
Cirra AI Article
Salesforce Enterprise AI Harness Explained: Trusted Context, Action and Governance
Summary
- 01The Enterprise AI Harness is best understood as a composable architecture and operating model, not a new edition, license, or single installable product.
- 02Organizations do not need to wait for fiscal 2028 to establish identity, permissions, API governance, semantic definitions, testing, tracing, and cost attribution.
- 03The practical conclusion is to prepare the governance foundation now, adopt available components deliberately, and treat the unified Harness and Control Plane as a staged roadmap rather than a finished switch.
- 04When Salesforce no longer owns every interface, trust cannot depend on the interface. It must travel with the identity, context, tool, policy, and record of action.
Inside this article
- 01Executive Summary
- 02Introduction and Background
- 03What the Salesforce Enterprise AI Harness Is
- 04Three Operational Pillars: Context, Action, and Governance
- 05Product Reality: Available Now Versus Roadmap
- 06Headless Salesforce, MCP, and Bring-Your-Own AI
- 07Implementation Guide for Salesforce Admins and Architects
- 08Data Analysis and Evidence
- 09Implications and Future Directions
- 10Frequently Asked Questions (FAQs)
- 11Conclusion
Executive Summary
The Salesforce Enterprise AI Harness is Salesforce's architectural answer to a problem larger than any one model or agent: enterprises need common context, controlled actions, identity, policy, observability, and cost management across a growing population of AI systems. It began as a platform thesis articulated by Salesforce engineering leader Rohan Kumar in his August 2026 LinkedIn essay, Building the Trusted Platform for the Agentic Enterprise, and became an official architecture announcement in September 2026. Salesforce now describes six capabilities, Trusted Models, Trusted Context, Trusted Agency, Trusted Actions, Trusted Governance, and Trusted Security, coordinated through an AI Control Plane [1]. The architecture draws on Data 360, Informatica, MuleSoft Agent Fabric, Tableau, Agentforce, Salesforce Guardian, and the Salesforce Platform, but it is not one generally available product today [2]. Salesforce says new capabilities and the unified experience are planned to begin rolling out in early fiscal 2028 [3].
The thesis is commercially important because Salesforce sits near revenue, service, commerce, and customer workflows. Success should therefore be measured by adoption, workflow penetration, satisfaction, conversion, margin, and business outcomes, not a count of AI features. Independent analysts similarly recommend defining outcomes before use cases [4], while Constellation Research includes conversion and customer satisfaction among agent measures [5]. Salesforce reported 29,000-plus Agentforce deals, 2.4 billion Agentic Work Units, and 112 trillion Data 360 records ingested in fiscal 2026 [6] [7] [8]. Those are scale signals, not proof that every deployment produces value.
For administrators and architects, the immediate work is concrete: assign each service agent a dedicated identity, grant minimum permission sets, inventory every action and referenced object, test only in sandboxes, maintain agent metadata in version control, require approvals for change, and retain audit evidence. Salesforce's agent user begins with minimal access [9]; Setup Audit Trail provides 180 days of downloadable history [10]; and Agentforce testing is sandbox-only [11].
The most consequential design choice is headless Salesforce. Salesforce's standard hosted Model Context Protocol servers are generally available, Headless 360 is beta, and the local Salesforce DX MCP Server handles retrieve and deploy work from a developer environment [12] [13]. Cirra AI is a complementary commercial Salesforce Admin MCP option that writes metadata, runs as the OAuth-connected user within that user's permissions, retains no org data, and works across several AI clients [14] [15]. The practical conclusion is to prepare the governance foundation now, adopt available components deliberately, and treat the unified Harness and Control Plane as a staged roadmap rather than a finished switch.
Introduction and Background
Salesforce's enterprise AI harness thesis starts from a sober observation: a language model is not an operating system for a business. An agent needs to know what a customer, case, order, entitlement, policy, and metric mean. It needs sanctioned ways to act. It must inherit identity and permissions, leave evidence, expose cost, and stop when the organization tells it to stop. Those requirements become harder when the interface could be Agentforce, Slack, a coding environment, ChatGPT, Claude, Gemini, Microsoft 365 Copilot, or a future client.
