Salesforce, Einstein and Agentforce

Research date: 4 October 2026
Edition: First Salesforce baseline report
Method: Review of Salesforce's public documentation. No signed-in business account was inspected and no controls were tested in a live account.

Summary

Salesforce distinguishes predictive features, generative assistance and agents that act. Their access depends partly on the identity and permissions used to run them.

  • By default: Customer-data access for global predictive training, improvement and research is documented as allowed unless an exclusion or opt-out applies. The report does not establish that all agents are enabled by default.
  • Beyond the default: Scoring, recommendations, record summaries, generated replies, customer-service agents and lead-nurturing agents that send emails and book meetings.
  • Outside Salesforce: Activity Capture connects email and calendars. Agent actions and connected processes can operate across other systems.
  • Business exposure and learning: A service agent may run under a dedicated account rather than the customer’s permissions. Additional configuration is needed to prevent access to another customer’s records. System-context flows can have broader access. Trust Layer masking is disabled for Agentforce agents, although covered external model providers have no-retention and no-training commitments.

The main exposure: An agent’s authority can exceed the authority of the person interacting with it. That affects both disclosure and changes to customer records.

Business finding

A business can deactivate individual agents, restrict permissions, stop selected Einstein features and refuse specified uses of customer information. These are separate controls. This review did not establish one switch that stops every form of Salesforce AI processing.

Salesforce is a customer relationship management service, often shortened to CRM. Its AI can work with customer records, sales opportunities, support requests and connected communications. Agentforce can also perform actions, so the business needs to assess what it can change as well as what it can read. [1]

Salesforce's protection against training by third-party language-model providers should not be treated as a complete refusal of all training or service-improvement uses. Salesforce documents separate global-model and feature-specific uses. [2][4]

Where is AI operating?

Predictions and recommendations: Einstein includes features such as opportunity scoring, search, case classification and reply recommendations. These may influence everyday work without an employee opening an AI chat. Global predictive models identify patterns across participating customers; other models are tailored to an individual Salesforce environment. [4]

Generative assistance: Einstein and Agentforce can summarise records, generate replies and answer questions using configured business information. The available sources and actions differ by feature. [1]

Agents that act: Employee agents assist staff. Service agents interact with customers, while Lead Nurturing agents can send emails, book meetings and answer prospect questions. These agent types do not necessarily operate using the same person's permissions. [5]

Connected communications: Einstein Activity Capture connects email and calendar accounts. Review this information-access route separately from an AI assistant. [6]

Salesforce is a family of products. Record the editions, add-ons and enabled features actually used. The published Agentforce setup guidance lists Enterprise, Performance, Unlimited and Developer editions, with additional licences varying by agent type. Do not assume every small-business subscription has the same capabilities. [7]

Who controls it?

Administrators manage setup, permissions and data-sharing choices. Activating or deactivating an agent requires Manage AI Agents and the permissions required for that agent type. Changing Salesforce's customer-data sharing consent requires Opt Out of Customer Data Access. [8][3]

The business should name an owner for each deployed agent, its connected services and the business process it handles. If an implementation partner manages Salesforce, record who in the business can require a change and who can make it.

Identify the account each agent uses. A customer-facing agent can have access beyond the individual customer's records. [5]

What can the business switch off?

Individual Agentforce agents

Open Agentforce Studio → Agents, select the agent and its active version, then click Deactivate. In the legacy builder, use Setup → Agentforce Agents → select the agent → Open in Builder → Deactivate. [8]

Salesforce says deactivation interrupts ongoing conversations. Users are not notified of the deactivation and may receive a system error. An existing panel can remain visible until closed. Arrange an alternative customer-support route before relying on this as an operational stop. [8]

Platform and feature settings

Review Setup → Einstein Setup and the individual feature settings. Salesforce says Einstein is automatically on in new environments. Its Agentforce enablement article announces a planned August 2026 change to enable the platform for eligible environments and remove the Agentforce toggle. The article still contains older toggle instructions, so this report does not assume a platform-wide off switch remains available in every account. [9][7]

Check individual agents, user access and their deployments rather than treating an absent platform switch as evidence of either complete activity or complete inactivity.

