Back to searchCanonical Registry Record · slug: salesforce-agentforce

Salesforce Agentforce

v2026.10-enterprise
bySalesforce·SalesUnverified Provider

Autonomous AI agent platform built for customer service, sales operations, and CRM workflow automation.

TR2 — Limited Assurance(53.07/100)
Assessment: TR-2026-000002
Version:2026.10-enterprise
Runtime category:salesforce_atlas_reasoning_engine

Capabilities

(4)
Descriptive presence only · Not a quality or performance rating
CRM Record Readcrm.read

Queries standard and custom CRM objects subject to tenant sharing rules.

Incident & Case Resolutioncrm.write

Updates service tickets, reassigns queues, and logs resolution notes.

Customer Email Draftingemail.draft

Generates draft responses for sales follow-ups and support inquiries.

Multi-App Action Automationworkflow.execute

Executes actions across 6,000+ connected cloud applications.

Integrations

(2)
Documented interfaces · Factual connection support
Enterprise CRM SystemsVendor: Salesforce / Generic
salesforce_crm
Slack IntegrationVendor: Slack
slack

Deployment & Execution Environment

Public runtime architecture · Excludes private keys and credentials
Execution Environment:salesforce-cloud-enterprise
Runtime Engine:salesforce_atlas_reasoning_engine
Assessed Invocation Tools (6):
crm_record_querycrm_record_create_updateflow_action_executionapex_action_executionexternal_service_rest_calloutslack_channel_message_dispatch
Assessed Permissions (5):
crm_object_read_accounts_contactscrm_object_read_write_leads_casescrm_object_read_opportunitiesflow_execute_service_actionsapex_execute_whitelisted_classes
Assessed Boundary Controls (7):
einstein_trust_layer_gatewaysalesforce_platform_rbacfield_level_security_flsdata_masking_and_zero_retentionprompt_defense_and_toxicity_filterdata_cloud_audit_trail_loggingtrusted_urls_outbound_filter

TrustRank Assurance

Assessment ID: TR-2026-000002
Assessed TrustRank
53.07/ 100
TR2 — Limited Assurance
Limited Assurance
Evidence Confidence
32.6%

Strength, testability, and independence of submitted audit evidence.

Methodology v0.2
Assessment Metadata
Type: Public Assessment
Status: VALID
Assessed: 1 October 2026
Valid Until: 30 December 2026
Assurance Cap Applied
  • PUBLIC_ASSESSMENT_CAP (Ceiling: 79): Public assessments are capped at 79 and ineligible for verified status or TR4/TR5.
Understanding Score vs Evidence Confidence:

TrustRank reflects the assessed control outcome. Evidence Confidence reflects the strength, independence and testability of the supporting evidence. They are separate metrics and are never combined or averaged.

Scope of Assessment:

TrustRank evaluates a specific Agent Assessment Object (AAO), including the agent version, model, deployment profile, tools, permissions, runtime and security controls. A TrustRank result should not be interpreted as a universal rating of the provider or every deployment of this agent.

Public Findings (2)

Audited security & control findings
CF2Zero-Click CRM Data Exfiltration via Indirect Prompt Injection in Web Forms (ForcedLeak)
Status: RESOLVED

Vulnerability in Agentforce web form processing permitted indirect prompt injection payloads submitted via public Web-to-Lead forms to execute unauthorized CRM record queries and exfiltrate customer data to external endpoints. Disclosed by Noma Security in September 2025 and remediated by Salesforce with enhanced context validation and URL restrictions.

Finding ID: CF-AF-001 · Control: TR04.02
CF2Trusted URL Filter Bypass and Unauthenticated Slack Channel Messaging (SalesBleed)
Status: RESOLVED

Vulnerability chain in Agentforce permitted indirect prompt injection payloads in Web-to-Lead records to bypass Trusted URL restrictions via image-tag DNS queries, exfiltrating Accounts table CRM data, and dispatched unauthenticated phishing messages into internal Slack channels under the Agentforce identity. Disclosed by Zenity Labs on September 24, 2026 and remediated by Salesforce via production hotfix.

Finding ID: CF-AF-002 · Control: TR06.02
Critical Control Coverage (30 Controls)
25Applicable
0E3 Tested
1Not Testable
Evidence Distribution (7 Records)
0E0
61E1
6E2
0E3
Operational Profile & Autonomy Boundaries
Autonomy Level:A2
Financial Authority:F0
Guardrails:GD3
Composition Risk:CE2
Cryptographic Assessment Fingerprint:
6f15e88d935bef40c230f99e14a56c91c5d3bc4134ee098a4bcb4fab8fe1d2d9
View Full Trust Passport

Sources & Provenance

(0)
Information observed: 1 October 2026

Registry Provenance Distinction: Registry Source Provenance is NOT TrustRank Assessment Evidence. Sources above document registry facts. TrustRank assessment evidence measures technical control test results.

No public registry provenance is currently available for this profile.