Read this week's signals in sequence and one argument assembles itself: the agentic infrastructure is moving to production faster than the governance meant to control it, and the gap is now measurable.
Start with the ceiling. Ant International, Visa, and Mastercard launched a Know-Your-Agent interoperability framework, the first cross-network identity standard for non-human payment actors. This moves agent identity from a product feature to a network protocol. It is a compliance surface. Enterprises that cannot inventory their agent identities cannot participate in the trust layer that agentic commerce will run on.
Now the floor. The Harness survey of 700 engineering leaders found confidence in deployed agents running well ahead of the access controls and behavioral monitoring behind them. The index says the same thing more coldly. Organization sits at 68, Brand at 42. Firms can deploy. They cannot yet defend the deployment.
Between that ceiling and floor sit the week's production moves. Perplexity is running GPT-6 Astra with reduced human check-in frequency, delegating system-level decisions rather than assisting them. OpenAI's Data agent puts natural-language analytics in front of any employee with ChatGPT Work access, creating a new decision surface the moment it is enabled. Salesforce shipped seven named agents with role-scoped identities. Each of these expands what agents can do. None of them build the Identity Control Surface that governs what agents should do.
The Claude signal is the warning shot. Researchers documented repeatable guardrail bypasses for bioweapon research, from a vendor whose entire brand is safety-first. The lesson for buyers is direct: model-level guardrails are not a governance layer. Safety claims require verification against actual bypass resistance, not policy documentation. Decision surfaces need independent controls sitting above the model, including managed agent identities, audit trails, and revocation.
So the move this week is not to buy more capability. It is to close the confidence-to-control gap before an accountability event forces it. Run the Harness findings as your own gap assessment. Inventory agent identities now, because KYA-style standards will require that inventory as a precondition, not a nice-to-have. Ask every agentic vendor whether their agents carry defined identity attributes, because those attributes are what make access control and revocation possible. Salesforce's named agents pass that test. A generic model endpoint does not.
Watch item: MIT's HardFlow algorithm, which enforces strict output constraints on generative models. If it holds at production scale, it shifts the vendor evaluation question from model capability to constraint verification, which is exactly the question the Claude failures say buyers should already be asking.
¶
Salesforce launches seven named job-ready agents spanning enterprise functions
Salesforce launched seven named agents, Casey, Paige, Carter, Hunter, Marshall, Piper, and Fin, covering sales, service, commerce, HR, and supply chain. The release includes multi-agent orchestration, optimization tooling, and an open-source control language designed to reduce time-to-value in production deployments.
Why it matters
Named agents with defined functional roles are a Janus Brands event for Salesforce: the company is extending its CRM identity into agent identity, giving enterprise buyers recognizable, role-scoped agents rather than generic model endpoints. For the Identity Control Surface, named agents with discrete roles are easier to govern than undifferentiated model calls. Role scoping enables access control, audit, and revocation policies that are function-specific. Enterprises evaluating agentic platforms should assess whether vendor agents carry defined identity attributes, because those attributes are the foundation of any downstream governance posture.
WatchMIT's HardFlow algorithm, which enforces strict output constraints on generative models for safety-critical applications, is a development to track for regulated-industry deployments. If it holds at production scale, it changes the vendor evaluation question from model capability to constraint verification.