Enterprise AI has changed the security boundary. A Salesforce agent can read CRM records, retrieve knowledge, invoke actions, and interact with external systems. That makes the prompt a potential control plane, not merely a conversational input. Prompt injection exploits this shift. Instead of manipulating a database query, an attacker manipulates the instructions an LLM interprets. This leads to malicious instructions to alter model behavior, expose sensitive information, or influence connected functions. Direct attacks come from user input, while indirect prompt injection comes from external content the model later reads, such as documents, websites, emails, or retrieved knowledge.
For Salesforce teams, the implication of these Agentforce security risks is practical: they need to go beyond identity, permissions, and data access when it comes to preventing these risks. So, how to prevent such severe LLM security vulnerabilities? Especially when the agent’s entire input-to-action path becomes part of the attack surface. This blog will cover prompt injection Salesforce risks, impact and share best practices to prepare you for situations when an AI agent attack surfaces.
What’s insideWhat Is a Prompt Injection?Understanding the AI Agent Attack Surface in AgentforceIndirect Prompt Injection: Is Your Salesforce Agentforce AI the New Attack Surface?What Are the Key Agentforce Security Risks?Prompt Injection Risks: 7 Steps to Keep Your Agents SecureAgentforce Security Assessment ChecklistWrapping It Up
What Is a Prompt Injection?
Prompt injection occurs when untrusted content causes an LLM to follow instructions that conflict with its intended task. In an agentic system, the risk increases because the model may have tools and permissions that let it act on the result.
How to Know Your Agentforce Has Been Prompt Injected
For better prevention, you must identify signs that prompt injection Salesforce teams should look out for:
Unexpected actions: Agents trigger updates/calls to CRM/executing tools that weren’t requested by the user.Anomalous responses: Using instructions or content that the user didn’t provide, often based on external documents or knowledge bases.Data leakage attempts: Agent discloses sensitive data from the CRM, configurations, or instructions beyond the scope of the query.Redirected behavior: The agent follows links or APIs outside the trusted URL list, indicating unsafe external access.Context poisoning indicators: Persistent changes in agent reasoning or repeated references to malicious content across sessions.
Understanding the AI Agent Attack Surface in Agentforce
An AI agent attack surface includes every place where untrusted input can influence model reasoning, tool selection, data retrieval, or downstream actions. For Agentforce, that can include:
User prompts and conversation historyCRM and Data Cloud records used for groundingKnowledge articles and uploaded filesExternal websites, documents, emails, and API responsesAgent instructions, topics, actions, and connected toolsURLs and external systems the agent can access
Salesforce provides protections through the Einstein Trust Layer, including prompt injection detection, system policies, secure data retrieval, audit capabilities, and trusted URL controls. But the user must treat Agentforce security as a shared responsibility: Salesforce secures the platform, while customers configure permissions, guardrails, monitoring, and agent-specific controls.
Indirect Prompt Injection: Is Your Salesforce Agentforce AI the New Attack Surface?
Indirect prompt injection is particularly relevant to CRM environments because agents increasingly consume information they did not receive directly from the user. A malicious instruction could be embedded in a knowledge article, customer-submitted document, webpage, or retrieved source. When the agent processes that material, the content can attempt to redirect its behavior.
The attack path can be simple:
External content → Agent context → Model decision → Tool or action → Business system
What Are the Key Agentforce Security Risks?
Data exposure:The agent may be manipulated into revealing information beyond the request.Excessive agency:Over-permissioned tools can turn a manipulated response into a real business action.Instruction leakage:Attackers may attempt to extract system instructions or configuration details.Context poisoning:Malicious content can influence reused or persistent context.Unsafe external access:Using third-party links or APIs can cause data leaks or unauthorized use.
Prompt Injection Risks: 7 Steps to Keep Your Agents Secure
1Treat External Content as UntrustedClassify user input, retrieved documents, websites, emails, and API responses as data, not instructions. Define trust boundaries before content enters the agent context to reduce prompt injection Salesforce exposure.2Apply Least PrivilegeGive the agent only the Salesforce objects, fields, actions, URLs, and services required for its function. Salesforce recommends customer-side controls such as least-privilege permissions and agent guardrails.3Validate Actions, Not Only PromptsA prompt filter may spot suspicious text, but controls must also check if the action matches what the user asked for. Critical tasks should only continue after double verification or approval from human agents.4Restrict Outbound DestinationsSalesforce Trusted URLs controls reduce the risk of malicious links and outbound requests following prompt injection. In February 2026, Salesforce removed default domain *.salesforce.com. Customers are now expected to create an explicit list of domains their agents need. This change reduces exposure, limits unnecessary endpoints, and enforces tighter control over external access.5Adversarial Input TestSecurity testing should include direct injection, indirect injection through knowledge and documents, tool manipulation, data-exfiltration attempts, and unauthorized-action scenarios. OWASP recommends penetration testing and breach simulations for LLM applications.6Monitor and Audit Agent BehaviorTrack prompts, responses, tool calls, permission use, blocked actions, and anomalies. Detailed logs strengthen Salesforce security assessment and help contain Agentforce security risks tied to LLM security vulnerabilities.7Embed Security into LifecycleIntegrate security reviews across design, testing, rollout, and updates. Embedding controls early limits indirect prompt injection CRM risks and aligns with Salesforce Security & Compliance Consulting standards.
Agentforce Security Assessment Checklist
Data Sources: Review all agent inputs to confirm only trusted records and documents are consumed.Instructions: Examine agent instructions to prevent leakage or manipulation.Permissions: Audit access rights to enforce least-privilege across Salesforce objects and fields.Actions: Validate tool and action execution against approved workflows.Integrations: Inspect APIs and external systems for unsafe exposure.External URLs: Restrict outbound requests to a defined trusted list.Human Approval: Define checkpoints for sensitive or high-impact operations.Logging: Enable capture of prompts, responses, tool calls, and blocked actions.Failure Paths: Map recovery processes to ensure safe handling of injection attempts.Blast Radius: Test containment controls to limit manipulated instructions.Context Poisoning: Monitor for malicious influence across persistent agent sessions.Governance: Include compliance checks alongside technical controls before deployment.
Wrapping It Up
Prompt injection is becoming an enterprise application security issue because AI agents can translate manipulated language into access, decisions, and actions. For Salesforce organizations, Agentforce security requires more than prompt hygiene. It requires a deliberate review of the agent’s attack surface, trust boundaries, permissions, integrations, and operational controls.
Seeking a Salesforce Security & Compliance Consulting partner can help you assess these controls, identify agentic AI exposure, and build a security framework aligned with enterprise governance requirements.
.gkx-blog{
--gkx-accent:#1a73e8; --gkx-dark:#0f4fa8; --gkx-light:#e8f0fe; --gkx-hl:#f3f7ff;
--gkx-line:#e4e9f2; --gkx-ink:#101828; --gkx-body:#3f4a5a; --gkx-mute:#697586;
--gkx-ok:#0f7a4a; --gkx-ok-bg:#eefaf3; --gkx-ok-line:#c3ead6;
--gkx-warn:#a35c00; --gkx-warn-bg:#fff8ec; --gkx-warn-line:#f5dfb8;
--gkx-alt:#6537c9; --gkx-alt-bg:#f5f2ff; --gkx-alt-line:#ddd4f7;
--gkx-neg:#b42318; --gkx-neg-bg:#fdf1f1; --gkx-neg-line:#f6d5d2;
--gkx-r:10px;
width:100%; font-size:17px; line-height:1.75; color:var(--gkx-body);
-webkit-font-smoothing:antialiased;
}
.gkx-blog *,.gkx-blog *::before,.gkx-blog *::after{box-sizing:border-box;}
.gkx-blog p{margin:0 0 20px;}
.gkx-blog h2{font-size:29px; line-height:1.3; letter-spacing:-.015em; margin:52px 0 18px; color:var(--gkx-ink); font-weight:700; scroll-margin-top:90px;}
.gkx-blog h3{font-size:20px; line-height:1.38; letter-spacing:-.01em; margin:32px 0 10px; color:var(--gkx-ink); font-weight:700; scroll-margin-top:90px;}
.gkx-blog h2 + p,.gkx-blog h3 + p{margin-top:0;}
.gkx-blog img{max-width:100%; height:auto; display:block; margin:0 auto; border-radius:var(--gkx-r);}
.gkx-blog hr{border:0; border-top:1px solid var(--gkx-line); margin:44px 0;}
.gkx-blog ul,.gkx-blog ol{margin:0 0 22px; padding:0; list-style:none;}
.gkx-blog svg{fill:none; stroke:currentColor; stroke-width:1.8; stroke-linecap:round; stroke-linejoin:round;}
.gkx-blog code{font-family:ui-monospace,SFMono-Regular,Menlo,Consolas,monospace; font-size:.88em; color:var(--gkx-ink); background:#f5f7fa; border:1px solid var(--gkx-line); border-radius:5px; padding:1px 6px; overflow-wrap:anywhere;}
.gkx-blog a{
color:var(--gkx-accent); font-weight:600;
background-image:none !important;
text-decoration:underline !important;
text-decoration-thickness:1px; text-underline-offset:3px;
text-decoration-skip-ink:auto;
transition:color .15s ease, text-decoration-thickness .15s ease;
}
.gkx-blog a:hover,.gkx-blog a:focus-visible{color:var(--gkx-dark); text-decoration-thickness:2px;}
.gkx-blog a:visited{color:var(--gkx-accent);}
.gkx-toc-list a,.gkx-blog .gkx-btn{text-decoration:none !important;}
.gkx-blog a:focus-visible{outline:2px solid var(--gkx-accent); outline-offset:3px; border-radius:3px;}
.gkx-kw{color:var(--gkx-ink); font-weight:700;}
.gkx-lede{
background:var(--gkx-hl); border-left:4px solid var(--gkx-accent);
border-radius:0 var(--gkx-r) var(--gkx-r) 0;
padding:20px 24px; margin:0 0 26px; font-size:18px; line-height:1.7; color:var(--gkx-ink);
}
.gkx-lede p{margin:0;}
.gkx-toc{
border:1px solid var(--gkx-line); border-radius:var(--gkx-r);
background:#fff; padding:20px 24px 8px; margin:30px 0 38px;
}
.gkx-toc-head{
font-size:11px; font-weight:700; letter-spacing:.11em; text-transform:uppercase;
color:var(--gkx-mute); margin:0 0 14px;
}
.gkx-toc-list{counter-reset:gkxtoc; margin:0; padding:0;}
@media (min-width:700px){.gkx-toc-2 .gkx-toc-list{columns:2; column-gap:34px;}}
.gkx-toc-2 .gkx-toc-list li{break-inside:avoid;}
.gkx-toc-list li{counter-increment:gkxtoc; position:relative; padding:0 0 12px 34px; font-size:15.5px; line-height:1.5;}
.gkx-toc-list li::before{
content:counter(gkxtoc,decimal-leading-zero);
position:absolute; left:0; top:1px;
font-size:11px; font-weight:700; color:var(--gkx-accent);
background:var(--gkx-light); border-radius:5px; padding:2px 6px; letter-spacing:.02em;
}
.gkx-toc-list a{color:var(--gkx-body); font-weight:600;}
.gkx-toc-list a:hover{color:var(--gkx-accent); text-decoration:underline !important;}
.gkx-list li{position:relative; padding:0 0 12px 24px; line-height:1.7;}
.gkx-list li::before{
content:""; position:absolute; left:2px; top:11px;
width:7px; height:7px; border-radius:50%; background:var(--gkx-accent);
}
.gkx-list strong{color:var(--gkx-ink);}
.gkx-chips{display:grid; grid-template-columns:repeat(2,minmax(0,1fr)); gap:10px; margin:22px 0 26px;}
.gkx-chips li{
display:block; position:relative;
background:var(--gkx-hl); border:1px solid var(--gkx-line); border-radius:8px;
padding:12px 16px 12px 34px; font-size:15px; line-height:1.55; color:var(--gkx-ink);
}
.gkx-chips li::before{
content:""; position:absolute; left:15px; top:20px;
width:6px; height:6px; border-radius:50%; background:var(--gkx-accent);
}
.gkx-chips-ck li{padding-left:42px;}
.gkx-chips-ck li::before{
left:14px; top:14px; width:18px; height:18px; border-radius:50%;
background:var(--gkx-ok-bg); border:1px solid var(--gkx-ok-line);
}
.gkx-chips-ck li::after{
content:""; position:absolute; left:21px; top:18px; width:4px; height:8px;
border:solid var(--gkx-ok); border-width:0 2px 2px 0; transform:rotate(45deg);
}
.gkx-cards{display:grid; grid-template-columns:repeat(2,minmax(0,1fr)); gap:16px; margin:24px 0 30px;}
.gkx-cards-3{grid-template-columns:repeat(3,minmax(0,1fr));}
.gkx-card{
border:1px solid var(--gkx-line); border-radius:var(--gkx-r); background:#fff;
padding:20px 22px 6px; transition:box-shadow .18s ease, transform .18s ease;
}
.gkx-card:hover{box-shadow:0 6px 22px rgba(16,24,40,.07); transform:translateY(-2px);}
.gkx-card-top{display:flex; align-items:center; gap:11px; margin-bottom:10px;}
.gkx-card-icon{
width:34px; height:34px; flex:0 0 34px; border-radius:8px;
background:var(--gkx-light); color:var(--gkx-accent);
display:flex; align-items:center; justify-content:center;
}
.gkx-card-icon svg{width:19px; height:19px;}
.gkx-card-t{font-size:16px; font-weight:700; color:var(--gkx-ink); line-height:1.35; margin:0;}
.gkx-card p{font-size:15.5px; line-height:1.68; margin:0 0 14px;}
.gkx-cards-risk .gkx-card-icon{background:var(--gkx-neg-bg); color:var(--gkx-neg);}
.gkx-ops{display:grid; gap:14px; margin:24px 0 30px;}
.gkx-op{
display:flex; gap:18px; align-items:flex-start;
border:1px solid var(--gkx-line); border-radius:var(--gkx-r); background:#fff;
padding:20px 22px; transition:box-shadow .18s ease, border-color .18s ease;
}
.gkx-op:hover{box-shadow:0 6px 22px rgba(16,24,40,.07); border-color:#d3ddec;}
.gkx-op-n{
flex:0 0 38px; width:38px; height:38px; border-radius:50%;
background:var(--gkx-accent); color:#fff;
display:flex; align-items:center; justify-content:center;
font-size:13px; font-weight:700; letter-spacing:.02em;
}
.gkx-op-b{min-width:0; flex:1;}
.gkx-op-b h3{margin:1px 0 6px; font-size:17.5px;}
.gkx-op-b p{font-size:15.5px; line-height:1.68; margin:0;}
.gkx-op-b p + p{margin-top:12px;}
.gkx-steps{position:relative; margin:26px 0 32px; padding-left:26px;}
.gkx-steps::before{content:""; position:absolute; left:5px; top:8px; bottom:8px; width:2px; background:var(--gkx-line);}
.gkx-step{position:relative; padding:0 0 8px;}
.gkx-step::before{
content:""; position:absolute; left:-26px; top:12px;
