
The VA is betting $1.6 billion that a decade of accumulated complexity is an asset rather than an obstacle. We think that's the right bet. Here's the condition attached to it.
Every human who has ever worked in a large Salesforce org has a private list of things that are… roughly, approximately true.
The field that means one thing in the West region and something slightly different in the East… That status value that three teams use correctly and one team uses as a workaround. The automation everyone knows to disable before a data load, documented precisely nowhere.
Largely, people navigate that fine.
A human reading a record brings twenty years of context to the interpretation, notices when something looks wrong, and asks somebody.
Approximation is survivable because humans hold the correction in their heads.
An agent, though, has no such list.
It reads the configuration and takes it as the state of the world. A field that is used consistently 80% of the time is not 80% useful to an agent… it is a source of confident, wrong action at whatever volume you have granted it. Across more than 40,000 provider services nationwide, 80% correct is a number with a body count attached.
That is the actual meaning of "close enough for government work" in an agentic environment. Not sloppiness. Ordinary, accumulated, entirely reasonable imprecision, only now it’s executed at machine speed.
FedRAMP High certifies the platform, not your configuration
The Salesforce agents going into the VA are FedRAMP High-authorized and HIPAA-ready. That is a serious bar, and it addresses a specific category of risk… how data is encrypted, where it is stored, who at the vendor can touch it, what controls the cloud provider maintains.
It says nothing about whether permission sets are correct.
Compliance certification and configuration governance are two different problems that often get filed under the same word. But a FedRAMP High-authorized agent operating on an over-provisioned permission set is a compliant system doing something you did not intend. SQUARES, the VA's eligibility system, gives more than 2,100 authorized users access to veteran eligibility information. Every access grant in an environment that size was made by someone, for a reason, at a moment… and access grants outlive their reasons.
Human over-provisioning is latent risk. Somebody can reach data their role does not require, and for years nothing happens, because they never had cause to look. Agents remove the social friction that kept that grant harmless. An agent exercises the full surface of what it is given, immediately, without the hesitation that keeps a person from wandering somewhere they technically can go.
The permission set nobody has reviewed since 2016 is not a problem until an autonomous actor holds it.
The existing footprint is the advantage and the obligation
Salesforce is expanding what the VA already runs rather than replacing it.
That program began around $10 billion in 2018 and deployments were suspended in April 2023 over patient safety concerns, before resuming. Wholesale replacement asks clinicians to learn new workflows overnight. Expansion basically tells them that they can keep working.
Expansion also means the agents inherit everything.
Every field created under deadline pressure, every automation built by an admin who has since moved on, every dependency that exists in practice and nowhere in writing. The institutional logic your promo describes is real and it is valuable, it encodes how veteran care actually works in more detail than any policy document. It is also, in most orgs of this vintage, undocumented.
Which makes the work in front of the VA a visibility problem before it is an AI problem…
The one-year term is a feature
The AELA runs one year with options for two additional one-year renewals against the $1.6 billion ceiling. Most coverage compressed that into "three-year, $1.6 billion," which overstates the commitment considerably.
The shorter leash is the healthiest thing about the deal. Traditional enterprise license agreements hide their own failures. Seats get bought, seats go unused, renewal happens anyway because the alternative is a migration nobody wants to run. Consumption-linked pricing and annual checkpoints surface reality on a schedule. Agents that get deployed and quietly abandoned show up in the numbers.
That also compresses the timeline for the unsexy work. Twelve months is enough time to move a scheduling metric if the underlying configuration can explain itself. It is not enough time, however, to move a scheduling metric and simultaneously discover, from scratch, what a decade of implementation built.
The pattern transfers
Almost nobody aside from the VA operates 170 medical centers. The structural facts hold anyway.
Your agents will treat your configuration as ground truth, including the parts that are only mostly true. That failure mode is quiet, because it looks like an agent that works most of the time.
Your compliance posture and your governance posture are different things, and the certification on your AI vendor does not extend to the access model in your org.
Your proving window is shorter than it used to be. Consumption pricing is becoming standard across agentic products, which means the Finance conversation about your agent program arrives before the governance work feels finished.
The VA is doing the thing we would actually advise: putting agents into an environment rich enough in context that they have something real to reason over. Generic AI in a clean, simple org has very little to work with. Twenty years of hard-won operational logic is exactly the substrate an agent needs.
Still, this experiment only works if the system can tell the agent the structural truth about itself.