Rohan Kumar, Salesforce's President and Chief Platform and Engineering Officer, framed that challenge in his August 2026 LinkedIn essay, Building the Trusted Platform for the Agentic Enterprise, written about two months after joining the company [16]. The original argument emphasized three ideas: optimize for customer outcomes instead of feature volume; unite context, action, and governance beneath many models and interfaces; and change the product operating model toward simplification, craftsmanship, small teams, and rapid feedback. Salesforce's September announcement expanded the taxonomy to six trusted capabilities and put an AI Control Plane beside them.
This report evaluates that thesis for Salesforce administrators, architects, RevOps leaders, and consulting partners as of September 16, 2026. It separates available products from announced direction, translates each pillar into operating controls, and examines the emerging MCP ecosystem. The aim is not to predict one winning interface. It is to identify which controls remain necessary regardless of which agent or model a company chooses.
What the Salesforce Enterprise AI Harness Is
The Enterprise AI Harness is best understood as a composable architecture and operating model, not a new edition, license, or single installable product. It places a governed layer between AI reasoning and the enterprise's data and systems of action. The name now has first-party standing, but the completeness implied by the word “harness” remains directional.
Salesforce says the Harness is being built headlessly and exposed through MCP, APIs, skills, and plug-ins. Diginomica interprets the related Headless 360 strategy as making capabilities available without requiring a Salesforce user interface [17]. Forrester similarly reads the platform as a governed system of action that third-party agents can reach [18].
Outcomes before features
The strongest part of Kumar's thesis is its unit of measurement. An AI program should not report only agents created, prompts executed, or features shipped. It should connect leading indicators to business results:
- Usage: active users, sessions, completed tasks, and workflow penetration.
- Adoption: eligible users who try, return to, and rely on an agent.
- Quality: acceptance versus override, escalation, grounded-answer, and task-success rates.
- Experience: customer and employee satisfaction, time to resolution, and effort.
- Economics: cost per successful task, incremental revenue, margin, and avoided rework.
- Risk: permission exceptions, blocked actions, policy breaches, and recovery time.
McKinsey's measurement framework uses daily active users, workflow penetration, and acceptance-versus-override rates as adoption measures [19]. Constellation's review of enterprise buying evidence found business cases shifting toward revenue, margin, cycle time, and quality [20]. That supports Kumar's emphasis on growth because Salesforce governs customer-facing work, but it does not make efficiency irrelevant. A balanced scorecard should show both.
The six-capability model
Table 1 translates Salesforce's announced taxonomy into concrete administrative questions and currently available building blocks.
| Capability | Meaning in the Harness | Admin or architect test | Available building blocks in September 2026 |
|---|---|---|---|
| Trusted Models | Select and route models by accuracy, performance, cost, and business need. | Which models are approved for each data class and action risk? | Salesforce Default, AWS-hosted, and Gemini options; external foundation models through Data 360 [21]. |
| Trusted Context | Combine data, metadata, semantics, knowledge, real-time signals, and memory. | Can the agent identify the right customer and apply the organization's business definitions? | Data 360, Salesforce metadata, Knowledge, Tableau Semantics, zero copy federation. |
| Trusted Agency | Supply reasoning, planning, state, memory, collaboration, and orchestration. | Who owns instructions, handoffs, evaluation, versioning, and failure behavior? | Agentforce 360, Agent Script, Agent Fabric orchestration, testing APIs. |
| Trusted Actions | Connect AI to applications, APIs, workflows, tools, and processes. | Is every tool allowlisted, permission-scoped, reversible where possible, and tested? | Flow, Apex, prompt templates, MuleSoft connectors and APIs, MCP tools. |
| Trusted Governance | Govern data, metadata, policy, process, quality, lineage, lifecycle, and evidence. | Can owners discover every agent, trace a decision, evaluate it, and retire it? | Data 360 governance, MuleSoft Agent Fabric, session tracing, Setup Audit Trail, version control. |
| Trusted Security | Apply identity, permissions, privacy, protection, and runtime controls. | Can the agent do only what its identity is allowed to do, from every interface? | Salesforce sharing and permissions, Trust Layer, Trusted Agent Identity, Omni Gateway, Guardian. |
The table shows why the Harness is broader than Agentforce. Agentforce is an agent platform inside the architecture. Data 360 supplies customer context, Tableau supplies business semantics, MuleSoft connects and governs cross-system actions, Informatica contributes data management, and the core platform supplies metadata, identity, automation, and security. The Harness proposition is that those layers should operate coherently even when Salesforce does not own the interface.
