Skip to main content
Back to BlogSalesforce Guides

Is Agentforce Safe for a Small Business? The Settings to Check Now

Avinash Vatsya· Salesforce Consultant, SAASKOOL · 12+ years on the platform2 October 202610 min read

Whether Agentforce is safe for a small business depends on its configuration, not its defaults. Winter '27 turns the platform on in eligible orgs, but Salesforce says agents reach end users only when active. Salesforce provides the platform and Trust Layer; you decide who builds agents, what each can see, which links it may output and what gets logged.

Sources: Salesforce help articles, release notes and Trust data, two research teams and New Zealand's Privacy Commissioner, as at October 2026. Do the basics in our security settings checklist first.

What does "Agentforce Platform Enabled by Default" switch on?

The platform, not the agents. Salesforce's Winter '27 release note (as at October 2026) says the platform "is enabled by default for all orgs with Agentforce access, as granted by SKUs, licensing, and editions", in "Enterprise, Performance, Unlimited, and Developer Editions with Foundations or Agentforce 1 Editions", with existing orgs enabled "on a rolling basis starting the first week of September". Starter Suite, Pro Suite and Professional Edition are not listed; they get the Help Agent, covered in our Winter '27 service post.

Changes when the platform is onDoes not change
"all admins have access to Agentforce Studio, Agentforce Builder, and analytics and observability features"Agents "are only available to end users when the agent is active"
Agentforce Studio appears in the App Launcher by default "to all users in orgs with access to Agentforce"Other users still need the Manage AI Agents permission to build agents
Removing the Agentforce setting from the Agentforce Agents page is "planned for later in Winter ʼ27""no additional cost and there are no changes to billing"

No billing change is not free use: Salesforce meters usage "when you preview an agent in chat or voice" and in sandbox testing. Our cost guide and Foundations explainer cover credits.

Your upgrade is a separate clock. Salesforce Trust schedules Winter '27 production upgrades on 3 October and 9 to 10 October 2026 (UTC), with every Australian-hosted (AUS) and AP production instance on 10 October (UTC). Check your instance there, or see our dates post.

The off switch: "To turn off the Agentforce platform, in Setup, turn off the Einstein setting on the Einstein Setup page." That setting controls Einstein generative AI "across Salesforce", not just agents.

What does the Einstein Trust Layer protect, and what does it not?

It covers data travelling to and from the language model; it does not decide what your agent may read. Salesforce describes the Trust Layer as "a collection of features, processes, and policies", and its setup (Setup, Quick Find "Einstein", then Einstein Trust Layer) requires Data Cloud, which newer pages call Data 360.

ControlWhat Salesforce documentsThe catch for agents
Zero data retentionExternal model providers such as OpenAI do not retain or train on your data"Customers' use of other features including agents may result in data storage"
Secure data retrievalPrompts are "grounded only with data that the executing user has access to"For a customer-facing agent, that is usually the agent user you configure
Data maskingSensitive data masked before the model sees it; on by defaultMasking "is disabled for agents"
Prompt defence"one way to defend against jailbreaking and prompt injection attacks"Not a guarantee; see the disclosures below
Audit trailPrompts, masked prompts, responses and toxicity scores stored in your Data 360It can contain personal information

The masking row matters most. Salesforce's agent masking article says that in some cases masking "can affect the accuracy and relevance of the agent's response", so it is off for agents. It still applies to embedded features such as Einstein Service Replies, though Salesforce notes of pattern-based masking that "no model can guarantee 100% accuracy".

Salesforce also keeps audit data "for 30 days for compliance purposes" (response journey). With one data space, collection is "turned on by default when Agentforce is turned on", and storage over your allocation is billed.

What can an agent see and do?

Whatever its running user can, within the subagents and actions you give it. Salesforce's shared responsibility article (25 February 2026) says employee agents "execute in the context of the logged-in user", while customer agents on public channels "operate as a dedicated Agent User".

That agent user matters most. Configure Service Agent Access says it is created as "EinsteinServiceAgent User" "with minimal access so that your agent is secure by default", governed by its own profile, permissions, field-level security and sharing rules. The warning: "if the agent has access to data it doesn't need, the agent can expose proprietary information to customers."

Subagents (called topics until April 2026) and actions bound what it does. A flow-based custom action "adheres to the permissions, field-level security, and sharing settings configured in the flow" (Trust and Agentforce), and a custom action that changes a record can be set to "ask the user to confirm the change" first.

The shared responsibility article leaves Salesforce the platform, the Trust Layer and broad threat detection, and gives you least privilege, permission sets, field-level security, "restricting topics and actions" and monitoring.

What did ForcedLeak and SalesBleed show?

According to the researchers, text the public submits to Salesforce can steer an agent, and link filtering, which Salesforce calls a "defense-in-depth control", can be bypassed. Both teams say the issues they reported have been fixed.

ForcedLeak. Noma Security (25 September 2025) described a "critical severity (CVSS 9.4)" vulnerability chain: instructions hidden in a Web-to-Lead form ran when an employee asked Agentforce about that lead, sending CRM data to an allowlisted domain that "had expired and become available for purchase". Noma says Salesforce implemented "Trusted URLs Enforcement for Agentforce & Einstein AI" on 8 September 2025. Salesforce's knowledge article 005135034, which does not name ForcedLeak, describes that enforcement; a 13 February 2026 update says the *.salesforce.com wildcard would be removed from the default allowlist effective 28 February 2026.

SalesBleed. Zenity Labs (24 September 2026) reports bypassing the URL redaction itself, through the same Web-to-Lead route, and reading Accounts data because "the default General CRM subagent ships" with access to leads and accounts: "Those are defaults, not misconfigurations." A second post reports that the Reply to a Slack Thread action could post "without user confirmation". Zenity reports all fixes "confirmed and tested" on 21 September 2026, and warns that disabling confirmation takes "a single click of a button".

