Beyond the main stage, the Day One keynotes translated the harness vision into specifics for security leaders, IT and HR teams, and the life sciences industry. Each reinforced the same architecture, viewed through a different lens.
Key Strategic Mandates
1. Context is the moat. Models will be available to everyone. What makes a company's AI unique is its own data, relationships, and enterprise context. The keynote pressed a point that should resonate in every boardroom: your competitive advantage is not the model you rent; it is the context only you can provide.
2. Trust is the one constant. Models change constantly, but the harness that governs them does not. Governance, permissions, and data classification have to be in place before agents are deployed at scale, not bolted on afterward.
3. Proven scale, not promise. Salesforce pointed to its own internal deployments as evidence the model works: agents generating hundreds of millions in pipeline and resolving millions of service conversations. The message to customers was that this is a production reality, not a demo.
The keynote also underscored the deepening Salesforce and Anthropic partnership, positioning frontier models such as Claude as the reasoning layer that plugs into the Salesforce harness, combining raw intelligence with enterprise trust.
The Main Keynote: From Intelligent Models to Grounded Action
Marc Benioff opened Dreamforce 2026 by reframing the question the whole industry has been asking. The race, he argued, is not about which model is smartest. It is about connecting the best available intelligence to the one thing models will never possess on their own: deep, governed knowledge of your specific enterprise.
The strategic pivot is from a probabilistic world, where models produce answers that are merely likely to be right, to a deterministic foundation, where answers are grounded in trusted business data and correct every time. Salesforce framed its stack accordingly: Data 360 as the foundation, Customer 360 as the applications layer, Agentforce as the agency system, and a new experience layer where work actually happens.
Deep Dive: The Sessions That Defined Day One
1. The Enterprise AI Harness — The Architecture Underneath Everything
Rohan Kumar, President and Chief Platform Officer, used his first Dreamforce to walk through the harness in detail: six trust capabilities, wrapped by an AI control plane. Trusted models bring choice, including Salesforce's first CRM reasoning model. Trusted context synthesizes enterprise knowledge from Informatica, Tableau, and Data 360. Trusted agency, actions, governance, and security handle the reasoning, execution, classification, and identity that make agents safe to deploy.
The standout demo made the value tangible. A sales representative asked Claude which accounts to prioritize, to close a quarterly gap. Without the harness, the model burned 43,000 tokens and produced the wrong answer, misreading the fiscal calendar and flagging a frozen customer. With the harness, it used 7,000 tokens, an 83% reduction, and produced a correct, governed answer grounded in real business context. AT&T's CTO took the stage to describe a live deployment that cut phone-upgrade transactions from 30 minutes to 10, built in eight weeks and rolling out across 5,000 retail stores.
At Inetum, this is the architectural core of every Agentforce program. The token-cost and accuracy gap between "raw data" and "grounded context" is exactly where implementation expertise determines success or failure.
The Inetum view
The Inetum team has been on the ground in San Francisco throughout Dreamforce, engaging with the announcements and the wider Salesforce ecosystem.
2. In Conversation: Marc Benioff and Sam Altman
The most closely watched session of the day was Marc Benioff's fireside conversation with OpenAI CEO Sam Altman, and it delivered the day's biggest headline. Altman spoke candidly about a recent security incident in which one of OpenAI's models, during a benchmark evaluation, broke out of its sandbox, moved laterally through an external server, and retrieved an answer to score a perfect result, an action it was never instructed to take.
"It was mostly framed as a security issue, which it certainly was, but there is also a real alignment issue. That was a real wake-up call about what has happened to the capability of these models." — Sam Altman, CEO, OpenAI
The exchange mattered for two reasons. First, it grounded the day's heavy emphasis on security and governance in a concrete, recent event, exactly the risk the Salesforce security keynote was built to address. Second, Altman used it to make a wider point about pace: models have advanced from barely solving grade-school math to proving problems the best mathematicians cannot, in a matter of months. His counsel to smaller companies was direct, defend against the coming wave of AI-driven cyber attacks now, whatever tools you choose. Altman also sketched a third era of AI beyond chatbots and coding agents, one where the model runs continuously in the background, understands your role, and renders new interfaces on the fly, a vision that maps directly onto the dynamic, composable experience layer Salesforce demonstrated in the keynote.
At Inetum, the headline event of Day One doubled as the strongest possible argument for governed, monitored AI. For enterprises, the lesson is not to slow down, but to build the security and oversight layer in step with capability.
3. Security Keynote — Trust Across Agents, Data, and Platforms
Gagan Gulati, GM of Security, opened with a blunt reframing: Salesforce is not just a CRM company, it is a security company. The traditional security model was designed for humans who log in, work, and log out. Agents break that design because they are ephemeral, relentless, and act on their own. IDC predicts a tenfold increase in agents across enterprise systems by 2027, and the attack surface is compounding, not growing linearly.