Three Operational Pillars: Context, Action, and Governance
The six-capability announcement refines the original three-pillar thesis. For implementation, context, action, and governance remain a useful operating model because models and agency consume context, actions change systems, and security is enforced through governance.
Trusted context
Trusted context is the managed information environment an agent uses to interpret a request and decide. Academic work defines context engineering as designing and managing the entire informational environment around a decision [22]. In Salesforce, that environment includes records, object and field metadata, sharing rules, Knowledge articles, business terminology, policy, conversation state, and retrieved information.
Data 360 can federate some external data through zero copy, making it available for identity resolution and segmentation without duplication [23]. Architects still need to understand latency and support boundaries: identity-resolution schedules range from 60 minutes to 24 hours by source [24], and near-real-time identity resolution is not supported for all zero copy patterns [25].
Tableau Semantics maps data to familiar business terms and standardized logic [26]. That is significant for agents. “Revenue,” “qualified pipeline,” and “active customer” should resolve to governed definitions, not model improvisation. Admins should therefore treat descriptions, formula definitions, picklist meanings, Knowledge freshness, and ownership metadata as production AI inputs.
Salesforce describes an intelligence flywheel in which interactions and actions create new signals, outcomes, and memory. That loop only improves intelligence if feedback is labeled, relevant, consented, and governed. Otherwise, it merely accumulates activity.
Trusted action
Context becomes commercially useful when an agent can act. Agentforce actions can invoke Flow, prompt templates, or Apex classes [27]. MuleSoft can let Agentforce retrieve information and act through APIs and connectors [28], while MCP Bridge can turn an existing API or software-as-a-service system into an MCP server [29].
For every action, an owner should document:
- Purpose: the business outcome and eligible requests.
- Identity: the user or agent principal under which it executes.
- Scope: objects, fields, records, APIs, and environments it can reach.
- Preconditions: data quality, approvals, and policy checks.
- Side effects: writes, notifications, downstream automation, and consumption.
- Evidence: inputs, output, approver, execution ID, and resulting changes.
- Recovery: compensation, rollback, escalation, and deactivation procedure.
Agent Script can call actions deterministically or expose them as model-selectable tools [30]. Deterministic sequencing is preferable for high-consequence operations. Model-selected tools may be appropriate for bounded, observable work with clear approvals.
Trusted governance and security
The proposed AI Control Plane is the connective idea: inventory which models and agents exist, identify the data and tools they touch, enforce policy, observe behavior, evaluate quality, attribute cost, and map results to value. Salesforce describes it as a new layer with registration, identity, policy, lifecycle, evaluation, observability, and cost controls, but the unified plane is not yet a standalone generally available product [31].
Several component controls already exist. MuleSoft Agent Fabric can discover, govern, orchestrate, and observe agents [32]. MuleSoft positions Omni Gateway as governing the traffic those agents generate [33]. Salesforce reported AI Gateway, MCP Bridge, and Trusted Agent Identity generally available in April 2026 [34]. Salesforce Guardian adds deeper visibility, real-time enforcement, and operational resilience [35].
Trust must follow an agent beyond a single screen. NIST's agent identity work highlights identification, authorization, auditing, and non-repudiation [36]. OWASP recommends minimum permissions at each MCP server and tool [37]. Salesforce's Trust Layer includes zero-data-retention agreements with third-party large language model providers [38]. That promise should be stated precisely: it concerns specified third-party model arrangements, not every data flow in the wider architecture.
The named architecture exists and Salesforce has introduced it, but its unified experience is a roadmap.
Product Reality: Available Now Versus Roadmap
The September 2026 announcement changes the answer to “does the Salesforce Enterprise AI Harness exist?” The named architecture exists and Salesforce has introduced it, but its unified experience is a roadmap. Many constituent products are already available at different maturity levels.