width:12px; height:12px; border-radius:50%;
background:#fff; border:3px solid var(--gkx-accent);
}
.gkx-step h2,.gkx-step h3{
font-size:20px; line-height:1.38; margin:22px 0 8px; letter-spacing:-.005em;
}
.gkx-step:first-child h2,.gkx-step:first-child h3{margin-top:0;}
.gkx-step p{font-size:16px; line-height:1.72; margin:0 0 4px;}
.gkx-blog .gkx-seq{counter-reset:gkxseq; position:relative; margin:26px 0 30px; padding:0;}
.gkx-seq::before{content:""; position:absolute; left:17px; top:20px; bottom:20px; width:2px; background:var(--gkx-line);}
.gkx-seq li{counter-increment:gkxseq; position:relative; padding:4px 0 20px 56px; line-height:1.7; min-height:36px;}
.gkx-seq li:last-child{padding-bottom:0;}
.gkx-seq li::before{
content:counter(gkxseq); position:absolute; left:0; top:0;
width:36px; height:36px; border-radius:50%;
background:var(--gkx-accent); color:#fff; border:3px solid #fff; box-shadow:0 0 0 1px var(--gkx-line);
display:flex; align-items:center; justify-content:center;
font-size:13px; font-weight:700;
}
.gkx-seq strong{color:var(--gkx-ink);}
.gkx-dgrid{display:grid; grid-template-columns:repeat(2,minmax(0,1fr)); gap:16px; margin:24px 0 30px;}
.gkx-dgrid-3{grid-template-columns:repeat(3,minmax(0,1fr));}
.gkx-dcard{border:1px solid var(--gkx-line); border-radius:var(--gkx-r); padding:20px 22px 6px; background:#fff; border-top:3px solid var(--gkx-accent); display:grid; grid-template-columns:34px minmax(0,1fr); column-gap:12px; align-items:center; align-content:start;}
.gkx-dcard h3{margin:0 0 8px; font-size:17px;}
.gkx-dcard .gkx-card-t{margin:0 0 10px; font-size:17px;}
.gkx-dcard p{font-size:15.5px; line-height:1.68; margin:0 0 14px;}
.gkx-dtag{
display:inline-block; font-size:10.5px; font-weight:700; letter-spacing:.08em;
text-transform:uppercase; border-radius:5px; padding:3px 9px; margin-bottom:11px;
background:var(--gkx-light); color:var(--gkx-dark);
}
.gkx-dcard .gkx-card-icon{margin:0 0 10px;}
.gkx-dcard p:not(.gkx-card-t){grid-column:1 / -1;}
.gkx-d-ok{border-top-color:var(--gkx-ok);}
.gkx-d-ok .gkx-dtag,.gkx-d-ok .gkx-card-icon{background:var(--gkx-ok-bg); color:var(--gkx-ok);}
.gkx-d-warn{border-top-color:var(--gkx-warn);}
.gkx-d-warn .gkx-dtag,.gkx-d-warn .gkx-card-icon{background:var(--gkx-warn-bg); color:var(--gkx-warn);}
.gkx-d-go{border-top-color:var(--gkx-accent);}
.gkx-d-go .gkx-dtag,.gkx-d-go .gkx-card-icon{background:var(--gkx-light); color:var(--gkx-dark);}
.gkx-d-alt{border-top-color:var(--gkx-alt);}
.gkx-d-alt .gkx-dtag,.gkx-d-alt .gkx-card-icon{background:var(--gkx-alt-bg); color:var(--gkx-alt);}
.gkx-verdict{
background:var(--gkx-hl); border:1px solid var(--gkx-line); border-radius:8px;
padding:13px 16px; font-size:15px; line-height:1.65; color:var(--gkx-ink); margin:2px 0 16px;
}
.gkx-qs{counter-reset:gkxq; display:grid; grid-template-columns:repeat(2,minmax(0,1fr)); gap:14px; margin:22px 0 28px;}
.gkx-qs li{
counter-increment:gkxq; position:relative;
border:1px solid var(--gkx-line); border-radius:var(--gkx-r); background:#fff;
padding:16px 18px 14px 18px;
}
.gkx-qs-head{
display:block; font-size:13.5px; font-weight:700; letter-spacing:.01em;
color:var(--gkx-accent); margin-bottom:6px;
}
.gkx-qs li p{font-size:15px; line-height:1.62; margin:0;}
.gkx-faq{display:grid; gap:14px; margin:24px 0 10px;}
.gkx-faq-i{border:1px solid var(--gkx-line); border-radius:var(--gkx-r); background:#fff; padding:20px 22px 6px;}
.gkx-faq-i h3{margin:0 0 8px; font-size:17.5px; line-height:1.4;}
.gkx-faq-i p{font-size:15.5px; line-height:1.68; margin:0 0 14px;}
.gkx-table-wrap{
overflow-x:auto; -webkit-overflow-scrolling:touch;
border:1px solid var(--gkx-line); border-radius:var(--gkx-r); margin:24px 0 10px;
}
.gkx-table{width:100%; border-collapse:collapse; min-width:560px; font-size:15px;}
.gkx-table th,.gkx-table td{padding:13px 16px; text-align:left; vertical-align:top; line-height:1.6;}
.gkx-table thead th{
background:var(--gkx-hl); color:var(--gkx-dark);
font-size:11.5px; font-weight:700; letter-spacing:.07em; text-transform:uppercase;
border-bottom:1px solid var(--gkx-line); white-space:nowrap;
}
.gkx-table tbody td,.gkx-table tbody th{border-top:1px solid var(--gkx-line);}
.gkx-table tbody tr:nth-child(even) td,.gkx-table tbody tr:nth-child(even) th{background:#fbfcfe;}
.gkx-table th:first-child,.gkx-table td:first-child{
position:sticky; left:0; z-index:1;
background:#fff; font-weight:700; color:var(--gkx-ink); font-size:14.5px;
border-right:1px solid var(--gkx-line);
}
.gkx-table thead th:first-child{background:var(--gkx-hl); color:var(--gkx-dark); font-size:11.5px;}
.gkx-table tbody tr:nth-child(even) td:first-child,.gkx-table tbody tr:nth-child(even) th:first-child{background:#fbfcfe;}
.gkx-pill{
display:inline-block; font-size:12.5px; font-weight:700; letter-spacing:.01em;
border-radius:999px; padding:3px 11px; white-space:nowrap;
}
.gkx-pill-pos{background:var(--gkx-ok-bg); color:var(--gkx-ok); border:1px solid var(--gkx-ok-line);}
.gkx-pill-mid{background:var(--gkx-warn-bg); color:var(--gkx-warn); border:1px solid var(--gkx-warn-line);}
.gkx-pill-neg{background:var(--gkx-neg-bg); color:var(--gkx-neg); border:1px solid var(--gkx-neg-line);}
.gkx-tag{
display:inline-block; font-size:13px; font-weight:600; color:var(--gkx-body);
background:#f5f7fa; border:1px solid var(--gkx-line); border-radius:6px; padding:3px 9px;
}
.gkx-num{font-variant-numeric:tabular-nums; font-weight:700; color:var(--gkx-ink); white-space:nowrap;}
.gkx-table-hint{display:none; font-size:12.5px; color:var(--gkx-mute); margin:0 0 30px; text-align:right;}
.gkx-stats{border:1px solid var(--gkx-line); border-radius:var(--gkx-r); background:var(--gkx-hl); padding:20px 22px 22px; margin:26px 0 30px;}
.gkx-stats-head{display:flex; align-items:center; gap:10px; font-size:16px; font-weight:700; color:var(--gkx-dark); margin:0 0 16px; line-height:1.35;}
.gkx-stats-head svg{width:20px; height:20px; flex:0 0 20px;}
.gkx-stats-grid{display:grid; grid-template-columns:repeat(3,minmax(0,1fr)); gap:14px;}
.gkx-stat{background:#fff; border:1px solid var(--gkx-line); border-radius:8px; padding:16px 18px 6px; font-size:15.5px; line-height:1.65; color:var(--gkx-ink);}
.gkx-stat p{margin:0 0 12px;}
.gkx-stat strong{color:var(--gkx-accent); font-weight:700;}
.gkx-stat .gkx-card-icon{margin:2px 0 10px;}
.gkx-plans{display:grid; grid-template-columns:repeat(3,minmax(0,1fr)); gap:16px; margin:24px 0 30px;}
.gkx-plan{border:1px solid var(--gkx-line); border-top:3px solid var(--gkx-accent); border-radius:var(--gkx-r); background:#fff; padding:20px 22px 8px;}
.gkx-plan-n{font-size:12px; font-weight:700; letter-spacing:.1em; text-transform:uppercase; color:var(--gkx-dark); margin:0 0 6px;}
.gkx-plan-p{font-size:20px; line-height:1.3; font-weight:800; letter-spacing:-.01em; color:var(--gkx-ink); margin:0 0 16px; font-variant-numeric:tabular-nums;}
.gkx-blog .gkx-plan-list{margin:0 0 14px;}
.gkx-plan-list li{position:relative; padding:0 0 10px 28px; font-size:15.5px; line-height:1.6; color:var(--gkx-ink);}
.gkx-plan-list li::before{
content:""; position:absolute; left:0; top:3px; width:18px; height:18px; border-radius:50%;
background:var(--gkx-ok-bg); border:1px solid var(--gkx-ok-line);
}
.gkx-plan-list li::after{
content:""; position:absolute; left:7px; top:7px; width:4px; height:8px;
border:solid var(--gkx-ok); border-width:0 2px 2px 0; transform:rotate(45deg);
}
.gkx-blog .gkx-ck{display:grid; grid-template-columns:repeat(2,minmax(0,1fr)); gap:10px; margin:22px 0 28px;}
.gkx-ck li{
position:relative; border:1px solid var(--gkx-line); border-radius:8px; background:#fff;
padding:14px 16px 14px 50px; font-size:15.5px; line-height:1.62;
}
.gkx-ck li::before{
content:""; position:absolute; left:17px; top:17px; width:18px; height:18px;
border:2px solid var(--gkx-accent); border-radius:5px; background:#fff;
}
.gkx-ck strong{color:var(--gkx-ink);}
.gkx-flow{display:flex; flex-wrap:wrap; align-items:stretch; gap:8px 6px; margin:22px 0 28px;}
.gkx-flow-i{
background:var(--gkx-hl); border:1px solid var(--gkx-line); border-radius:8px;
padding:9px 14px; font-size:14.5px; line-height:1.4; font-weight:600; color:var(--gkx-ink);
display:flex; align-items:center;
}
.gkx-flow-a{align-self:center; color:var(--gkx-accent); font-weight:700; font-size:16px; line-height:1;}
.gkx-callout,.gkx-tip{
display:flex; gap:14px; align-items:flex-start;
border-radius:var(--gkx-r); padding:17px 20px; margin:24px 0; font-size:16px; line-height:1.68;
}
.gkx-callout{background:var(--gkx-hl); border-left:4px solid var(--gkx-accent); color:var(--gkx-ink);}
.gkx-tip{background:var(--gkx-warn-bg); border-left:4px solid var(--gkx-warn); color:var(--gkx-ink);}
.gkx-callout svg,.gkx-tip svg{width:20px; height:20px; flex:0 0 20px; margin-top:3px;}
.gkx-callout svg{color:var(--gkx-accent);} .gkx-tip svg{color:var(--gkx-warn);}
.gkx-callout p,.gkx-tip p{margin:0;}
.gkx-quote{
margin:26px 0; padding:20px 24px; border-left:4px solid var(--gkx-accent);
background:var(--gkx-hl); border-radius:0 var(--gkx-r) var(--gkx-r) 0;
font-size:18.5px; line-height:1.65; font-style:italic; color:var(--gkx-ink);
}
.gkx-quote p{margin:0;}
.gkx-takeaway{
background:var(--gkx-hl); border:1px solid var(--gkx-line); border-radius:var(--gkx-r);
padding:22px 26px; margin:28px 0 22px;
}
.gkx-takeaway p{margin:0 0 14px;} .gkx-takeaway p:last-child{margin:0;}
.gkx-emph{
border-left:4px solid var(--gkx-accent); padding:4px 0 4px 20px; margin:24px 0 8px;
font-size:19px; line-height:1.6; font-weight:600; color:var(--gkx-ink);
}
.gkx-cta{
background:var(--gkx-ink); border-radius:var(--gkx-r); padding:26px 30px; margin:32px 0;
}
.gkx-cta-h{font-size:20px; font-weight:700; color:#fff; margin:0 0 9px; line-height:1.35;}
.gkx-cta p{color:#cfd6e2; font-size:16px; line-height:1.65; margin:0 0 18px;}
.gkx-blog .gkx-btn{
display:inline-block; background:var(--gkx-accent) !important; color:#fff !important;
font-size:14.5px; font-weight:700; padding:11px 24px; border-radius:7px;
text-decoration:none !important; transition:background .15s ease;
}
.gkx-blog .gkx-btn:hover,.gkx-blog .gkx-btn:focus-visible,.gkx-blog .gkx-btn:visited{
background:var(--gkx-dark) !important; color:#fff !important; text-decoration:none !important;
}
@media (max-width:900px){
.gkx-blog h2{font-size:26px; margin-top:44px;}
.gkx-cards-3{grid-template-columns:repeat(2,minmax(0,1fr));}
}
@media (max-width:820px){
.gkx-dgrid-3,.gkx-plans,.gkx-stats-grid{grid-template-columns:1fr;}
.gkx-stat{display:grid; grid-template-columns:34px minmax(0,1fr); column-gap:14px; align-items:start;}
}
@media (max-width:700px){
.gkx-cards,.gkx-cards-3,.gkx-dgrid{grid-template-columns:1fr;}
}
@media (max-width:640px){
.gkx-table-hint{display:block;}
.gkx-blog{font-size:16.5px;}
.gkx-blog h2{font-size:23px;}
.gkx-blog h3,.gkx-step h2,.gkx-step h3{font-size:18.5px;}
.gkx-lede{font-size:17px; padding:17px 18px;}
.gkx-toc{padding:18px 18px 6px;}
.gkx-chips,.gkx-qs,.gkx-ck{grid-template-columns:1fr;}
.gkx-op{flex-direction:column; gap:12px; padding:18px;}
.gkx-cta{padding:22px 20px;}
.gkx-emph{font-size:17.5px;}
.gkx-quote{font-size:17px; padding:17px 18px;}
.gkx-takeaway{padding:18px 18px;}
.gkx-steps{padding-left:22px;}
.gkx-step::before{left:-22px;}
.gkx-stats{padding:16px 16px 18px;}
.gkx-flow{flex-direction:column; align-items:flex-start;}
.gkx-flow-a{transform:rotate(90deg); margin-left:16px;}
}
@media (prefers-reduced-motion:reduce){
.gkx-blog *{transition:none !important;}
.gkx-card:hover{transform:none;}
}
An Agentforce demo can give positive results in a controlled conversation. The agent understands a request, selects an action, retrieves information, and produces a convincing response. Production is different. Customers don’t follow scripted demos. They ask incomplete questions, change direction in mid-conversation, provide unexpected inputs, and expect the agent to handle each interaction correctly. Therefore, a response that looks impressive in a controlled demonstration can behave very differently at scale. Businesses need Agentforce Testing Center to act as the QA gate between a promising prototype and a production-ready AI agent.
Having the right Agentforce QA process brings conversations, actions, guardrails, regression checks, and deployment criteria into one repeatable process. But how to ensure you’re effectively Agentforce testing? What are the challenges and best practices for the Agentforce QA process? In this blog, we’ll cover these. This blog will discuss how to test AI agents Salesforce and key considerations you need to focus on for optimal Agent regression testing.
What’s inside
Why Agentforce Testing Needs a Dedicated QA Gate
How to Test AI Agents in Salesforce
Agentforce QA Process: What Should the Gate Measure?
Agentforce Deployment Checklist: The Final QA Gate
Closing Remarks
Why Agentforce Testing Needs a Dedicated QA Gate
An unreliable agent creates problems well beyond poor customer interaction. If the system takes a wrong action, it may lead to an unintended CRM update or workflow change. The main cause of these risks comes from the non-deterministic nature of AI agents. Testing one successful conversation does not establish that an agent will behave consistently across hundreds of variations.
Traditional application QA is built around deterministic inputs and expected outputs. AI agents introduce variability. An agent may interpret the same request differently depending on context, conversation history, retrieved information, or available actions.
Before deployment, teams need answers to 6 questions:
Does the agent identify intent correctly?
Does it use approved Salesforce data?
Does it invoke the right action with valid inputs?
Does it refuse out-of-scope requests?
Does it preserve access controls?
Can it recover from ambiguity or failure?
What an Agentforce Testing Center Should Cover
A testing center is a controlled environment for evaluating the complete agent experience.
1. Intent and conversation testingTest agent performance across varied customer journeys. Include misspellings, incomplete inputs, followups, multiple intents, and direction changes. Go beyond simple queries to cover address changes, multiple orders, or incomplete details.
2. Action and integration testingValidate correct action selection, parameter handling, error management, and accurate communication. Ensure responses align with actual operations, avoiding failures, stale data, or restricted information exposure. Cover both conversational flow and backend execution.
3. Guardrail and security testingAssess boundaries, sensitive data handling, unsupported requests, injection attempts, and escalation rules. Confirm agents consistently decline invalid tasks while completing valid ones. Security and predictability must be part of the test suite.
