The problem agent sprawl creates once nobody is counting
Salesforce used its Dreamforce 2026 conference to address a problem that has been building quietly across enterprises all year: nobody keeping a reliable count of how many AI agents are actually running, what they can access, or who owns them once a department spins one up outside a formal review process. That gap sounds like a minor administrative failure until an agent with the wrong permissions takes an action nobody authorized, at which point it becomes an incident report and, potentially, a regulatory disclosure that lands squarely on the CIO's desk.
The company's answer is a set of governance tools built around the assumption that agent sprawl is already happening and needs to be discovered, not merely prevented going forward from this point on. That framing matters. Most enterprise AI governance guidance published over the past two years assumes organizations are deploying agents deliberately and can build controls in from the start. Salesforce's Dreamforce announcements instead assume many enterprises already have agents running that nobody centrally tracks, and design for cleanup rather than for a clean slate that no longer exists.
What Guardian and Agent Fabric actually do
Salesforce Guardian focuses on agent identity management and what the company calls rogue agent discovery, giving security and IT teams a way to identify agents operating without proper oversight, including ones that were never formally provisioned through IT in the first place. That capability targets exactly the shadow AI problem surveys have flagged repeatedly this year: business units standing up agents through low-code tools or vendor trials without informing the technology organization responsible for securing them or their access to sensitive systems.
Agent Fabric is the broader piece, a central registry designed to track AI agents across multiple providers rather than only agents built natively on Salesforce's own platform. That multi-vendor scope is the more consequential design choice here. An agent registry that only sees Salesforce-native agents offers limited use to an enterprise running agents from several vendors at once, which describes most large organizations at this stage of their AI adoption journey, regardless of which platform anchors their core systems of record.
The data retention commitment aimed at the holdouts
The Trusted Enterprise AI Harness adds zero-data-retention commitments to the governance stack, a direct answer to the enterprises, disproportionately in regulated industries, that have kept sensitive workloads out of agentic AI specifically because they could not get firm guarantees about what happened to the data an agent touched during a task. Zero-retention commitments narrow that specific blocker considerably, removing one of the more common reasons risk-averse legal and compliance teams have declined to approve agent deployment on anything touching regulated data, though broader governance questions remain.
Combined with Guardian and Agent Fabric, the harness rounds out a stack addressing three distinct governance failure modes at once: not knowing what agents exist, struggling to identify unauthorized ones once deployed, and being unable to guarantee what happens to sensitive data those agents process along the way. Enterprises that have stalled agentic AI deployment specifically over one of these three gaps now have a named product to evaluate against that exact blocker, rather than a generic AI governance pitch.
Why a registry is becoming table-stakes infrastructure
The comparison worth drawing is to device and software asset management, which went from a nice-to-have to mandatory infrastructure once device sprawl and shadow IT outgrew what manual tracking could handle a decade ago. Agent sprawl is following the same trajectory, but faster, because the barrier to standing up an agent is lower than the barrier to provisioning a laptop, and the blast radius of an unmonitored agent with broad data access can exceed that of an unmanaged device by a wide margin.
CIOs who have not yet built or bought an agent inventory should treat that gap with the same urgency device fleets received a decade ago, rather than as a lower-priority cleanup item for next year. The specific vendor and tool matter less than the underlying requirement: a current, centrally maintained record of every agent running in the organization, what it can access, and who is accountable for it, updated as a standing operational process rather than an annual audit exercise.
What this means for your governance roadmap
Salesforce's announcements are, unsurprisingly, a Salesforce product pitch, and CIOs already committed to other platforms should evaluate whether Agent Fabric's multi-provider registry actually delivers cross-vendor visibility in practice or favors Salesforce-native agents in ways that only become clear once implementation is underway. That verification belongs in any proof of concept before a purchase decision gets made, not discovered afterward when switching costs are already sunk and the registry is already load-bearing for security reporting.
The underlying requirement stands regardless of vendor choice. If your organization cannot currently produce an accurate list of every AI agent in production, along with its data access and ownership, treat that gap as worth closing before the next incident forces the question on someone else's timeline. Device and identity management eventually received that same seriousness once their absence became too costly to ignore, and agent governance is on the same trajectory now, just moving considerably faster than either of those disciplines did in their own early years. Building the inventory now, before the board asks for it, is cheaper than building it under incident-response pressure later.



