Solutions
Implementation Org Review Org Monitoring Managed Services
Agents
Discovery Agent Metadata Agent Design Agent Build Agent Test Agent Governance Agent Support Agent
Industry Solutions
Financial Services
Healthcare & Life Sciences
NDIS & Disability Services
Nonprofit
Not-for-Profit
Other Industries
Recruitment & Staffing Real Estate Cosmetic Procedures
Agentforce Claudeforce Blogs Pricing
Blogs This article

Agentforce Readiness Checklist: 12 Checks Before You Switch On Agents

AC Written by Amit Choudhary October 6, 2026
Summarize with AI ChatGPT Claude Perplexity

Search for an Agentforce readiness checklist and you will be offered five checks, ten checks, twelve, twenty. One result promises that twelve weeks of data remediation produces an 89 percent success rate, a figure with no study behind it and no definition of success. The checklists overlap on data quality and then diverge completely on everything else.

That is a signal, not a nuisance. Nobody agrees on what readiness means because most of these lists were assembled by asking what sounds prudent rather than by asking what has actually gone wrong.

In September 2026 something did go wrong, publicly and in detail, and it reorganizes the whole question.

A fixed Agentforce exploit shows what a readiness check is for

On 24 September 2026, the AI agent security firm Zenity Labs disclosed three vulnerabilities it collectively named SalesBleed. Salesforce Ben’s write-up of the disclosure sets out the chain. Salesforce has fixed the issues, so this is not a live warning. It is the clearest available evidence of what an agent readiness audit is supposed to catch.

The attack needed no login and no victim click. It worked like this.

An attacker submitted an ordinary-looking lead through a public Web-to-Lead form, with a prompt injection hidden in one of the fields. Later, an internal user asked their agent something unremarkable: check my latest leads and help me with the newest one. The agent read the malicious lead and followed the instructions embedded in it. Those instructions told it to query the Accounts table using the General CRM subagent’s Query Records tool, pull a few fields such as company name and deal size, encode those values as a subdomain of an attacker-controlled hostname, and print the result back to the user as an HTML image tag. Rendering that tag fired a DNS query to the attacker’s own name server, carrying the data out.

Salesforce blocks untrusted URLs. Encoding the payload into the first-level domain of the hostname went around that block, and that specific bypass is what Salesforce repaired.

Read the chain again and notice what no step required. No credential was stolen. No permission was misconfigured in the ordinary sense. Every component behaved as designed. The agent read a record it was allowed to read, called a tool it was allowed to call, and rendered output it was allowed to render. The vulnerability lived in the combination.

That is why a readiness checklist built from generic prudence misses. Data quality would not have stopped this. A governance policy document would not have stopped this.

Three ingredients decide whether an agent stays contained

Zenity’s conclusion is more useful than its exploit, and it generalizes beyond Salesforce.

Any agent that reads records submitted by an external source, renders links back to users, and holds tool access to sensitive data has what the researchers called the same ingredients. Michael Bargury, Zenity’s cofounder and chief technology officer, framed the wider lesson as being about what it takes to keep agents contained, adding that secure-by-design remains essential but for agents may no longer be enough.

Three properties, and the risk is in their intersection. Remove any one and the chain breaks.

So the twelve checks below are not grouped by theme. They are grouped by the three properties plus the one thing that bites after activation rather than during it.

GroupThe question it answersChecks
InputsWhat can reach the agent1 to 3
ReachWhat the agent can reach4 to 6
OutputWhat the agent can emit7 to 9
RuntimeWhat happens once it is live10 to 12

Each check below carries a pass bar. A check without a pass bar is a conversation topic, not a control.

GetGenerative.ai agents answer the checks that require reading the org

An honest readiness audit is mostly org archaeology. Which objects can anonymous users write to. Which free-text fields exist on those objects. Which flows and validation rules already touch them. Which permission sets grant what to the identity an agent will run under.

That work is slow, it is unbilled when a partner does it during presales, and it is the first thing dropped when a client wants agents switched on this quarter. A checklist nobody completes is worth nothing, so the production cost of the evidence matters as much as the list.

This is where the Metadata Agent inside GetGenerative.ai earns its place on a readiness page. It inspects the org itself, so answers to the configuration questions below come from deployed metadata rather than from a workshop recollection or a design document written two releases ago. Findings then flow into Discovery and Design, which turns a readiness gap into scoped remediation work instead of a note in somebody’s file.

What the platform does not do is decide your risk appetite. Check 7 below asks whether agent responses may render links to users. That is a risk call a business has to make, and no tool makes it. Teams wanting agents scoped and activated against these checks can review the Agentforce activation packages.

What can reach an agent sets its grounding surface

Check 1. Name every path by which an unauthenticated party can create a record the agent can read. Web-to-Lead and Email-to-Case are the obvious ones. Experience Cloud guest user write access, chat transcripts, survey responses and inbound integration users are the ones people forget. Pass bar: a written list of every anonymous or external write path into any object within the agent’s query scope, confirmed in Setup rather than assumed.

Check 2. Decide which free-text fields from those paths reach the agent’s context. Prompt injection needs somewhere to live, and a long free-text description field on a record anyone can create is exactly that. Pass bar: free-text fields originating from untrusted sources are either excluded from the agent’s grounding or passed through a sanitization step you can describe.

Check 3. Give every grounding source an owner and a review date. Knowledge articles, files and structured records all age, and an agent grounded on a superseded refund policy will state the superseded policy confidently. Pass bar: no source in use without a named human owner and a review interval it is currently inside. Preparing that corpus properly is its own task, covered in getting a knowledge base ready for agents.