4. Agent regression testingChanges in instructions, actions, or knowledge can alter behavior. Maintain a baseline suite of critical journeys and failure cases. Run after each update, compare results, and investigate deviations before release. Prioritize highimpact flows.
How to Test AI Agents in Salesforce
1. Start with manual testingUse Agentforce Builder to test individual conversations while the agent is being configured. This helps teams examine how the agent interprets an input, selects a subagent or action, and constructs its response. Manual testing is particularly useful when troubleshooting a newly created instruction, action, or guardrail.
2. Build representative test scenariosSalesforce specifically recommends positive and negative testing, so teams can validate both expected behavior and how an agent responds to invalid or unexpected requests. A strong test set should include:Common customer requestsAmbiguous or incomplete questionsInvalid inputsRequests outside the agent’s scopeMulti-turn conversationsKnowledge retrieval scenariosAction executionAttempts to bypass restrictionsEdge cases and unexpected phrasing
3. Run batch tests in Testing CenterTeams can create or upload test scenarios and evaluate agents across multiple interactions instead of manually checking every conversation. The newer Testing Center experience in Agentforce Studio supports batch testing across many conversation scenarios, with built-in and custom scorers for evaluating responses.
4. Analyze failures and scorer resultsReview failed scenarios, scorer results, incorrect actions, weak responses, and unexpected behavior across the test set. Group recurring failures by cause, such as instructions, knowledge, actions, or guardrails. This helps teams identify what needs refinement before the next test cycle.
5. Validate against deployment criteriaBefore moving the agent to production, confirm that critical scenarios meet predefined quality thresholds. Review unresolved failures, escalation behavior, permissions, and high-risk actions. Document the results and obtain the required approval, so testing becomes a defined release gate rather than an informal check.
Agentforce QA Process: What Should the Gate Measure?
An effective Agentforce QA process should evaluate more than whether an answer sounds correct. Salesforce Testing Center includes evaluations covering response quality, action execution, instruction adherence, completeness, coherence, conciseness, latency, and related measures. Consider measuring:
Response accuracy: Does the agent provide the expected information?
Instruction adherence: Does it follow defined business rules and communication requirements?
Subagent and action selection: Does it identify the right capability and execute the appropriate action?
Knowledge retrieval: Does it get relevant information with appropriate supporting references where required?
Consistency and efficiency: Does the agent perform reliably across scenarios and finish tasks within required time limits?
Agentforce Deployment Checklist: The Final QA Gate
Before moving an agent from sandbox to production, teams should verify:
Critical customer journeys have been tested
Positive, negative, and edge-case scenarios are covered
Key actions execute correctly
Knowledge responses have been validated
Guardrails and instructions behave as intended
Regression tests pass after configuration changes
High-impact failures have been resolved
Test results have been reviewed by both technical and business stakeholders
Production deployment uses the organization’s approved Salesforce release process
Testing should remain isolated from production. Salesforce documentation notes that agent testing can interact with CRM data, making sandbox-based testing an important safeguard.
Closing Remarks
The difference between an impressive Agentforce demo and a dependable production agent is not presentation quality. It is evidence. Agentforce Testing Center gives teams a way to turn that evidence into a repeatable QA process. For businesses moving Agentforce from experimentation to production, QA should be designed alongside the agent rather than added after it. A disciplined testing strategy gives teams a clearer deployment decision, a stronger operational baseline, and a more controlled path from AI capability to customer-facing automation.
Girikon’s Salesforce AI services helps organizations design, configure, test, and deploy Salesforce solutions with the operational requirements of production in mind. If your Agentforce implementation is ready to move beyond the demo stage, our structured testing and deployment approach can help establish the QA gate it needs.
.gkt-blog{--accent:#1a73e8;--accent-dk:#0f4fa8;--accent-light:#e8f0fe;--bg-highlight:#f3f7ff;--line:#e4e9f2;--tbl-border:#dde3ec;--white:#ffffff;--text-main:#101828;--text-body:#3f4a5a;--text-muted:#697586;--pos-fg:#0a7040;--pos-bg:#e7f5ee;--pos-bd:#bfe3d1;--mid-fg:#8a5a00;--mid-bg:#fdf4e3;--mid-bd:#f0dcb4;--neg-fg:#b42318;--neg-bg:#fef3f2;--neg-bd:#fbd5d2;--amber:#d97706;--amber-bg:#fffaf0;--amber-line:#fcd9a4;--amber-fg:#7c4a03;width:100%;box-sizing:border-box;color:var(--text-body);line-height:1.75;font-size:17px;-webkit-font-smoothing:antialiased}
.gkt-blog *,.gkt-blog *::before,.gkt-blog *::after{box-sizing:border-box}
.gkt-blog h2{font-size:clamp(22px,3.2vw,30px);line-height:1.28;font-weight:700;color:var(--text-main);letter-spacing:-.015em;margin:46px 0 16px;scroll-margin-top:90px}
.gkt-blog h3{font-size:clamp(17px,2.2vw,20px);line-height:1.4;font-weight:700;color:var(--text-main);letter-spacing:-.01em;margin:30px 0 10px;scroll-margin-top:90px}
.gkt-blog p{margin:0 0 18px}
.gkt-blog p:last-child{margin-bottom:0}
.gkt-blog strong{font-weight:650;color:var(--text-main)}
.gkt-blog .gkt-kw{color:var(--accent-dk);font-weight:650}
.gkt-blog img{max-width:100%;height:auto;border-radius:12px}
.gkt-blog a{color:var(--accent) !important;font-weight:600;transition:color .18s ease;background-image:none !important;text-decoration:underline !important;text-decoration-thickness:1px;text-underline-offset:3px;text-decoration-skip-ink:auto}
.gkt-blog a:hover,.gkt-blog a:focus-visible{color:var(--accent-dk) !important;text-decoration-thickness:2px}
.gkt-blog a:focus-visible{outline:2px solid var(--accent);outline-offset:3px;border-radius:3px}
.gkt-blog svg{width:100%;height:100%;display:block;fill:none;stroke:currentColor;stroke-width:1.8;stroke-linecap:round;stroke-linejoin:round}
.gkt-lede{background:var(--bg-highlight);border:1px solid var(--line);border-left:4px solid var(--accent);border-radius:0 12px 12px 0;padding:22px 26px;margin:0 0 24px}
.gkt-lede p{font-size:clamp(17px,2.1vw,19px);line-height:1.7;color:var(--text-main);font-weight:400;margin:0}
.gkt-toc{background:var(--white);border:1px solid var(--line);border-radius:14px;padding:20px 22px 8px;margin:28px 0 8px;box-shadow:0 1px 2px rgba(16,24,40,.04)}
.gkt-toc-head{display:flex;align-items:center;gap:9px;font-size:12px;font-weight:700;letter-spacing:.1em;text-transform:uppercase;color:var(--text-muted);margin:0 0 14px !important}
.gkt-toc-head svg{width:16px;height:16px;flex:0 0 16px;color:var(--accent);stroke-width:2}
.gkt-toc-list{list-style:none;counter-reset:gkttoc;margin:0;padding:0;display:grid;gap:2px}
.gkt-toc-list li{counter-increment:gkttoc;margin:0;padding:0}
.gkt-toc-list li::before{content:none}
.gkt-toc-list a{display:flex;align-items:baseline;gap:11px;padding:9px 10px;border-radius:8px;font-size:15.5px;font-weight:550;color:var(--text-body) !important;background-image:none !important;text-decoration:none !important;transition:background-color .15s ease,color .15s ease}
.gkt-toc-list a::before{content:counter(gkttoc,decimal-leading-zero);flex:0 0 auto;font-size:12px;font-weight:700;color:var(--accent);font-variant-numeric:tabular-nums}
.gkt-toc-list a:hover{background-color:var(--accent-light);color:var(--accent-dk) !important}
.gkt-table-wrap{overflow-x:auto;-webkit-overflow-scrolling:touch;border:1px solid var(--line);border-radius:14px;margin:24px 0 8px;box-shadow:0 1px 2px rgba(16,24,40,.04)}
.gkt-table{width:100%;min-width:680px;border-collapse:collapse;font-size:15.5px;background:var(--white)}
.gkt-table th,.gkt-table td{padding:14px 18px;text-align:left;vertical-align:middle;border-bottom:1px solid var(--line)}
.gkt-table thead th{font-size:12.5px;font-weight:700;letter-spacing:.06em;text-transform:uppercase;color:var(--text-muted);background:#f8fafd;border-bottom:2px solid var(--line);white-space:nowrap}
.gkt-table tbody th{font-weight:650;color:var(--text-main);background:var(--white);position:sticky;left:0;z-index:1;min-width:200px;box-shadow:1px 0 0 var(--line)}
.gkt-table thead th:first-child{position:sticky;left:0;z-index:2;box-shadow:1px 0 0 var(--line)}
.gkt-table tbody tr:nth-child(even) th,.gkt-table tbody tr:nth-child(even) td{background:#fbfcfe}
.gkt-table tbody tr:last-child th,.gkt-table tbody tr:last-child td{border-bottom:none}
.gkt-pill{display:inline-block;padding:3px 11px;border-radius:999px;font-size:13px;font-weight:650;line-height:1.45;white-space:nowrap;border:1px solid transparent}
.gkt-pos{color:var(--pos-fg);background:var(--pos-bg);border-color:var(--pos-bd)}
.gkt-mid{color:var(--mid-fg);background:var(--mid-bg);border-color:var(--mid-bd)}
.gkt-neg{color:var(--neg-fg);background:var(--neg-bg);border-color:var(--neg-bd)}
.gkt-tag{display:inline-block;padding:3px 11px;border-radius:6px;font-size:13px;font-weight:650;line-height:1.45;color:var(--accent-dk);background:var(--accent-light);border:1px solid #c4dbfb;white-space:nowrap}
.gkt-num{font-variant-numeric:tabular-nums;font-weight:650;color:var(--text-main);white-space:nowrap}
.gkt-table-hint{font-size:13px;color:var(--text-muted);margin:10px 0 18px !important;display:none}
.gkt-chips{list-style:none;display:grid;grid-template-columns:repeat(auto-fit,minmax(230px,1fr));gap:11px;margin:22px 0 24px;padding:0}
.gkt-chips li{position:relative;display:block;background:var(--white);border:1px solid var(--line);border-radius:10px;padding:13px 15px 13px 34px;margin:0;font-size:15.5px;font-weight:550;color:var(--text-main);line-height:1.4;transition:border-color .15s ease,box-shadow .15s ease,background-color .15s ease}
.gkt-chips li::before{content:"";position:absolute;left:15px;top:20px;width:8px;height:8px;border-radius:50%;background:linear-gradient(135deg,#5ea2ff,var(--accent))}
.gkt-chips li:hover{border-color:#b9d2f7;background-color:#fbfdff;box-shadow:0 3px 12px rgba(26,115,232,.09)}
.gkt-chips.gkt-check{grid-template-columns:repeat(auto-fit,minmax(300px,1fr))}
.gkt-chips.gkt-check li{padding:13px 15px 13px 46px}
.gkt-chips.gkt-check li::before{left:14px;top:14px;width:22px;height:22px;border-radius:50%;border:1px solid var(--pos-bd);background:var(--pos-bg) url("data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 24 24' fill='none' stroke='%230a7040' stroke-width='3' stroke-linecap='round' stroke-linejoin='round'%3E%3Cpath d='M6 12.5l4 4 8-9'/%3E%3C/svg%3E") center/13px 13px no-repeat}
.gkt-list{list-style:none;margin:22px 0 24px;padding:0}
.gkt-list li{position:relative;padding:0 0 0 32px;margin:0 0 14px}
.gkt-list li:last-child{margin-bottom:0}
.gkt-list li::before{content:"";position:absolute;left:5px;top:.62em;width:9px;height:9px;border-radius:2px;background:linear-gradient(135deg,#5ea2ff,var(--accent));transform:rotate(45deg)}
.gkt-steps{list-style:none;margin:26px 0 8px;padding:0}
.gkt-step{position:relative;padding:0 0 30px 44px;margin:0}
.gkt-step::before{content:"";position:absolute;left:3px;top:7px;width:16px;height:16px;border-radius:50%;background:var(--accent-light);border:2px solid var(--accent);z-index:1}
.gkt-step::after{content:"";position:absolute;left:10px;top:28px;bottom:6px;width:2px;background:linear-gradient(180deg,#cfe0fb,#eef3fa)}
.gkt-step:last-child{padding-bottom:0}
.gkt-step:last-child::after{display:none}
.gkt-step>h3{margin:0 0 8px}
.gkt-step>p:last-child{margin-bottom:0}
.gkt-cards{display:grid;grid-template-columns:repeat(auto-fit,minmax(300px,1fr));gap:18px;margin:26px 0 8px}
.gkt-card{position:relative;background:var(--white);border:1px solid var(--line);border-radius:14px;padding:24px;overflow:hidden;transition:border-color .18s ease,box-shadow .18s ease,transform .18s ease}
.gkt-card::before{content:"";position:absolute;inset:0 0 auto 0;height:3px;background:linear-gradient(90deg,var(--accent),#5ea2ff);opacity:0;transition:opacity .18s ease}
.gkt-card:hover{border-color:#b9d2f7;box-shadow:0 10px 28px rgba(16,24,40,.08);transform:translateY(-2px)}
.gkt-card:hover::before{opacity:1}
.gkt-card-top{display:flex;align-items:center;gap:13px;margin-bottom:12px}
.gkt-card-icon{flex:0 0 40px;width:40px;height:40px;border-radius:10px;background:var(--accent-light);color:var(--accent);padding:9px}
.gkt-card-t{font-size:clamp(16px,2.2vw,18px);font-weight:700;color:var(--text-main);line-height:1.35;letter-spacing:-.01em}
.gkt-card p{font-size:16px;margin:0}
.gkt-qs{background:var(--white);border:1px solid var(--line);border-radius:14px;padding:22px 24px 24px;margin:26px 0;box-shadow:0 1px 2px rgba(16,24,40,.04)}
.gkt-qs-head{font-size:clamp(16px,2.2vw,18px);font-weight:700;color:var(--text-main);line-height:1.4;letter-spacing:-.01em;margin:0 0 16px !important}
.gkt-qs ol{list-style:none;counter-reset:gktq;margin:0;padding:0;display:grid;gap:10px}
.gkt-qs li{counter-increment:gktq;position:relative;background:var(--bg-highlight);border:1px solid var(--line);border-radius:10px;padding:13px 16px 13px 56px;margin:0;font-size:16px;font-weight:550;color:var(--text-main);line-height:1.5}
.gkt-qs li::before{content:counter(gktq);position:absolute;left:14px;top:10px;width:30px;height:30px;border-radius:50%;background:var(--accent-light);border:1.5px solid #c4dbfb;color:var(--accent-dk);font-size:13.5px;font-weight:700;display:flex;align-items:center;justify-content:center;font-variant-numeric:tabular-nums}
.gkt-callout{display:flex;gap:16px;align-items:flex-start;background:var(--bg-highlight);border:1px solid #cfe0fb;border-left:4px solid var(--accent);border-radius:0 12px 12px 0;padding:20px 24px;margin:26px 0}
.gkt-callout-icon{flex:0 0 26px;width:26px;height:26px;color:var(--accent);margin-top:3px}
.gkt-callout p{margin:0;font-size:16.5px;line-height:1.65;color:var(--text-main)}
.gkt-tip{display:flex;gap:16px;align-items:flex-start;background:var(--amber-bg);border:1px solid var(--amber-line);border-left:4px solid var(--amber);border-radius:0 12px 12px 0;padding:20px 22px;margin:26px 0}
.gkt-tip-icon{flex:0 0 26px;width:26px;height:26px;color:var(--amber);margin-top:3px}
.gkt-tip p{margin:0;font-size:16.5px;line-height:1.65;color:var(--amber-fg)}
.gkt-emph{font-size:clamp(17px,2.1vw,19px);font-weight:600;color:var(--text-main);line-height:1.6;border-left:3px solid var(--accent);padding:2px 0 2px 18px;margin:26px 0 !important}
.gkt-takeaway{background:var(--bg-highlight);border:1px solid #cfe0fb;border-radius:14px;padding:24px 26px;margin:26px 0 24px}
.gkt-takeaway p{font-size:clamp(16.5px,2.1vw,18px);line-height:1.7;color:var(--text-main);font-weight:400;margin:0}
.gkt-cta{display:flex;align-items:center;justify-content:space-between;gap:18px;flex-wrap:wrap;background:var(--bg-highlight);border:1px solid #cfe0fb;border-left:4px solid var(--accent);border-radius:0 10px 10px 0;padding:14px 20px;margin:32px 0}
.gkt-cta p{flex:1 1 300px;margin:0;font-size:15.5px;line-height:1.55;color:var(--text-main)}
.gkt-blog .gkt-btn{flex:0 0 auto;display:inline-flex;align-items:center;justify-content:center;padding:10px 20px;border-radius:8px;font-size:14.5px;font-weight:650;line-height:1.2;text-align:center;background-color:var(--accent);color:#fff !important;background-image:none;text-decoration:none !important;border:1.5px solid transparent;white-space:nowrap;box-shadow:0 3px 10px rgba(26,115,232,.28);transition:transform .16s ease,box-shadow .16s ease,background-color .16s ease}
.gkt-blog .gkt-btn:hover,.gkt-blog .gkt-btn:focus,.gkt-blog .gkt-btn:focus-visible,.gkt-blog .gkt-btn:active,.gkt-blog .gkt-btn:visited{color:#fff !important;background-image:none !important;background-size:0 0 !important;text-decoration:none !important}
.gkt-blog .gkt-btn:hover,.gkt-blog .gkt-btn:focus-visible{transform:translateY(-1px);background-color:#1668d6;box-shadow:0 6px 16px rgba(26,115,232,.38)}
.gkt-blog .gkt-btn:focus-visible{outline:2px solid var(--accent-dk);outline-offset:3px}
@media (min-width:640px){.gkt-toc-list{grid-template-columns:1fr 1fr;column-gap:14px}}
@media (min-width:760px){.gkt-qs ol{grid-template-columns:1fr 1fr}}
@media (max-width:680px){.gkt-blog{font-size:16px;line-height:1.72}.gkt-lede{padding:18px 20px}.gkt-callout,.gkt-tip{padding:18px 18px;gap:13px}.gkt-takeaway{padding:20px}.gkt-card{padding:20px}.gkt-card-top{align-items:flex-start}.gkt-qs{padding:18px 16px 20px}.gkt-cta{padding:18px;gap:14px}.gkt-blog .gkt-btn{width:100%}.gkt-step{padding-left:36px}.gkt-table th,.gkt-table td{padding:12px 14px}.gkt-table tbody th{min-width:160px}.gkt-table-hint{display:block}}
@media (max-width:400px){.gkt-chips,.gkt-chips.gkt-check,.gkt-cards{grid-template-columns:1fr}}
@media (prefers-reduced-motion:reduce){.gkt-blog *{transition:none !important}.gkt-blog .gkt-btn:hover,.gkt-card:hover{transform:none}}
@media print{.gkt-cta{display:none !important}.gkt-blog{font-size:11pt}.gkt-card,.gkt-table tr,.gkt-step{break-inside:avoid}.gkt-table-wrap{overflow:visible}.gkt-table{min-width:0}}
To say clearing the AppExchange security review is a paperwork step, understates its impact. A failed or delayed review doesn’t just cost engineering time. It costs revenue, strains contractual deadlines, and erodes the trust of a customer who’s already waiting. Therefore, treat AppExchange app submission requirements as a release-readiness testing because that’s what helps your app function as expected. If you push it to the end of the timeline, you spend more time and resources repairing issues in an app than you did in building it.