Which settings should a small team check this month?

Our ten checks, each at a location Salesforce documents:

CheckWhereWhat we look for
Is Einstein on, by decision?Setup, Quick Find "Einstein Setup"On only if someone owns AI
Who holds Manage AI Agents?Setup, Permission Sets and ProfilesNamed admins; it grants "org-wide management access to all agents"
Which agents are active?Agentforce Studio, AgentsEach has an owner; deactivate the rest
What can each agent user see?Setup, Users, filtered on the Einstein Agent User profileOnly the objects its actions need
Who can use each employee agent?Agentforce Builder, Settings, Agent AccessA permission set, not a shared profile
Do record-changing actions ask first?The action's "Require user confirmation" settingOn for anything that writes or sends
Are Trusted URLs tight?Setup, Quick Find "Trusted URLs"No broad wildcards; entries apply "throughout your entire Salesforce Org"
Who can read the audit trail?Data 360 data governance, for the data space chosen under Quick Find "Einstein Audit"Default Allow All data policy deleted or narrowed
Do you keep conversation logs?Agent setting "Keep a record of conversations with enhanced event logs"A deliberate choice; logs keep messages "for seven days"
Can model requests leave your region?Einstein Setup, in-region settingOn if your privacy assessment requires it

If a public web form feeds records an agent reads, Noma advises auditing that data "for suspicious submissions".

For New Zealand organisations: what does the Privacy Act 2020 expect?

The same principles as any tool, with a privacy impact assessment first. The Privacy Commissioner's AI guidance (21 September 2023, current as at October 2026) says "the Privacy Act applies to everyone using AI tools in New Zealand" and recommends a Privacy Impact Assessment "before you start". Its generative AI expectations add senior leadership approval, transparency and "human review prior to acting".

IPP 12. Principle 12 limits disclosing personal information outside New Zealand, but the Commissioner's AI and the IPPs guidance says: "Using offshore technology providers to store or process your data is not treated as a disclosure under IPP12, so long as they are not using that information for their own purposes." The trade-off, per its third-party provider guidance (26 November 2024), is that under section 11 "your organisation remains fully responsible". Whether your contract passes is for you or your adviser.

Where requests go. Salesforce's routing table sends GPT 4.1 requests from an Australia-hosted org to an Australian endpoint with no secondary region; if that endpoint is unresponsive, requests fall back to "Azure OpenAI in the United States" unless you turn that fallback off in Einstein Setup. Its agent considerations list OpenAI GPT-4o, which that table does not cover, so ask your account executive where agent requests run; audit data shows routing.

What is not known or not published?

  • When your org was enabled: only "a rolling basis starting the first week of September".
  • When the setting disappears: "Check back for more details."
  • Whether enablement creates an agent: not stated; look in Agentforce Studio.
  • Where Salesforce's 30-day audit copy is held: not stated.
  • Agent-specific New Zealand privacy guidance: none found; the Commissioner's AI material dates from 2023.
  • CVE numbers: none appears in either team's write-ups or in Salesforce's Trusted URLs article.

Should a small business just turn it off?

In our view, if nobody will own agent permissions this quarter, turning Einstein off is a reasonable holding position, at the cost of other Einstein generative AI features. Planning an agent? We suggest starting from minimal access, testing, then activating. Our plain-English Agentforce guide and data quality checklist cover the groundwork.

Ask a Salesforce question

Want to try this in your own org?

SAASKOOL builds and governs Salesforce AI for small teams, from a read-only Claude or ChatGPT connection to a first Agentforce agent. Tell us your edition and what you want the AI to do, and we will reply within 1 business day with what is possible today, what is still beta, and what it costs. Free, no obligation.

By sending, you agree to SAASKOOL processing your details to reply, as set out in the Privacy Policy.

See Salesforce AI and Agentforce services

Salesforce PartnerPledge 1% Proud Member

Frequently Asked Questions

Does Agentforce turn itself on in Winter '27? The platform does, in Enterprise, Performance, Unlimited and Developer Editions with Foundations or Agentforce 1, rolling out from September 2026. Admins get Agentforce Studio and Agentforce Builder. Salesforce says individual agents are only available to end users when active, and that billing does not change.

Does the Einstein Trust Layer mask customer data that agents send to the LLM? No. Salesforce states that data masking is disabled for agents because it can reduce response accuracy. Agent prompts are still covered by the zero data retention agreement with external model providers, and masking still applies to embedded features such as Einstein Service Replies.

Can I turn Agentforce off? Yes: turn off the Einstein setting on the Einstein Setup page, per Salesforce's release note. That also switches off Einstein generative AI features, so check what else you use first. Deactivating a single agent in Agentforce Studio is the narrower option.

Were ForcedLeak and SalesBleed fixed? The researchers say so. Noma Security, which reported ForcedLeak in July 2025, says Salesforce began enforcing Trusted URLs for Agentforce on 8 September 2025. Zenity Labs' SalesBleed timeline says all fixes were confirmed and tested on 21 September 2026, and Zenity warns that turning off user confirmation on an action takes a single click, so we suggest checking your actions.

Is using Agentforce a cross-border disclosure under New Zealand's IPP 12? Not automatically. The Privacy Commissioner's AI guidance says offshore providers that store or process data on your behalf, without using it for their own purposes, are not treated as a disclosure under IPP 12. You remain responsible for the information, and the Commissioner expects a privacy impact assessment first.


SAASKOOL's Agentforce and AI services cover agent builds with defined actions, data-use rules and human oversight. To see where your org stands first, start with the free health check.

Tags

agentforceai securityeinstein trust layerdata privacywinter 27