Table 2 separates the current product surfaces from planned unification.
| Layer or product | Status as of September 16, 2026 | What that status means |
|---|---|---|
| Enterprise AI Harness unified experience | Announced; rollout planned to begin in early fiscal 2028. | Treat it as architectural direction and procurement roadmap, not one generally available SKU. |
| AI Control Plane | Introduced as part of the Harness direction. | Component controls exist, but Salesforce has not documented a standalone generally available product with this exact name. |
| Agentforce 360 | Globally available [39]. | Organizations can build and operate Salesforce agents now. |
| MuleSoft Agent Fabric and Omni Gateway | Governance components generally available; Omni Gateway available through MuleSoft [40]. | Use for cross-agent discovery, traffic governance, APIs, and interoperability. |
| Informatica | Acquisition completed November 18, 2025 [41]. | It is part of Salesforce's data-management foundation, but integration into one Harness experience remains ongoing. |
| Hosted standard MCP servers | Generally available in Summer 2026 [12]. | Remote clients can access scoped Salesforce tools under the authorizing user's permissions. |
| Data 360 MCP Server | Generally available in August 2026, exposing nearly 200 APIs [42]. | External agents can reach Data 360 through an open protocol. |
| Headless 360 MCP Server | Beta from July 2026 [13]. | Evaluate in controlled environments; do not describe it as generally available. |
| Salesforce DX MCP Server | Beta in the Summer 2026 developer guide [43]. | Local developer tooling can retrieve and deploy metadata for CLI-authenticated orgs. |
| Cirra AI Salesforce Admin MCP Server | Commercial hosted service available in September 2026. | A direct, complementary option for permission-bounded Salesforce administration and metadata writes from multiple AI clients. |
The important implication is sequencing. Organizations do not need to wait for fiscal 2028 to establish identity, permissions, API governance, semantic definitions, testing, tracing, and cost attribution. They also should not assume today's collection of controls already behaves as one consistent console. Architecture diagrams and operating procedures must identify which product owns each control.
Headless Salesforce, MCP, and Bring-Your-Own AI
“Headless Salesforce” means Salesforce need not own the conversational or development interface. The platform can supply governed context and action beneath another model, agent, or user experience. That is a substantial extension of the platform model, not simply a new chatbot channel.
The Model Context Protocol (MCP) is an open standard for connecting AI applications to external systems [44]. Anthropic originally described it as enabling secure two-way connections between data sources and AI tools [45]. The specification requires explicit user consent before tool invocation [46]. Protocol openness does not itself guarantee secure implementation. Identity, scopes, approvals, tool descriptions, logging, and data handling still determine risk.
Salesforce's surfaces now differ materially:
- Hosted standard MCP servers: remote, Salesforce-operated servers for scoped services. Calls run with the permissions of the user who authorized the connection [47]. One SObject mutation surface supports create and update but not delete [48].
- Salesforce DX MCP Server: local developer tooling that works with orgs already authenticated in Salesforce CLI [49]. Its metadata tools retrieve and deploy between an org and a DX project [50].
- Headless 360 MCP Server: a beta surface with four tools backed by a growing operation library [51]. It applies object, field, sharing, profile, and permission-set controls [52].
- Metadata Experts MCP Server: a separate hosted service designed for metadata generation [53].
Cirra AI sits in this ecosystem as a commercial Salesforce Admin MCP Server. Its first-party documentation says it can create objects and fields, configure permissions, build layouts, and write and test metadata [54]. It authenticates through Salesforce OAuth and cannot exceed the connected user's permissions [55]. It supports Claude, ChatGPT, Cursor, Gemini Enterprise, Codex, and VS Code, and says org data is discarded after each session [56]. Its open-source skills library publishes task guidance and validation scripts for Salesforce administration [57].
The comparison should remain precise. Standard hosted Salesforce MCP services expose scoped data and context tools, while metadata modification is associated with separate developer-oriented or beta surfaces. Cirra offers a hosted admin-oriented write path. Salesforce is the governed platform underneath both approaches, and no partnership or endorsement is implied.
Implementation Guide for Salesforce Admins and Architects
The Harness roadmap should trigger governance work now, not a wait-and-see posture. The following sequence applies whether an organization uses Agentforce, Salesforce MCP services, Cirra AI, or another client.
1. Establish inventory and ownership
- Inventory agents and models: record owner, purpose, model, interface, environment, data classes, actions, and dependencies.
