Article

Agentforce readiness: a data, security and governance checklist

What to check in your Salesforce org before you build an AI agent: data quality, permissions, knowledge, automation conflicts, evaluation and ownership.

Your Salesforce org is ready for Agentforce when the agent will have clean data to work from, permissions that limit what it can see and do, trusted knowledge to ground its answers, no conflicting automation to trip over, a way to evaluate its output, and a named owner. Most orgs need some preparation on at least two of those. This checklist covers what to review before you build.

1. Data quality

  • Duplicate rate on accounts, contacts and cases is known and falling.
  • The fields the agent will read are consistently filled and mean the same thing to everyone.
  • Stale records are archived or clearly flagged.
  • Data the agent needs from other systems is either integrated or deliberately out of scope.

2. Permissions and security

  • The agent’s access follows least privilege: only the objects, fields and actions its use case needs.
  • Sharing rules are understood; an agent will expose any record its permissions allow.
  • Sensitive fields are identified and excluded where appropriate.
  • Actions that change records or contact customers require a human step until results are proven.

3. Knowledge and grounding

Service agents are only as good as the knowledge behind them. For a biotech company, an AI agent grounded in 19 well-maintained knowledge articles produced send-ready draft responses for 30% of question-type cases. Before building, check that articles are current, have owners, and cover the questions customers actually ask.

4. Automation conflicts

Old workflow rules, Process Builder and overlapping Flows can fire when an agent updates a record, producing results nobody intended. Inventory the automation on every object the agent will touch and consolidate it first.

5. Evaluation

  • A set of real historical cases or requests to test the agent against.
  • Clear criteria for a good answer or action, agreed by the business.
  • A way to review a sample of live agent output every week at first.
  • A threshold for widening the agent’s scope, and one for pulling it back.

6. Ownership and governance

  • A business owner accountable for what the agent does.
  • A technical owner for its configuration, topics and actions.
  • A change process for prompts, actions and knowledge.
  • A plan to tell customers or employees when they are interacting with AI, where required.

Start small

The best first use case has high volume, clear answers and low risk: drafting responses for common service questions, summarizing records, or triaging inbound leads. For a business lender triaging 24,000 leads a month, the right first step was a lead-prioritization framework and a Data Cloud architecture, not a fully autonomous agent.

Chris Gooding, Founder & President of Abstrakt Solutions
Founder & President, Abstrakt Solutions
LinkedIn →
Call (314) 916-4095 Book a consultation
Call (314) 916-4095 Book a call