy that ties it together: six trusted capabilities (Context, Agency, Action, Governance, Security, Models) spanning Data 360, MuleSoft, Informatica, Tableau, Agentforce, and Guardian. The underlying products are sold today. The unifying piece is not: the AI Control Plane, which would discover, register, govern, observe, and cost-control Salesforce and third-party agents from one place, is planned to begin rolling out in early fiscal 2028, February 2027 at the earliest, with no pricing or packaging published. Salesforce's own safe-harbor line says it plainly: base purchasing decisions on what is currently available.
The competitive context explains the urgency. Microsoft's Agent 365 went GA in May 2026 and AWS Bedrock AgentCore in June; ServiceNow's AI Control Tower and IBM's watsonx Orchestrate are aimed at the same control-plane budget. Salesforce's differentiation claim is span, context plus reasoning plus action plus governance rather than runtime control alone, delivered headless into Claude, Slack, and Teams. Whether span beats shipping is the 2027 question.
The Questions the Skeptics Are Asking
The best critique published so far comes from Moor Insights, and every buyer should steal its questions. One: access creep, because an agent inheriting a user's permissions reads hundreds of records at machine speed, so entitlements that sat safely unused suddenly get used. Two: drift, because today's controls largely depend on agents self-reporting deviations from approved plans, where a control plane should enforce company-wide rules from outside. Three: handoffs, because when work passes agent to agent, it is genuinely unclear whether the original permissions still bind by the second or third hop. Four: neutrality, because a vendor offering to govern everyone's agents has to prove its registry stays open to rivals.
Add the one nobody has answered in print: when an agent acts badly, who owns the liability? We found no source, Salesforce or analyst, that assigns it. That is not a reason to wait, but it is a clause your legal team should be writing into agent-era contracts now, and a question to put to every vendor including us. The AgentExchange listing question is the same one at buy-time: security review vets a listing at publish, but who watches behavior after install?
What a Mid-Market Team Should Do Now
You do not need the Control Plane to be defensible in 2026. The sequence we run:
- Turn on the tracing you already own. Session Tracing, Agent Analytics, and Health Monitoring are GA; an agent without traces is an agent you cannot audit.
- Write guardrails as Agent Script, not prose. Deterministic rules for anything involving money, PII, or irreversible actions; LLM reasoning only inside declared boundaries.
- Make Testing Center evals a release gate. Custom scorers for compliance and brand voice, run on every agent change, exactly like tests before a deploy.
- Inventory your agents this quarter, even in a spreadsheet: platform, permissions, owner, escalation path. Agent Fabric's scanners can seed it if you span clouds. You cannot govern what you have not counted.
- Give agents their own identity story. Do not wait for Guardian's dates: scope dedicated permission sets for agent use today instead of letting agents ride broad user profiles.
- Ask every vendor the drift question: what, outside the agent itself, detects and stops behavior outside the approved plan?
This is the readiness layer we build alongside every Agentforce implementation, because an agent your auditors trust is one you can actually scale. If you want your org's answer to the six bullets above, bring it to a free 30-minute scoping call at cal.com/cloudsheer-consulting/30min and we will map your gaps against what is real today, not what is dated 2027.
