Trust is a prerequisite
It’s tempting toview trust as the final step. First, you build the agent; then, you address security and governance. Yettrust determines in advance whether you’ll dare to go live.
Consider an agent that sends an invoice on its own, grants a customer a discount, or summarizes a file for a colleague. At every step that really matters, you want to know whether you can delegate this task. That depends less on how smart the agent is and more on how much you trust it.
What trust means in concrete terms
Trust may sound abstract, but you can make it very concrete. An agent operates within fixed rules and does only what it’s allowed to do. Every step is traceable, so you can see afterward why it did what it did.Certinia made a conscious choice to do this with Veda, the AI engine for the service sector. Certinia refers to these agents as “rules-bound, trusted.” They operate in a deterministic and auditable manner (Certinia, Veda launch, April 2026). The agent doesn’t make anything up on its own and follows fixed steps within the boundaries you set. Because you know how it works, your trust grows.
Not every process requires the same level of trust
How much trust an agent needs depends on the work you assign to it. For many processes, efficiency is key. An agent who drafts texts, looks up information, or makes an initial assessment saves on manual labor. If they occasionally get it wrong, an employee corrects it. An accuracy rate of 70 to 75 percent already delivers value in these cases.
Other processes require nearly complete reliability. Consideran agent who sends out invoices for a business service provider. Or patient data in healthcare and the life sciences, where you specify in advance exactly which data an agent is not allowed to view. There can be no room for error here, and you must be able to demonstrate who had access to which data. Trust determines whether you’re even allowed to begin in the first place.
Salesforce and Certinia demonstrate how this can be achieved. An agent can process sensitive information while enforcing Salesforce’s access rules. In their own example, an agent working for a healthcare organization summarizes extensive records at scale, within the access rules defined in Salesforce (Salesforce, Nemotron for regulated industries). In the most stringent cases, the processing remains within the organization’s own secure environment. Your AI and data then remain within your own boundaries. This applies more broadly than just the most sensitive processes. What’s mandatory for financial processes and sensitive data is prudent everywhere. An agent who stays within the rules and works in a traceable manner is someone you can confidently scale up in any organization.
Where Your Data Stays
Trust begins with the question of where your data goes. Salesforce addresses this with the Einstein Trust Layer. It shields sensitive data before a model sees it. External models store nothing, thanks to a “zero data retention” policy. Every action respects the rights and roles you’ve already configured in Salesforce (Salesforce, Einstein Trust Layer). We’ll leave the technical details of exactly how that works to the platform’s creators. What matters most to you is that trust is built into the platform’s architecture.
There’s also a sign closer to home. Commissioned by the Dutch government and in collaboration with the Association of Netherlands Municipalities (VNG), Privacy Company conducted an independent DPIA on Salesforce Sales Cloud and Service Cloud. This is an assessment of how personal data is handled. The investigation identified eleven privacy risks. For the majority of these, Salesforce implemented contractual and technical measures. If organizations follow the additional recommendations, no known high privacy risks will remain. The national government and municipalities can therefore safely use both cloud services. In the debate over data sovereignty, this represents a strong counterargument.
What this means for your organization
If a promising AI project gets stuck in your organization, it’s rarely due to technical issues. More often than not, it’s a lack of trust that prevents you from taking the final step. Asking which model is the smartest won’t get you any further. Instead, look at your own rules. Does the agent stay within those boundaries? Can you see what it did? Does your data stay where it belongs? If you can answer “yes” to those questions, then trust becomes the reason to scale up. Only then does the value of AI become visible in euros and hours.
On September 9 and 10, I was at Data Expo at the Jaarbeurs Utrecht with the CBEE Remarkable team. We demonstrated how to get AI up and running safely and verifiably, even when the bar is set high. Did you miss it? Feel free to contact us. I’d be happy to discuss it with you.
Author: Chris Boonstra