Skip to main content
Field Notes/brynagentsgovernanceaudit-logdreamforceunbound

Dreamforce and UNBOUND Are Putting Agents Inside Their Platforms. Your Pipeline Runs Across Six Tools.

Dreamforce and UNBOUND are showing what agents can do inside Salesforce and HubSpot. Most growth teams I talk to do not work inside one platform: buyer activity moves across the website, product, CRM, Slack, outbound, and the data warehouse. The practical question is who is allowed to act across those systems, and where you can review the decisions and actions across the workflow.

Chris Hart
Chris Hart, Chief Executive Officer
13 min read
Where the agent lives versus where the work happens. Your pipeline crosses six systems. Its controls need to cross them too. Left: an agent inside a platform, one platform with its own rules and log. Right: one approved workflow and one Bryn audit log across the stack, connected to six tools: Website, Product, CRM, Slack, Outbound, Warehouse. One account, six systems, before a seller responds. The question for every agent demo: who can act across the tools, under what rules, and where can you review what the agent decided and did?
tl;dr

Dreamforce and UNBOUND are showing agents working inside Salesforce and HubSpot. Most growth teams do not work inside one platform: one account touches the website, product, CRM, Slack, outbound, and the warehouse before a seller responds. The question this week is not whether an agent can act. It is who is allowed to act across those systems, and where you can review the decisions. Three questions to ask in every demo, including ours.

Dreamforce and UNBOUND are showing what agents can do inside Salesforce and HubSpot. Most growth teams I talk to do not work inside one platform: buyer activity moves across the website, product, CRM, Slack, outbound, and the data warehouse. The practical question is who is allowed to act across those systems, and where you can review the decisions and actions across the workflow.

Dreamforce runs September 15 to 17 in San Francisco, built around what Salesforce calls the Agentic Enterprise (Salesforce). UNBOUND, the event HubSpot used to call INBOUND, runs September 16 to 18 in Boston (HubSpot), with its Breeze agents at the center of the program.

That is useful progress. The question is no longer only whether agents can do useful work. It is how a company governs them once they can act in production systems.

Salesforce's 2026 Agentic Enterprise Index says the average number of activated agents per organization nearly tripled between February 2025 and April 2026, while average creation time fell 53 percent (Salesforce). Creating agents is getting easier. Running more of them safely is the harder job.

Why agents inside one platform make sense

Agents inside a platform have real advantages.

An agent inside your CRM starts close to the data it acts on. It can inherit permissions your admin already manages, and there is one vendor accountable for the platform. If most of your customer work already happens inside that platform, this is a strong design.

The limitation appears when the work crosses platforms.

Your pipeline crosses the tools

At a 50 to 500 person software company, one active account can touch six systems before a seller responds.

A prospect at a target account visits pricing three times in a week. Two people from the same company are active in a trial. The account is already in the CRM with a stale owner. Your team expects alerts in Slack, follow-up through the outbound tool, and reporting in the warehouse. That is one account spread across six systems.

Even when agents connect to other systems, permissions, actions, and logs can still be managed platform by platform. The operating question is whether anyone can see and govern the full sequence.

Deloitte surveyed 501 US leaders involved in agentic AI programs between April and June 2026. The three factors they cited most often as preventing agents from scaling were the lack of a unified and accessible data foundation (72 percent), an inability to trust and govern agents (70 percent), and the cost and complexity of integration (67 percent) (Deloitte). Those are separate problems, but they converge in one operating challenge: coordinating work across systems while keeping data, permissions, and records consistent.

As the number of agents grows, the problem compounds. When a deal moves or stalls, can the growth lead answer one question in one place: what happened on this account, what action did we take, and why?

BRYN byCivicLabor Day offer ⬩ through September 17

Save Your Labor (Day)

Bryn watches your site, scores the account, runs the Play, and files the run. A free month of it, on any tier.

One place to approve cross-tool actions, one log to review them

You need one place to define what agents are allowed to do across tools, and one audit log that shows what the workflow actually did. The rules should state which accounts, channels, and actions are allowed and what is prohibited. The log should show the trigger, decision, and action for every run in a format growth, finance, and compliance can review.

