Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

MuleSoft Agent Fabric vs Workday Agent System of Record

MuleSoft Agent Fabric

Control plane for agents, MCP servers, and APIs across platforms

Workday Agent System of Record

Workday system of record to find, add, register, configure, monitor, and manage AI agents

Short answer

MuleSoft Agent Fabric is a control plane for agents, MCP servers, and APIs across platforms; Workday Agent System of Record (ASOR) is set up per Workday tenant to register and manage agents.⁠Source 1, Source 2, Source 3 Agent Fabric enforces policy at a gateway in managed agents’ request path; ASOR gives each agent a unique Workday identity under Workday security.⁠Source 4, Source 5, Source 6

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both keep a registry that includes agents built outside the vendor’s own products, control what agents can reach, and keep audit records.⁠Source 3, Source 4, Source 6, Source 7, Source 8, Source 9
Where they differ
Agent Fabric places Omni Gateway in managed agents’ request path; brokers orchestrate A2A-compliant agents.⁠Source 4, Source 10 ASOR is set up per Workday tenant; for agents working with Workday, tools are Workday APIs.⁠Source 2, Source 3
Running both
Neither vendor publicly documents using the two together. MuleSoft’s docs say agents can be registered by uploading an agent card; Workday’s say external agents are registered through the ASOR API.⁠Source 7, Source 11
Public sources · checked 2 October 2026
  • Offered
  • Not publicly documented

MuleSoft Agent Fabric

  • Build agents: OfferedAgent brokers in Agent Script⁠Source 4
  • Host and run agents: OfferedAgent brokers on CloudHub 2.0⁠Source 4
  • Identity and access: OfferedOmni Gateway authentication and authorization⁠Source 4
  • Registry and governance: OfferedAgent Registry in Anypoint Exchange⁠Source 4
  • Traffic between agents, tools, and models: OfferedOmni Gateway in request path⁠Source 4
  • Agents across organizations: Not publicly documented

Workday Agent System of Record

  • Build agents: Not publicly documented
  • Host and run agents: Not publicly documented
  • Identity and access: OfferedAgent System User per agent⁠Source 5
  • Registry and governance: OfferedAgent Registry in Management Hub⁠Source 3
  • Traffic between agents, tools, and models: OfferedAgent Gateway for Workday APIs⁠Source 12
  • Agents across organizations: Not publicly documented

At a glance

TopicMuleSoft Agent FabricWorkday Agent System of Record
What it isControl plane for agents, MCP servers, and APIs across platforms.⁠Source 1 MuleSoft says it discovers, governs, orchestrates, and observes agents.⁠Source 13A functional area you enable in each Workday tenant to find, register, configure, monitor, and manage AI agents.⁠Source 2, Source 3
Agents it coversAgents, MCP servers, and APIs, whatever platform built them.⁠Source 4 Scanners add what they find on supported platforms.⁠Source 4Workday-built, partner-built, and self-built agents.⁠Source 3 External agents are registered through the ASOR API.⁠Source 7
Where access is enforcedAt Omni Gateway, placed in the request path of each managed agent, API, or MCP server.⁠Source 4 The gateway can be managed or self-managed.⁠Source 1In Workday: each agent has a unique Workday identity, governed by Workday security policies and groups.⁠Source 5, Source 6
Pricing modelMuleSoft packages start at $2,000 a month, billed annually; usage is metered in Mule Credits.⁠Source 14 MuleSoft lists the Agent Fabric package with no price: contact sales.⁠Source 14 A credit’s price is not publicly documented.No additional specific SKU for ASOR.⁠Source 3 Registering Workday-built agents in production needs a Flex Credits policy opt-in.⁠Source 3 A credit’s price is not publicly documented.
Generally availableYes, MuleSoft says, with new capabilities each month.⁠Source 15 The first release note is dated 3 October 2025.⁠Source 10Generally available since February 2026.⁠Source 16

What each one is

MuleSoft Agent Fabric

MuleSoft documents Agent Fabric as an AI control plane for agents, MCP servers, and APIs across platforms.⁠Source 1 Scanners and manual registration fill its registry, Omni Gateway enforces policy in managed agents’ request path, and agent brokers orchestrate A2A-compliant agents.⁠Source 4, Source 10, Source 11

Workday Agent System of Record

Workday Agent System of Record (ASOR) is a functional area you enable in a Workday tenant to find, register, configure, monitor, and manage AI agents.⁠Source 2, Source 3 Its Agent Management Hub manages Workday-built, partner-built, and self-built agents, each with a unique Workday identity.⁠Source 3, Source 5