Einstein Activity Capture

Use Setup → Quick Find: Einstein Activity Capture → Settings → Settings tab → General, then turn the feature off and confirm. Salesforce says some configurations, including Activity Metrics or an ongoing migration to Sync Email as Salesforce Activity, require Customer Support assistance. [6]

Disabling capture stops contact and event synchronisation. Previously captured emails and events can be hidden while remaining stored, and an email connection can remain available for Salesforce Inbox. This is not complete deletion or proof that every email access route has closed. [6]

What information and actions can the business restrict?

Information or capability Relevant business check
Customer and sales records Inspect object permissions, field access and sharing rules for the person or agent account actually running the feature. [5]
Knowledge articles and other sources Review the sources configured for each agent and the data used by its actions. [1][2]
Email and calendar connections Review Activity Capture and other connected applications separately. [6]
Record changes and other actions Inspect the action list, its permissions and approval settings. [10]
Stored AI interaction records Review Data 360 access and retention; audit records can contain sensitive information. [11]

Customer-specific access

Salesforce distinguishes employee agents running as the logged-in employee from agents running as a dedicated agent user. It expressly warns that a service agent using its own account needs additional configuration to limit access to the verified customer's records. [5]

Ask the implementation owner to demonstrate that customer A cannot retrieve or change customer B's information. Check the underlying automated processes too: Salesforce documents system-context flows with broader object and field access than ordinary user-context flows. [5]

Approval before action

Salesforce documents Require user confirmation for relevant agent actions. Its current developer example enables confirmation before escalating, commenting on or closing support cases. Review this setting for each action needing approval; do not assume it is on because the action changes a record. [10]

A request to confirm is not the same as approval by an authorised business employee. Establish whose confirmation is being requested and whether that person should be able to authorise the change.

What the Trust Layer protects

Salesforce says Trust Layer data masking is disabled for Agentforce agents. Its zero-retention commitment to external language-model providers remains, but the information sent to a model should not be assumed anonymised. [2]

This distinction matters when choosing what customer information to make available. Protection against a provider retaining data is different from preventing sensitive information from being processed in the first place.

Can the business refuse use of its information for training?

Third-party language models: Salesforce says providers used through its Trust Layer do not retain customer information or use it to train their models. Salesforce also explains that information remains in underlying Salesforce services, subject to those services' retention rules. “Zero retention” at the model provider does not mean the business has no stored AI-related records. [12]

The June 2025 privacy FAQ also says Salesforce does not currently train generative AI models on customer information and that future training would require opt-in under the applicable product terms. This differs from the predictive-model uses below. The FAQ excludes arrangements where the business supplies its own model provider; review that provider separately. [12]

Salesforce customer-data sharing: Where available, use Setup → Quick Find: Opt Out of Customer Data Access and turn consent off. Salesforce documents sharing for global predictive training, service improvement and research. Access is allowed by default unless an exclusion or previous opt-out applies; Government Cloud is excluded by default. [3]

Salesforce says no new data is shared after opt-out. Information collected for service improvement may be retained for up to 30 days before deletion. This is not a stated promise to remove previous learning from every trained model. [3]

If the control is unavailable, Salesforce documents a support case with the Activations Team using the subject Global Model opt-out request. Its guidance requires a case for each environment needing this assistance and says no business justification is required. [4]

Feature-specific learning: Salesforce says global models do not apply directly to the Agentforce platform and actions, but other AI features called by an agent can use them. Separately, its global opt-out guidance says enabled Einstein features can still use information to train models tailored to the business's own environment. [1][4]

The business therefore needs to identify the model and feature involved. Refusing contribution to shared models is different from disabling a feature that processes its records.