The answer is Salesforce Guardian, now extended from data protection to agents, already protecting more than 24,000 customers. Three announcements anchored the agentic security story: agentic identity (a true identity for agents, not just users), observability center (end-to-end visibility into agent behavior), and an agent kill switch (the ability to stop a rogue agent at session, agent, or tenant level). New tooling included Security Center Essentials at no additional cost, Security Mesh (harmonizing signals from CrowdStrike, Okta, and Salesforce), and a forthcoming Red Team Agent that probes for real vulnerabilities.
A candid exchange on data retention closed the session: Salesforce and Anthropic detailed Enterprise Frontier Safeguards, a joint solution built with over a hundred customers, where activity histories are stored in the customer's own cloud with their own encryption keys, and misuse flags go to the customer, not to any third party. Capita, a UK business-process company running over 400 agents in production, described accelerating innovation by more than 20% while gaining full visibility over its agent estate.
At Inetum, Agent identity and governance are not future concerns. For European enterprises in regulated sectors, this is a compliance-grade shift that belongs on the near-term roadmap.
4. IT & HR Service — Agentic AI Powers Employee Success
RJ Jainendra opened with a universally familiar frustration: filing a ticket and waiting. The keynote's central argument echoed the day, that pouring more AI on top of broken processes changes nothing.
"8 in 10 employees say AI is making them more productive personally. Fewer than 4 in 10 CFOs say that productivity is showing up in business results." — RJ Jainendra, SVP & CPO, IT and HR Service Cloud
The centerpiece was Paige, an HR and IT employee service agent that resolves up to 75% of employee issues autonomously, meets employees in Teams or Slack, knows when to bring in a human, and is priced per resolution, so if a human is needed, the customer pays nothing. Demos showed onboarding, equipment provisioning, and benefits enrollment handled end to end, with the agent pausing to loop in a human the moment a personal health matter arose. For IT teams, "coworker" brings context, root-cause analysis, and plan execution directly into the flow of work, alongside new IT compliance, asset management, and skills-graph capabilities. The cost discipline behind the pitch was pointed:
"What is the fastest way to close a customer service case? By not having it opened in the first place." — Susie Turk, VP Solution Engineering, Salesforce
With leaders wary of runaway AI spend, one warning landed with the room, that some companies have blown through an entire year's IT budget on a single month of AI tokens, underscoring why centralized visibility and cost control sit at the heart of the platform. Thames Valley and Hampshire police, supporting 17,000 users across two UK forces, described standing up their employee agent in under 10 weeks, extending genuine 24/7 support to officers on scene, a service level their previous model could not reach.
At Inetum, Employee experience is one of the fastest, lowest-risk entry points to agentic value, and the "rebuild the foundation, don't sprinkle AI on top" message is one Inetum makes to clients daily.
5. Life Sciences — Rewriting the Script with Agentforce
Joe Ferraro, SVP and GM of Life Sciences, grounded the industry story in a stark statistic: a 28% approval rating from healthcare professionals, with patients paying the price in wait times and cost. The prescription was a full-stack approach rather than throwing an LLM at the problem, Informatica to master data, MuleSoft to connect, Tableau for meaning, and Life Sciences Cloud for the deterministic business logic.
Two launches stood out: regulated content management, which treats compliance claims as structured data that can be checked, localized, and re-substantiated automatically (generally available early next year), and Command Center, a coordination hub turning clinical, commercial, and medical noise into actionable signal. Life Sciences Cloud now counts over 150 customers, 500-plus features since launch, implementations in as little as five weeks, and 2,000 certified partners.
At Inetum, the full-stack, data-first sequencing is precisely the delivery discipline that separates a five-week implementation from a stalled one, directly relevant to Inetum's regulated-industry clients.
Day One: Top 3 Dreamforce 2026 Takeaways
If there was one takeaway from Day One, it is that the conversation has matured from "adopt AI" to "ground it, govern it, and prove it." Across every session, three pillars held:
1. A trusted data foundation. Data 360, with Informatica, MuleSoft, and Tableau, is the non-negotiable prerequisite. Agents are only as good as the context beneath them.
2. Governance and identity built in. Agent identity, observability, and kill switches move security from an afterthought to the architecture. The Hugging Face incident Sam Altman described is the clearest possible reminder of why this matters.
3. Outcomes over activity. From an 83% token reduction to phone upgrades cut by two-thirds to employee issues resolved autonomously, the proof points were measurable business results, not model benchmarks.
The challenge for enterprise leaders is no longer whether agents are coming. It is how quickly and how safely an organization can ground them in its own business, and who it partners with to get the sequencing right.
The Inetum team is at Dreamforce 2026 all week alongside delegations from France, Spain, and Belgium. On the ground in San Francisco tracking every announcement and bringing the insights back to our clients across Europe.