The differences that matter

  1. How agents get into the registry

    MuleSoft Agent Fabric

    Scanners register the agents, APIs, and MCP servers they find on supported platforms; other agents can be registered by uploading an agent card.⁠Source 4, Source 11

    Workday Agent System of Record

    External agents are currently registered only through the ASOR API; the registration call is based on the A2A Agent Card and records each agent’s platform.⁠Source 7, Source 17

    MuleSoft lists scanner limits of one run a day and 10,000 services.⁠Source 18 Workday says some agents, including those for HiredScore and Evisort, are not part of ASOR.⁠Source 3

  2. Who decides what an agent can reach

    MuleSoft Agent Fabric

    Omni Gateway, in managed agents’ request path, can require authentication and authorization and limit which tools and APIs an agent can call.⁠Source 4

    Workday Agent System of Record

    Workday security policies and groups set each agent’s access; acting for a user, an agent gets only what both may do.⁠Source 5, Source 6

    MuleSoft says policy at the communication layer lets third-party agents be governed without being modified.⁠Source 15 Workday’s Agent Interaction Policy sets which users may use an agent’s delegate-mode skills.⁠Source 19

  3. Where each one runs

    MuleSoft Agent Fabric

    Agent Fabric runs on MuleSoft-hosted regional control planes; Omni Gateway can be self-managed, including in a data center or on EKS, GKE, or AKS.⁠Source 1, Source 20, Source 21

    Workday Agent System of Record

    ASOR is set up in each Workday tenant, with no current way to migrate its configuration; external agents’ definitions record where they are hosted.⁠Source 2, Source 17

    A self-hosted Agent Fabric control plane is not publicly documented, and neither is a self-hosted ASOR.

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicMuleSoft Agent FabricWorkday Agent System of Record
Network exposureOmni Gateway sits in managed agents’ request path; agent-network ingress gateways get a public endpoint, egress gateways none.⁠Source 4, Source 22Third-party agents reach Workday APIs through Agent Gateway, a single regional endpoint.⁠Source 12 Inbound endpoint needs: not publicly documented.
IdentityFor rogue-agent detection, agents are set up as identity-provider service identities; an Omni Gateway policy supports OAuth 2.0 token exchange.⁠Source 23, Source 24Unique identity per agent.⁠Source 5 External agents use OAuth 2.0 or signed JWTs; tokens for third-party (self-built) agents last 4 hours.⁠Source 3, Source 5, Source 25
Access changes and revocationAfter review, quarantine stops a flagged agent from acting and blocks it at model proxies with the Kill Switch policy.⁠Source 23Deactivating an agent hides it from users; the change may take up to a minute to reach Agent Gateway.⁠Source 3, Source 12
Audit trailAnypoint Platform audit logs are kept one year by default; Omni Gateway can keep a traffic audit trail.⁠Source 4, Source 8An audit trail report covers agent transactions; delegated actions record both the agent and the user.⁠Source 5, Source 9
ComplianceMuleSoft says Anypoint Platform meets ISO 27001, SOC 2, PCI DSS, and HIPAA.⁠Source 26 Agent Fabric’s own scope: not publicly documented.Workday says its SOC 2 report covers Workday Enterprise Products; ASOR isn’t named.⁠Source 27 ISO 42001 covers Workday Platform.⁠Source 27

