Agentforce, Vertex AI, and Microsoft Copilot need one business control model
Major platforms provide serious native controls. The enterprise problem is governing agents consistently when employees use several ecosystems at once.
Vendor controls remain essential, but they produce different identities, policies, logs, connectors, and approval experiences. Business risk lives across those boundaries.

The multi-platform agent estate is already normal
Sales teams may use Agentforce, knowledge workers may use Microsoft 365 Copilot and Copilot Studio agents, and data or engineering teams may deploy agents on Vertex AI. At the same time, developers run coding agents and product teams build custom workflows. Choosing a strategic cloud does not eliminate the others because agents follow business applications, employee preference, acquisitions, and specialized capabilities.
The CISO and CIO need a control model that respects vendor-native security while making risk comparable across platforms. Without it, every platform team invents different terms for ownership, sensitive access, approval, incident evidence, and decommissioning.
What native platforms do well
Salesforce describes Agentforce security through a shared responsibility model. The platform provides a trust layer and audit capabilities, while customers remain responsible for permissions, least privilege, and agent-specific guardrails. Microsoft provides identity, data policies, DLP, lifecycle management, real-time protection, and governance across Copilot and agent products. Google documents VPC Service Controls for Vertex AI Agent Engine to reduce data exfiltration by keeping access inside defined perimeters.
These are valuable controls and should not be replaced by a generic overlay. Platform identity knows the tenant and resource. Native DLP understands platform data. Network perimeters constrain egress. Vendor logs capture service-specific events. The cross-platform layer should solve the gaps between them.
Where fragmentation creates risk
An employee can be correctly authenticated in each platform while an agent still misunderstands the task. A connector can comply with platform policy while moving data in a way the business did not intend. Approval may exist in one system, appear only in logs in another, and be unavailable before execution in a third. Cost budgets and incident evidence are also split.
The organization needs common definitions for an agent, owner, identity, connected tool, high-impact action, decision, outcome, and expiration. These definitions let governance survive vendor changes and make incidents easier to coordinate.
- Different agent inventories and ownership models
- Different identities, delegated permissions, and service accounts
- Different definitions of sensitive data and high-impact action
- Different approval channels, retention, and audit formats
- Different cost meters, quotas, and budget controls
- Different enforcement timing, from pre-action blocking to retrospective logs

Create one business action taxonomy
Define the consequences the company cares about independent of vendor. Examples include sending external communications, exporting regulated data, changing customer records, modifying production, granting access, creating a financial commitment, and executing a bulk operation. Map each vendor's agent actions to that taxonomy.
Then assign a control objective. Some actions should be prevented by platform policy. Some should require an action-time human decision. Some can run automatically with evidence. Some sources may only support retrospective detection. The taxonomy creates honesty about what is and is not enforceable.
One attention path for people
Employees should not learn a different approval ritual for every agent. A review should explain which agent is acting, under whose identity, in which system, what will change, why it was escalated, and whether it is reversible. The response must resolve only the request that created it.
Mobile attention matters because valuable agents continue working while people move between meetings and devices. It should be optional and securely enrolled, not a broadcast channel. Desktop and web remain important for detailed evidence and policy settings.

How Business Leash Cloud complements vendor controls
Leash gives supported agents one consistent protection and approval experience. It stops risky actions before they run wherever interception is available, and provides honest after-the-fact visibility where it is not. Business Leash Cloud is the managed business offer for team-wide visibility and control.
The practical value is one security and budget-control layer for the AI tools a team chooses. Native Salesforce, Microsoft, Google, and other controls continue doing what they understand best. Leash focuses on consistent action safety, clear decisions, and cross-device attention.
A cross-platform pilot plan
Select two different agents, such as a coding agent and a SaaS agent. Choose one shared risk, such as external publishing or sensitive data movement. Connect both to the same policy, then compare what each platform can stop and what it can only report.
Use the results to define policy, not vendor preference. If a platform cannot expose a pre-action event, document that gap and use its native controls plus retrospective visibility. Expand only after owners understand the resulting approvals and evidence.