> ## Content Index
> Fetch the complete content index at: https://blog.aperion.ai/llms.txt
> Use this file to discover other available public pages before exploring further.

# Agentforce Governance: How to Secure Salesforce AI Agents
- URL: https://blog.aperion.ai/agentforce-governance-guide/
- Published: 2026-10-06T21:41:41.000Z
- Updated: 2026-10-06T21:41:41.000Z
- Description: LLM data masking is disabled for Agentforce agents, so what an agent can reach decides what it can expose. How to govern Agentforce in seven steps.
- Author: Craig Alberino
- Tags: Guides, AI Agents, AI Security

*Updated October 6, 2026\. Part 4 of APERION's Agent Platforms series.*

**Agentforce governance starts with the agent's permissions: an agent reaches what its running user, permission sets and sharing rules allow, and Salesforce's Einstein Trust Layer, Agentforce Gateway and observability work on top of that.** To govern Agentforce agents, give each agent its own narrow permission set, register and allowlist the external MCP servers and actions it may call, decide which models it uses, turn on session tracing, and export the record before Salesforce's retention window closes. Salesforce documents that LLM data masking is disabled for agents, so data exposure is controlled by what the agent can reach.

Agentforce is Salesforce's platform for building and running agents across sales, service and custom workflows. Salesforce reported Agentforce annual recurring revenue above $1.5 billion for its quarter ended July 31, 2026, a figure that now includes Slackbot and Headless 360 ([Salesforce, August 2026](https://s205.q4cdn.com/626266368/files/doc%5Ffinancials/2027/q2/CRM-Q2-FY27-Earnings-Press-Release.pdf)). Agents act inside the CRM, so their permissions are customer-data permissions.

## What Salesforce Ships for Governance

| Control                  | What it does                                                                                                                                        | What to check                                                                     |
| ------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------- |
| Agent permissions        | The agent's running user, permission sets, field-level security and sharing rules decide what it can read and change                                | Service agents run as a dedicated agent user; scope its permission sets per agent |
| Einstein Trust Layer     | Secure data retrieval, dynamic grounding, toxicity detection, an audit trail with feedback, and zero data retention with third-party model partners | LLM data masking is disabled for agents                                           |
| Agentforce Gateway       | Salesforce's policy point for outbound Agentforce traffic: authentication, authorization and auditing of requests                                   | Which tools each agent is assigned, and the quota limits applied                  |
| MuleSoft Agent Fabric    | Agent Registry, Broker and Visualizer, with Flex Gateway policies for MCP and A2A traffic                                                           | Whether your non-Salesforce agents are registered                                 |
| Agentforce Observability | Session tracing of user input, planner decisions, prompt and action flows, gateway inputs and outputs, and final output                             | Session tracing must be turned on, and requires Data 360                          |
| Testing                  | Testing Center, conversation tests and custom scorers before release                                                                                | Run tests at every agent change                                                   |

Sources: Salesforce [Agentforce trust guide](https://developer.salesforce.com/docs/ai/agentforce/guide/trust.html), [Einstein Trust Layer on Trailhead](https://trailhead.salesforce.com/content/learn/modules/the-einstein-trust-layer/meet-the-einstein-trust-layer), [Salesforce Architects](https://architect.salesforce.com/docs/architect/fundamentals/guide/mulesoft-architecting-agentic-enterprise.html) and [Agentforce Observability](https://www.salesforce.com/blog/agentforce-observability/), verified October 6, 2026.

## What the Trust Layer Covers for Agents

Salesforce's Trailhead module on the Einstein Trust Layer states: "Data masking for LLMs is currently disabled for agents." Masking remains available for embedded generative features such as service replies and work summaries. Salesforce has explained that masking adds latency and interferes with the planner and action workflows that agents depend on ([Salesforce, June 2025](https://www.salesforce.com/blog/llm-data-masking/)). For agents, the protection against data exposure is the set of records and fields the agent can reach.