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

MuleSoft Agent Fabric and Workday Agent System of Record compared on 18 criteria
MuleSoft Agent FabricWorkday Agent System of Record
What it is
What it is and who it’s forControl plane for agents, MCP servers, and APIs across platforms.⁠Source 1 MuleSoft says it discovers, governs, orchestrates, and observes agents.⁠Source 13Set up in each Workday tenant to find, register, configure, monitor, and manage AI agents built by Workday, partners, or the customer.⁠Source 2, Source 3
MaturityMuleSoft says it is generally available, with new capabilities each month.⁠Source 15 Its first release note is dated 3 October 2025.⁠Source 10Announced in February 2025; generally available since February 2026.⁠Source 16, Source 28 Agent Gateway was announced in June 2025.⁠Source 29
Control
Agent registry and discoveryOne inventory of agents, MCP servers, and APIs, whatever platform built them.⁠Source 4 Scanners fill it; agents can also be added by uploading an agent card.⁠Source 4, Source 11The Agent Management Hub lists Workday-built, partner-built, and self-built agents with status.⁠Source 3 Some, such as HiredScore and Evisort agents, aren’t in ASOR.⁠Source 3
Identity and access controlOmni Gateway can require authentication and authorization and limit which tools and APIs an agent can call.⁠Source 4 User roles come from Anypoint access management.⁠Source 1Each agent has a unique Workday identity, governed by security policies and groups.⁠Source 5, Source 6 Acting for a user, an agent gets only what both may do.⁠Source 5
Ownership, policy, and revocationGovernance strategies set rules for in-scope agents, APIs, and MCP servers and can block or flag noncompliance.⁠Source 4 MuleSoft says scanners pull ownership metadata.⁠Source 15Admins set each agent’s skills and who can use it, and activate or deactivate it.⁠Source 3, Source 30 Each agent’s profile shows who built it.⁠Source 7
Audit log and observabilityOmni Gateway can keep a traffic audit trail.⁠Source 4 Platform audit logs are kept a year by default; Integration Advanced or Titanium adds export to third-party tools.⁠Source 8An audit trail report covers agent transactions; delegated actions record the agent and the user.⁠Source 5, Source 9 Per-agent analytics reports cover Workday-built agents only.⁠Source 3
Connection
How agents connectOmni Gateway sits in the request path of each managed agent, API, or MCP server.⁠Source 4 An egress gateway carries agent networks’ calls to agents outside the network.⁠Source 22Third-party agents must route Workday API traffic through Agent Gateway, a single regional endpoint.⁠Source 12 Outbound-only use is not publicly documented.
Agents across organizationsAgent networks can use agents from another agent network or elsewhere in your company.⁠Source 31 Partner-held access controls: not publicly documented.ASOR manages partner-built agents; a definition can carry an ID locating one in the partner’s system.⁠Source 3, Source 17 Partner-held access controls: not publicly documented.
Protocol supportOmni Gateway supports MCP and A2A.⁠Source 32 A2A powers orchestration in agent networks, and MCP Bridge turns an API into an MCP server without custom code.⁠Source 4, Source 33API registration is based on the A2A Agent Card.⁠Source 17 Outside assistants can call the Self-Service Agent over A2A, and tool search can filter by SOAP, REST, or MCP.⁠Source 34, Source 35
Frameworks, models, and clouds supportedMuleSoft calls it vendor agnostic and says its scanners cover Amazon, Google, Microsoft, Databricks, and more.⁠Source 13, Source 15 Brokers orchestrate only A2A-compliant agents.⁠Source 4Registration records each agent’s platform, or OTHER.⁠Source 17 Workday names Google Gemini Enterprise as an outside assistant able to call its Self-Service Agent.⁠Source 34
Operations
Deployment options and data residencyAgent Fabric runs on MuleSoft-hosted regional control planes.⁠Source 20 Omni Gateway can be self-managed.⁠Source 1, Source 21 Self-hosting its control plane isn’t publicly documented.Set up in each Workday tenant.⁠Source 2 Agent Gateway endpoints: US, EU, UK, Canada, Australia, Singapore, India, Japan.⁠Source 12 Self-hosting: not publicly documented.
Compliance attestationsMuleSoft says Anypoint Platform meets ISO 27001, SOC 2, PCI DSS, HIPAA, and GDPR.⁠Source 26 An attestation naming Agent Fabric is not publicly documented.Workday says its SOC 2 report covers Workday Enterprise Products.⁠Source 27 Its ISO 42001 certificate covers named products including Workday Platform; ASOR isn’t named.⁠Source 27
Support and SLAMuleSoft’s Cloud Offerings SLA commits to 99.95% monthly for covered services, on subscriptions started by 1 May 2025.⁠Source 36 Anypoint plans include Premier Success.⁠Source 37Workday says its company-wide support is 24/5, with severity 1 cases 24/7/365, or 24/7/365 with Success Plans.⁠Source 38 An ASOR uptime SLA is not publicly documented.
Time and effort to get runningWith product access, an admin turns Agent Fabric on.⁠Source 1 Agent networks need a Managed Omni Gateway; scanners need a connected cloud provider for each source.⁠Source 1Enable the ASOR functional area and set its security policies.⁠Source 2 Registering an external agent includes finding the IDs of the Workday APIs it will use.⁠Source 7
Pricing model and public pricesMuleSoft packages start at $2,000 a month, billed annually, with usage in Mule Credits.⁠Source 14 MuleSoft lists the Agent Fabric package with no price: contact sales.⁠Source 14No additional specific SKU for ASOR.⁠Source 3 Workday-built agents in production need a Flex Credits policy opt-in.⁠Source 3 A credit’s price is not publicly documented.
Building
Agent building toolsAgent networks are defined in YAML, brokers in Agent Script.⁠Source 4, Source 31 MuleSoft says Salesforce’s separate Agentforce is for building agents within Salesforce.⁠Source 15You provide an external agent’s definition through an API.⁠Source 3 Workday announced the low-code Flowise Agent Builder for Workday’s separate Workday Build in 2025.⁠Source 39
Model accessBrokers support OpenAI, Azure OpenAI, Bedrock OpenAI, and Gemini models.⁠Source 31 Model Proxy is one access layer for several providers, with spend caps.⁠Source 4, Source 40Workday’s AI agents use large language models.⁠Source 3 Which models ASOR supports or includes is not publicly documented.
Integrations and ecosystemThe catalog has curated MCP servers from the Official MCP Registry and Informatica.⁠Source 4 Policies can apply to Apigee, Kong Gateway, and Azure API Management APIs.⁠Source 41In February 2026, Workday said more than 65 partners were connecting agents to ASOR.⁠Source 16 Workday says partner agents reached its Marketplace in June 2025.⁠Source 29

