All field notesWorkflow Ownership

The Next ERP Is the Control Plane Above Your Systems

ERP and CRM remain systems of record. The next operational advantage is a governed control plane that coordinates context, agents, permissions, actions, evidence, and cost across them.

The Next ERP Is the Control Plane Above Your Systems

ERP is not going away.

Neither is CRM, your contract repository, analytics stack, ticketing platform, or the spreadsheets that still hold critical operating knowledge.

The important shift is happening above them.

On 11 September, Salesforce introduced what it calls a Trusted Enterprise AI Harness: six capabilities spanning context, agency, action, governance, security, and models. It also announced an AI Control Plane intended to provide one place to discover and register agents, establish identity and policy, manage their lifecycle, evaluate performance, observe behaviour and outcomes, and control cost across Salesforce and third-party systems.[1]

This is a product announcement, not proof that any company has solved agentic transformation. But the architecture points to the real problem operators now need to address.

Buying more agents is not the same as building an agentic business.

Systems of record are necessary, but they do not coordinate the work

An ERP records inventory, orders, fulfilment, invoices, and financial transactions. A CRM records customers, opportunities, interactions, and commitments. Each system is valuable because it preserves an authoritative part of the business.

But most business outcomes cross several systems.

Salesforce uses a simple question to illustrate this: “Can we fulfil this order today?” The CRM knows the customer relationship. The ERP knows inventory and fulfilment. Contracts contain commitments and entitlements. Analytics defines business terms. Policies determine what can be promised. Previous interactions provide context.[1]

A person handling that question has to gather the facts, interpret the situation, check the rules, decide what is safe to promise, and trigger the next action.

A useful digital coworker must do the same work without inventing certainty or bypassing authority.

That is why the control plane matters. It does not replace the systems of record. It coordinates how intelligence moves across them.

The six layers operators should design

Salesforce describes six capability areas. Strip away the product language and they become a practical operating checklist.

1. Context: What does the agent know?

Context is not “give the model access to everything.” It is the governed combination of data, definitions, memory, policies, and current signals required for a specific outcome.

For an order decision, the agent may need the customer’s contract, current inventory, payment status, fulfilment rules, and recent correspondence. It probably does not need unrestricted access to payroll or every customer record.

Start with the minimum trusted context required to do the job. Name the source of truth for each field. Decide how stale data can be before the agent must stop or ask.

2. Agency: What is the agent responsible for?

An agent needs a bounded objective, not a vague instruction to “handle operations.”

Define the outcome, the stopping conditions, the decisions it may make, and the situations it must escalate. If several agents collaborate, assign one orchestrator to hold the shared state, route work, and reconcile the result.

Orchestrate, do not merely operate a collection of disconnected bots.

3. Action: What can the agent actually change?

Reading an inventory figure is different from reserving stock. Drafting a customer update is different from sending it. Recommending a discount is different from changing the price.

List the allowed actions explicitly. Separate read, draft, propose, approve, and execute permissions. Make consequential changes pass through deterministic checks rather than hoping a prompt will behave like a policy engine.

4. Governance: Which rules must always hold?

Open-ended reasoning can be useful. Enterprise execution cannot be open-ended everywhere.

Governance should define data lineage, quality thresholds, approval gates, exception handling, retention, and rollback. It should also answer a basic question: if the agent makes the wrong change, can the business reconstruct what happened and reverse it safely?

Human-in-the-loop does not mean asking a person to approve every click. It means placing human judgment at the points where ambiguity, risk, or accountability genuinely requires it.

5. Security: Who is the agent, and what is it permitted to access?

Every digital coworker needs an identity. That identity needs scoped permissions, not borrowed administrator access.

Operators should be able to answer: Which agent acted? On whose authority? Through which tool? Against which record? Under what policy? With what result?

If those answers are missing, the business has automation without accountability.

6. Models: Which intelligence fits the task?

Not every step needs the most capable model. Classification, extraction, summarisation, planning, and final judgment carry different cost and risk.

Route work accordingly. Use deterministic software where rules are fixed. Use lower-cost models for reversible preparation. Reserve stronger models and human review for uncertain or consequential decisions.

Model choice is a control decision, not a popularity contest.

Redesign the workflow before buying the control plane

The danger is turning “AI Control Plane” into the next software category every company feels pressured to purchase.

A platform cannot repair a workflow nobody has examined.

Before adding agents, map one real outcome from request to completion. Identify every handoff, duplicate entry, approval, exception, and system boundary. Ask which steps exist because they create value and which survive only because the old tools could not coordinate the work.

Then redesign.

A good agentic workflow may remove steps rather than automate all of them. It may replace three status meetings with an audit trail. It may turn a blanket approval into a policy-based exception queue. It may let an agent prepare and validate routine changes while a domain expert handles the few cases requiring judgment.

Domain experts should be the architects here. They know which fields are unreliable, which promises carry commercial risk, which exceptions matter, and which “efficient” shortcut will create work downstream.

A bounded pilot for SME leaders

Do not begin with an enterprise-wide agent programme.

Choose one cross-system workflow with a measurable outcome. Order fulfilment, invoice exception handling, CRM follow-up preparation, or service escalation can all work if the boundary is clear.

For that single workflow:

  1. Define the outcome. What does “done” mean, and how will you measure it?
  2. Name the trusted context. Which systems and fields are authoritative?
  3. Give every agent an identity. What can it read, propose, and change?
  4. Set approval points. Which decisions require human judgment?
  5. Instrument the work. Record actions, exceptions, latency, outcomes, and cost.
  6. Design the undo path. Know how to reverse a bad action before granting autonomy.
  7. Expand only with evidence. Increase scope when the logs show that the workflow is reliable, useful, and controlled.

The goal is not maximum autonomy.

The goal is dependable execution with clear ownership.

ERP and CRM will continue to hold the business record. The emerging advantage is the governed layer that helps digital coworkers understand that record, coordinate across it, act within permission, and leave evidence behind.

That is the control plane worth building—whether you buy a platform, assemble one, or start with a disciplined workflow and grow from there.

Sources

[1] https://www.salesforce.com/ap/news/press-releases/2026/09/11/ph-salesforce-introduces-the-trusted-enterprise-ai-harness — Salesforce Introduces the Trusted Enterprise AI Harness

Continue the work

Turn a capable model into dependable execution.

Nexius Labs helps SMEs design the context, tools, permissions, approval gates, and evidence trails around useful Digital Coworkers.