The Trust Layer's audit trail records the prompt, the original response, toxicity scores and feedback ([Trailhead](https://trailhead.salesforce.com/content/learn/modules/the-einstein-trust-layer/follow-the-response-journey)). A July 2025 Salesforce engineering post cites a contractually mandated 30-day audit data retention window ([Salesforce Engineering, July 2025](https://engineering.salesforce.com/architecting-ai-agent-auditing-systems-in-agentforce-overcoming-data-cloud-and-kafka-integration-challenges/)). Plan an export if your obligations run longer.

## Where Agentforce's Control Points Are

**Models.** By default, agents run on a Salesforce-managed mix of models. Claude is available on Amazon Bedrock inside the Salesforce trust boundary ([Anthropic, October 2025](https://www.anthropic.com/news/salesforce-anthropic-expanded-partnership)). Agent Script sets the model at the org, agent or subagent level ([Salesforce](https://developer.salesforce.com/docs/ai/agentforce/guide/ascript-model.html)). Bring-your-own-model options in Model Builder include the LLM Open Connector, which Salesforce describes as an API specification "closely based on the OpenAI API, that lets you create API gateways and proxy servers that connect any language model to the Einstein AI Platform" ([Salesforce open source](https://opensource.salesforce.com/einstein-platform/open-connector)). Salesforce documents that path for prompt templates, custom actions and the Models API ([supported models](https://developer.salesforce.com/docs/ai/agentforce/guide/supported-models.html)). It does not document running the reasoning engine's own calls through a customer gateway. When you bring your own model, Salesforce's privacy FAQ treats the provider as a non-Salesforce application governed by your own contract ([Agentforce privacy FAQ](https://www.salesforce.com/en-us/wp-content/uploads/sites/4/documents/legal/Privacy/agentforce-privacy-FAQ.pdf)).

**Tools.** Agents call Flows, Apex, prompt templates, MuleSoft APIs and external MCP servers. Salesforce describes connecting external MCP servers with either a service account or per-user OAuth ([Salesforce, July 2026](https://www.salesforce.com/blog/connect-agentforce-external-mcp-servers/)). The choice decides whether each tool call carries the person who asked for it.

**Salesforce as a tool for other agents.** Salesforce Hosted MCP Servers, generally available since April 2026, let outside agents work in Salesforce, and "every transaction runs as the authenticated user," with field-level security and sharing rules applied ([Salesforce Developers, April 2026](https://developer.salesforce.com/blogs/2026/04/salesforce-hosted-mcp-servers-are-now-generally-available)).

## How to Govern Agentforce Agents in 7 Steps

### 1\. Give each agent its own narrow permission set

Create one permission set per agent, grant only the objects and fields its topics need, and review the agent user's sharing. For customer-facing agents, filter records to the verified customer explicitly. Identity in a conversation does not limit record access on its own.

### 2\. Treat untrusted input as untrusted

Web-to-Lead forms, case descriptions, emails and chat transcripts all reach agents as data. Restrict the outbound destinations agents can use, keep Trusted URLs enforcement current, and test agents against instructions hidden in the fields they read.

### 3\. Register and allowlist every external tool

Register external MCP servers in the Agentforce registry and allowlist individual tools rather than whole servers. Use per-user OAuth where the server supports it. Assign specific tools to each agent, and apply the quota limits the Agentforce Gateway provides.

### 4\. Decide which models each agent may use

Set the model per agent or subagent in Agent Script. If you bring your own model, route it through a gateway you control with the LLM Open Connector, and confirm the provider's data retention terms in your own contract.

### 5\. Turn on session tracing

Enable Agentforce Observability and session tracing in every production org. Salesforce made observability unmetered for all Agentforce customers in July 2026\. Baseline each agent user's activity before go-live.

### 6\. Require approval for consequential actions

Route actions that issue refunds, change entitlements, update financial fields or send external messages to a person. Build the approval into the Flow or action, or pause the tool call at a gateway, and record who approved.

### 7\. Export the record before retention closes

Export Trust Layer audit data and session traces to your own store on a schedule shorter than the retention window, and join them with your MCP gateway logs so one record covers what the agent read, what it called and who approved it.

