14 SEP 2026 — Salesforce has given its agents names. Casey resolves service issues across voice, SMS, WhatsApp and web chat. Paige takes IT and HR requests through Slack and internal portals. Carter works the shopper path to in-chat checkout, Marshall orchestrates back-office processes, Piper qualifies inbound leads, Fin handles complex customer-experience workflows. Hunter does outbound sales, and is the one worth looking at properly.

Six are generally available today. Hunter is in pilot and reaches general availability in November. The naming is the part everyone will notice and the least interesting thing in the announcement.

What was actually shipped

All seven sit on Customer 360, the data platform Salesforce customers already have, and operate inside the business rules, permissions and security configuration those customers already run. That is architecture rather than marketing. An agent inheriting an existing permission model cannot see records its human equivalent could not see.

Alongside the agents came Multi-Agent Orchestration, now generally available, with AI Skills in Agentforce Coworker and Agent Optimizer both reaching general availability in October. Salesforce puts its running total at 7 billion Agentic Work Units delivered across Agentforce and Slack, 3.2 billion of them in the second quarter alone.

Neither figure is auditable from outside. An Agentic Work Unit is a metric Salesforce defines, counts and reports, and the quarter-on-quarter shape it implies is a function of that definition as much as of adoption. Treat it as a vendor claim, because that is what it is.

Hunter is the actual news

Hunter is the first of the seven to use what Salesforce calls a long-horizon runtime. It pursues an objective across days and weeks rather than within a single conversation, through what the company describes as preserved memory, durable execution and dynamic steering.

That is a different product from the other six. A service agent answering a ticket is bounded — the customer asks, the agent responds, the interaction ends and can be inspected as a unit. An outbound sales agent working a prospect over three weeks is a process with no natural boundary, making decisions between observations, and each of those decisions conditions the next.

Two things follow that the announcement does not address. Review is the first. A bounded interaction can be sampled after the fact, while a long-horizon run has to be supervised as it happens or not at all. The failure mode is the second. A short agent that gets something wrong produces one bad answer; a long-horizon agent that drifts produces three weeks of consistent, compounding, plausible wrongness aimed at a customer who does not know they are being worked by software.

Hunter being the one held in pilot suggests Salesforce knows this, and November is not a long hold. Marshall is the counter-example worth noting: Salesforce describes it as running with deterministic execution and an audit record of every action taken. The agent that makes the fewest open-ended decisions is the one that ships with the audit trail.

7Named agents announced
6Generally available; Hunter is in pilot
WeeksHunter's goal horizon, against a single session
Vendor-definedWhat an agentic work unit counts

Why give software a first name

The naming is a deliberate interface decision and it cuts two ways.

In its favour, a name is a scope. Casey does service, Marshall does supply chain, and a buyer who has spent two years being told that AI will transform their business can now point at a specific thing with a specific job. That is clearer than a platform with a capability list, and it makes the unit of purchase legible.

Against it: a first name is also the oldest trick for making a system feel accountable when it is not. People extend courtesy and credibility to named things, and a customer who has been emailed by Hunter for three weeks has formed an impression of a colleague. Whether the recipient was told they were corresponding with software is a disclosure question, and in several jurisdictions it is now a legal one — the European Union's transparency obligations for AI systems came into force in August and require that people be told when they are interacting with one.

The permission question underneath

Inheriting an existing permission model is the strongest thing Salesforce can say here. It covers less than it sounds like.

It covers data access. It does not cover action scope, which is a different axis: a permission model built for a human who reads a hundred records a day behaves differently under an agent that reads a hundred thousand, and a rule written to let a sales representative send an email was not written with a system that sends ten thousand in mind.

The general shape of this problem is measurable rather than theoretical. We read every tool in a popular agent toolkit to answer the same question at the developer end, and found that the one line of configuration granting an agent its tools says nothing about what any of them can do. The enterprise version of that gap is the same gap at a larger blast radius.

What a buyer should ask

Ask what a long-horizon run looks like in the audit log. Marshall's audit record of every action is named in the announcement and Hunter's is not, which is the difference a buyer should be asking about rather than assuming.

Ask what stops one. An agent working a goal for three weeks needs an interrupt that a human can reach in seconds, and whether that exists is a more useful question than any benchmark.

Ask how the recipient is told. Disclosure to the person on the other end is not a feature Salesforce can leave to its customers, given where regulation is now, and a buyer who deploys Hunter without settling it inherits the exposure.

What to watch

Hunter's November general-availability date is the first checkpoint. A date that holds says the long-horizon runtime survived its pilot; a date that slips says more about the state of long-horizon agents than any benchmark would.

Then watch for the first published number that Salesforce did not define itself. Seven billion Agentic Work Units tells a reader nothing about whether the work was any good. A disclosed rate of escalation to humans, or of customer-reported errors, would tell them a great deal.