Assessments
Salesforce Agentforce security assessment
Agentforce agents act inside your CRM with the permissions you gave them. We find out what a lead form, an email, or a customer can make them do.
What the platform covers, and what it leaves to you
Salesforce describes the Einstein Trust Layer as “secure data retrieval” that works “while maintaining permissions and data access controls,” data masking that “replaces sensitive Personally Identifiable Information (PII) or proprietary business data with non-identifiable tokens before the prompt is sent to the LLM,” toxicity detection on generated content, and zero data retention with third-party model providers. (Salesforce, Trusted AI)
Every one of those protects data on its way to and from the model. None of them decides which records the agent user can read, which actions the agent is allowed to take, or what the agent does when the text in a lead form was written for it rather than for your sales team. Those are configuration choices in your org. An assessment tests the choices, not the platform.
Salesforce Agentforce is named here as a system we assess in our clients' orgs. NXT has no commercial relationship with Salesforce.
What an Agentforce agent reaches
Where an Agentforce agent's input comes from, and what it can read and do on the other side.
CRM records
Leads, contacts, accounts, cases, and opportunities, read through the agent user's permission set and sharing rules.
Knowledge and data
Knowledge articles, Data 360 objects, and connected sources used to ground answers.
Actions
Flows, Apex, record updates, and outbound email. The agent does not only answer; it changes things.
Channels
Web chat, customer portals, email, messaging, and voice. Some of these carry text written by people who are not your customers.
Four ways it goes wrong
An agent user with too much reach
The agent runs as a user. If that user can see every account and every case, so can anyone who talks to the agent convincingly enough. Sharing rules and field-level security decide the outcome, not the conversation.
Untrusted text arriving through forms and email
A lead form, a case email, or a chat message can carry instructions aimed at the agent rather than at your team. Public disclosures in 2025 and 2026 showed form submissions steering Agentforce agents into sending CRM data outside the org.
Actions without a second look
An agent that can update a record, issue a credit, or send an email turns one injected instruction into one completed action. The guardrail is the scope and checks on each action, not the tone of the agent's reply.
Confirmation across records
A caller states details and asks the agent to confirm them. Our published research found that models treat a data match as identity verification, and disclose. In a CRM, the next record is one name away.
What the assessment covers
01
The agent as deployed
We work through the channels your customers use, in a sandbox or staging org, and record what the agent reveals and does for someone who has not been verified.
02
Untrusted channels
Lead forms, case emails, and chat are tested with content written for the agent, not for your staff, and the agent's actions are traced end to end.
03
Topics, actions, and instructions
We compare what the topic instructions say the agent will and will not do with what it actually does under pressure, action by action.
04
Findings, fixes, and a re-test
Each finding ships with the input, the agent's response or action, and the record it touched. Remediation is mapped to Salesforce's own controls. We run it again after your team acts.
What you receive
A findings register where each entry has the input, the agent's response or action, the record it touched, and a severity. A remediation plan that names the Salesforce control that closes each finding, prioritized by exposure. A compliance mapping to the EU AI Act, NIST AI RMF, and OWASP LLM Top 10. And, once your team has acted, a re-test with an attestation you can hand to a customer, an auditor, or a regulator.
Remediation is written against the controls your admins already have:
- Agent user permission sets, profiles, and sharing rules
- Topic scope and action availability per agent
- Input handling in Flow and Apex actions the agent can call
- Einstein Trust Layer data masking configuration
- Web-to-Lead, Email-to-Case, and messaging channel handling
- Agent session logs and audit review
Questions we get
Doesn't the Einstein Trust Layer handle this?
It handles part of it. Salesforce describes secure data retrieval that maintains permissions, data masking before prompts reach the model, toxicity detection on outputs, and zero data retention with model providers. What it does not decide is which records your agent user can reach, which actions the agent can take, or what the agent does with text that arrived from outside. Those are your configuration, and that is what we test.
Is this a penetration test of Salesforce?
No. We test your agents in your org, under your authorization and within Salesforce's rules of engagement. The platform is Salesforce's; the agent user, topics, actions, and channels are yours.
Can you test in a sandbox?
Yes, and we prefer it. A sandbox with representative, non-production records lets us test actions fully without touching customer data.
We only use a service agent for FAQs. Does this apply?
If the agent can read any customer record or take any action, yes. The narrowest-looking agents are often the ones nobody reviewed after launch.
Find out what your agents will do when asked the wrong way.
A short call to scope the agents, channels, and actions in your org. Testing runs in a sandbox under your authorization, with no production customer data required.
Written by the NXT AI research team. Platform statements are Salesforce's own and linked to source. Last updated October 6, 2026.