Back to Blog
AI News

Who Watches the Agents? Salesforce’s Governance Stack, Explained

TS

Tushar Sharma

Chief Executive Officer

11 min read - Sep 29, 2026

The short version

  • A real governance layer exists today: the Einstein Trust Layer, open-sourced Agent Script guardrails, Testing Center with custom scoring evals, Session Tracing into Data 360, and Agent Fabric's cross-vendor registry and broker, most of it generally available.
  • Guardian is not a new agent watchdog: it is Salesforce's existing suite of security add-ons (Shield, Security Center, Privacy Center and more), repositioned at Dreamforce for agent identity and rogue-agent detection, with no dates published for those additions.
  • The Enterprise AI Harness, announced September 10, names six trusted capabilities, but its AI Control Plane, the piece that would govern all your agents in one place, is planned for early fiscal 2028, which means February 2027 at the earliest.
  • The sharpest open questions come from analysts, not the keynote: agents inheriting user permissions at machine scale, drift controls that rely on agents self-reporting, and what happens to permissions after the second handoff.

The Question Nobody Answered at the Keynote

2026 was the year agents got jobs: seven of them, with names, plus every custom agent teams are shipping themselves. The governance question follows immediately, and it is not hypothetical. In a VentureBeat survey (their own, and directional), 85% of enterprises already run agents on two or more platforms, averaging 3.1. Gartner has predicted that over 40% of agentic AI projects will be cancelled by the end of 2027, largely on cost and risk-control grounds. And analysts frame this whole product cycle as a response to what one called a stunning lack of adequate guardrails attached to agent activity.

Salesforce's answer spans products announced years apart, some real today and some dated 2027. This post sorts them honestly into three piles: what you can turn on now, what Guardian actually is, and what waits for the AI Control Plane.

Pile One: What You Can Turn On Today

The unglamorous truth is that most of Salesforce's working governance shipped before the keynote language arrived:

  • The Einstein Trust Layer still does the quiet work: data masking, toxicity detection, contractually enforced zero data retention with approved model providers, and an audit trail of AI interactions. (One press snippet called Guardian its replacement; Salesforce's own docs say otherwise, and the Trust Layer remains live.)
  • Agent Script, open-sourced with spec, parser, and compiler on GitHub, is where guardrails become code: typed rules, explicit transitions, and a declared boundary between deterministic behavior and LLM reasoning.
  • Testing Center, generally available since May 2026, runs custom scoring evals against brand voice, compliance, and resolution quality, including multi-turn and voice simulation. Custom scorers on live production sessions are GA via API, beta in the UI; A/B testing of agent versions is in pilot.
  • Session Tracing and observability: every input, response, reasoning step, LLM call, and guardrail check lands in a session data model inside Data 360, with Agent Analytics and Agent Health Monitoring generally available, and OpenTelemetry export of full traces in beta.
  • Shield Event Monitoring and Transaction Security audit agent activity and can block abnormal access in real time, the same controls your org already uses for humans.
  • Security Mesh, announced September 14 and GA for core integrations, pulls security telemetry (including Okta, CrowdStrike, and DigitSec feeds) into one OCSF-normalized view, delivered through the Security Center add-on with Data 360. Its companion, MCP Risk Scores, will scan MCP servers at registration for prompt injection, tool poisoning, and rug-pull attacks with continuous re-scoring, but carries no published GA date yet.

Agent Fabric: The Cross-Vendor Layer That Already Exists

The most underappreciated piece predates the hype: MuleSoft's Agent Fabric launched in September 2025, a year before Dreamforce made agent governance fashionable, and has been expanding since. The registry catalogs your agents wherever they live; automated scanners discover them across Agentforce, Amazon Bedrock, Vertex AI, and Copilot Studio (GA since January 2026, with Microsoft Foundry and MCP-server scanning added through spring). The Agent Broker routes work between them with what MuleSoft calls guided determinism, Agent Script rules wrapped around LLM reasoning, generally available since June 2026.

Two details matter for architects. First, A2A bridging: Flex Gateway translates protocols so non-A2A agents present as A2A-compliant without code changes, and policy is enforced on every agent-to-agent and agent-to-tool interaction. Second, the observability view already shows lineage, latency, error rates, policy violations, and cost per agent. The gap: registering bespoke agents by URL slipped to early fiscal 2027, so fully custom agents outside the scanned platforms still wait.

Guardian, Sorted Out

You will read that Salesforce announced Guardian at Dreamforce as its agent watchdog. The accurate version is less dramatic. Guardian has existed since at least March 2026 as the umbrella name for Salesforce's security add-on suite: Shield (Event Monitoring, Platform Encryption, Transaction Security), Security Center, Privacy Center, Data Mask, Backup and Recover, and related products, each separately priced.

What Dreamforce added is a repositioning for the agent era, with two promised focus areas: agent identity, constraining agents beyond the permissions they inherit from users, and detection of agents behaving outside expected boundaries. Neither carries a published date, and notably, Guardian appears in press coverage of the keynote but not in Salesforce's own Dreamforce announcement blogs. Our read: treat Guardian as the security suite you may already license, and treat the agent-identity additions as roadmap until Salesforce dates them.

