Salesforce Agentforce
Enterprise autonomous AI agent platform powered by the Atlas Reasoning Engine and Einstein Trust Layer, executing business actions, CRM workflows, and multi-step customer operations within Salesforce Cloud.
This Trust Passport applies specifically to the assessed agent configuration shown below. It is not an enterprise-wide rating of Salesforce, Inc. or every version/deployment of Salesforce Agentforce.
TrustRank Assessment & Evidence Confidence
Deterministic weighted composite outcome evaluated across active control domains.
Measures the independence, rigor, and reproducibility of the supporting evidence records.
- PUBLIC_ASSESSMENT_CAP: Public assessments are capped at 79 and ineligible for verified status or TR4/TR5. (capped at 79)
TrustRank reflects assessed control outcomes. Evidence Confidence reflects the strength, independence and testability of the supporting assessment evidence. These metrics are not combined, averaged, or converted into an empirical probability of safety.
Record Integrity
The current canonical assessment record matches its stored assessment fingerprint.
Record integrity verification establishes that this assessment record exactly matches its stored assessment fingerprint without tampering. This verifies record integrity only. It does not verify the identity of the issuer through a digital signature or cryptographic attestation.
Assessed Configuration
Scope Boundary:
This Trust Passport applies to the specific assessed agent configuration shown here. It is not a universal rating of the provider, all versions of the agent, or every deployment.
Material Change Principle: A material change to the assessed configuration (including model weights, tool boundaries, execution permissions, or network access) may require reassessment before the stated validity date.
Assessment Findings
(2)Vulnerability in Agentforce web form processing permitted indirect prompt injection payloads submitted via public Web-to-Lead forms to execute unauthorized CRM record queries and exfiltrate customer data to external endpoints. Disclosed by Noma Security in September 2025 and remediated by Salesforce with enhanced context validation and URL restrictions.
Vulnerability chain in Agentforce permitted indirect prompt injection payloads in Web-to-Lead records to bypass Trusted URL restrictions via image-tag DNS queries, exfiltrating Accounts table CRM data, and dispatched unauthenticated phishing messages into internal Slack channels under the Agentforce identity. Disclosed by Zenity Labs on September 24, 2026 and remediated by Salesforce via production hotfix.
Control Coverage & Evidence Distribution
Critical Control Coverage(25 applicable)
Controls marked as not testable are applicable to the agent but could not be independently tested with available evidence. They remain in the scoring denominator at zero score and are not treated as safe or passing.
Evidence Distribution(7 total records)
E0 = Vendor self-declaration; E1 = Documented implementation or internal testing; E2 = Independently verified artifact; E3 = Independently adversarially tested. E3 evidence cannot be vendor self-testing.
Operational Profile & Autonomy Boundaries
Assessment Validity & Lifecycle Status
Temporal validity window, assessment cycle, and canonical lifecycle status.
Important distinction: Record Integrity vs. Lifecycle Validity
Record Integrity establishes that the assessment data presented on this page exactly matches the SHA-256 fingerprint generated at assessment time without tampering.
Lifecycle Validity establishes whether the assessment is currently within its 90-day operational validity window and has not been revoked or marked as requiring reassessment. A record may be tamper-free (Verified Integrity) while simultaneously being expired or superseded.
Material Change Principle: A material change to the assessed agent code, system prompt, tool definitions, runtime environment, or permissions requires reassessment before the stated validity date.
Domain Assessment Breakdown (12 Domains)
| Domain | Weight | Applicable | Domain Score | Weighted Contribution |
|---|---|---|---|---|
| TR01 - Identity & Provenance | 8% | 5 | 52.00 | 4.16 |
| TR02 - Permissions & Least Privilege | 12% | 6 | 48.75 | 5.85 |
| TR03 - Data Protection & Privacy | 10% | 6 | 62.08 | 6.21 |
| TR04 - Prompt Injection & Goal Hijacking | 12% | 6 | 34.17 | 4.10 |
| TR05 - Tool & Action Safety | 12% | 7 (5 N/A) | 52.50 | 6.30 |
| TR06 - Boundary & Goal Adherence | 10% | 5 | 58.25 | 5.83 |
| TR07 - Human Control & Intervention | 8% | 5 | 61.75 | 4.94 |
| TR08 - Auditability & Transparency | 7% | 5 | 61.75 | 4.32 |
| TR09 - Memory & Context Integrity | 6% | 9 | 51.67 | 3.10 |
| TR10 - Agent & External Communications | 5% | 6 | 45.00 | 2.25 |
| TR11 - Operational Reliability & Recovery | 5% | 5 | 58.50 | 2.93 |
| TR12 - Governance & Change Control | 5% | 5 | 61.75 | 3.09 |
Portable Passport Record
Canonical portable fields representing the public Trust Passport record.
trust-passport-v0.2 · Public allowlist projection