What Salesforce Agentforce does
Agentforce lets organizations configure customer- and employee-facing agents with topics, instructions, trusted data, actions, monitoring, and Salesforce security controls.
Salesforce Agentforce is an enterprise agent platform built around business context and actions rather than a generic chat window. Administrators define topics, instructions, knowledge, and the functions an agent may call; the agent then interprets a request, builds a plan, retrieves authorized information, and executes permitted steps. Customer-facing agents can answer or resolve service work, while employee-facing agents can assist inside business processes. The platform is most credible when the target task already has owned data, clear policy, and a reversible action path in Salesforce.
Pricing has several dimensions. Salesforce's current page lists Foundations at $0, Flex Credits at $500 per 100,000 credits, conversations at $2 each, and an Agentforce User License at $5 per user per month that still requires Flex Credits. The February 23, 2026 rate card lists 20 credits for a standard or custom production action and 30 for a production voice action, with other prompt and speech rates. Product licenses, Data 360 usage, implementation, and connected services can add cost. Model real conversations step by step because one customer outcome may invoke several billable actions.
Agentforce inherits meaningful Salesforce controls. Official documentation says agents respect licenses, permissions, field-level security, and sharing settings, and model interactions use the Einstein Trust Layer with a zero-data-retention policy for third-party model providers. Trusted URL controls and action confirmations reduce some risks. These are foundations, not a substitute for configuration: Salesforce explicitly describes a shared-responsibility model, and administrators must prevent excessive access, unsafe actions, weak instructions, prompt injection paths, and inappropriate retention.
A safe rollout starts with a narrow read-oriented task, representative adversarial tests, and a clear handoff to a person. Do not grant an agent broad write permissions merely because the underlying user could perform those actions. Separate topics, minimize action inputs, require confirmation for consequential operations, log decisions, and monitor both outcomes and credit consumption in Digital Wallet. Agentforce is unlikely to justify its implementation burden for a small team without Salesforce data or administration expertise. It fits organizations already operating on Salesforce that can treat agent design as a governed product with owners, testing, release controls, and ongoing evaluation.
How Salesforce Agentforce works
An Agentforce agent classifies a request into configured topics, follows topic instructions, retrieves permitted Salesforce or connected context, and plans one or more approved actions. Actions can call flows, prompts, Apex, APIs, or other supported capabilities. The Einstein Trust Layer mediates model interactions, while Salesforce permissions and agent guardrails constrain available data and behavior.
Match the request to an allowed topic
The agent receives a customer or employee message and decides whether it fits a configured topic. Topic scope, instructions, identity, channel, and escalation rules determine whether the agent proceeds, asks for clarification, refuses, or hands off.
Retrieve trusted, permitted context
Agentforce uses accessible Salesforce data, knowledge, Data 360 context, or connected sources. Standard licenses, sharing, field-level permissions, trusted URLs, and Einstein Trust Layer controls shape what can reach the model and response.
Invoke narrow business actions
The reasoning engine selects from allowed flows, prompts, Apex, APIs, or standard actions and can perform several steps toward an outcome. Each production action currently draws Flex Credits; sensitive operations should validate inputs and require confirmation.
Review behavior, safety, and cost
Administrators inspect conversations, plans, action traces, handoffs, errors, and Digital Wallet usage. Sandbox and adversarial tests must continue after release so permission changes, new knowledge, prompt injection, and action updates do not silently weaken controls.
How to set up Salesforce Agentforce
Define one bounded agent job
Document the user, channel, eligible requests, source data, allowed outcomes, prohibited behavior, success metric, and human escalation path.
Audit data and permissions
Confirm licenses, sharing, field-level access, sensitive data, retention, and the least-privilege integration identity before connecting knowledge or actions.
Build topics and actions
Create narrow topics with explicit instructions, trusted sources, validated inputs, and only the flows, prompts, Apex, or APIs needed for the job.
Test trust boundaries
Use sandbox scenarios covering ambiguity, prompt injection, unauthorized records, unsafe URLs, action failures, and handoff; require confirmation for consequential changes.
Release and monitor
Roll out gradually, review transcripts and action traces, track containment, corrections and incidents, and reconcile Flex Credit usage with completed business outcomes.
Salesforce Agentforce FAQs
How much does Agentforce cost?
Current public options include Foundations at $0, Flex Credits at $500 per 100,000 credits, conversations at $2 each, and a $5 per-user monthly license that also requires usage credits. Other Salesforce products and implementation may add cost.
How many Flex Credits does an action use?
The February 23, 2026 rate card lists 20 credits for a standard or custom production Agentforce action and 30 for a production voice action; other usage types have different rates.
Does Agentforce follow Salesforce permissions?
Salesforce says agents respect licenses, permissions, field-level security, and sharing settings. Administrators still need to configure those controls correctly and constrain each agent's actions.
Does Salesforce use customer data to train third-party models?
Salesforce states that the Einstein Trust Layer applies zero data retention so third-party LLMs do not store prompts or use customer data for training. Buyers should verify the exact covered service and contract.
Listing reviewed 2026-07-15. Product details and pricing can change; verify important terms on the provider's website.
Related Sales AI tools
Related AI guides
Reviews
Tell the community what you made, what worked, and what you wish you knew before starting.