Which to choose

Choose MuleSoft Agent Fabric if

  • Your agents run on several platforms, and you want scanners that MuleSoft says cover Amazon, Google, Microsoft, and more.⁠Source 4, Source 13
  • You want policy enforced in the request path of managed agents, MCP servers, and APIs, at a gateway you can self-manage.⁠Source 1, Source 4
  • You want brokers to orchestrate A2A-compliant agents, and a reversible quarantine for rogue agents after an admin reviews them.⁠Source 4, Source 10, Source 23
  • You already run MuleSoft’s Anypoint Platform: Agent Fabric uses Anypoint Platform access management and is turned on there.⁠Source 1

Choose Workday Agent System of Record if

  • Your agents mostly work in Workday, and each should have a unique Workday identity under your existing security policies and groups.⁠Source 3, Source 5, Source 6
  • You want an agent acting for a user limited to what both may do, with audit entries naming both.⁠Source 5
  • You want Workday-built, partner-built, and self-built agents listed with their status in one Agent Management Hub.⁠Source 3
  • You already run Workday and want agent governance in the same tenant, with no additional specific SKU to buy for ASOR.⁠Source 2, Source 3

Questions buyers ask

Does either one build or host agents?

Agent Fabric’s brokers run on CloudHub 2.0 or Runtime Fabric; MuleSoft says Salesforce’s separate Agentforce is for building agents within Salesforce.⁠Source 4, Source 15 ASOR takes an external agent’s definition through an API; Workday announced a low-code agent builder for Workday’s separate Workday Build.⁠Source 3, Source 39

How is each one priced?

MuleSoft packages start at $2,000 a month, billed annually.⁠Source 14 MuleSoft lists the Agent Fabric package with no price: contact sales.⁠Source 14 ASOR needs no additional specific SKU; Workday-built agents in production need a Flex Credits policy opt-in.⁠Source 3 Credit prices are not publicly documented.

Do they support MCP and A2A?

Agent Fabric’s Omni Gateway supports MCP and A2A, and A2A powers orchestration in its agent networks.⁠Source 32, Source 33 Workday bases external agent registration on the A2A Agent Card and lists MCP as a tool type; outside assistants can call its Self-Service Agent over A2A.⁠Source 17, Source 34, Source 35

Can either one connect agents across companies?

Agent networks can use agents from elsewhere in your company, and an egress gateway enforces policy on their outbound calls.⁠Source 22, Source 31 ASOR manages partner-built agents, which Workday calls second-party agents.⁠Source 3 For both, access controls held by the partner company are not publicly documented.

