Welcome to Catchup with JANUS, a periodic note from the iAgentic team on what’s moving in agent orchestration. Platform announcements, security incidents, enterprise deployments, the developer-tools fault lines, and the things we think enterprise buyers should actually care about. No vendor spin.
For weeks these notes have followed two long threads: a security story about how agents can be turned against you, and a platform story about incumbents racing to control how agents get built and governed. This week the security thread went quiet, and the platform thread hit its first real audit. The signal turned commercial: shipping is fast, and buyers are starting to ask whether any of it works.
Headline moves
Salesforce. This is the next chapter of the Summer ‘26 story we have tracked since Multi-Agent Orchestration and the Agent Fabric control plane went generally available in June. On July 6, Salesforce made its Shopper, Buyer and Merchant commerce agents generally available and launched a Help Agent priced per resolution. Then on July 15, KeyBanc analysts said their customer checks came back weak, reporting that Agentforce “isn’t winning over clients” even as its annual recurring revenue passes $1B. The “can they prove it works” question we raised when the control plane shipped now has a number attached to it.
Cognition. After the $1B raise and the Devin Desktop pivot covered in earlier issues, Devin’s maker went vertical. It shipped Devin Security Swarm on July 1, an agent that finds, validates and fixes vulnerabilities and topped a 50-item benchmark at lower cost per finding, then followed with SWE-1.7 on July 9, an in-house model posting near-frontier coding scores at roughly 1,000 tokens per second. The trajectory is consistent: own the interface, then the model, then specialized products on top.
Mercor. Two weeks after the breach notifications and lawsuits we reported, the money has not slowed. Mercor is in talks to raise $500M at a $20B valuation, double its September mark, citing $2B in annualized June revenue, and is acquiring the agent-training firm Deeptune. A security incident that would sink a slower company has, so far, been a footnote to its growth.
Microsoft. Advancing the Agent 365 governance push from earlier briefings, Foundry Agent Service hosted agents reached general availability: a framework-agnostic managed runtime that hosts agents built on LangGraph, the Copilot SDK or Microsoft’s Agent Framework, with sandboxed sessions, durable state and scheduled routines. Microsoft is now in the business of running other people’s agents, not just governing them.
LangChain. Agent memory became a product. After a July 2 cluster of releases, LangChain launched OpenWiki Brains on July 10: general-purpose Markdown “wiki memory” that agents maintain themselves from Gmail, Notion, git and web sources. It continues the pattern of the leading open framework moving up the stack. Glean also shipped its July Drop of new content formats and governed workflows.
Where the landscape is shifting
The clearest shift is that agent hosting is becoming a commodity cloud service. With Foundry Agent Service generally available, a major cloud will run your agents regardless of the framework that built them, which absorbs part of what standalone platforms used to sell. LangChain is pushing the other way, turning an open framework upward into memory and orchestration. The middle of the stack is getting squeezed from both ends.
Pricing is moving too. Salesforce’s pay-per-resolution model, arriving right after the same company spent June building a cross-vendor control plane, sets an expectation buyers will carry into every agent conversation: pay for outcomes, not seats. Easy to announce, hard to sustain, but once a large vendor offers it the question spreads.
And the KeyBanc checks matter beyond Salesforce. Through June, the platform story was incumbents claiming the control-plane and governance narrative faster than they could prove it. KeyBanc is the first widely reported, demand-side read on whether those claims hold at scale, and at $1B in recurring revenue the answer was lukewarm. The velocity of announcements has outrun the evidence of adoption, and analysts are now measuring the difference.
Where the openings are
Three places worth attention if you are evaluating orchestration vendors right now:
- Ask for evidence, not demos. The KeyBanc read suggests headline revenue and reference logos can mask weak adoption. Ask for outcome data from customers who look like you, not a staged walkthrough.
- Test the pricing claim. Pay-per-resolution sounds buyer-friendly. Check what counts as a “resolution,” who adjudicates it, and whether the effective price at your volume beats a seat model.
- Confirm framework portability. Managed runtimes now host multiple frameworks. If avoiding lock-in matters, verify your agents, memory and state can move between a hyperscaler runtime and your own without a rebuild.
On the calendar
- Mercor’s $500M round is expected to close this month: watch whether the pending lawsuits affect terms.
- Salesforce commerce agents gain native ChatGPT and Gemini app integration: a template for distributing agents through consumer AI surfaces.
- IBM holds a July 23 webinar on scaling agents across frameworks and clouds, which may finally date its remaining control-plane modules, still open from earlier briefings.
- Still open: Databricks Omnigent adoption, and whether Sentry or MCP vendors ship a root-cause fix for the Agentjacking attack class.
From the community
A quiet week for developer threads, but the governance-lag theme from prior issues is intensifying in analyst coverage: Gartner now projects 40% of enterprise applications will embed agents by year-end, up from under 5% in 2025. The Agentjacking storyline that dominated recent weeks is fading from front pages without a fix shipping, which reads as quiet risk rather than resolution. Early reaction to LangChain’s OpenWiki is positive, with one recurring question: who maintains an agent’s memory after go-live. Commentary points the same way, with Ethan Mollick arguing the real skill is now managing agents rather than prompting them. The through-line holds: developers want capability that gets out of the way; buyers want systems that refuse to act until an outcome is verified.
Subscribe to get the next briefing in your inbox. We send when there’s something worth saying. Get notified →