The Harness and the FY28 Control Plane

The Enterprise AI Harness, announced September 10, is the strategy that ties it together: six trusted capabilities (Context, Agency, Action, Governance, Security, Models) spanning Data 360, MuleSoft, Informatica, Tableau, Agentforce, and Guardian. The underlying products are sold today. The unifying piece is not: the AI Control Plane, which would discover, register, govern, observe, and cost-control Salesforce and third-party agents from one place, is planned to begin rolling out in early fiscal 2028, February 2027 at the earliest, with no pricing or packaging published. Salesforce's own safe-harbor line says it plainly: base purchasing decisions on what is currently available.

The competitive context explains the urgency. Microsoft's Agent 365 went GA in May 2026 and AWS Bedrock AgentCore in June; ServiceNow's AI Control Tower and IBM's watsonx Orchestrate are aimed at the same control-plane budget. Salesforce's differentiation claim is span, context plus reasoning plus action plus governance rather than runtime control alone, delivered headless into Claude, Slack, and Teams. Whether span beats shipping is the 2027 question.

The Questions the Skeptics Are Asking

The best critique published so far comes from Moor Insights, and every buyer should steal its questions. One: access creep, because an agent inheriting a user's permissions reads hundreds of records at machine speed, so entitlements that sat safely unused suddenly get used. Two: drift, because today's controls largely depend on agents self-reporting deviations from approved plans, where a control plane should enforce company-wide rules from outside. Three: handoffs, because when work passes agent to agent, it is genuinely unclear whether the original permissions still bind by the second or third hop. Four: neutrality, because a vendor offering to govern everyone's agents has to prove its registry stays open to rivals.

Add the one nobody has answered in print: when an agent acts badly, who owns the liability? We found no source, Salesforce or analyst, that assigns it. That is not a reason to wait, but it is a clause your legal team should be writing into agent-era contracts now, and a question to put to every vendor including us. The AgentExchange listing question is the same one at buy-time: security review vets a listing at publish, but who watches behavior after install?

What a Mid-Market Team Should Do Now

You do not need the Control Plane to be defensible in 2026. The sequence we run:

  • Turn on the tracing you already own. Session Tracing, Agent Analytics, and Health Monitoring are GA; an agent without traces is an agent you cannot audit.
  • Write guardrails as Agent Script, not prose. Deterministic rules for anything involving money, PII, or irreversible actions; LLM reasoning only inside declared boundaries.
  • Make Testing Center evals a release gate. Custom scorers for compliance and brand voice, run on every agent change, exactly like tests before a deploy.
  • Inventory your agents this quarter, even in a spreadsheet: platform, permissions, owner, escalation path. Agent Fabric's scanners can seed it if you span clouds. You cannot govern what you have not counted.
  • Give agents their own identity story. Do not wait for Guardian's dates: scope dedicated permission sets for agent use today instead of letting agents ride broad user profiles.
  • Ask every vendor the drift question: what, outside the agent itself, detects and stops behavior outside the approved plan?

This is the readiness layer we build alongside every Agentforce implementation, because an agent your auditors trust is one you can actually scale. If you want your org's answer to the six bullets above, bring it to a free 30-minute scoping call at cal.com/cloudsheer-consulting/30min and we will map your gaps against what is real today, not what is dated 2027.

FAQ

Frequently Asked Questions

What governance tools does Salesforce offer for AI agents today?

Generally available now: the Einstein Trust Layer (masking, zero data retention with model providers, audit trail), Agent Script for coded guardrails, Testing Center with custom scoring evals, Session Tracing with Agent Analytics and Health Monitoring, Shield Event Monitoring with Transaction Security, MuleSoft's Agent Fabric (registry, scanners, broker, A2A policy enforcement), and Security Mesh's core integrations through Security Center. A/B testing, custom-scorer UI, and OpenTelemetry trace export are in pilot or beta.

What is the Salesforce AI Control Plane and when does it ship?

The AI Control Plane is the unifying layer of the Enterprise AI Harness, announced September 10, 2026: one place to discover, register, govern, observe, and cost-control agents across Salesforce and third-party platforms. Salesforce says it is planned to begin rolling out in early fiscal year 2028, which means February 2027 at the earliest, with no pricing or packaging published. Salesforce's own guidance is to base purchasing decisions on currently available products.

What is Salesforce Guardian?

Guardian is the umbrella name for Salesforce's suite of security, privacy, and resilience add-ons: Shield, Security Center, Privacy Center, Data Mask, Backup and Recover, and related products. At Dreamforce 2026 it was repositioned for the agent era with promised agent-identity and rogue-agent-detection capabilities, but those additions carry no published dates, so treat them as roadmap rather than product.

What is Agent Fabric?

Agent Fabric is MuleSoft's cross-vendor agent governance layer, launched in September 2025: a registry of agents wherever they run, automated scanners for Agentforce, Amazon Bedrock, Vertex AI, and Copilot Studio, an Agent Broker with guided determinism (GA June 2026), A2A protocol bridging, and policy enforcement on every agent-to-agent and agent-to-tool call through Flex Gateway, plus per-agent observability of latency, errors, violations, and cost.

Want to see how this applies to your business?

Book a free 30-minute call. We will walk through your specific use case and show you what's possible.

Book Free Discovery Call
Ask me anything