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

46 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Get Started with Agent Fabric Salesforce · checked Back:abcdefghijkl

  2. Source 2: Set Up Agent System of Record (Workday Administrator Guide) Workday · checked Back:abcdefghi

  3. Source 3: About Workday Agents (Workday Administrator Guide) Workday · checked Back:abcdefghijklmnopqrstuvwxyz272829

  4. Source 4: Agent Fabric Overview Salesforce · checked Back:abcdefghijklmnopqrstuvwxyz2728293031

  5. Source 5: Concept: Agent Security (Workday Administrator Guide) Workday · checked Back:abcdefghijklm

  6. Source 6: Setup Considerations: Agent Security (Workday Administrator Guide) Workday · checked Back:abcdef

  7. Source 7: Register External Agents (Workday Administrator Guide) Workday · checked Back:abcdef

  8. Source 8: Audit Logging in Anypoint Platform Salesforce · checked Back:abc

  9. Source 9: FAQ: Agent Security (Workday Administrator Guide) Workday · checked Back:abc

  10. Source 10: Agent Fabric Release Notes Salesforce · checked Back:abcde

  11. Source 11: Register Services Manually Salesforce · checked Back:abcd

  12. Source 12: Concept: Workday Agent Gateway (Workday Administrator Guide) Workday · checked Back:abcde

  13. Source 13: MuleSoft Agent Fabric | Agent Governance and Orchestration Salesforce · checked Back:abcd

  14. Source 14: MuleSoft Pricing | Plans From $2,000 a Month Salesforce · checked Back:abcdef

  15. Source 15: See Every Agent. Govern Every Agent. Control AI Costs. (mulesoft.com home page) Salesforce · checked Back:abcdefg

  16. Source 16: The Workday Agent System of Record Is Now Generally Available Workday · checked Back:abc

  17. Source 17: ASOR API Documentation v1.2 (Workday/asor on GitHub) Workday · checked Back:abcdef

  18. Source 18: Discovering and Cataloging External Services with Scanners Salesforce · checked Back to text

  19. Source 19: Concept: Agent Interaction Policy (Workday Administrator Guide) Workday · checked Back to text

  20. Source 20: Salesforce Hyperforce Overview Salesforce · checked Back:ab

  21. Source 21: Requirements and Limits for Omni Gateway Salesforce · checked Back:ab

  22. Source 22: Deploying Agent Network Ingress and Egress Managed Omni Gateways Salesforce · checked Back:abc

  23. Source 23: Detect and Contain Rogue Agents Salesforce · checked Back:abc

  24. Source 24: OAuth 2.0 OBO Credential Injection Policy Salesforce · checked Back to text

  25. Source 25: Concept: External Agent ASU Considerations (Workday Administrator Guide) Workday · checked Back to text

  26. Source 26: Anypoint Platform Trust Center Salesforce · checked Back:ab

  27. Source 27: Workday Compliance | Workday US Workday · checked Back:abcd

  28. Source 28: The Next Generation of Workforce Management is Here - Workday Unveils New Agent System of Record Workday · checked Back to text

  29. Source 29: Workday Announces New AI Agent Partner Network and Agent Gateway Workday · checked Back:ab

  30. Source 30: Workday Agent System of Record | Workday US Workday · checked Back to text

  31. Source 31: Building Agent Networks for Agent Fabric Salesforce · checked Back:abcd

  32. Source 32: Securing Agent Interactions with Omni Gateway Salesforce · checked Back:ab

  33. Source 33: Using A2A Protocol in Agent Networks Salesforce · checked Back:ab

  34. Source 34: Connect External Agents to Workday Using A2A (Workday Administrator Guide) Workday · checked Back:abc

  35. Source 35: Concept: ASOR Agent Resource Search API (Workday Administrator Guide) Workday · checked Back:ab

  36. Source 36: MuleSoft Cloud Offerings Service Level Agreement (SLA) for subscriptions with an Order Start Date on or before May 1, 2025 Salesforce · checked Back to text

  37. Source 37: MuleSoft Subscription Plans - effective for Customer purchases made from Salesforce on or after June 27, 2025 Salesforce · checked Back to text

  38. Source 38: Workday Support | Workday US Workday · checked Back to text

  39. Source 39: Workday Unveils Workday Build, Giving Developers the Tools to Build the Future of Work Workday · checked Back:ab

  40. Source 40: Creating and Managing Model Proxies Salesforce · checked Back to text

  41. Source 41: Enhanced MuleSoft Experience Overview Salesforce · checked Back to text

  42. Source 42: Your company's private network Blocks.ai · checked Back to text

  43. Source 43: Network requirements Blocks.ai · checked Back to text

  44. Source 44: Solutions: Agent sprawl Blocks.ai · checked Back to text

  45. Source 45: Solutions: Partner networks Blocks.ai · checked Back to text

  46. Source 46: Pricing Blocks.ai · checked Back to text