- Assign business accountability: name the executive outcome owner and the operational product owner.
- Define success: select adoption, quality, experience, economics, and risk metrics before release.
- Map lifecycle: document build, review, activate, monitor, version, deactivate, and retire states.
NIST's AI Risk Management Framework calls for mechanisms to inventory AI systems and for ongoing monitoring and periodic review [58] [59]. An inventory is also the minimum viable version of the future control plane.
2. Create a dedicated agent identity
- Use an agent user: avoid a shared human administrator identity.
- Start minimal: the Agentforce service user is secure by default with minimal access [9].
- Grant through permission sets: separate read context from write actions and privileged operations.
- Verify record access: profile, permissions, field-level security, and sharing rules govern what a service agent can access [60].
- Check every referenced object: adding an action requires access to all objects it references [61].
- Do not confuse context with authorization: knowing a customer's identity through a context variable does not restrict data access [62].
3. Govern actions and metadata
- Classify tools: read-only, low-risk write, privileged write, external side effect, or destructive.
- Require approval: retain explicit approval for file changes and external calls, consistent with Salesforce's safe defaults [63].
- Use deterministic paths: reserve model-selected tools for bounded decisions.
- Version metadata: keep agent source in a version-control system as the production source of truth [64].
- Review dependencies: change sets must include flows, Apex, objects, permission sets, and agent metadata that depend on one another [65].
4. Test in a sandbox before production
- Use a sandbox: Salesforce limits formal Agentforce testing to sandboxes.
- Isolate data: tests consume requests and credits and can modify records [66].
- Build representative cases: include success, ambiguity, missing context, permission denial, escalation, and recovery.
- Repeat stochastic tests: Salesforce suggests five runs across five records, or 25 runs per model, when comparing models [67].
- Promote through normal change control: peer review, automated checks, deployment evidence, approval, and rollback remain mandatory.
5. Build auditability and operational stops
- Setup Audit Trail: the user interface shows the 20 most recent setup changes [68]; download the full 180-day file on a schedule.
- AI attribution: Setup Audit Trail can record an AI agent's name and ID [69].
- Session tracing: capture turn-level interactions, reasoning executions, actions, prompts, and gateway inputs and outputs [70].
- Data protection: apply dynamic masking and field-specific exclusion to traces where needed [71].
- Operational stop: deactivation interrupts ongoing conversations and functions as the documented stop control [72].
Field Audit Trail should not be described as indefinite without qualification. Current documentation says archived data remains until the customer deletes it, supports up to 200 tracked fields per object, and archives after 18 months in production and one month in sandboxes [73] [74] [75]. Paid Event Monitoring retains logs for 30 days by default, extendable to one year [76]. Retention policy therefore needs multiple controls, not one audit feature.
- 01Establish inventory
record owner, purpose, model, interface, environment, data classes, actions, and dependencies.
- 02Create agent identity
avoid a shared human administrator identity.
- 03Govern actions
read-only, low-risk write, privileged write, external side effect, or destructive.
- 04Test in sandbox
Salesforce limits formal Agentforce testing to sandboxes.
- 05Build auditability
deactivation interrupts ongoing conversations and functions as the documented stop control.
The most credible near-term path is incremental. Start with a narrow outcome, high-quality context, a dedicated identity, a small action set, explicit approval, sandbox evaluation, and observable production release.
Data Analysis and Evidence
The market evidence supports both urgency and restraint. Adoption and platform usage are growing quickly, but governance maturity and proof of value lag.
Table 3 compares quantitative signals from vendor filings and independent or named research originators.
