Is Agentforce Safe for a Small Business? The Settings to Check Now
Whether Agentforce is safe for a small business depends on its configuration, not its defaults. Winter '27 turns the platform on in eligible orgs, but Salesforce says agents reach end users only when active. Salesforce provides the platform and Trust Layer; you decide who builds agents, what each can see, which links it may output and what gets logged.
Sources: Salesforce help articles, release notes and Trust data, two research teams and New Zealand's Privacy Commissioner, as at October 2026. Do the basics in our security settings checklist first.
What does "Agentforce Platform Enabled by Default" switch on?
The platform, not the agents. Salesforce's Winter '27 release note (as at October 2026) says the platform "is enabled by default for all orgs with Agentforce access, as granted by SKUs, licensing, and editions", in "Enterprise, Performance, Unlimited, and Developer Editions with Foundations or Agentforce 1 Editions", with existing orgs enabled "on a rolling basis starting the first week of September". Starter Suite, Pro Suite and Professional Edition are not listed; they get the Help Agent, covered in our Winter '27 service post.
| Changes when the platform is on | Does not change |
|---|---|
| "all admins have access to Agentforce Studio, Agentforce Builder, and analytics and observability features" | Agents "are only available to end users when the agent is active" |
| Agentforce Studio appears in the App Launcher by default "to all users in orgs with access to Agentforce" | Other users still need the Manage AI Agents permission to build agents |
| Removing the Agentforce setting from the Agentforce Agents page is "planned for later in Winter ʼ27" | "no additional cost and there are no changes to billing" |
No billing change is not free use: Salesforce meters usage "when you preview an agent in chat or voice" and in sandbox testing. Our cost guide and Foundations explainer cover credits.
Your upgrade is a separate clock. Salesforce Trust schedules Winter '27 production upgrades on 3 October and 9 to 10 October 2026 (UTC), with every Australian-hosted (AUS) and AP production instance on 10 October (UTC). Check your instance there, or see our dates post.
The off switch: "To turn off the Agentforce platform, in Setup, turn off the Einstein setting on the Einstein Setup page." That setting controls Einstein generative AI "across Salesforce", not just agents.
What does the Einstein Trust Layer protect, and what does it not?
It covers data travelling to and from the language model; it does not decide what your agent may read. Salesforce describes the Trust Layer as "a collection of features, processes, and policies", and its setup (Setup, Quick Find "Einstein", then Einstein Trust Layer) requires Data Cloud, which newer pages call Data 360.
| Control | What Salesforce documents | The catch for agents |
|---|---|---|
| Zero data retention | External model providers such as OpenAI do not retain or train on your data | "Customers' use of other features including agents may result in data storage" |
| Secure data retrieval | Prompts are "grounded only with data that the executing user has access to" | For a customer-facing agent, that is usually the agent user you configure |
| Data masking | Sensitive data masked before the model sees it; on by default | Masking "is disabled for agents" |
| Prompt defence | "one way to defend against jailbreaking and prompt injection attacks" | Not a guarantee; see the disclosures below |
| Audit trail | Prompts, masked prompts, responses and toxicity scores stored in your Data 360 | It can contain personal information |
The masking row matters most. Salesforce's agent masking article says that in some cases masking "can affect the accuracy and relevance of the agent's response", so it is off for agents. It still applies to embedded features such as Einstein Service Replies, though Salesforce notes of pattern-based masking that "no model can guarantee 100% accuracy".
Salesforce also keeps audit data "for 30 days for compliance purposes" (response journey). With one data space, collection is "turned on by default when Agentforce is turned on", and storage over your allocation is billed.
What can an agent see and do?
Whatever its running user can, within the subagents and actions you give it. Salesforce's shared responsibility article (25 February 2026) says employee agents "execute in the context of the logged-in user", while customer agents on public channels "operate as a dedicated Agent User".
That agent user matters most. Configure Service Agent Access says it is created as "EinsteinServiceAgent User" "with minimal access so that your agent is secure by default", governed by its own profile, permissions, field-level security and sharing rules. The warning: "if the agent has access to data it doesn't need, the agent can expose proprietary information to customers."