Across six applications we’ve taken through Salesforce’s AppExchange security review process, one lesson kept repeating: what a clean automated scan tells you and what the review actually demands are two different things. Salesforce doesn’t lean on a single tool to make that call. Reviewers work through static analysis, dynamic testing, and manual inspection carried out by specialists who know how Apex, Lightning components, and third-party integrations behave once they’re deployed together, not in isolated test conditions. In this blog, we’ll explore these lessons in the way we managed to match Salesforce AppExchange requirements. We’ll also share a few practical tips on how to pass the Salesforce security review and common issues to avoid for a successful ISV security review process.
What’s inside
Lessons From Shipping Six Apps Through Salesforce AppExchange Security Review
7 Tips on How to Pass Salesforce Security Review + Common Pitfalls to Avoid
What Does Salesforce Say About AppExchange Security Review Timelines
How Girikon Can Help ISV in Security Review process
Conclusion
Lessons From Shipping Six Apps Through Salesforce AppExchange Security Review
When we went through a Salesforce AppExchange security review, there were few lessons we learned. And now sharing with you all, a quick AppExchange security review checklist:
Lesson 1: A clean static scan doesn’t mean you’re ready
Automated tools miss context-dependent flaws. Sharing rules and object permissions can break in certain setups, even though the scan shows no issues.
Lesson 2: Field-level security gets missed more often
This is in comparison to object-level security. Reviewers check both. Inconsistent field permissions across different profiles come up repeatedly as findings, and they’re entirely avoidable.
Lesson 3: Lightning Web Components carry their own client-side risk
These risks separate from anything a traditional Apex review would catch. Unescaped data binding showed up twice in our submissions. So did insecure use of `lwc:dom` manual mode.
Lesson 4: Integration endpoints need authentication flows
Such endpoints need to be documented and actually tested, not assumed. Undocumented API behavior slows reviewers down, and it tends to invite closer scrutiny of the whole package, not just that one piece.
Lesson 5: Named credentials and connected app settings must match
This helps in showing what’s actually live in the org. Even small mismatches between documentation and configuration will likely stall a review.
Lesson 6: Rushed remediation costs more time than it saves
This is by far the most humbling lesson. Fixing a finding without checking it against the reviewer’s original note is how a second round of review happens. Avoid it.
7 Tips on How to Pass Salesforce Security Review + Common Pitfalls to Avoid
Step 1: Build Security into Design
Security must be embedded in architecture from the start. Teams that design with secure coding principles avoid latestage fixes and reduce review delays. Your AppExchange security review checklists must treat every integration and data flow as a risk surface.
Run threat modeling before development begins
Apply secure coding standards consistently
Avoid leaving security checks until submission
Watch out for overlooked Lightning and clientside risks
Step 2: Run Static Code Analysis
Static scans catch insecure patterns before runtime but aren’t enough alone. Use them to flag obvious flaws, while deeper checks and manual review handle the risks automation cannot.
Enforce linting and security rules
Check dependencies for known vulnerabilities
Don’t assume a clean scan guarantees approval
Manually review code that trigger issue instead of skipping it
Step 3: Conduct Dynamic Security Testing (DAST)
Runtime testing shows issues static scans miss. It flags injection flaws, weak session handling, and risks that only appear when the app runs in real conditions.
Run authenticated DAST tests on your app
Validate session and token handling thoroughly
Avoid relying only on static analysis results
Pay attention to runtime injection vulnerabilities
Step 4: Perform Manual Validation
Human review can spot logic flaws and configuration mistakes that automated tools miss. Manual checks of Lightning components and API flows bring out risks that only appear in real use.
Carry out peer code reviews
Walk through Lightning components manually
Resist the urge to skip validation under deadline pressure
Don’t assume automation covers business logic
Step 5: Ensure Submission Readiness
A package must be complete, consistent, and accessible. Reviewers reject submissions with missing metadata, broken credentials, or incomplete documentation.
Provide working test org credentials
Attach full metadata and package notes
Check that login details are current before submission
Keep documentation complete and up to date
Step 6: Remediate and Retest Thoroughly
The results regarding security or performance issues are expected. What matters is how they’re fixed and at what stage. Document remediation clearly, retest to confirm, and avoid partial or delayed corrections. It’s important that you’ve a proper trail because reviewers want proof of closure.
Keep detailed remediation logs
Retest and record evidence for each fix
Never submit without proof of remediation
Close out all known issues before resubmitting
Step 7: Document Everything for Review
Clear documentation speeds approval. It’s very common for reviewers to know how issues were identified, fixed, and validated. A structured security report reduces backandforth cycles.
Provide complete security test reports
Add remediation and validation notes
Avoid vague or generic documentation
Always include evidence of fixes
What Does Salesforce Say About AppExchange Security Review Timelines
The published guidelines by Salesforce AppExchange review timeline point to “several weeks” as a rough benchmark. So, there’s no fixed timeline. The timing shifts depend on app complexity, how many integrations are involved, and how many rounds of remediation get triggered. Teams that plan around the most optimistic estimate tend to miss their own launch dates. Building in buffer time isn’t excessive caution; it’s a reasonable response to a process that’s genuinely unpredictable.
How Girikon Can Help ISV in Security Review process
For ISVs, clearing Salesforce’s AppExchange security review is often the most critical step before launching. Girikon supports ISVs by combining technical expertise with structured preparation, ensuring that vulnerabilities are addressed early, submissions are complete, and documentation meets Salesforce’s AppExchange app submission requirements.
Why Our Salesforce Consulting Services:
Competent AppExchange security review checklist helps your business reduce review cycles, avoid costly delays, and gives teams confidence in their release readiness
Proven track record of guiding multiple ISVs through successful listings
Deep Salesforce platform knowledge that aligns with reviewer expectations
Tailored presubmission framework to cut down review cycles
Endtoend support from vulnerability assessment to documentation delivery
Conclusion
It’s very evident that passing an AppExchange security review isn’t about surviving a scan. Meeting AppExchange app submission requirements is about building an app that holds up under the same scrutiny Salesforce applies internally, before that scrutiny arrives. As a business, you must understand that the Salesforce ISV security review process brings positive results only when security is considered a design decision, not a submission-stage fix.
Hopefully, this blog has given you an understanding of how to pass the Salesforce security review successfully. Our AppExchange security review checklist will also give your business the confidence to launch without friction and the assurance that review won’t become a roadblock to growth.
/* ══════════════════════════════════════════════════════════
Scope: .gka-blog | Zero JS | Safe for WP columns
══════════════════════════════════════════════════════════ */
.gka-blog{
--accent:#1a73e8;
--accent-dk:#0f4fa8;
--accent-light:#e8f0fe;
--bg-highlight:#f3f7ff;
--line:#e4e9f2;
--tbl-border:#dde3ec;
--white:#ffffff;
--text-main:#101828;
--text-body:#3f4a5a;
--text-muted:#697586;
--pos-fg:#0a7040; --pos-bg:#e7f5ee; --pos-bd:#bfe3d1;
--mid-fg:#8a5a00; --mid-bg:#fdf4e3; --mid-bd:#f0dcb4;
--neg-fg:#b42318; --neg-bg:#fef3f2; --neg-bd:#fbd5d2;
--amber:#d97706; --amber-bg:#fffaf0; --amber-line:#fcd9a4; --amber-fg:#7c4a03;
width:100%;
box-sizing:border-box;
color:var(--text-body);
line-height:1.75;
font-size:17px;
-webkit-font-smoothing:antialiased;
}
.gka-blog *,
.gka-blog *::before,
.gka-blog *::after{box-sizing:border-box;}
/* ── Typography ───────────────────────────────────────── */
.gka-blog h2{
font-size:clamp(22px,3.2vw,30px);
line-height:1.28;
font-weight:700;
color:var(--text-main);
letter-spacing:-.015em;
margin:46px 0 16px;
scroll-margin-top:100px;
}
.gka-blog h3{
font-size:clamp(17px,2.2vw,20px);
line-height:1.4;
font-weight:700;
color:var(--text-main);
letter-spacing:-.01em;
margin:30px 0 10px;
scroll-margin-top:100px;
}
.gka-blog p{margin:0 0 18px;}
.gka-blog p:last-child{margin-bottom:0;}
.gka-blog strong{font-weight:650;color:var(--text-main);}
.gka-blog .gka-kw{color:var(--accent-dk);font-weight:650;}
.gka-blog img{max-width:100%;height:auto;border-radius:12px;}
/* ── Links ────────────────────────────────────────────── */
.gka-blog a{
color:var(--accent) !important;
font-weight:600;
text-decoration:none;
background-image:linear-gradient(currentColor,currentColor);
background-size:100% 1px;
background-repeat:no-repeat;
background-position:0 100%;
transition:color .18s ease,background-size .18s ease;
}
.gka-blog a:hover,
.gka-blog a:focus-visible{color:var(--accent-dk) !important;background-size:100% 2px;}
.gka-blog a:focus-visible{outline:2px solid var(--accent);outline-offset:3px;border-radius:3px;}
/* ── Shared SVG defaults ──────────────────────────────── */
.gka-blog svg{
width:100%;height:100%;display:block;
fill:none;stroke:currentColor;stroke-width:1.8;
stroke-linecap:round;stroke-linejoin:round;
}
/* ── Lede ─────────────────────────────────────────────── */
.gka-lede{
background:var(--bg-highlight);
border:1px solid var(--line);
border-left:4px solid var(--accent);
border-radius:0 12px 12px 0;
padding:22px 26px;
margin:0 0 24px;
}
.gka-lede p{
font-size:clamp(17px,2.1vw,19px);
line-height:1.7;
color:var(--text-main);
font-weight:400;
margin:0;
}
/* ── Table of contents ────────────────────────────────── */
.gka-toc{
background:var(--white);
border:1px solid var(--line);
border-radius:14px;
padding:20px 22px 8px;
margin:28px 0 8px;
box-shadow:0 1px 2px rgba(16,24,40,.04);
}
.gka-toc-head{
display:flex;align-items:center;gap:9px;
font-size:12px;font-weight:700;letter-spacing:.1em;text-transform:uppercase;
color:var(--text-muted);margin:0 0 14px !important;
}
.gka-toc-head svg{width:16px;height:16px;flex:0 0 16px;color:var(--accent);stroke-width:2;}
.gka-toc-list{list-style:none;counter-reset:gkatoc;margin:0;padding:0;display:grid;gap:2px;}
.gka-toc-list li{counter-increment:gkatoc;margin:0;padding:0;}
.gka-toc-list li::before{content:none;}
.gka-toc-list a{
display:flex;align-items:baseline;gap:11px;
padding:9px 10px;border-radius:8px;
font-size:15.5px;font-weight:550;
color:var(--text-body) !important;
background-image:none !important;
transition:background-color .15s ease,color .15s ease;
}
.gka-toc-list a::before{
content:counter(gkatoc,decimal-leading-zero);
flex:0 0 auto;font-size:12px;font-weight:700;
color:var(--accent);font-variant-numeric:tabular-nums;
}
.gka-toc-list a:hover{background-color:var(--accent-light);color:var(--accent-dk) !important;}
/* ── Comparison table ─────────────────────────────────── */
.gka-table-wrap{
overflow-x:auto;-webkit-overflow-scrolling:touch;
border:1px solid var(--line);
border-radius:14px;
margin:24px 0 8px;
box-shadow:0 1px 2px rgba(16,24,40,.04);
}
.gka-table{
width:100%;min-width:680px;
border-collapse:collapse;
font-size:15.5px;background:var(--white);
}
.gka-table th,
.gka-table td{
padding:14px 18px;text-align:left;vertical-align:middle;
border-bottom:1px solid var(--line);
}
.gka-table thead th{
font-size:12.5px;font-weight:700;
letter-spacing:.06em;text-transform:uppercase;
color:var(--text-muted);
background:#f8fafd;
border-bottom:2px solid var(--line);
white-space:nowrap;
}
.gka-table tbody th{
font-weight:650;color:var(--text-main);
background:var(--white);
position:sticky;left:0;z-index:1;min-width:200px;
box-shadow:1px 0 0 var(--line);
}
.gka-table thead th:first-child{position:sticky;left:0;z-index:2;box-shadow:1px 0 0 var(--line);}
.gka-table tbody tr:nth-child(even) th,
.gka-table tbody tr:nth-child(even) td{background:#fbfcfe;}
.gka-table tbody tr:last-child th,
.gka-table tbody tr:last-child td{border-bottom:none;}
.gka-pill{
display:inline-block;padding:3px 11px;border-radius:999px;
font-size:13px;font-weight:650;line-height:1.45;white-space:nowrap;
border:1px solid transparent;
}
.gka-pos{color:var(--pos-fg);background:var(--pos-bg);border-color:var(--pos-bd);}
.gka-mid{color:var(--mid-fg);background:var(--mid-bg);border-color:var(--mid-bd);}
.gka-neg{color:var(--neg-fg);background:var(--neg-bg);border-color:var(--neg-bd);}
.gka-table-hint{
font-size:13px;color:var(--text-muted);
margin:10px 0 18px !important;display:none;
}
/* ── Chip list ────────────────────────────────────────── */
.gka-chips{
list-style:none;
display:grid;grid-template-columns:repeat(auto-fit,minmax(230px,1fr));
gap:11px;margin:22px 0 24px;padding:0;
}
.gka-chips li{
display:flex;align-items:center;gap:11px;
background:var(--white);border:1px solid var(--line);
border-radius:10px;padding:13px 15px;margin:0;
font-size:15.5px;font-weight:550;color:var(--text-main);line-height:1.4;
transition:border-color .15s ease,box-shadow .15s ease,background-color .15s ease;
}
.gka-chips li::before{
content:"";flex:0 0 8px;width:8px;height:8px;border-radius:50%;
background:linear-gradient(135deg,#5ea2ff,var(--accent));
}
.gka-chips li:hover{border-color:#b9d2f7;background-color:#fbfdff;box-shadow:0 3px 12px rgba(26,115,232,.09);}
/* ── Bullet list (prose length) ───────────────────────── */
.gka-list{list-style:none;margin:22px 0 24px;padding:0;}
.gka-list li{position:relative;padding:0 0 0 32px;margin:0 0 14px;}
.gka-list li:last-child{margin-bottom:0;}
.gka-list li::before{
content:"";position:absolute;left:5px;top:.62em;
width:9px;height:9px;border-radius:2px;
background:linear-gradient(135deg,#5ea2ff,var(--accent));transform:rotate(45deg);
}
