Dreamforce's Unified Agent Trust Vision Shatters on Fragmented Reality
Salesforce's Dreamforce event has highlighted its vision of a unified agent trust architecture. However, the reality on the ground is far more fragmented, with three distinct layers: governance specification, runtime authority, and runtime enforcement.
The governance layer is currently a crowded field, where organizations attempt to define agent behavior before execution. The OWASP Top 10 for Agentic Applications has highlighted critical risks such as Agent Goal Hijack and Identity and Privilege Abuse. Enterprises are cobbling together a governance stack from vendors like Okta, IBM, Broadcom, and Dataiku.
The challenge shifts to runtime authority once specifications are set, where the industry is moving away from static permissions toward more dynamic models. Akeyless has introduced intent-based access control, while CrowdStrike is pushing SPIFFE-based identities to ensure agents are cryptographically verifiable.
Runtimes enforcement is the final hurdle, where security policies meet live traffic. This is the domain of bidirectional API security and agent fabrics, recently exemplified by the expanded integration between Akamai and MuleSoft.