Subagents (called topics until April 2026) and actions bound what it does. A flow-based custom action "adheres to the permissions, field-level security, and sharing settings configured in the flow" (Trust and Agentforce), and a custom action that changes a record can be set to "ask the user to confirm the change" first.
The shared responsibility article leaves Salesforce the platform, the Trust Layer and broad threat detection, and gives you least privilege, permission sets, field-level security, "restricting topics and actions" and monitoring.
What did ForcedLeak and SalesBleed show?
According to the researchers, text the public submits to Salesforce can steer an agent, and link filtering, which Salesforce calls a "defense-in-depth control", can be bypassed. Both teams say the issues they reported have been fixed.
ForcedLeak. Noma Security (25 September 2025) described a "critical severity (CVSS 9.4)" vulnerability chain: instructions hidden in a Web-to-Lead form ran when an employee asked Agentforce about that lead, sending CRM data to an allowlisted domain that "had expired and become available for purchase". Noma says Salesforce implemented "Trusted URLs Enforcement for Agentforce & Einstein AI" on 8 September 2025. Salesforce's knowledge article 005135034, which does not name ForcedLeak, describes that enforcement; a 13 February 2026 update says the *.salesforce.com wildcard would be removed from the default allowlist effective 28 February 2026.
SalesBleed. Zenity Labs (24 September 2026) reports bypassing the URL redaction itself, through the same Web-to-Lead route, and reading Accounts data because "the default General CRM subagent ships" with access to leads and accounts: "Those are defaults, not misconfigurations." A second post reports that the Reply to a Slack Thread action could post "without user confirmation". Zenity reports all fixes "confirmed and tested" on 21 September 2026, and warns that disabling confirmation takes "a single click of a button".
Which settings should a small team check this month?
Our ten checks, each at a location Salesforce documents:
| Check | Where | What we look for |
|---|---|---|
| Is Einstein on, by decision? | Setup, Quick Find "Einstein Setup" | On only if someone owns AI |
| Who holds Manage AI Agents? | Setup, Permission Sets and Profiles | Named admins; it grants "org-wide management access to all agents" |
| Which agents are active? | Agentforce Studio, Agents | Each has an owner; deactivate the rest |
| What can each agent user see? | Setup, Users, filtered on the Einstein Agent User profile | Only the objects its actions need |
| Who can use each employee agent? | Agentforce Builder, Settings, Agent Access | A permission set, not a shared profile |
| Do record-changing actions ask first? | The action's "Require user confirmation" setting | On for anything that writes or sends |
| Are Trusted URLs tight? | Setup, Quick Find "Trusted URLs" | No broad wildcards; entries apply "throughout your entire Salesforce Org" |
| Who can read the audit trail? | Data 360 data governance, for the data space chosen under Quick Find "Einstein Audit" | Default Allow All data policy deleted or narrowed |
| Do you keep conversation logs? | Agent setting "Keep a record of conversations with enhanced event logs" | A deliberate choice; logs keep messages "for seven days" |
| Can model requests leave your region? | Einstein Setup, in-region setting | On if your privacy assessment requires it |
If a public web form feeds records an agent reads, Noma advises auditing that data "for suspicious submissions".
For New Zealand organisations: what does the Privacy Act 2020 expect?
The same principles as any tool, with a privacy impact assessment first. The Privacy Commissioner's AI guidance (21 September 2023, current as at October 2026) says "the Privacy Act applies to everyone using AI tools in New Zealand" and recommends a Privacy Impact Assessment "before you start". Its generative AI expectations add senior leadership approval, transparency and "human review prior to acting".
IPP 12. Principle 12 limits disclosing personal information outside New Zealand, but the Commissioner's AI and the IPPs guidance says: "Using offshore technology providers to store or process your data is not treated as a disclosure under IPP12, so long as they are not using that information for their own purposes." The trade-off, per its third-party provider guidance (26 November 2024), is that under section 11 "your organisation remains fully responsible". Whether your contract passes is for you or your adviser.