Last week I wrote about Workday's earnings call, where its CEO emphasized the controls around agents. I reduced those controls to three: boundaries, approval, and an audit log. A platform can enforce those controls for the systems it owns. Once a workflow crosses into third-party tools, the same controls need to follow the work across those boundaries. Whatever coordinates the workflow needs visibility across the whole sequence.

That is the test I would use for every agent demo this week: can you control and review the full cross-tool workflow, or only what happens inside one platform?

How Bryn does this

Bryn is Civic's GTM agent for founders, first GTM hires, and growth teams. It watches activity across your website, product, and CRM, scores that activity against the customer profile you define for fit, intent, and timing, and runs a workflow when the conditions you approved are met. Bryn calls that workflow a Play.

Each Play carries the rules your team approved: when this pattern appears on an account like this, take these actions through these channels, and no others. In Run mode, Bryn executes when the conditions match. In Approve mode, it waits for a one-click confirmation before the final action. Either way, Bryn writes the run to one audit log showing what it saw, why it scored the account the way it did, and what it did.

Those actions go through the tools you already use. Bryn can write to collaboration, CRM, outbound, and messaging systems, with webhooks for other destinations (Bryn). Nothing needs to be replaced: your CRM remains the CRM, your outbound tool remains the sender, and Bryn keeps the cross-tool decision and its audit record in one place.

In practice, that changes three things.

  • Signals that arrive overnight can be scored and acted on before someone starts a manual review, with the evidence attached to the resulting task or alert.
  • High-intent activity can trigger a response while it is recent. In Civic's first live Bryn run, Bryn moved from signal to action in under five minutes, and we publish that run on the product page.
  • Finance and compliance can review one exportable record of Bryn's decisions and actions instead of reconstructing the workflow across multiple systems.

One boundary matters. Bryn controls and records what it initiates, but it does not control the internal behavior of a third-party tool after that tool receives the request. Bryn's audit log is therefore the complete record of Bryn's decisions and actions, not a replacement for the downstream tool's own logs.

We are Bryn's first customer, and it runs our own pipeline today. It is currently US-only, and the trust center describes what it does and does not do (trust). Bryn starts at $49 a month with a seven-day trial and no contract minimum (pricing).

Three questions to ask in every agent demo

If you're in San Francisco or Boston this week, or watching online, ask these three questions in every agent demo, including ours.

When buyer activity starts in one system and the response happens in another, what decided to act, under whose rules, and where is that decision recorded?

Can I see every action the agent took across my tools in one audit log, and can I export it?

Who approved the agent's authority, where is that approval recorded, and how do I change or stop it?

What a complete answer looks like

Open a question to compare an answer that is visible in the product with one that is not finished.

Wording drawn from this article. A complete answer is visible in the product; an unfinished one exists only in policy documents or roadmap slides.

Three questions, as Chris asks them above, each opening to what a complete answer looks like and what an unfinished one sounds like. No score, no quiz.

If those answers are visible in the product, you have the information needed to operate agents in production. If the answers exist only in policy documents or roadmap slides, the operating model is not finished.

If you're working through this for your own stack, at either event or after, I'm glad to talk.


Sources: Salesforce, The Architect's Guide to Dreamforce 2026 · HubSpot, UNBOUND 2026 Returns to Boston · Salesforce, Agentic Enterprise Index 2025 to 2026 · Deloitte, The Path to Agentic Transformation, 2026 · Bryn · Bryn trust center · Bryn pricing

Chris Hart

Chris Hart

Chief Executive Officer

More essays by Chris

Chris Hart is the CEO at Civic; he brings together decades of experience across technology, finance, and identity to help businesses navigate the shift to agentic AI. His Silicon Valley career spans more than 25 years, from running infrastructure at early internet and fintech startups to leading finance and operations teams at high-growth technology companies.

Beyond Civic, Chris has championed veteran leadership as Vice Chair of the Pat Tillman Foundation since 2006. When he isn't thinking about the future of identity and AI, you'll probably find him surfing or hanging out with his Dalmatian.