| Signal | Measured result | Interpretation and limitation |
|---|---|---|
| Salesforce fiscal 2026 scale | Agentforce and Data 360 annual recurring revenue reached $2.9 billion, up more than 200% year over year [77]. | Audited company reporting shows commercial scale, not customer-level outcome causality. |
| Salesforce enterprise survey | 2,025 AI decision-makers across 20 countries; production users reported ROI in about eight months and 53% employee adoption [78] [79]. | Results are self-reported and apply to the survey cohort with agents in production. |
| Salesforce service survey | 3,075 service professionals; agent adoption rose from 39% to 66% between 2025 and 2026 [80] [81]. | Indicates rapid adoption in service, not universal deployment. |
| Gartner application-leader survey | Only 15% were considering, piloting, or deploying fully autonomous agents, and 13% strongly agreed they had the right governance [82] [83]. | Governance, not model access, remains a binding constraint. |
| Deloitte governance study | Only 21% reported a mature agentic-AI governance model; 74% expected at least moderate agent use by 2027 [84] [85]. | Expected adoption substantially exceeds current governance maturity. |
| IBM technology-executive study | 11% felt completely prepared, respondents expected 38% more agents by 2027, and 85% lacked full real-time AI-spend visibility [86] [87]. | This directly supports the need for inventory, policy, observability, and cost control. |
| Microsoft Work Trend Index | 31,000 workers in 31 markets; 81% of leaders expected moderate or extensive agent integration within 12 to 18 months [88] [89]. | Broad intent does not equal production readiness, but it indicates interface diversity will grow. |
The pattern is consistent: agent counts, usage, and executive expectations are climbing faster than governance, cost visibility, and measurement discipline. McKinsey found fewer than one in five respondents tracked generative-AI key performance indicators in a 1,491-participant survey [90]. BCG found only 25% of 1,221 respondents reported fully mature responsible-AI frameworks [91]. Diginomica's practitioner network was more positive on results, with 42% reporting clear, demonstrable AI value [92].
Other research reinforces the gap between ambition and operational readiness. IBM respondents expected AI-enabled workflows to rise from 3% to 25% by the end of 2025, while 69% named improved decision-making as the leading benefit [93] [94]. PwC found 17% of 300 senior executives reported company-wide agent adoption and another 27% reported limited adoption [95] [96]. In a separate 1,004-executive financial-services survey, 77% said most AI investments were not producing measurable ROI [97] [98]. BCG found measurable revenue effects in some agentic-marketing programs and separately concluded from nearly 12,000 workers that strategic clarity drives durable AI results [99] [100]. Gartner's August 2026 research said only 10% of organizations reported agentic AI in production [101]. NIST's Generative AI Profile accordingly extends trustworthiness across design, development, use, and evaluation, not merely deployment approval [102]. SalesforceDevOps.net summarizes the Harness as surrounding the model loop with context, governance, security, and cost accounting [103]. Forrester adds that shared organizational memory supplies agents with business intent, while Constellation includes headless capabilities among its evaluation criteria [104] [105].
These figures should not be blended into one market average because they use different populations, dates, definitions, and sponsors. Their shared lesson is directional: an enterprise control layer becomes more valuable as agents proliferate, but the control layer must measure outcomes rather than only consumption.
Implications and Future Directions
The Harness thesis has five practical implications.
- The durable asset is governed context. Models will change. Customer identity, permission-aware metadata, semantic definitions, process logic, and evidence are harder to replace.
- Interfaces will fragment. A Salesforce action may begin in Slack, Claude, ChatGPT, a developer tool, or Agentforce. Controls must bind to identity and action, not only to a screen.
- The control plane must be measurable. Registry, evaluation, lineage, policy, observability, spend, and value attribution should converge. Digital Wallet already reports consumption by agent [106], but consumption is only one part of value.
- Modularity is strategic. Forrester recommends capabilities designed to evolve with models, tools, governance, and requirements [107]. That argues for stable contracts around context, tools, identity, and telemetry.
- Operating models must change. Small outcome-focused teams and feedback loops align with the thesis better than feature factories. McKinsey describes small teams aligned to end-to-end outcomes [108] and recommends increasing autonomy only as trust is earned [109].
The most credible near-term path is incremental. Start with a narrow outcome, high-quality context, a dedicated identity, a small action set, explicit approval, sandbox evaluation, and observable production release. Add autonomy only when evidence supports it. Treat each new interface as another client of the same governed capabilities, not as an exception.
Frequently Asked Questions (FAQs)
Is the Salesforce Enterprise AI Harness a product available today?
It is an officially announced Salesforce architecture, but not one generally available product or SKU. Existing components are available at different maturity levels. Salesforce plans the unified experience and new capabilities to begin rolling out in early fiscal 2028.
What is trusted AI context in Salesforce?