Where requests go. Salesforce's routing table sends GPT 4.1 requests from an Australia-hosted org to an Australian endpoint with no secondary region; if that endpoint is unresponsive, requests fall back to "Azure OpenAI in the United States" unless you turn that fallback off in Einstein Setup. Its agent considerations list OpenAI GPT-4o, which that table does not cover, so ask your account executive where agent requests run; audit data shows routing.
What is not known or not published?
- When your org was enabled: only "a rolling basis starting the first week of September".
- When the setting disappears: "Check back for more details."
- Whether enablement creates an agent: not stated; look in Agentforce Studio.
- Where Salesforce's 30-day audit copy is held: not stated.
- Agent-specific New Zealand privacy guidance: none found; the Commissioner's AI material dates from 2023.
- CVE numbers: none appears in either team's write-ups or in Salesforce's Trusted URLs article.
Should a small business just turn it off?
In our view, if nobody will own agent permissions this quarter, turning Einstein off is a reasonable holding position, at the cost of other Einstein generative AI features. Planning an agent? We suggest starting from minimal access, testing, then activating. Our plain-English Agentforce guide and data quality checklist cover the groundwork.
Ask a Salesforce question
Want to try this in your own org?
SAASKOOL builds and governs Salesforce AI for small teams, from a read-only Claude or ChatGPT connection to a first Agentforce agent. Tell us your edition and what you want the AI to do, and we will reply within 1 business day with what is possible today, what is still beta, and what it costs. Free, no obligation.
Frequently Asked Questions
Does Agentforce turn itself on in Winter '27? The platform does, in Enterprise, Performance, Unlimited and Developer Editions with Foundations or Agentforce 1, rolling out from September 2026. Admins get Agentforce Studio and Agentforce Builder. Salesforce says individual agents are only available to end users when active, and that billing does not change.
Does the Einstein Trust Layer mask customer data that agents send to the LLM? No. Salesforce states that data masking is disabled for agents because it can reduce response accuracy. Agent prompts are still covered by the zero data retention agreement with external model providers, and masking still applies to embedded features such as Einstein Service Replies.
Can I turn Agentforce off? Yes: turn off the Einstein setting on the Einstein Setup page, per Salesforce's release note. That also switches off Einstein generative AI features, so check what else you use first. Deactivating a single agent in Agentforce Studio is the narrower option.
Were ForcedLeak and SalesBleed fixed? The researchers say so. Noma Security, which reported ForcedLeak in July 2025, says Salesforce began enforcing Trusted URLs for Agentforce on 8 September 2025. Zenity Labs' SalesBleed timeline says all fixes were confirmed and tested on 21 September 2026, and Zenity warns that turning off user confirmation on an action takes a single click, so we suggest checking your actions.
Is using Agentforce a cross-border disclosure under New Zealand's IPP 12? Not automatically. The Privacy Commissioner's AI guidance says offshore providers that store or process data on your behalf, without using it for their own purposes, are not treated as a disclosure under IPP 12. You remain responsible for the information, and the Commissioner expects a privacy impact assessment first.
SAASKOOL's Agentforce and AI services cover agent builds with defined actions, data-use rules and human oversight. To see where your org stands first, start with the free health check.
Tags
Related Articles
Nonprofit Cloud Core, Advanced and Max: Pricing for NZ Nonprofits
Nonprofit Cloud now comes as Core, Advanced and Max. US prices, what Power of Us donates, the missing AUD prices and what NZ charities should check.
Read more Salesforce GuidesSalesforce for Outlook Retires 30 January 2027: A Migration Checklist
Salesforce for Outlook now retires on 30 January 2027. What stops working, how to find who still uses it, what replaces each feature, and a cutover plan.
Read more Salesforce GuidesSalesforce Now Owns Fin: What Intercom and Service Cloud Teams Should Do
Salesforce closed its Fin (formerly Intercom) deal on 10 September 2026. What has changed, what Fin costs next to Agentforce, and when to switch or stay.
Read more