/* ── Numbered step timeline ───────────────────────────── */
.gka-steps{list-style:none;counter-reset:gkastep;margin:26px 0 8px;padding:0;}
.gka-steps > li{
counter-increment:gkastep;position:relative;
padding:0 0 26px 60px;margin:0;
}
.gka-steps > li::before{
content:counter(gkastep);
position:absolute;left:0;top:-4px;
width:38px;height:38px;border-radius:50%;
background:var(--accent-light);border:1.5px solid #c4dbfb;
color:var(--accent-dk);font-size:14.5px;font-weight:700;
display:flex;align-items:center;justify-content:center;
font-variant-numeric:tabular-nums;
}
.gka-steps > li::after{
content:"";position:absolute;left:19px;top:40px;bottom:6px;width:1.5px;
background:linear-gradient(180deg,#cfe0fb,#eef3fa);
}
.gka-steps > li:last-child{padding-bottom:0;}
.gka-steps > li:last-child::after{display:none;}
.gka-steps.gka-plain > li::after{display:none;}
.gka-steps.gka-plain > li{padding-bottom:20px;}
/* ── Capability / definition cards ────────────────────── */
.gka-cards{
display:grid;grid-template-columns:repeat(auto-fit,minmax(300px,1fr));
gap:18px;margin:26px 0 8px;
}
.gka-card{
position:relative;background:var(--white);
border:1px solid var(--line);border-radius:14px;
padding:24px;overflow:hidden;
transition:border-color .18s ease,box-shadow .18s ease,transform .18s ease;
}
.gka-card::before{
content:"";position:absolute;inset:0 0 auto 0;height:3px;
background:linear-gradient(90deg,var(--accent),#5ea2ff);
opacity:0;transition:opacity .18s ease;
}
.gka-card:hover{border-color:#b9d2f7;box-shadow:0 10px 28px rgba(16,24,40,.08);transform:translateY(-2px);}
.gka-card:hover::before{opacity:1;}
.gka-card-top{display:flex;align-items:center;gap:13px;margin-bottom:12px;}
.gka-card-icon{
flex:0 0 40px;width:40px;height:40px;border-radius:10px;
background:var(--accent-light);color:var(--accent);padding:9px;
}
.gka-card-t{
font-size:clamp(16px,2.2vw,18px);font-weight:700;
color:var(--text-main);line-height:1.35;letter-spacing:-.01em;
}
.gka-card p{font-size:16px;margin:0;}
/* ── Callouts ─────────────────────────────────────────── */
.gka-callout{
display:flex;gap:16px;align-items:flex-start;
background:var(--bg-highlight);
border:1px solid #cfe0fb;border-left:4px solid var(--accent);
border-radius:0 12px 12px 0;padding:20px 24px;margin:26px 0;
}
.gka-callout-icon{flex:0 0 26px;width:26px;height:26px;color:var(--accent);margin-top:3px;}
.gka-callout p{margin:0;font-size:16.5px;line-height:1.65;color:var(--text-main);}
.gka-tip{
display:flex;gap:16px;align-items:flex-start;
background:var(--amber-bg);
border:1px solid var(--amber-line);border-left:4px solid var(--amber);
border-radius:0 12px 12px 0;padding:20px 22px;margin:26px 0;
}
.gka-tip-icon{flex:0 0 26px;width:26px;height:26px;color:var(--amber);margin-top:3px;}
.gka-tip p{margin:0;font-size:16.5px;line-height:1.65;color:var(--amber-fg);}
.gka-emph{
font-size:clamp(17px,2.1vw,19px);font-weight:600;
color:var(--text-main);line-height:1.6;
border-left:3px solid var(--accent);padding:2px 0 2px 18px;
margin:26px 0 !important;
}
/* ── Takeaway ─────────────────────────────────────────── */
.gka-takeaway{
background:var(--bg-highlight);border:1px solid #cfe0fb;
border-radius:14px;padding:24px 26px;margin:26px 0 8px;
}
.gka-takeaway p{
font-size:clamp(16.5px,2.1vw,18px);line-height:1.7;
color:var(--text-main);font-weight:400;margin:0;
}
/* ── Slim inline CTA ──────────────────────────────────── */
.gka-cta{
display:flex;align-items:center;justify-content:space-between;
gap:18px;flex-wrap:wrap;
background:var(--bg-highlight);
border:1px solid #cfe0fb;border-left:4px solid var(--accent);
border-radius:0 10px 10px 0;
padding:14px 20px;margin:32px 0;
}
.gka-cta p{flex:1 1 300px;margin:0;font-size:15.5px;line-height:1.55;color:var(--text-main);}
.gka-blog .gka-btn{
flex:0 0 auto;
display:inline-flex;align-items:center;justify-content:center;
padding:10px 20px;border-radius:8px;
font-size:14.5px;font-weight:650;line-height:1.2;text-align:center;
background-color:var(--accent);color:#fff !important;
background-image:none;border:1.5px solid transparent;white-space:nowrap;
box-shadow:0 3px 10px rgba(26,115,232,.28);
transition:transform .16s ease,box-shadow .16s ease,background-color .16s ease;
}
/* must out-specify `.blog a:hover` (0,2,1) or the label repaints blue-on-blue */
.gka-blog .gka-btn:hover,
.gka-blog .gka-btn:focus,
.gka-blog .gka-btn:focus-visible,
.gka-blog .gka-btn:active,
.gka-blog .gka-btn:visited{
color:#fff !important;
background-image:none !important;
background-size:0 0 !important;
}
.gka-blog .gka-btn:hover,
.gka-blog .gka-btn:focus-visible{
transform:translateY(-1px);
background-color:#1668d6;
box-shadow:0 6px 16px rgba(26,115,232,.38);
}
.gka-blog .gka-btn:focus-visible{
outline:2px solid var(--accent-dk);
outline-offset:3px;
}
/* ══════════════ RESPONSIVE ══════════════ */
@media (min-width:640px){
.gka-toc-list{grid-template-columns:1fr 1fr;column-gap:14px;}
}
@media (max-width:680px){
.gka-blog{font-size:16px;line-height:1.72;}
.gka-lede{padding:18px 20px;}
.gka-callout,.gka-tip{padding:18px 18px;gap:13px;}
.gka-takeaway{padding:20px;}
.gka-card{padding:20px;}
.gka-card-top{align-items:flex-start;}
.gka-cta{padding:18px;gap:14px;}
.gka-blog .gka-btn{width:100%;}
.gka-steps > li{padding-left:50px;}
.gka-steps > li::before{width:34px;height:34px;font-size:13.5px;}
.gka-steps > li::after{left:17px;top:36px;}
.gka-table th,.gka-table td{padding:12px 14px;}
.gka-table tbody th{min-width:160px;}
.gka-table-hint{display:block;}
}
@media (max-width:400px){
.gka-chips,.gka-cards{grid-template-columns:1fr;}
}
/* Motion / print safety */
@media (prefers-reduced-motion:reduce){
.gka-blog *{transition:none !important;}
.gka-blog .gka-btn:hover,.gka-card:hover{transform:none;}
}
@media print{
.gka-cta{display:none !important;}
.gka-blog{font-size:11pt;}
.gka-card,.gka-table tr,.gka-steps > li{break-inside:avoid;}
.gka-table-wrap{overflow:visible;}
.gka-table{min-width:0;}
}
The Salesforce security audit checklist ensures two things: one, your customer data and business critical information stays protected. Second, it prepares you against any slips in security or compliance risks, fortifying your security posture. Salesforce may secure the infrastructure underneath your org. The responsibility for access rules, configurations, and data visibility rests with your team. Every control that defines who can view or act on data must be reviewed and governed internally.
So, it makes sense to conduct a Salesforce security review before renewal. It’s the one point in the year when you’re closely monitoring the account. Also, Salesforce keeps bringing new updates or features that can introduce changes in your security settings or how it affects data exposure, and it’s hard to notice at first. Therefore, a follow-up Salesforce profile security check can catch any gaps and fill them before any risks or harm occurs to your company’s data. In this blog, we’ll help you prepare a solid Salesforce access review checklist.
Why Conduct a Salesforce Security Review Before Renewal?
Renewal offers a checkpoint to assess not just one but review the security and integrity of your entire infrastructure. Budgets get scrutinized, licenses get recounted, and how securely the data moves and get stored, is also evaluated. Here’s what that review tends to turn up
Fewer opportunities for data to be misused or breached
Unused licenses that have been quietly adding to costs
Well-defined audit trails for any compliance review
Old misconfigurations caught before carrying into another license year
Documented metrics to track future review outcomes
Salesforce Security Audit Checklist: 12 Steps for Renewal Readiness
The 12 checks at a glance
Phase 1 · Identity & Governance
Salesforce Profile Security Review
Conduct a Salesforce Permission Set Audit
Deactivate Dormant Users and Cleanse Licenses
Phase 2 · Data Visibility
Review Organization-Wide Defaults (OWDs)
Inspect Role Hierarchies and Sharing Rules
Audit Field-Level Security (FLS)
Phase 3 · Authentication
Use Multi‑Step Login Security
Review Network Settings and IP Restrictions
Initiate Salesforce’s Native Health Tool
Phase 4 · External Access
Audit Connected Apps and API Access
Inspect Public Sites and Communities
Validate Backup and Recovery Protocols
01
Phase 1: Identity and Governance Management
1: Salesforce Profile Security Review
Many organizations continue to depend on legacy, broad profiles that give excessive privileges beyond the roles may need. Start with reviewing each profile to ensure it provides only the necessary access for the role and remove extra permissions. Where possible, shift role‑specific access decisions from profiles to permission only. It enforces essential‑only permissions, refines ongoing changes, and overall governance.
2: Conduct a Salesforce Permission Set Audit
The review takes time, but it prevents uncontrolled privileges. Without it, organizations often end up with multiple users holding admin rights that have no clear business reason. Document each permission set, confirm the need, and remove anything unnecessary, keeping access accountable and reducing hidden risks.
3: Deactivate Dormant Users and Cleanse Licenses
Login history reports will show which accounts are no longer in use. These accounts represent both security exposure and an unnecessary licensing cost. They should be frozen or deactivated, and the resulting license count should be reconciled against the employees actually working within the system.
02
Phase 2: Data Visibility and Sharing Rules
4: Review Organization-Wide Defaults (OWDs)
Organization-wide defaults ensure record visibility across the org. Get this wrong and every other control you put in place afterward is working against a poor foundation. Set these to the most restrictive level your business can reasonably operate with. ‘Private’ wherever sensitivity demands it, and ‘Public Read/Write’ only where there’s a clear reason for it.
5: Inspect Role Hierarchies and Sharing Rules
Role hierarchies and sharing rules exist specifically to extend access beyond those defaults, which is precisely why periodic review matters. An outdated rule can, over time, give visibility to agents with no legitimate reason to hold it. Each rule should be examined carefully to confirm if the access it provides still matches the current requirements. If not, then the access is no longer justified, remove or revise the rule to restore essential‑only permissions.
6: Audit Field-Level Security (FLS)
Object-level access alone doesn’t help you get complete control. Field-level security governs whether particular fields: Social Security numbers, compensation figures, banking information, remain visible to a given role. independent of broader object permissions. These fields should be restricted to the roles that require them, rather than left visible by default convention.
Halfway through — and this is where most orgs find their first surprise.
Over-permissioned profiles and stale sharing rules are the two findings we hit most often. Have a certified architect pressure-test yours with a Salesforce security review before the renewal paperwork lands.
Get my org reviewed
03
Phase 3: Authentication and Platform Controls
7: Use Multi‑Step Login Security
It’s a basic requirement, though a policy on paper does not guarantee enforcement in practice. Every login should be confirmed to pass through two‑step verification without exception. Any legacy authentication path that might bypass it should be identified and closed to maintain consistent protection across all user accounts.
8: Review Network Settings and IP Restrictions
Define trusted IP ranges for login access and session settings that determine where access to the org is even possible. Logins should be restricted to trusted company networks or an approved VPN. Session timeout settings also needed particular attention, since an unattended device left logged in is a more common point of entry than many organizations assume.
9: Initiate Salesforce’s Native Health Tool
Salesforce provides an integrated Health Check function that scores your org against a recognized baseline and flags the weak points automatically. It’s worth running as a final pass, since it reveals what a manual review may miss. It’s also a quick way to confirm your meeting security best practices across the board.
04
Phase 4: Integrations and External Access
10: Audit Connected Apps and API Access
APIs can stay in the apps or platforms way beyond the purpose they were ingested in the first place. Go through every connected app that has API access to your org and pull OAuth tokens for anything abandoned, deprecated, or no longer serving an actual business need.
11: Inspect Public Sites and Communities
For organizations running Experience Cloud sites, guest user access requires close examination. It should be confirmed that guest profiles cannot reach internal objects or records under any circumstances. It’s an often-overlooked exposure but quite simpler to correct once identified. Remove unnecessary permissions and restrict guest access to only what is explicitly intended for public use.
12: Validate Backup and Recovery Protocols
Confirm that automated backups covering both data and metadata are running and completing successfully, particularly ahead of any major system update. Only tested recovery plans provide assurance of risk control. Therefore, regularly perform restoration checks to verify that backups work as expected and are reliable during an actual incident.
Key Takeaways from Salesforce Security Audit Checklist
The Salesforce security audit checklist helps businesses close the most common security, permissions, and compliance gaps before renewal and add resilience across both data and metadata. However, for a successful Salesforce security review before renewal, embed these checks into a recurring schedule, not a one‑time exercise. Hopefully this blog has given you a Salesforce access review checklist, letting you deliver compliance, transparency, and gain long‑term protection against unexpected exposures.
If the entire process seems complex, you can seek support from a Salesforce Security services provider, as their experts would manage the entire Salesforce profile security check process while you focus on critical business operations.
Salesforce Security Services
Walk into your renewal knowing exactly what your org exposes.
Girikon is a certified Salesforce consulting partner. Our security team runs all 12 checks against your org, scores the findings by risk, and gives you a remediation plan your admins can action — plus the audit trail your compliance reviewer will ask for.
