# Dreamforce and UNBOUND Are Putting Agents Inside Their Platforms. Your Pipeline Runs Across Six Tools.

*Published 2026-09-15* | Author: chris-hart

> **tl;dr** Dreamforce and UNBOUND are showing agents working inside Salesforce and HubSpot. Most growth teams do not work inside one platform: one account touches the website, product, CRM, Slack, outbound, and the warehouse before a seller responds. The question this week is not whether an agent can act. It is who is allowed to act across those systems, and where you can review the decisions. Three questions to ask in every demo, including ours.

*Dreamforce and UNBOUND are showing what agents can do inside Salesforce and HubSpot. Most growth teams I talk to do not work inside one platform: buyer activity moves across the website, product, CRM, Slack, outbound, and the data warehouse. The practical question is who is allowed to act across those systems, and where you can review the decisions and actions across the workflow.*

Dreamforce runs September 15 to 17 in San Francisco, built around what Salesforce calls the Agentic Enterprise ([Salesforce](https://www.salesforce.com/blog/salesforce-architect-guide-dreamforce-2026)). UNBOUND, the event HubSpot used to call INBOUND, runs September 16 to 18 in Boston ([HubSpot](https://unbound.hubspot.com/blog/inbound-2026-returns-to-boston)), with its Breeze agents at the center of the program.

That is useful progress. The question is no longer only whether agents can do useful work. It is how a company governs them once they can act in production systems.

Salesforce's 2026 Agentic Enterprise Index says the average number of activated agents per organization nearly tripled between February 2025 and April 2026, while average creation time fell 53 percent ([Salesforce](https://www.salesforce.com/news/stories/agentic-enterprise-index-insights-2026)). Creating agents is getting easier. Running more of them safely is the harder job.

## Why agents inside one platform make sense

Agents inside a platform have real advantages.

An agent inside your CRM starts close to the data it acts on. It can inherit permissions your admin already manages, and there is one vendor accountable for the platform. If most of your customer work already happens inside that platform, this is a strong design.

The limitation appears when the work crosses platforms.

## Your pipeline crosses the tools

At a 50 to 500 person software company, one active account can touch six systems before a seller responds.

A prospect at a target account visits pricing three times in a week. Two people from the same company are active in a trial. The account is already in the CRM with a stale owner. Your team expects alerts in Slack, follow-up through the outbound tool, and reporting in the warehouse. That is one account spread across six systems.

ONE ACCOUNT, SIX TOOLS (interactive: select a tool to compare two operating models, separate rules in each platform versus one approved workflow across the stack)
Tool | Separate rules and logs | One approved workflow
Website | Pricing activity is scored and logged in the web tool. | Pricing activity becomes a signal on the account and can trigger the approved workflow.
Product | Trial activity is logged in the product tool, separately from the pricing activity. | Trial activity is added to the same account and included in the fit, intent, and timing score.
CRM | The CRM uses its own data and rules to decide whether to create a task. | The approved workflow creates the CRM task and attaches the evidence that triggered it.
Slack | A separate Slack rule posts an alert using the data available to that rule. | The workflow posts the alert to the approved channel with the supporting evidence attached.
Outbound | The sequencer uses its own rules to decide whether to enroll the contact. | The workflow enrolls the contact only when the approved conditions are met and sends the supporting evidence with it.
Warehouse | Reporting has to combine activity from several logs and formats. | Bryn's audit log provides one record of the trigger, decision, and actions Bryn took across the workflow.
Illustrative sequence. The six tools are a typical growth stack for a 50 to 500 person software company, not survey data. In the one-workflow model, approved rules define which accounts, actions, and channels are allowed, and the audit log records the trigger, score, decision, and actions Bryn took.
One account, six tools. Select a tool to compare separate rules and logs in each platform with one approved workflow and one audit log across the stack. Terms as used in this article.

Even when agents connect to other systems, permissions, actions, and logs can still be managed platform by platform. The operating question is whether anyone can see and govern the full sequence.

Deloitte surveyed 501 US leaders involved in agentic AI programs between April and June 2026. The three factors they cited most often as preventing agents from scaling were the lack of a unified and accessible data foundation (72 percent), an inability to trust and govern agents (70 percent), and the cost and complexity of integration (67 percent) ([Deloitte](https://www.deloitte.com/us/en/insights/industry/technology/path-to-agentic-transformation.html)). Those are separate problems, but they converge in one operating challenge: coordinating work across systems while keeping data, permissions, and records consistent.

As the number of agents grows, the problem compounds. When a deal moves or stalls, can the growth lead answer one question in one place: what happened on this account, what action did we take, and why?

## One place to approve cross-tool actions, one log to review them

You need one place to define what agents are allowed to do across tools, and one audit log that shows what the workflow actually did. The rules should state which accounts, channels, and actions are allowed and what is prohibited. The log should show the trigger, decision, and action for every run in a format growth, finance, and compliance can review.

Last week I wrote about [Workday's earnings call](https://www.civic.com/field-notes/workday-credited-the-guardrails), where its CEO emphasized the controls around agents. I reduced those controls to three: boundaries, approval, and an audit log. A platform can enforce those controls for the systems it owns. Once a workflow crosses into third-party tools, the same controls need to follow the work across those boundaries. Whatever coordinates the workflow needs visibility across the whole sequence.

