What happened with the UNC6395 Salesloft-Drift Supply Chain Attack? 
Learn More

Agentforce at work. Obsidian on watch.

Agentforce gives your teams autonomous agents with access to your most sensitive customer data. Obsidian makes sure that access stays controlled.

Shield graphic representing Obsidian SaaS Security Posture Management (SSPM) solution

Why your teams are using Agentforce

Agentforce gives sales, service, and ops teams autonomous agents that act on live CRM data, purpose-built for Salesforce environments, not bolted on from outside.

Automate complex workflows

Orchestrate multi-step tasks like lead routing, case escalation, opportunity updates, and contract renewals — powered by agents that act directly on your Salesforce data.

Accelerate delivery

Use Agentforce to automate follow-ups, surface next best actions, and handle routine service requests, so sales and service teams spend less time on manual work and more time closing.

Empower the workforce

Give sales, service, and ops teams autonomous AI agents that interact directly with customers and act on live CRM data, all within their existing Salesforce environment, without requiring engineering resources or custom development.

Agentforce agents operate inside your most sensitive CRM data — is anyone watching?

Unmonitored Agentforce agents silently spread risk across every Salesforce object they access and every external system they connect to.

Inherited permissions create hidden exposure

Agentforce agents inherit user permissions across Salesforce, often gaining access to sensitive customer records, financial data, and pipeline information far beyond what the task requires.

Privilege escalation goes undetected

Agents can operate with greater rights than the users who built them, accessing and acting on Salesforce data they were never explicitly authorized to touch.

Shadow agents spread without oversight

Sales and service teams can build and deploy Agentforce agents without security review, leaving unknown agents operating across your CRM environment without guardrails.

Sensitive data leaves through unsecured agents

Over-permissioned or misconfigured Agentforce agents can exfiltrate customer data across connected applications faster than traditional security tools can detect.

Salesforce built Agentforce for productivity, not for security teams

Agentforce gives your teams powerful CRM automation, but visibility into what those agents access, invoke, and expose across your Salesforce environment is left entirely to you.

Siloed visibility across tenants

No single view of which agents, MCP servers, and models are running across your tenants.

No single control plane

Native logs weren't built to capture risky tool calls and cross-service actions, especially from agents running outside Agentforce on platforms like Claude.

Over-permissioned agents

Agent permissions are scattered across every app they touch. Without a unified view, you can't know your true exposure until something goes wrong.

Privilege escalation

Agents act on behalf of users but aren't always bound by the same limits. Without a full identity graph, you won't know when an agent quietly exceeds the access its user was granted.

Your single control pane for every Agentforce agent

Map, monitor, and manage your agents with a single governance layer.

Inventory every Agentforce agent

Discover every agent across your Salesforce environment so nothing operates outside your security team's view.


Key benefits:
  • Shadow AI and auditability: Find unsanctioned agents including their owners and executions.

  • Consolidate every agent: Map agents and their risks no matter the platform they are built on.

Dashboard showing Salesforce Agentforce agents, their SaaS connections, risks, and owners.
Graph visualization of Salesforce Agentforce agents linked across SaaS apps and workflows.

Enforce least privilege across every agent

Detect over-permissioned Agentforce agents and automatically recommend right-sized permissions, removing unnecessary access before it becomes a liability.


Key benefits:
  • Right-size permissions: Remove unused privileges without breaking workflows.

  • Protect sensitive systems: Limit agent access to only approved Salesforce objects and connected apps.

Prevent data exfiltration through agent actions

Trace Agentforce actions to detect when customer data, contracts, or PII is at risk of leaving your environment.


Key benefits:
  • Continuous monitoring: Track every action an agent takes across your Salesforce environment in real time.

  • Policy alignment: Ensure agent behavior stays within your security guardrails before an incident occurs.

Risk details panel highlighting Salesforce Agentforce activity logs and data exposure risks.
Workflow diagram of Salesforce Agentforce agents and third-party connectors, showing potential vulnerabilities.

Protect the supply chain

Monitor AI and SaaS integrations connected to Agentforce for third- and fourth-party threats, preventing compromised integrations from becoming a launchpad for broader attacks.


Key benefits:
  • Integration visibility: See every app and connector your Agentforce agents touch.

  • Supply chain defense: Detect and respond to threats introduced through connected third-party services before they expand the blast radius.