Profile, permission set & license cleanup
OWD, role hierarchy & FLS review
MFA, IP range & Health Check remediation
Connected app, guest user & backup validation
Book a free security review
Explore Salesforce security services
Renewal date approaching? Call +1‑480‑241‑8198 (USA)
/* ══════════════════════════════════════════════════════════
Salesforce Security Audit Checklist — blog styles
Scope: .gks-blog | Zero JS | Safe for WP columns
══════════════════════════════════════════════════════════ */
.gks-blog{
--accent:#1a73e8;
--accent-dk:#0f4fa8;
--accent-light:#e8f0fe;
--navy:#0d1f38;
--navy-2:#122b4d;
--bg-highlight:#f3f7ff;
--line:#e4e9f2;
--white:#ffffff;
--text-main:#101828;
--text-body:#3f4a5a;
--text-muted:#697586;
--teal:#0d8f7a;
--teal-light:#e3f6f2;
width:100%;
box-sizing:border-box;
font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Helvetica Neue",Arial,sans-serif;
color:var(--text-body);
line-height:1.75;
font-size:17px;
-webkit-font-smoothing:antialiased;
}
.gks-blog *,
.gks-blog *::before,
.gks-blog *::after{box-sizing:border-box;}
/* ── Typography ───────────────────────────────────────── */
.gks-blog h2{
font-size:clamp(22px,3.2vw,30px);
line-height:1.28;
font-weight:700;
color:var(--text-main);
letter-spacing:-.015em;
margin:46px 0 16px;
scroll-margin-top:100px;
}
.gks-blog h3{
font-size:clamp(18px,2.4vw,22px);
line-height:1.35;
font-weight:700;
color:var(--text-main);
letter-spacing:-.012em;
margin:0;
scroll-margin-top:100px;
}
.gks-blog h4{
font-size:clamp(16.5px,2.1vw,19px);
line-height:1.4;
font-weight:700;
color:var(--text-main);
letter-spacing:-.008em;
margin:0 0 9px;
scroll-margin-top:100px;
}
.gks-blog p{margin:0 0 18px;}
.gks-blog p:last-child{margin-bottom:0;}
.gks-blog strong{font-weight:650;color:var(--text-main);}
.gks-blog img{max-width:100%;height:auto;border-radius:12px;}
/* ── Links ────────────────────────────────────────────── */
.gks-blog a{
color:var(--accent);
font-weight:600;
text-decoration:none;
background-image:linear-gradient(currentColor,currentColor);
background-size:100% 1px;
background-repeat:no-repeat;
background-position:0 100%;
transition:color .18s ease,background-size .18s ease;
}
.gks-blog a:hover,
.gks-blog a:focus-visible{color:var(--accent-dk);background-size:100% 2px;}
.gks-blog a:focus-visible{outline:2px solid var(--accent);outline-offset:3px;border-radius:3px;}
/* ── Shared SVG defaults ──────────────────────────────── */
.gks-blog svg{
width:100%;height:100%;display:block;
fill:none;stroke:currentColor;stroke-width:2;
stroke-linecap:round;stroke-linejoin:round;
}
/* ── Lede ─────────────────────────────────────────────── */
.gks-lede{
background:var(--bg-highlight);
border:1px solid var(--line);
border-left:4px solid var(--accent);
border-radius:0 12px 12px 0;
padding:22px 26px;
margin:0 0 24px;
}
.gks-lede p{
font-size:clamp(17px,2.1vw,19px);
line-height:1.7;
color:var(--text-main);
font-weight:400;
}
/* ── Buttons ──────────────────────────────────────────── */
.gks-blog .gks-btn{
display:inline-flex;align-items:center;justify-content:center;gap:8px;
padding:12px 22px;border-radius:8px;
font-size:15px;font-weight:650;line-height:1.2;text-align:center;
background-image:none;border:1.5px solid transparent;
transition:transform .16s ease,box-shadow .16s ease,background-color .16s ease,color .16s ease,border-color .16s ease;
}
.gks-blog .gks-btn:hover{transform:translateY(-1px);background-size:0 0;}
.gks-blog .gks-btn-solid{
background-color:var(--accent);color:#fff !important;
box-shadow:0 4px 14px rgba(26,115,232,.32);width:100%;
}
.gks-blog .gks-btn-solid:hover{background-color:#1668d6;box-shadow:0 7px 20px rgba(26,115,232,.42);}
.gks-blog .gks-btn-light{
background-color:#fff;color:var(--navy) !important;
box-shadow:0 4px 14px rgba(0,0,0,.18);
}
.gks-blog .gks-btn-light:hover{background-color:#eef4ff;}
.gks-blog .gks-btn-ghost{
background-color:transparent;color:#dbe7f7 !important;
border-color:rgba(255,255,255,.32);
}
.gks-blog .gks-btn-ghost:hover{border-color:#fff;color:#fff !important;background-color:rgba(255,255,255,.08);}
/* ── Outcome list ─────────────────────────────────────── */
.gks-outcomes{
list-style:none;margin:22px 0 8px;padding:0;
display:grid;grid-template-columns:repeat(auto-fit,minmax(280px,1fr));gap:11px;
}
.gks-outcomes li{
position:relative;margin:0;
padding:14px 16px 14px 46px;
background:var(--white);
border:1px solid var(--line);
border-radius:11px;
font-size:15.5px;line-height:1.5;
color:var(--text-main);
transition:border-color .15s ease,box-shadow .15s ease;
}
.gks-outcomes li::before{
content:"";position:absolute;left:15px;top:19px;
width:13px;height:7px;
border-left:2.4px solid var(--teal);
border-bottom:2.4px solid var(--teal);
transform:rotate(-45deg);
}
.gks-outcomes li:hover{border-color:#b7e3da;box-shadow:0 3px 12px rgba(13,143,122,.10);}
/* ── At a glance ──────────────────────────────────────── */
.gks-glance{
background:var(--white);
border:1px solid var(--line);
border-radius:14px;
padding:22px 24px 18px;
margin:24px 0 34px;
box-shadow:0 1px 2px rgba(16,24,40,.04);
}
.gks-glance-head{
display:flex;align-items:center;gap:9px;
font-size:12px;font-weight:700;letter-spacing:.1em;text-transform:uppercase;
color:var(--text-muted);margin:0 0 18px !important;
}
.gks-glance-head svg{width:17px;height:17px;flex:0 0 17px;color:var(--accent);stroke-width:1.9;}
.gks-glance-grid{
display:grid;grid-template-columns:repeat(auto-fit,minmax(220px,1fr));
gap:20px 26px;
}
.gks-glance-phase{
font-size:11.5px;font-weight:700;letter-spacing:.05em;text-transform:uppercase;
color:var(--accent);margin:0 0 9px !important;
padding-bottom:8px;border-bottom:1px solid var(--line);
}
.gks-glance-list{margin:0;padding:0 0 0 22px;}
.gks-glance-list li{
margin:0 0 7px;padding:0;
font-size:14.5px;line-height:1.45;
color:var(--text-muted);
}
.gks-glance-list li::marker{font-weight:700;color:var(--accent);font-size:12.5px;}
.gks-glance-list a{
color:var(--text-body) !important;font-weight:550;
background-image:none !important;
transition:color .15s ease;
}
.gks-glance-list a:hover{color:var(--accent) !important;}
/* ── Phase band ───────────────────────────────────────── */
.gks-phase{
display:flex;align-items:center;gap:15px;
background:linear-gradient(95deg,var(--accent-light) 0%,rgba(232,240,254,.35) 100%);
border-left:4px solid var(--accent);
border-radius:0 11px 11px 0;
padding:15px 20px;
margin:34px 0 20px;
}
.gks-phase-tag{
flex:0 0 auto;
font-size:13px;font-weight:800;
font-variant-numeric:tabular-nums;
letter-spacing:.02em;
color:#fff;background:var(--accent);
border-radius:7px;padding:5px 10px;
box-shadow:0 2px 8px rgba(26,115,232,.28);
}
/* ── Check cards ──────────────────────────────────────── */
.gks-checks{display:grid;gap:14px;margin:0 0 8px;}
.gks-check{
display:flex;gap:16px;align-items:flex-start;
background:var(--white);
border:1px solid var(--line);
border-radius:13px;
padding:20px 22px;
transition:border-color .18s ease,box-shadow .18s ease,transform .18s ease;
}
.gks-check:hover{
border-color:#b9d2f7;
box-shadow:0 8px 24px rgba(16,24,40,.07);
transform:translateY(-1px);
}
.gks-check-box{
flex:0 0 30px;width:30px;height:30px;
margin-top:3px;padding:6px;
border-radius:8px;
background:var(--teal-light);
border:1.5px solid #b7e3da;
color:var(--teal);
}
.gks-check-body{min-width:0;}
.gks-check-body p{font-size:16px;margin:0;}
.gks-num{
color:var(--accent);
font-variant-numeric:tabular-nums;
margin-right:2px;
}
/* ── Inline mid-article CTA ───────────────────────────── */
.gks-cta-inline{
display:flex;align-items:center;gap:22px;flex-wrap:wrap;
background:var(--bg-highlight);
border:1px solid #cfe0fb;
border-radius:14px;
padding:24px 26px;
margin:34px 0;
}
.gks-cta-inline-text{flex:1 1 340px;min-width:0;}
.gks-cta-inline-title{
font-size:18px;font-weight:700;color:var(--text-main);
line-height:1.4;margin:0 0 6px;
}
.gks-cta-inline-sub{font-size:15px;line-height:1.6;color:var(--text-body);margin:0;}
.gks-cta-inline .gks-btn-solid{width:auto;flex:0 0 auto;}
/* ── Takeaway ─────────────────────────────────────────── */
.gks-takeaway{
background:var(--bg-highlight);
border:1px solid #cfe0fb;
border-radius:14px;
padding:24px 26px;
margin:0 0 20px;
}
.gks-takeaway p{
font-size:clamp(16.5px,2.1vw,18px);
line-height:1.7;color:var(--text-main);
font-weight:400;margin:0;
}
/* ── Final conversion block ───────────────────────────── */
.gks-cta-final{
position:relative;
background:linear-gradient(155deg,var(--navy) 0%,var(--navy-2) 55%,#173861 100%);
border-radius:16px;
padding:clamp(28px,4vw,44px);
margin:34px 0 0;
overflow:hidden;
color:#b9c9dc;
}
.gks-cta-final::before{
content:"";position:absolute;top:-90px;right:-70px;
width:280px;height:280px;border-radius:50%;
background:radial-gradient(circle,rgba(26,115,232,.34) 0%,rgba(26,115,232,0) 70%);
pointer-events:none;
}
.gks-cta-eyebrow{
position:relative;display:inline-block;
font-size:11px;font-weight:700;letter-spacing:.1em;text-transform:uppercase;
color:#7fb2ff;border:1px solid rgba(127,178,255,.32);
border-radius:99px;padding:5px 12px;margin-bottom:16px;
}
.gks-cta-final-title{
position:relative;
font-size:clamp(21px,3vw,27px);line-height:1.32;font-weight:700;
color:#fff;letter-spacing:-.015em;margin:0 0 12px;
}
.gks-cta-final-copy{
position:relative;font-size:16px;line-height:1.7;
margin:0 0 20px;max-width:62ch;
}
.gks-cta-points{
position:relative;list-style:none;
display:grid;grid-template-columns:repeat(auto-fit,minmax(240px,1fr));
gap:10px 20px;margin:0 0 26px;padding:0;
}
.gks-cta-points li{
position:relative;margin:0;padding-left:26px;
font-size:15px;font-weight:550;color:#dbe7f7;line-height:1.5;
}
.gks-cta-points li::before{
content:"";position:absolute;left:2px;top:7px;
width:11px;height:6px;
border-left:2px solid #5ea2ff;border-bottom:2px solid #5ea2ff;
transform:rotate(-45deg);
}
.gks-cta-actions{position:relative;display:flex;flex-wrap:wrap;gap:12px;}
.gks-cta-tel{position:relative;font-size:14px;margin:18px 0 0;color:#8fa6c0;}
.gks-cta-tel a{color:#9cc4f5 !important;font-weight:700;background-image:none !important;}
.gks-cta-tel a:hover{color:#fff !important;}
/* ══════════════ RESPONSIVE ══════════════ */
@media (max-width:680px){
.gks-blog{font-size:16px;line-height:1.72;}
.gks-lede{padding:18px 20px;}
.gks-glance{padding:20px;}
.gks-glance-grid{gap:18px;}
.gks-phase{padding:13px 16px;gap:12px;margin:28px 0 16px;}
.gks-check{padding:18px;gap:13px;}
.gks-check-box{flex:0 0 26px;width:26px;height:26px;padding:5px;}
.gks-cta-inline{padding:20px;gap:16px;}
.gks-cta-inline .gks-btn-solid{width:100%;}
.gks-cta-actions .gks-btn{width:100%;}
}
@media (max-width:400px){
.gks-outcomes,
.gks-cta-points{grid-template-columns:1fr;}
}
/* Motion / print safety */
@media (prefers-reduced-motion:reduce){
.gks-blog *{transition:none !important;}
.gks-blog .gks-btn:hover,
.gks-check:hover{transform:none;}
}
@media print{
.gks-cta-inline,
.gks-cta-final{display:none !important;}
.gks-blog{font-size:11pt;}
.gks-check{break-inside:avoid;}
}
Enterprise AI has moved from being in the experiment stage to production at scale. Inside most Salesforce orgs, it’s already running support queues, scoring leads, and shaping decisions that impact revenue directly. But many businesses weren’t ready for it, which is why the ROI formula they’ve used for decades is starting to prove insufficient to decode what AI actually does.
Earlier return on investment models followed the simple logic: spend the money, get the return, close the file. AI value builds gradually through efficiency, expanded capacity, and stronger data foundations. That’s why ROAI is becoming the most accurate measure for Salesforce teams.
But businesses must understand what ROAI is to fully replace traditional return on investment in Salesforce projects. In this blog, we’ll explore 5 Salesforce Agentforce impact tracking metrics that show how to track impact more effectively. We’ll also talk about how to build a strategy to help you transit from traditional AI investment metrics enterprise to return on AI investment Salesforce.
Why Enterprises are Rethinking AI Investment Impact in Salesforce
Businesses assume stability once they have invested in the AI project. But it doesn’t work well with AI because it keeps evolving. When teams apply legacy formulas, they face issues like:
⚠
Fixed-input thinking breaks down fast — AI systems keep improving without any extra spending behind them.
⚠
Watching single transactions in isolation misses how one gain tends to spread quietly into other workflows.
⚠
Capacity gains from handling more work without new headcount are rarely included in ROI.
⚠
Data quality improvements from AI rollouts don’t appear in financial reporting, even though they create measurable returns.
What is ROAI?
ROAI offers a wider lens for evaluating what Salesforce AI projects actually produce. It calculates token consumption and model usage costs alongside efficiency, scalability, and data quality improvements. Thus, providing a more precise view than traditional ROI for Agentforce and enterprise AI investments.
ROAI Formula
ROAI = Economic Return / (Cost of Human Intelligence + Cost of Tokens)
ROAI vs ROI AI Projects: What is the Difference?
If traditional ROI focuses on knowing whether a project paid for itself, then ROAI asks something more useful — what can the business do now that it couldn’t manage before? That question only gets more important as agentic tools take on a bigger role. Salesforce Agentforce ROI metrics, for instance, need to reflect the independent judgment calls an agent makes on its own, not just how many tickets got closed by end of day.
Factor
Traditional ROI
ROAI
Core Metric Basis
Net financial gain versus investment cost
Business value from AI adoption across efficiency, revenue, and data quality
Formula Basis
ROI = (Gain – Cost) / Cost
No fixed formula — mixes cost savings, productivity, new revenue, and risk reduction
Focus Area
Purely financial outcomes: profits, margins, payback
Broader enterprise outcomes: automation, decision speed, customer experience
Time Horizon
Short-to-medium term, tied to a project’s lifecycle
Medium-to-long term, tracking AI maturity and scaling impact
How it Measures
Straightforward, drawn from accounting data
More complex, requiring tracking of intangible benefits like agility and competitive edge
Common Salesforce Agentforce ROI Metrics
Case Resolution Speed
Track the reduction in average time taken to close customer cases.
Agent Productivity
Calculates the boost in cases handled per agent without adding staff.
Customer Satisfaction
Focuses on any improvement in CSAT or NPS scores tied to faster resolutions.
Cost Efficiency
Measures savings from reduced escalations and lower support expenses.
Scalability
Assesses the ability to manage higher case volumes during peak demand without disruption.
5 Steps to Begin Transitioning to an ROAI Framework
Step 01
Audit What You’re Already Tracking
Review every metric tied to current technology projects and separate those that only measure speed or efficiency. This exposes gaps in reporting and sets the stage for a broader framework that captures value beyond operational quick wins.