That is the test I would use for every agent demo this week: can you control and review the full cross-tool workflow, or only what happens inside one platform?

## How Bryn does this

Bryn is Civic's GTM agent for founders, first GTM hires, and growth teams. It watches activity across your website, product, and CRM, scores that activity against the customer profile you define for fit, intent, and timing, and runs a workflow when the conditions you approved are met. Bryn calls that workflow a Play.

Each Play carries the rules your team approved: when this pattern appears on an account like this, take these actions through these channels, and no others. In Run mode, Bryn executes when the conditions match. In Approve mode, it waits for a one-click confirmation before the final action. Either way, Bryn writes the run to one audit log showing what it saw, why it scored the account the way it did, and what it did.

Those actions go through the tools you already use. Bryn can write to collaboration, CRM, outbound, and messaging systems, with webhooks for other destinations ([Bryn](https://www.civic.com/bryn)). Nothing needs to be replaced: your CRM remains the CRM, your outbound tool remains the sender, and Bryn keeps the cross-tool decision and its audit record in one place.

In practice, that changes three things.

- Signals that arrive overnight can be scored and acted on before someone starts a manual review, with the evidence attached to the resulting task or alert.
- High-intent activity can trigger a response while it is recent. In Civic's first live Bryn run, Bryn moved from signal to action in under five minutes, and we publish that run on the product page.
- Finance and compliance can review one exportable record of Bryn's decisions and actions instead of reconstructing the workflow across multiple systems.

One boundary matters. Bryn controls and records what it initiates, but it does not control the internal behavior of a third-party tool after that tool receives the request. Bryn's audit log is therefore the complete record of Bryn's decisions and actions, not a replacement for the downstream tool's own logs.

We are Bryn's first customer, and it runs our own pipeline today. It is currently US-only, and the trust center describes what it does and does not do ([trust](https://www.civic.com/bryn/trust)). Bryn starts at $49 a month with a seven-day trial and no contract minimum ([pricing](https://www.civic.com/bryn/pricing)).

## Three questions to ask in every agent demo

If you're in San Francisco or Boston this week, or watching online, ask these three questions in every agent demo, including ours.

When buyer activity starts in one system and the response happens in another, what decided to act, under whose rules, and where is that decision recorded?

Can I see every action the agent took across my tools in one audit log, and can I export it?

Who approved the agent's authority, where is that approval recorded, and how do I change or stop it?

WHAT A COMPLETE ANSWER LOOKS LIKE (interactive: open a question to compare an answer that is visible in the product with one that is not finished)
1. When buyer activity starts in one system and the response happens in another, what decided to act, under whose rules, and where is that decision recorded? A COMPLETE ANSWER, VISIBLE IN THE PRODUCT: One place defines what agents are allowed to do across tools. The rules state which accounts, channels, and actions are allowed and what is prohibited. One audit log shows the trigger, decision, and action for every run. AN UNFINISHED ANSWER: Permissions, actions, and logs are managed platform by platform. Nobody can see and govern the full sequence. The answer exists only in policy documents or roadmap slides.
2. Can I see every action the agent took across my tools in one audit log, and can I export it? A COMPLETE ANSWER, VISIBLE IN THE PRODUCT: One audit log shows what the workflow actually did, in a format growth, finance, and compliance can review. Finance and compliance review one exportable record of the agent's decisions and actions. AN UNFINISHED ANSWER: Each platform keeps its own log. Answering what happened on this account means reconstructing the workflow across multiple systems.
3. Who approved the agent's authority, where is that approval recorded, and how do I change or stop it? A COMPLETE ANSWER, VISIBLE IN THE PRODUCT: Each workflow carries the rules your team approved: when this pattern appears on an account like this, take these actions through these channels, and no others. Boundaries, approval, and the audit log follow the work across third-party tools. AN UNFINISHED ANSWER: A platform enforces those controls only for the systems it owns. Once the workflow crosses into third-party tools, the same controls do not follow the work. The operating model is not finished.
Wording drawn from this article. A complete answer is visible in the product; an unfinished one exists only in policy documents or roadmap slides.

If those answers are visible in the product, you have the information needed to operate agents in production. If the answers exist only in policy documents or roadmap slides, the operating model is not finished.

If you're working through this for your own stack, at either event or after, I'm glad to talk.

---

*Sources: [Salesforce, The Architect's Guide to Dreamforce 2026](https://www.salesforce.com/blog/salesforce-architect-guide-dreamforce-2026) · [HubSpot, UNBOUND 2026 Returns to Boston](https://unbound.hubspot.com/blog/inbound-2026-returns-to-boston) · [Salesforce, Agentic Enterprise Index 2025 to 2026](https://www.salesforce.com/news/stories/agentic-enterprise-index-insights-2026) · [Deloitte, The Path to Agentic Transformation, 2026](https://www.deloitte.com/us/en/insights/industry/technology/path-to-agentic-transformation.html) · [Bryn](https://www.civic.com/bryn) · [Bryn trust center](https://www.civic.com/bryn/trust) · [Bryn pricing](https://www.civic.com/bryn/pricing)*

Source: https://www.civic.com/field-notes/your-pipeline-runs-across-six-tools