Trusted context is permission-aware enterprise data, metadata, semantics, knowledge, signals, and memory used by an agent. In practice, it includes Data 360 profiles, Salesforce object and field definitions, Tableau Semantics, Knowledge, sharing rules, and retrieved information.
What is Salesforce AI governance?
It is the lifecycle of inventorying agents and models, assigning identity and permissions, governing data and actions, testing and approving changes, monitoring behavior and cost, retaining evidence, and deactivating agents when necessary. The future AI Control Plane seeks to unify these functions, while several products already cover parts of them.
How should Agentforce governance begin?
Begin with a dedicated agent user and minimum permission sets. Document every action and referenced object, keep source in version control, test in a sandbox, promote through standard change control, enable tracing, export Setup Audit Trail regularly, and define an owner and deactivation procedure.
What is Salesforce context engineering?
It is not a single named Salesforce product. It is the discipline of assembling and governing the information an agent needs, including customer identity, records, metadata, business semantics, Knowledge, instructions, memory, permissions, and real-time signals.
What does headless Salesforce mean?
It means models, agents, and interfaces outside the Salesforce user interface can consume governed Salesforce context and actions through APIs, MCP servers, skills, and plug-ins. Salesforce remains the system of context, action, and control beneath the interface.
Can Salesforce MCP servers change metadata?
Capabilities vary by server. Standard hosted servers expose scoped services; the DX MCP Server retrieves and deploys metadata through a local developer project; Metadata Experts focuses on generation; and Headless 360 beta can modify a defined configuration subset. Buyers should verify each server's current tool list and maturity.
How does Cirra AI fit the headless model?
Cirra AI is a commercial Salesforce Admin MCP Server focused on administrative read and write operations from multiple AI clients. It runs as the OAuth-connected Salesforce user, so Salesforce permissions remain the enforcement boundary, and it publishes an open-source skills library. It complements Salesforce's platform rather than replacing Agentforce or Salesforce governance.
Conclusion
The Salesforce Enterprise AI Harness is now more than an essay, but less than a finished unified product. It is an announced architecture that organizes existing and planned capabilities around a durable premise: enterprises need governed context and action beneath changing models, agents, and interfaces.
For Salesforce teams, the correct response is neither to wait for the complete control plane nor to treat every current component as already unified. Build the foundations that remain valid in either case: dedicated identity, least privilege, semantic and metadata quality, governed actions, sandbox-first testing, version control, audit evidence, production observability, cost attribution, and outcome measures.
The headless direction makes that work more important. When Salesforce no longer owns every interface, trust cannot depend on the interface. It must travel with the identity, context, tool, policy, and record of action. Organizations that establish those controls now will be better prepared for Agentforce, external agents, Salesforce's evolving Harness, and whatever interface comes next.
External Sources (109)
About
Cirra AI
About Cirra AI
Cirra AI is a software company dedicated to reinventing Salesforce administration through AI-powered tooling built on the Model Context Protocol (MCP). From its headquarters in Silicon Valley, the team has built the first commercial MCP server for Salesforce administration—a hosted service that lets any MCP-compatible AI tool (Claude, ChatGPT, Cursor, and others) connect to a Salesforce org and execute admin tasks through natural language. The product gives Salesforce administrators, revenue-operations teams, and consulting partners the ability to implement configuration changes in minutes instead of hours, while respecting org permissions and maintaining full auditability. Cirra AI's mission is to "let humans focus on design and strategy while software handles the clicks." To achieve that, the company develops two complementary product lines: Salesforce Admin MCP Server – A fully hosted MCP endpoint that connects any AI tool to Salesforce in minutes via OAuth. Administrators describe what they need in plain English—create custom objects and fields, configure page layouts, manage permission sets, build flows, provision users, generate documentation—and the MCP server translates those instructions into standard Salesforce Metadata and Tooling API calls, bounded by the user's existing permissions. No local infrastructure or custom code is required: sign up, authenticate, copy the MCP URL into your AI tool, and start working. Salesforce Skills Library – An open-source collection of domain-specific skills (available at skills.cirra.ai) that supercharge AI assistants with deep Salesforce expertise. Skills cover Apex development with 150-point scoring, Flow creation and validation with 110-point scoring, Lightning Web Component development with the PICKLES architecture methodology, metadata operations, permission auditing, data and SOQL operations, org-wide health audits, architecture diagramming, and Kugamon CPQ management. The skills are installable as a single plugin for Claude Cowork, Claude Code, and OpenAI Codex, or as individual skill files for Claude web, desktop, and ChatGPT. They enable AI assistants to perform complex, multi-step Salesforce tasks independently—run a comprehensive org audit, fix issues flagged in the report, generate field descriptions at scale—without prompt-by-prompt hand-holding. Together, these products address three chronic pain points in the Salesforce ecosystem: (1) the high cost of manual administration and repetitive setup-menu navigation, (2) the backlog created by scarce expert capacity, and (3) the risk of inconsistent, undocumented changes. Early adopter feedback shows time-on-task reductions of 70–90 percent for routine configuration work.