Step 02
Map Capability Gains Directly
Document where teams manage greater demands or more complex tasks without adding staff. These gains often go unnoticed, but they show expanded organizational capacity. Capturing them provides a clearer view of how investments reshape what the business can realistically handle.
Step 03
Score Your Data Health Gains
Check and improve the quality of data, including the introduction of a more restrictive approach to data quality improvement — through better records and fields and proper use of data and information governance. By applying these changes you can enhance reporting accuracy, ensure compliance, and boost system performance. Unlike tool-specific benefits, these upgrades remain valuable long after individual solutions are replaced.
Step 04
Build a Three-Tier Dashboard
You need a reporting dashboard that integrates velocity, scalability, and data foundation metrics into one structured view. With this layered approach, you can see the value of the project across different systems. Leadership gets a clearer insight into a system’s performance and can spot the gaps, if any.
Step 05
Review Performance Quarterly
Annual checkpoints miss rapid shifts in technology. Conduct structured evaluation every three months to identify compounding benefits and detect early warning signs. This method lets you make timely iterations before escalation and stay updated to ever-evolving advancement in artificial technology and its subsets.
Key Considerations Before Measuring ROAI
01
Scaling Benefits Take Time
Not every AI initiative shows scaling benefits right away, and that’s expected. Some projects exist mainly to build the data foundation that other tools will depend on later.
02
Leadership Commitment Required
Capability gains surface slower than efficiency wins. Therefore, leadership must sustain commitment, as early metrics may underreport long-term enterprise transformation.
03
Cross-Team Impact Counts
Don’t ignore cross-departmental inputs. Data architecture improvements frequently benefit teams outside the one that requested the AI tool — narrow reporting may understate the real impact.
04
Baseline Data Essential
Solid baseline data matters most of all. Without accurate pre-AI benchmarks, proving full enterprise impact becomes difficult to highlight later.
Wrapping It Up: What is ROAI
The real question behind ROAI vs ROI isn’t which formula is more precise — it’s which one to focus on initially. Because ROI tells you whether a project broke even, and ROAI tells you what the organization can now do, and how much sturdier its foundation has become.
So, to capture return on AI investment Salesforce fully, organizations need expert guidance. Partner with a Salesforce AI consulting provider — the certified Salesforce experts will help you accelerate adoption, strengthen data foundations, and enable you to realize enterprise-wide transformation.
ROI tells you whether a project broke even. ROAI tells you what the organization can now do — and how much sturdier its foundation has become. That’s the metric shift enterprise AI demands.
:root {
--accent: #1a73e8;
--accent-light: #f3f7ff;
--text: #2a2a2a;
--heading: #1a1a1a;
--border: #e5e7eb;
--card: #f8fafc;
--amber: #d97706;
--amber-light: #fffbeb;
}
/* BASE */
.blog-body {
font-size: 17px;
line-height: 1.78;
color: var(--text);
}
.blog-body p {
margin-bottom: 20px;
}
.blog-body h2 {
font-size: 28px;
line-height: 1.35;
margin: 48px 0 16px;
color: var(--heading);
}
.blog-body h3 {
font-size: 20px;
line-height: 1.4;
margin-bottom: 10px;
color: var(--heading);
}
.blog-body hr {
border: none;
border-top: 1px solid var(--border);
margin: 48px 0;
}
/* ISSUE GRID */
.issue-grid {
display: grid;
grid-template-columns: repeat(2, 1fr);
gap: 14px;
margin: 24px 0 8px;
}
.issue-card {
display: flex;
gap: 12px;
align-items: flex-start;
background: var(--amber-light);
border: 1px solid #fde68a;
border-radius: 10px;
padding: 16px 18px;
}
.issue-icon {
font-size: 18px;
color: var(--amber);
flex-shrink: 0;
margin-top: 2px;
}
.issue-card p {
margin: 0;
font-size: 15px;
line-height: 1.65;
}
/* FORMULA */
.formula-block {
background: var(--heading);
color: #fff;
border-radius: 10px;
padding: 24px 28px;
margin: 28px 0;
text-align: center;
}
.formula-label {
font-size: 11px;
font-weight: 700;
text-transform: uppercase;
letter-spacing: .1em;
color: #9ca3af;
margin-bottom: 10px;
}
.formula-text {
font-size: 20px;
font-weight: 700;
color: #fff;
line-height: 1.4;
font-family: 'Courier New', Courier, monospace;
}
/* TABLE */
.tbl-wrap {
overflow-x: auto;
margin: 24px 0 32px;
border: 1px solid var(--border);
border-radius: 8px;
}
.af-blog-table {
width: 100%;
border-collapse: collapse;
min-width: 540px;
}
.af-blog-table thead th {
background: var(--accent-light);
color: var(--accent);
padding: 14px 16px;
text-align: left;
font-size: 12px;
text-transform: uppercase;
letter-spacing: .05em;
}
.af-blog-table tbody td {
padding: 14px 16px;
border-top: 1px solid var(--border);
line-height: 1.65;
vertical-align: top;
font-size: 15px;
}
.af-blog-table tbody td:first-child {
font-weight: 700;
color: var(--heading);
white-space: nowrap;
font-size: 14px;
}
/* METRICS GRID */
.metrics-grid {
display: grid;
grid-template-columns: repeat(3, 1fr);
gap: 14px;
margin: 24px 0 8px;
}
.metric-card {
background: var(--card);
border: 1px solid var(--border);
border-radius: 10px;
padding: 18px 18px 14px;
}
.metric-head {
font-size: 14px;
font-weight: 700;
color: var(--accent);
text-transform: uppercase;
letter-spacing: .04em;
margin-bottom: 10px;
}
.metric-card p {
margin: 0;
font-size: 15px;
line-height: 1.65;
}
/* PARTNER CARDS */
.partner-card {
border: 1px solid var(--border);
border-radius: 10px;
overflow: hidden;
margin: 20px 0 24px;
}
.partner-head {
display: flex;
align-items: center;
gap: 14px;
background: var(--accent-light);
padding: 14px 20px;
}
.partner-head h3 {
margin: 0;
flex: 1;
}
.partner-num {
background: var(--accent);
color: #fff;
padding: 4px 12px;
border-radius: 6px;
font-size: 12px;
font-weight: 700;
flex-shrink: 0;
white-space: nowrap;
}
.partner-body {
padding: 20px 22px 8px;
}
.partner-body p:last-child {
margin-bottom: 12px;
}
/* TIPS GRID */
.tips-grid {
display: grid;
gap: 16px;
margin-top: 24px;
}
.tip-card {
display: flex;
gap: 18px;
background: var(--card);
border: 1px solid var(--border);
border-radius: 10px;
padding: 20px;
}
.tip-num {
min-width: 42px;
height: 42px;
background: var(--accent);
color: #fff;
border-radius: 50%;
display: flex;
align-items: center;
justify-content: center;
font-weight: 700;
font-size: 14px;
flex-shrink: 0;
}
.tip-body h3 {
margin-top: 2px;
}
.tip-body p {
margin-bottom: 0;
}
/* PULL QUOTE */
.pull {
background: var(--accent-light);
border-left: 4px solid var(--accent);
padding: 20px 24px;
border-radius: 6px;
line-height: 1.8;
font-size: 17px;
margin: 28px 0;
}
/* MOBILE */
@media (max-width: 768px) {
.blog-body h2 {
font-size: 24px;
}
.blog-body h3 {
font-size: 18px;
}
.issue-grid {
grid-template-columns: 1fr;
}
.metrics-grid {
grid-template-columns: repeat(2, 1fr);
}
.partner-head {
flex-direction: column;
align-items: flex-start;
}
.tip-card {
flex-direction: column;
align-items: flex-start;
}
.formula-text {
font-size: 16px;
}
}
@media (max-width: 480px) {
.metrics-grid {
grid-template-columns: 1fr;
}
}
Talking about Salesforce, the first few things that usually come up are CRM, AI Agents, customer journey maps, and cloud automation. It is often connected to what happens within the company — the sales team, the service team, and the workflow. Field operations rarely come to mind. But for many businesses, Salesforce is just as deeply tied to what happens outside the office as it is to what happens inside it. From technician dispatch and on-site repairs to installations and maintenance, field service has become a critical part of how customer-facing operations are managed.
That makes field service scheduling far more complex than simply assigning appointments. Every job has to align with technician skills, location, availability, and shifting service priorities throughout the day. As those variables change, Salesforce Field Service Lightning provides the foundation for intelligent scheduling, while Agentforce field service scheduling is becoming increasingly relevant by helping teams automate those decisions in real time as field conditions evolve.
What is Salesforce Field Service Scheduling?
Salesforce Field Service Scheduling is the operational system that bridges the gap between incoming service demand and the field workforce required to deliver those services. In other words, when service demand, maintenance tasks, or work orders enter into Salesforce, the scheduling process determines how that particular work is scheduled according to the calendar availability of the technicians, their skills, and geographical service territories, among other factors.
The process of field service scheduling is kinda like aligning resources, sort of, in a practical way. In other words, tasks get assigned to the right people at the right moment, and no extra inefficiency, or lag, ends up in the overall picture. Scheduling starts to matter more and more as field operations get bigger bigger in scale, to the point where it becomes this crucial, scheduling layer. And, yeah, on the other hand, picking the right Agentforce partner is essential if you want to roll out an intelligent scheduling solution that helps smooth the workflows, improves how resources are used, and keeps long term operational efficiency on track.
This is where field service AI automation in Salesforce is becoming more practical, allowing scheduling decisions to move faster as operational variables keep shifting.
How Does Dispatch Work in Salesforce Field Service?
Dispatch is the execution layer of scheduling. Once a work order is ready, the system evaluates multiple live variables before assigning it. That includes technician skill sets, territory coverage, current workload, travel distance, appointment windows, and service-level agreements.
Technician skill sets
Territory coverage
Current workload
Travel distance
Appointment windows
Service-level agreements
This is where Salesforce Field Service dispatch automation becomes critical. Instead of relying entirely on manual coordination, the platform can recommend or automate assignments based on what creates the most efficient outcome.
With Salesforce FSL Intelligent Scheduling 2026, dispatching has become dynamic such that changes in priorities, delayed technicians, or new important jobs added to the schedule can be automatically adjusted. That turns dispatching from a fixed daily plan into a live operational process that keeps moving with field conditions.
How Agentforce Dispatch Automation Optimizes Salesforce Field Service Scheduling
Optimizing field schedules does not simply involve identifying the next available technician. It depends on the system’s ability to manage the relationship between operational constraints, business preferences, and live disruptions on a day-to-day basis. This is where Agentforce field service scheduling changes the model, turning dispatch from static planning into continuous optimization. By working with an agentforce consulting partner, organizations can configure and optimize these intelligent scheduling capabilities to align with their unique operational goals, maximizing efficiency, resource utilization, and customer satisfaction.
All Available Technicians
Hard Constraints
certifications · territory · SLA windows
Qualified Technicians
Soft Constraints
drive time · workload balance · client familiarity
Best-Fit Assignment
1
Define Hard Constraints (Work Rules)
Every field job begins with non-negotiable conditions. Agentforce maps technician certifications, required skills, service territories, route limits, and live traffic conditions before placing a work order. SLA windows also shape this logic. Short SLA jobs can be prioritized for immediate assignment, while long SLA work can remain flexible. Addressing Agentforce implementation challenges, such as configuring complex business rules, integrating legacy systems, and maintaining accurate workforce data, is essential to ensure these assignments are both reliable and scalable. This is the operational base of Salesforce Field Service dispatch automation, where valid assignments are established before optimization begins.
2
Establish Soft Constraints (Work Objectives)
Once the hard rules are locked, Agentforce works toward efficiency. Grouping nearby appointments to minimize drive time, balancing workload to avoid overtimes, prioritizing technicians based on familiarity with the client or selling opportunities — these soft requirements allow the system to determine the most appropriate operational solution when more than one technician meets the qualifications.
3
Set Agent Permissions and Boundaries
For Agentforce work order automation, the agent must know both the business context and its limits. It reads asset history, active work orders, service timelines, and technician schedules to understand the full situation. Businesses then define what actions it can take, from adjusting appointments to filling gaps or escalating blocked workflows.
4
Deploy Dynamic Scheduling Logic
Not every job enters the schedule the same way. High-priority requests can be evaluated instantly and assigned into the nearest available slot to reduce service delays. Routine work can stay unscheduled until batch optimization runs, allowing the system to solve route efficiency and workload balancing across multiple technicians at once.
5
Handle Exceptions in Real Time
Field schedules change constantly. Delays, cancellations, and urgent tasks might create certain gaps and conflicts that impact the entire schedule further in the day. Agentforce continuously tracks all the changes in real-time and balances the schedule by filling open windows and reassigning work.
Live Schedule
Today, 2:40 PM
JM
J. Martinez
9:00 – 10:30
11:00 – 12:15
1:30 – 3:00
Open
RK
R. Khan
9:00 – 10:00
10:30 – 12:00 Delayed
Gap created
SP
S. Patel
9:00 – 11:00
12:00 – 1:30 Reassigned from R. Khan
Open
Agentforce detected the delay, closed the gap, and reassigned the job automatically — no dispatcher intervention.
Best Practices for Smarter Field Scheduling
Improving outcomes through Agentforce field service scheduling requires treating scheduling as an operational system rather than a task assignment layer. The most effective configurations are built on three key elements: good data, clear automation boundaries, and performance evaluations.
Start with Accurate Service Data
Technician skills, work order categories, service territories, and SLA rules need to stay current before automation can make reliable decisions.
Set Clear Decision Boundaries
The system should know where autonomous actions are allowed and where exceptions need human review. This becomes even more important when working through an Agentforce scheduling console dispatcher model.
Review Scheduling Performance Often
Travel efficiency, technician utilization, and exception trends can show whether the system is improving operations.
Keep Workflows Aligned with Field Realities
With Salesforce mobile workforce management AI, live field conditions should continuously shape scheduling decisions.
Conclusion
Field service scheduling has been about balancing time, manpower, distance, and customer expectations. Today, what matters is how balance is achieved.
With scheduling becoming dynamic, the key to success may no longer lie in scheduling the best possible day but in having a system capable of reacting to unexpected changes on the same day. For field operations, that shift could shape how service efficiency is defined ahead.
