One integration user, many agents
Agents run under a designated user with its own permission set. Several agents sharing that user look identical in the record history, and none of them maps to a person accountable for what it did.
Agentforce agents act on your CRM: they read Data Cloud, update records, run flows and Apex, call MuleSoft APIs, and talk to employees and customers alike. Agen governs each action at runtime, tied to a named owner, and records the verdict. Sales and service keep building.

Agentforce is built to act inside Salesforce and out through its integrations. These are the things an agent can do with the permissions it runs under.
Salesforce's controls are the right controls to keep. They govern the org, not the action, and they stop at the org boundary.
Agents run under a designated user with its own permission set. Several agents sharing that user look identical in the record history, and none of them maps to a person accountable for what it did.
A permission set grants the agent user write access to opportunities. It cannot say that this write, of this amount, on this account, in this conversation, should have paused for a human.
Flows, Apex and MuleSoft APIs reach systems the org's controls cannot see. The agent's reach is the union of everything those actions can do.
Grounding, masking and toxicity controls protect what goes into and out of the model. They do not judge whether the record update the agent then makes is one the company would have approved.
The gateway decides. Agentforce agents reach records and systems through actions, and every action is decided at the gateway in-line, on the employee's identity or the customer's. Nothing changes in Agent Builder.
Agentforce agents run inside Salesforce and reach your systems through flows, Apex and MuleSoft, so the gateway decides directly, on the employee's identity or the customer's. Shield covers the builders and admins: AgenShield on their devices, BrowserShield on what they paste.
Out-of-policy actions like touching production secrets or mass-deleting files are stopped before they execute. Everything else flows. Ships through your MDM.
Keys and sensitive data are recognised as they are pasted into AI tools, and the paste is blocked. Employees keep their tools. Only the leak stops.
Illustrative verdicts for common Agentforce actions under a typical policy.
| Agentforce action | Verdict | Why |
|---|---|---|
| Summarise a case for the service rep handling it | allow | In scope for the person and the agent. Logged, not interrupted. |
| Update a case status after resolving a customer question | allow | A low-risk write, within policy, tied to the agent's owner, and logged. |
| Read contact records with personal data for grounding | mask | The read runs. Personal data is masked before it enters the model context. |
| Change an opportunity amount or close date | human-in-the-loop | A financial write on the system of record. The agent's owner approves before it lands. |
| Issue a refund through a MuleSoft payment API | step-up | Above the policy threshold. The owner confirms from their phone, the run resumes. |
| Customer-facing agent retrieves an order for the signed-in customer | allow | Scoped to the record that customer is entitled to, on their identity, and logged. |
| Customer-facing agent reads a different customer's record | deny | Outside the customer's entitlement. Blocked before the read completes. |
| Run a flow that mass-updates or deletes records | deny | Destructive and outside task scope. Blocked and the owner notified. |
Verdicts are illustrative defaults. Every row is a policy you write once and Agen enforces per action, per identity.
Thirty minutes on the way your teams already use Agentforce. We show the verdict on each action, the named human behind the session, and the record it leaves. Bring your hardest question.
The agent pauses on the one crossing action, the named owner gets the decision with full context, and the run resumes. No ticket queue, no meeting.
Agent Builder, the Trust Layer and your permission sets stay exactly as they are.
The same three capabilities govern Agentforce and every other agent you run, internal and external.
Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.
Every agent owned, every record action judged at runtime, internal and customer-facing on one platform.