Leadership
Cirra AI was founded in 2024 by Jelle van Geuns, a Dutch-born engineer, serial entrepreneur, and veteran of the Salesforce ecosystem with over 14 years of platform experience. Before Cirra, Jelle bootstrapped Decisions on Demand, an AppExchange ISV whose rules-based lead-routing engine is used by multiple Fortune 500 companies. Under his leadership the firm reached seven-figure ARR without external funding, demonstrating a combination of deep technical innovation and pragmatic go-to-market execution. Jelle began his career at ILOG (later IBM), where he managed global solution-delivery teams and developed expertise in enterprise optimisation and AI-driven decisioning. He holds an M.Sc. in Computer Science from Delft University of Technology and speaks frequently on AI-assisted administration, MCP integration patterns, and human-in-the-loop automation at Salesforce community events and podcasts. The leadership team includes Jeff Bajayo (VP Sales), a seasoned Salesforce and SaaS professional with over a decade of experience, and Latrice Barnett (Advisor, Marketing), who brings 10+ years of partnership and ecosystem marketing expertise from the Salesforce ecosystem.
Why Cirra AI Matters
MCP-native architecture – Rather than building a proprietary agent UI, Cirra embraces the Model Context Protocol as a universal connector, letting customers use the AI tool they already prefer—Claude, ChatGPT, Cursor, or any future MCP-compatible client—while Cirra handles the Salesforce integration layer. Deep vertical focus – The Skills Library encodes thousands of Salesforce best-practice patterns, scoring rubrics, and validation scripts that generic AI assistants lack. This domain intelligence produces higher-quality, more reliable outputs for Apex, Flows, LWC, permissions, and metadata operations than general-purpose prompting alone. Enterprise-grade security – The platform uses OAuth authentication, encrypted endpoints, and inherits the connected user's Salesforce permission model. Cirra never stores Salesforce credentials, and all actions are logged for auditability—critical requirements for regulated industries adopting AI tooling. Works for admins and partners alike – Individual administrators use Cirra to eliminate setup-menu drudgery and respond faster to business requests. Consulting firms use it to scale senior-level expertise across delivery teams, enabling more projects delivered at higher quality and lower cost through improved documentation and test coverage. Accessible to non-developers – Anyone with a paid Claude or ChatGPT subscription can install the skills and connect the MCP server. No coding, no complex integrations—just sign up and start working.
Future Outlook
Cirra AI continues to expand its capabilities with the upcoming Admin Agent (launching June 2026), which will bring fully autonomous multi-step task execution to Salesforce administration. The company is also extending platform compatibility to additional AI marketplaces and broadening its skills library to cover more Salesforce clouds and use cases. By combining open standards, domain-specific intelligence, and a relentless focus on the admin experience, Cirra AI is building the de-facto AI integration layer for Salesforce administration.
Disclaimer
This document is provided for informational purposes only. No representations or warranties are made regarding the accuracy, completeness, or reliability of its contents. Any use of this information is at your own risk. Cirra AI shall not be liable for any damages arising from the use of this document. This content may include material generated with assistance from artificial intelligence tools, which may contain errors or inaccuracies. Readers should verify critical information independently. All product names, trademarks, and registered trademarks mentioned are property of their respective owners and are used for identification purposes only. Use of these names does not imply endorsement. This document does not constitute professional or legal advice. For specific guidance related to your needs, please consult qualified professionals.