:root {
--accent: #1a73e8;
--accent-light: #e8f0fe;
--text-main: #1f1f1f;
--text-body: #2a2a2a;
--text-muted: #6b7280;
--rule: #e5e7eb;
--tbl-border: #dde3ec;
--bg-highlight: #f3f7ff;
--bg-light: #f8f9fa;
--white: #ffffff;
}
/* ── Body ── */
.blog-body {
font-size: 17px;
line-height: 1.78;
color: var(--text-body);
width: 100%;
}
.blog-body p {
margin: 0 0 20px 0;
}
.blog-body h2 {
font-size: 24px;
font-weight: 700;
color: var(--text-main);
margin: 48px 0 14px;
line-height: 1.3;
}
.blog-body strong {
font-weight: 700;
color: var(--text-main);
}
.blog-body ul,
.blog-body ol {
margin: 0 0 20px 0;
padding-left: 22px;
}
.blog-body ul li,
.blog-body ol li {
margin-bottom: 8px;
line-height: 1.72;
}
/* ── Workflow Timeline ── */
.workflow-list {
margin: 8px 0 36px;
display: flex;
flex-direction: column;
gap: 0;
}
.workflow-item {
display: flex;
gap: 20px;
align-items: flex-start;
}
.workflow-marker {
display: flex;
flex-direction: column;
align-items: center;
flex-shrink: 0;
padding-top: 2px;
}
.workflow-num {
width: 36px;
height: 36px;
border-radius: 50%;
background: var(--accent);
color: var(--white);
font-size: 15px;
font-weight: 800;
display: flex;
align-items: center;
justify-content: center;
flex-shrink: 0;
}
.workflow-line {
width: 2px;
flex: 1;
min-height: 32px;
background: var(--tbl-border);
margin: 6px 0;
}
.workflow-line-hidden {
width: 2px;
min-height: 0;
}
.workflow-content {
padding-bottom: 32px;
flex: 1;
}
.workflow-title {
font-size: 18px;
font-weight: 700;
color: var(--text-main);
margin-bottom: 10px;
padding-top: 6px;
}
.workflow-content p {
margin: 0 !important;
font-size: 16px;
line-height: 1.75;
color: var(--text-body);
}
/* ── Best Practice Grid ── */
.practice-grid {
display: grid;
grid-template-columns: repeat(2, 1fr);
gap: 16px;
margin: 20px 0 36px;
}
@media (max-width: 600px) {
.practice-grid { grid-template-columns: 1fr; }
}
.practice-card {
background: var(--white);
border: 1px solid var(--tbl-border);
border-radius: 10px;
padding: 20px 20px 22px;
}
.practice-icon {
width: 44px;
height: 44px;
display: flex;
align-items: center;
justify-content: center;
background: var(--accent-light);
border-radius: 9px;
margin-bottom: 14px;
}
.practice-icon svg {
display: block;
}
.practice-title {
font-size: 15.5px;
font-weight: 700;
color: var(--text-main);
margin-bottom: 8px;
line-height: 1.35;
}
.practice-card p {
margin: 0 !important;
font-size: 14.5px;
line-height: 1.65;
color: var(--text-muted);
}
/* ── Variable Chip Cloud ── */
.var-cloud {
display: flex;
flex-wrap: wrap;
gap: 10px;
margin: 6px 0 24px;
padding: 18px 20px;
background: var(--bg-light);
border: 1px solid var(--tbl-border);
border-radius: 10px;
}
.var-chip {
display: inline-flex;
align-items: center;
gap: 6px;
background: var(--white);
color: var(--text-main);
font-size: 14px;
font-weight: 600;
padding: 7px 14px;
border-radius: 8px;
border: 1px solid var(--tbl-border);
}
.var-chip::before {
content: "";
width: 6px;
height: 6px;
border-radius: 50%;
background: var(--accent);
flex-shrink: 0;
}
/* ── Constraint Funnel ── */
.funnel-diagram {
display: flex;
flex-direction: column;
align-items: center;
margin: 24px 0 36px;
padding: 32px 20px;
background: var(--bg-light);
border: 1px solid var(--tbl-border);
border-radius: 12px;
}
.funnel-stage {
display: flex;
flex-direction: column;
align-items: center;
width: 100%;
}
.funnel-stage-label {
font-size: 13.5px;
font-weight: 700;
color: var(--text-main);
margin-bottom: 10px;
text-align: center;
}
.funnel-shape {
height: 40px;
background: linear-gradient(135deg, #1a73e8, #4a90f0);
border-radius: 6px;
}
.funnel-shape-1 { width: 100%; max-width: 520px; }
.funnel-shape-2 { width: 100%; max-width: 340px; }
.funnel-shape-3 { width: 100%; max-width: 190px; background: linear-gradient(135deg, #1558b0, #1a73e8); }
.funnel-rule {
display: flex;
flex-direction: column;
align-items: center;
gap: 3px;
margin: 14px 0;
}
.funnel-rule::before {
content: "";
width: 2px;
height: 14px;
background: #c8dcfa;
}
.funnel-rule-tag {
font-size: 11.5px;
font-weight: 800;
text-transform: uppercase;
letter-spacing: 0.06em;
color: var(--accent);
background: var(--accent-light);
border-radius: 20px;
padding: 4px 12px;
}
.funnel-rule-desc {
font-size: 13px;
color: var(--text-muted);
text-align: center;
}
/* ── Live Dispatch Board ── */
.dispatch-board {
margin: 18px 0 4px;
border: 1px solid var(--tbl-border);
border-radius: 12px;
overflow: hidden;
background: var(--white);
box-shadow: 0 2px 10px rgba(15, 35, 64, 0.06);
}
.db-header {
display: flex;
justify-content: space-between;
align-items: center;
background: #0f2440;
padding: 12px 18px;
}
.db-header-label {
font-size: 13px;
font-weight: 700;
color: #ffffff;
letter-spacing: 0.03em;
}
.db-header-time {
font-size: 12px;
color: #93aed2;
}
.db-row {
display: flex;
align-items: center;
gap: 14px;
padding: 14px 18px;
border-bottom: 1px solid var(--tbl-border);
flex-wrap: wrap;
}
.db-row:last-of-type {
border-bottom: none;
}
.db-row--flagged {
background: #fff8f8;
}
.db-tech {
display: flex;
align-items: center;
gap: 8px;
width: 130px;
flex-shrink: 0;
}
.db-avatar {
width: 28px;
height: 28px;
border-radius: 50%;
color: #fff;
font-size: 11px;
font-weight: 800;
display: flex;
align-items: center;
justify-content: center;
flex-shrink: 0;
}
.db-tech-name {
font-size: 13.5px;
font-weight: 700;
color: var(--text-main);
}
.db-slots {
display: flex;
flex-wrap: wrap;
gap: 8px;
flex: 1;
}
.db-block {
font-size: 12px;
font-weight: 600;
padding: 7px 12px;
border-radius: 7px;
white-space: nowrap;
display: flex;
align-items: center;
gap: 6px;
}
.db-block--done {
background: #eef1f5;
color: #6b7684;
}
.db-block--active {
background: var(--accent-light);
color: var(--accent);
border: 1px solid #b8d2f8;
}
.db-block--open {
background: #fbfbfb;
color: #9aa4b2;
border: 1px dashed #d5dbe3;
}
.db-block--delayed {
background: #fdeceb;
color: #c62828;
}
.db-block--gap {
background: #fdeceb;
color: #c62828;
border: 1px dashed #f3b8b3;
}
.db-block--reassigned {
background: #e8f5e9;
color: #2e7d32;
}
.db-tag-delay,
.db-tag-new {
font-size: 10px;
font-weight: 800;
text-transform: uppercase;
letter-spacing: 0.04em;
padding: 2px 6px;
border-radius: 4px;
}
.db-tag-delay {
background: #c62828;
color: #fff;
}
.db-tag-new {
background: #2e7d32;
color: #fff;
}
.db-footer {
padding: 12px 18px;
background: var(--bg-highlight);
font-size: 13px;
color: var(--text-main);
line-height: 1.55;
}
@media (max-width: 560px) {
.db-tech { width: 100%; }
}
/* ── Pull ── */
.pull {
background: var(--bg-highlight);
border-left: 4px solid var(--accent);
padding: 16px 20px;
font-size: 16.5px;
line-height: 1.75;
border-radius: 0 6px 6px 0;
margin: 28px 0;
color: var(--text-main);
}
A moment arrives when a workflow stops being just a checklist and starts becoming more like a living system: it reacts to customer actions, business priorities, regulatory requirements, and many other factors that might not be necessarily known beforehand. If it is still working yet differently than before. This is because, as a business grows, the processes become increasingly unpredictable. What was a straightforward process on paper gradually stacks up multiple layers internally: approvals dependent on a deal value, escalations based on customer behavior, compliance checks that only surface under certain conditions, and cross-team dependencies.
That is where static automation starts showing its limits. It can execute the logic it was given, but it cannot adjust when live business conditions change. This is where Agentforce triggered agents are becoming relevant, bringing autonomous adaptability into Salesforce workflows so processes can react, reassess, and continue execution as conditions change.
What Are Agentforce Triggered Agents?
The Agentforce triggered agents are event-based AI agents within Salesforce which trigger actions based on certain business events and act depending on the environment of the event. Instead of limiting to a set of predetermined rules, they can analyze the data, reason with it, and determine the course of action that needs to be followed.
This changes the focus from automation to decision-making. Unlike static workflows, an Agentforce event-triggered agent does not stop at the trigger itself. It can assess live CRM records, pull data from connected systems
, and execute multiple actions based on what the business situation looks like at that moment. That makes it a stronger fit for workflows where outcomes depend on live context rather than fixed paths.
How Are They Different from Traditional Automation?
Traditional Salesforce automation is built around predefined logic. The path is designed in advance, and each action follows the next based on conditions already configured. This works well when the workflow stays predictable. The difference becomes clearer in the discussion around Salesforce Flow vs Agentforce agent. A flow executes the logic it was assigned. An agent can evaluate the context before deciding what should happen next.
Salesforce Flow
Executes the logic it was assigned
VS
Agentforce Agent
Evaluates the context before deciding what should happen next
This is where Salesforce agentic process automation changes the model. The automation layer is no longer limited to following instructions. It becomes capable of operational reasoning. At the center of this is the Atlas Reasoning Engine, which allows triggered agents to analyze live data, connected records, and workflow signals before taking action. That could mean escalating a case, rerouting approvals, updating dependent records, or launching a sequence of actions without manual intervention. This is what makes Agentforce triggered agents more adaptable in workflows where conditions change while the process is still active.
How Agentforce Triggered Agents Automate Workflows Without Human Intervention
Agentforce triggered agents operate less like isolated automations and more like a layered workflow system. Each layer handles a specific function, allowing the process to move from detection to execution without waiting for manual intervention. This is what makes autonomous Agentforce workflow automation fundamentally different from static rule execution.
LAYER 1
The Sensing Layer: Detecting Business Events
Every workflow begins with an event. That could be a record update, a Platform Event, a Change Data Capture (CDC) signal, or an external system input entering Salesforce. This layer acts as the entry point.
The system detects the raw event as it happens. Until this point, no decisions have been made. The workflow has only recognized that something important has changed and may require action. This is the first step of Agentforce 2DX proactive workflows, where automation starts reacting the moment operational conditions shift.
LAYER 2
The Orchestration Layer: Building Operational Context
A trigger by itself does not contain enough information for making a decision. The orchestration layer is responsible for that part. Through integration with Flow, Apex, or Data Cloud (Data 360), Salesforce collects additional context information such as related records, customer history, dependencies, accounts, and possible conditions associated with the trigger.
That information is then structured into a usable payload. At this stage, the workflow shifts from raw event detection into contextual decision-making. This layer acts as the control point between system activity and agent reasoning.
LAYER 3
The Reasoning Layer: Deciding, Acting, and Verifying
This is where the Atlas Reasoning Engine Salesforce becomes central. The agent gets the contextual payload, decomposes the workflow into smaller tasks, and determines the sequential order of actions. It can choose between Flows, Apex classes, APIs, or third-party systems depending on the specific requirement.
Once execution happens, the agent verifies the outcome. If the workflow completes, the loop closes. But if some business rules prevent proceeding further, it can redirect, escalate, or even pass the task to a human queue.
Real-World Business Use Cases
Flexibility of Agentforce makes automation of operational workflows possible when time, collaboration, and context matter directly to the results.
Intelligent Customer Service
In case a customer faces a serious problem, triggered agents can analyze the situation’s severity, look into account history, find any similarities with previous cases, set the priority of the case, and notify relevant parties. This shortens response cycles and allows service teams to focus more on resolution than internal coordination.
Sales Pipeline Management
Sales processes often fail because of the high dependency on manual follow-ups. Triggered agents can identify stalled sales deals, notify account managers, suggest further action, and create reports after customer interactions. This keeps the pipeline active and reduces delays in decision-making.
Employee Onboarding
Employee Onboarding involves multiple teams working in sequence. Triggered agents can create employee records, assign training, notify IT for access setup, schedule orientation sessions, and track completion across departments. This creates a more connected onboarding process and reduces repetitive administrative effort.
Conclusion
Business workflows are becoming harder to predict. As operations grow more connected and conditions change faster, adaptability within the workflow may start carrying more value than speed alone. They will need to interpret, adjust, and keep moving.
That shift could redefine how businesses think about operational control.
Curious what triggered agents could automate in your own Salesforce org? Talk to Girikon’s Agentforce consulting team about building event-driven workflows tailored to your business.
:root {
--accent: #1a73e8;
--accent-light: #e8f0fe;
--text-main: #1f1f1f;
--text-body: #2a2a2a;
--text-muted: #6b7280;
--rule: #e5e7eb;
--tbl-border: #dde3ec;
--bg-highlight: #f3f7ff;
--bg-light: #f8f9fa;
--white: #ffffff;
}
/* ── Body ── */
.blog-body {
font-size: 17px;
line-height: 1.78;
color: var(--text-body);
width: 100%;
}
.blog-body p {
margin: 0 0 20px 0;
}
.blog-body h2 {
font-size: 24px;
font-weight: 700;
color: var(--text-main);
margin: 48px 0 14px;
line-height: 1.3;
}
.blog-body strong {
font-weight: 700;
color: var(--text-main);
}
.blog-body ul,
.blog-body ol {
margin: 0 0 20px 0;
padding-left: 22px;
}
.blog-body ul li,
.blog-body ol li {
margin-bottom: 8px;
line-height: 1.72;
}
/* ── VS Contrast ── */
.vs-grid {
display: grid;
grid-template-columns: 1fr auto 1fr;
align-items: stretch;
gap: 14px;
margin: 24px 0 28px;
}
@media (max-width: 580px) {
.vs-grid {
grid-template-columns: 1fr;
}
.vs-badge {
margin: 0 auto;
}
}
.vs-card {
border-radius: 10px;
padding: 20px 22px;
text-align: center;
}
.vs-card.vs-flow {
background: var(--bg-light);
border: 1px solid var(--rule);
}
.vs-card.vs-agent {
background: var(--bg-highlight);
border: 1px solid #c8dcfa;
}
.vs-label {
font-size: 13px;
font-weight: 800;
text-transform: uppercase;
letter-spacing: 0.07em;
margin-bottom: 8px;
}
.vs-flow .vs-label { color: var(--text-muted); }
.vs-agent .vs-label { color: var(--accent); }
.vs-card p {
margin: 0 !important;
font-size: 15.5px;
line-height: 1.6;
color: var(--text-body);
}
.vs-badge {
width: 44px;
height: 44px;
border-radius: 50%;
background: var(--accent);
color: var(--white);
font-size: 14px;
font-weight: 800;
display: flex;
align-items: center;
justify-content: center;
align-self: center;
flex-shrink: 0;
}
/* ── Layer Stack ── */
.layer-stack {
margin: 8px 0 36px;
display: flex;
flex-direction: column;
align-items: stretch;
}
.layer-card {
border: 1px solid var(--tbl-border);
border-radius: 10px;
overflow: hidden;
background: var(--white);
}
.layer-header {
display: flex;
align-items: center;
gap: 14px;
background: var(--bg-highlight);
padding: 15px 22px;
border-bottom: 1px solid var(--tbl-border);
}
.layer-badge {
font-size: 11px;
font-weight: 800;
letter-spacing: 0.08em;
color: var(--white);
background: var(--accent);
border-radius: 4px;
padding: 4px 9px;
flex-shrink: 0;
white-space: nowrap;
}
.layer-title {
font-size: 17px;
font-weight: 700;
color: var(--text-main);
line-height: 1.3;
flex: 1;
}
.layer-icon {
width: 40px;
height: 40px;
display: flex;
align-items: center;
justify-content: center;
background: var(--accent-light);
border-radius: 8px;
flex-shrink: 0;
}
.layer-icon svg {
display: block;
}
@media (max-width: 520px) {
.layer-icon { display: none; }
}
.layer-body {
padding: 18px 22px 6px;
}
.layer-body p {
margin-bottom: 14px;
}
.layer-arrow {
display: flex;
justify-content: center;
padding: 8px 0;
}
/* ── Use Case Cards ── */
.usecase-card {
display: flex;
gap: 18px;
align-items: flex-start;
border: 1px solid var(--tbl-border);
border-left: 4px solid var(--accent);
border-radius: 0 10px 10px 0;
padding: 20px 22px;
margin: 0 0 16px;
background: var(--white);
}
.usecase-icon {
width: 48px;
height: 48px;
display: flex;
align-items: center;
justify-content: center;
background: var(--accent-light);
border-radius: 10px;
flex-shrink: 0;
}
.usecase-icon svg {
display: block;
}
.usecase-content {
flex: 1;
}
.usecase-title {
font-size: 17px;
font-weight: 700;
color: var(--text-main);
margin-bottom: 8px;
}
.usecase-content p {
margin: 0 !important;
font-size: 16px;
line-height: 1.75;
color: var(--text-body);
}
@media (max-width: 520px) {
.usecase-card { flex-direction: column; gap: 12px; }
}
/* ── Pull ── */
.pull {
background: var(--bg-highlight);
border-left: 4px solid var(--accent);
padding: 16px 20px;
font-size: 16.5px;
line-height: 1.75;
border-radius: 0 6px 6px 0;
margin: 28px 0;
color: var(--text-main);
}