How can the business check that its choices worked?

The following are proposed business checks, rather than claims of testing completed for this report:

  1. Record Salesforce environments, editions, agents, active versions, owners, settings and change dates.
  2. Reopen each setting and verify the current state. Keep any support-case confirmation of an opt-out.
  3. After deactivation, test new and existing conversations through each deployed channel. Check what customers see and whether they can reach a person.
  4. Use harmless test records to check employee access and customer-specific access separately.
  5. Test record-changing actions. Verify who must approve them and that refusing approval prevents the action.
  6. After disabling capture, check for new activity, retained connections and previously stored records.
  7. Review AI audit and session records where available. Check what was collected before relying on them as evidence.

Salesforce documents Setup → Einstein Audit, Analytics, and Monitoring Setup → Audit and Feedback for relevant collection controls. Data 360 and qualifying access are required. Turning collection off retains existing records but creates a gap in the evidence available for that period. Restrict access to the records themselves because they may contain sensitive customer information. [11]

These checks can demonstrate settings and observable behaviour. They do not independently prove provider compliance, removal of previous training effects or the complete absence of background AI processing.

What does the business lose, retain or need to replace?

Deactivating an agent removes its assistance from service. Staff may need to answer enquiries, manage leads or update records themselves. Prepare that process so stopping AI does not leave customers with an error message and no working alternative. [8]

After stopping Activity Capture, staff may need to log activity manually. Review previously captured information separately. [6]

Salesforce says opting out of customer-data sharing can prevent participation in pilots or early access and reduce the relevance of search for business-specific terms. It is a different decision from switching off every enabled AI feature. [3]

For retained AI, compare the time saved with checking effort, corrections, support outcomes and licence or usage costs. Audit collection can also increase credit consumption, according to Salesforce's setup guidance. [9]

Approved templates, manual record updates and staff handling support are possible working alternatives. These are proposed business choices; this report did not independently measure productivity gains or savings.

Control assessment

Requirement Finding
Stop individual agents Documented deactivation; ongoing conversations are interrupted.
Disable all Salesforce AI with one switch Not established; platform controls and defaults are changing.
Restrict customer information access Permissions, agent identity and underlying process settings matter.
Require approval before changes Documented action-level confirmation; check the approver and actual behaviour.
Stop connected email/calendar capture Separate control, with support-dependent exceptions and retained data.
Refuse global training and specified improvement uses Documented consent control and support route.
Prevent third-party model training Published Trust Layer commitments for the covered route.
Verify complete absence of AI processing Not established from published information reviewed.

Sources and scope

All sources below are official Salesforce documentation checked on 4 October 2026. This report covers relevant core Salesforce, Einstein, Agentforce, Activity Capture and data-use controls. It is not a full audit of every Salesforce product, standalone Tableau service, Slack feature, marketplace application or custom integration.

Published capability is distinguished from availability in a particular environment. Some documentation contains rollout announcements alongside earlier instructions. Account-specific controls need checking. Provider statements are not independent verification of implementation.

  1. Agents and Data Usage
  2. Trust and Agentforce
  3. Manage Salesforce Access to Customer Data
  4. Salesforce Einstein: Global Model Opt-Out Process
  5. Agent Execution Context and Data Access by Type
  6. Enable or Disable Einstein Activity Capture
  7. Enable Agentforce
  8. Activate or Deactivate Your Agent
  9. Set Up Einstein Generative AI
  10. Manage Cases with Flow Actions — confirmation example
  11. Set Up Einstein Generative AI Audit and Feedback
  12. Agentforce Privacy FAQ

Unresolved: account-specific rollout and controls; complete coverage of external connections; interruption of actions already passed to another system; feature-specific training and retention outside covered routes; independent verification of background processing and provider commitments.

Changes since previous Salesforce report: None. This establishes the first Salesforce baseline for subsequent monthly research.