Sales AI agents are graduating from single-touch tasks to work that runs for weeks without a human restarting it, and the vendors selling that autonomy are now selling the oversight layer around it just as hard. Three announcements landed within two days of each other in September, from Salesforce, Talkdesk and Microsoft, and they point at the same shift: the pitch has moved from “the agent can do the task” to “the agent can be trusted with the job.”

From a single touch to a multi-week campaign

The industry has spent the past year moving agents from assisting reps to running parts of a deal outright, and Salesforce’s clearest evidence of the next step is Hunter, the outbound sales agent it has run in pilot and is now building around a new “long-horizon runtime.” Previously, Agentforce agents completed a task or a single interaction. Hunter is designed to hold a goal, such as rescuing at-risk deals before quarter-end, and keep working it over days and weeks: researching accounts, sequencing outreach, adjusting the plan as new information arrives, and flagging the moments where a seller has to approve the next step. Salesforce says the mechanism rests on three capabilities: memory that persists across sessions, durable execution that lets an agent resume after interruption, and dynamic steering that adapts behavior to a seller’s feedback.

The company is citing adoption numbers to back the shift: it says Hunter already builds 60% of client Perk’s sales pipeline, and that Agentforce and Slack combined have processed 7 billion “Agentic Work Units” to date, 3.2 billion of them in a single quarter. Those are vendor-reported figures without an independent methodology attached, which matters for what comes next.

Advertisement

Simplified Management — Advertisement

The pitch changes from capability to control

The same week, Salesforce introduced what it calls an Enterprise AI Harness: a control layer meant to give agents a shared, governed understanding of a customer and the business, then constrain what they are allowed to do with it. The company frames the problem as a coordination gap, not an intelligence gap: no single system holds inventory, contracts, entitlements and policy at once, so an agent acting confidently on partial context is a liability, not a feature. The Harness bundles six capabilities, spanning context, agency, action, governance, security and model routing, behind a new “AI Control Plane” meant to let a business see and manage every agent it has deployed, regardless of vendor.

“The Agentic Enterprise won’t be defined by which model a company chooses. Models will continue to change, and intelligence will increasingly be available everywhere,” said Rohan Kumar, President, Chief Platform and Engineering Officer at Salesforce. “What will differentiate an enterprise is the trusted, proprietary context it brings to that intelligence, starting with the customer, and its ability to securely turn that context into action.”

A customer reference in the same announcement makes the buyer-side logic explicit. “AI is moving faster than any technology we’ve seen, which is exactly why composability matters so much to us. We don’t want to bet our future on one closed stack; we want the freedom to adapt as the landscape shifts,” said Shawn Malhotra, CTO of Rocket Mortgage, describing why the harness model resonated internally.

A second vendor makes the same argument

Salesforce is not alone in reframing autonomy as a governance sale. Talkdesk and Microsoft expanded their partnership this month so enterprises can buy Talkdesk’s Customer Experience Automation directly against existing Azure commitments, collapsing a procurement step that otherwise slows contact-center AI deployments. The pitch, again, is not raw capability. “Enterprise leaders don’t need more standalone bots that simply pass calls along to human agents. They need solutions that solve complex tasks using the systems they already trust,” said Al Caravelli, Chief Revenue Officer at Talkdesk. Microsoft’s own framing leaned the same way: “CIOs are looking to simplify their technology stacks and get clear value out of their cloud spend,” said Alex Staton, EMEA Digital Natives Director at Microsoft, positioning the deal around consolidation and trust rather than a new feature.

Two vendors, in the same week, making a version of the same pitch to buyers who have spent two years hearing that agents can do more: the differentiator now is proof they can be controlled while doing it.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

What it means for the sales leader

A RevOps or sales-ops leader evaluating an autonomous agent this quarter is no longer just buying a capability; they are buying an audit trail. Three questions belong in every vendor conversation now that weren’t standard a year ago. First, what happens when the agent is wrong for three weeks before anyone notices, given that Hunter-style agents are explicitly designed to run without a human checking in on every step? Second, whose adoption numbers are independently verifiable versus self-reported by the vendor or a friendly reference customer? Third, does the governance layer being sold travel with the agent if the underlying model or vendor changes, or does it lock the business into one stack, which is precisely the risk Rocket Mortgage’s CTO named when he described wanting to avoid betting on “one closed stack.”

None of this is an argument against deploying long-horizon agents. It is an argument for treating the control plane, not the agent’s stated win rate, as the primary evaluation criterion, since the whole industry has just told buyers, in its own words, that this is now the differentiator.

What to do next

Sales and RevOps leaders piloting an autonomous agent should ask for the audit log before the demo, not after the contract: every action the agent can take unsupervised, every point where it must stop and ask a human, and whether that control layer is portable if the vendor relationship ends. Buyers who skip that step are still evaluating agents on last year’s terms, capability, while paying this year’s price for something the vendors themselves now call a trust product. For a skeptical look at how far vendor-reported adoption numbers can be trusted at face value, see this publication’s recent opinion piece on agentic AI vendors’ security claims.

Source: Salesforce Newsroom