## What ForcedLeak Showed

ForcedLeak, disclosed in September 2025 and rated CVSS 9.4, hid instructions in a Web-to-Lead form field. When an employee later asked Agentforce about the lead, the agent followed the instructions and sent CRM data to an allowlisted domain that had expired and been re-registered. Salesforce responded by enforcing Trusted URLs for Agentforce and Einstein AI ([Sombra, September 2026](https://sombrainc.com/blog/agentforce-security)). The pattern is the same one behind EchoLeak and GeminiJack: untrusted content the agent reads, plus a path out.

## Operating Limits

- **LLM data masking is disabled for agents.** Field and record permissions decide what reaches the model.
- **A service-account MCP connection acts as one identity.** Per-user OAuth carries the person.
- **The reasoning engine's model is Salesforce-managed.** Bring-your-own-model routing applies to prompts, actions and the Models API.
- **Trust Layer audit data has a retention window.** Export what you must keep.
- **Session tracing is off until you turn it on.**

## How APERION Fits

For Agentforce, APERION's Smartflow works on the paths Salesforce opens to customers. Agentforce agents can call its MCP gateway as an external MCP server over streamable HTTP, and the gateway applies tool rules, sends out-of-authority calls to a person with approval rights, and records each call. For models you bring through the LLM Open Connector, Smartflow can serve as the OpenAI-compatible endpoint when the connector authenticates with a bearer token. Salesforce's own Trust Layer and Agentforce Gateway govern the rest. [Talk to APERION](https://aperion.ai/contact).

## More in This Series

- [How to govern AI agents across platforms](https://aperion.ai/blog/govern-ai-agents-across-platforms-guide/)
- [CrewAI security and governance](https://aperion.ai/blog/crewai-security-governance-guide/)
- [Glean agents governance](https://aperion.ai/blog/glean-agents-governance-guide/)
- [Amazon Bedrock AgentCore governance](https://aperion.ai/blog/aws-bedrock-agentcore-governance-guide/)
- [Microsoft Copilot agent governance](https://aperion.ai/blog/microsoft-copilot-agent-governance-guide/)
- [Google, ServiceNow, OpenAI, Anthropic and LangChain](https://aperion.ai/blog/google-servicenow-openai-anthropic-agent-governance-guide/)

## Frequently Asked Questions

### What is the Einstein Trust Layer?

The Einstein Trust Layer is Salesforce's set of protections around generative AI: secure data retrieval, dynamic grounding, data masking, toxicity detection, an audit trail, and zero data retention agreements with third-party model providers. Salesforce documents that LLM data masking is currently disabled for agents.

### Does Agentforce mask sensitive data before it reaches the model?

Not for agents. Salesforce's Trailhead module states that data masking for LLMs is currently disabled for agents, while it remains available for embedded generative features. Control agent data exposure through permission sets, field-level security and sharing.

### Can Agentforce use my own LLM?

Model Builder supports models from OpenAI, Azure OpenAI, Vertex AI and Amazon Bedrock, and any model behind the LLM Open Connector, for prompt templates, custom actions and the Models API. Salesforce does not document running the agent's reasoning engine on a customer-supplied model.

### Does Agentforce support MCP?

Yes. Agentforce agents can call external MCP servers that an admin registers and allowlists, and Salesforce Hosted MCP Servers let outside agents work in Salesforce as the authenticated user.

### How long does Salesforce keep Agentforce audit data?

A July 2025 Salesforce engineering post cites a contractually mandated 30-day audit data retention window. Export audit data and session traces to your own store if your obligations require longer retention.

### What was ForcedLeak?

ForcedLeak was a vulnerability disclosed in September 2025 in which instructions hidden in a Web-to-Lead form led Agentforce to send CRM data to an expired, allowlisted domain. Salesforce responded by enforcing Trusted URLs for Agentforce and Einstein AI.

### How do I see what an Agentforce agent did?

Turn on Agentforce Observability and session tracing, which record user input, planner decisions, prompt and action flows, gateway inputs and outputs, and the final output for each session.

---

*Craig Alberino is the CEO and Founder of [APERION](https://aperion.ai), which provides Smartflow, the runtime governance layer for enterprise AI in regulated industries. [Learn more about Smartflow →](https://aperion.ai/products/smartflow)*