Data quality sits underneath all three. It is necessary, it is not what this page is for, and scoring it belongs in a data readiness assessment.

Tool permissions, not user intent, set the blast radius

Check 4. Confirm edition and add-on entitlement in Setup. Salesforce’s own considerations for Agentforce Service Agent restrict it to Enterprise, Performance, Unlimited and Developer editions, and the add-on license you need differs depending on which agent type you are deploying. Professional Edition is absent from that list. Pass bar: the edition and the specific add-on for your agent type are both visible in the org, not merely named in an order form.

Check 5. Reduce the agent identity’s access to the smallest set its topics need. The SalesBleed chain used tool access that existed because it came bundled, not because a topic required it. Pass bar: removing any single object or field permission from the agent’s identity breaks a required action. If you can strip a permission and everything still works, the permission was blast radius you were carrying for free.

Check 6. Inventory every tool attached to every topic, with its read and write reach. An agent’s capability surface is the union of its tools, and that union is usually wider than any individual designer intended. Pass bar: a table of topics against tools, with no tool present that no topic calls. How that mapping should be designed in the first place is set out in designing topics and actions.

This group contains the two checks most often skipped, because both require someone to say no to a default.

Rendered output doubles as an exfiltration channel

Check 7. Decide and document whether agent responses may render links, images or HTML. This is the ingredient most teams have never considered, and it is the one that turned a data read into a data leak. Pass bar: a stated position, with rendering restricted where it is not needed. Accepting the channel knowingly is a valid answer; not knowing you had a channel is not.

Check 8. Verify you can reconstruct a single past conversation end to end. Not aggregate metrics. One specific interaction, including what the agent retrieved and which tools it called. Pass bar: you retrieve a named conversation from last week and read what happened without asking Salesforce support.

Check 9. Test the escalation path with context intact. Handoff to a human is configured on most agents and tested on few. The failure mode is a customer repeating everything to an agent that has lost the thread. Pass bar: an escalation performed in a sandbox, where the receiving human saw the prior exchange. Broader test design belongs in how agent responses get tested.

Consumption and language support decide what happens after activation

Check 10. Price a single conversation in Flex Credits before you price a deployment. Agentforce meters each action an agent takes, drawing on Flex Credits, so a correct build estimate tells you nothing about the run cost. Pass bar: a per-conversation credit figure derived from the actions your topics actually invoke, with the current rate card dated. The mechanics are in how agent usage is metered.

Check 11. Set an expected monthly interaction volume and an alert nobody can ignore. Consumption pricing means successful adoption raises the bill, which is the pleasant failure mode nobody budgets for. Pass bar: a volume assumption written down and a threshold alert with a named owner who receives it.

Check 12. Confirm your required languages are generally available rather than Beta. Agentforce publishes its own locale list, separate from the languages the Salesforce platform supports, and twenty-five of its locales currently carry Beta status. Pass bar: every language your users need is checked against the Agentforce list specifically, with any Beta entry escalated as a business decision rather than logged as a detail.

Two patterns in that list deserve attention before a regional rollout is committed.

Hindi is generally available. Bengali, Gujarati, Kannada, Malayalam, Marathi, Punjabi, Tamil, Telugu and Urdu are all Beta. Any Indian deployment serving customers outside Hindi and English is therefore building on Beta support, and so is any deployment in Russian or Ukrainian.

Locale variants are also narrower than they look. Spanish appears as es_ES and Portuguese as pt_BR, so a Mexican or wider Latin American rollout is being served European Spanish, and a Portuguese deployment outside Brazil has no matching locale at all.

That check costs ten minutes and is expensive to discover late. A deployment can clear every other item on this page and still arrive at a Beta language conversation in week nine.

Four checks block activation and eight degrade it

Treating twelve checks as equally weighted is how a readiness audit becomes a delay rather than a decision. They are not equal.

CheckStatusWhy
1. External write pathsBlockingWithout the list you cannot assess containment at all
4. Edition and entitlementBlockingThe agent will not run, or will not run supported
5. Agent permission scopeBlockingSets the blast radius of any successful injection
12. Language availabilityBlockingBeta status is a business decision, not a configuration gap
2, 3, 6, 7, 8, 9, 10, 11DegradingEach raises risk, cost or quality without preventing a safe start

A blocking check fails and activation waits. A degrading check fails and you proceed with a dated, owned remediation item. The distinction matters because the alternative is either reckless activation or a readiness exercise that never ends.

Checks 1, 5 and 7 together are the containment test, and they map exactly onto Zenity’s three ingredients. An org that passes those three has broken the chain even if a comparable bypass appears in future.

Platform change resets the audit, so date your results

A readiness result is a photograph, not a property. Both Agentforce and the platform underneath it moved repeatedly through 2026, and each move can invalidate a check that passed.

Re-run the audit when any of four things happen. A Salesforce release alters agent capability or default permissions. You add a topic or an action, since check 6 is invalidated by definition. A new integration or form creates a write path that check 1 did not cover. Or the consumption rate card is revised, which resets checks 10 and 11.

Write the date and the person on the result. An undated readiness sign-off from an unnamed assessor is the artifact most likely to be waved at an auditor and least likely to survive the question of when it was done.

Who owns the re-run after go-live is a governance question rather than a readiness one, and it is set out in who owns agents after go-live. If this audit tells you the gap is wide, the sensible response is a tightly scoped first deployment rather than a remediation program, which is the argument in the thirty-day Agentforce pilot plan.

Readiness audits surface the same six objections

What does Agentforce readiness actually mean?

It means you can state what can reach your agent, what your agent can reach, what it is allowed to emit, and what it costs per conversation. Data quality is necessary but insufficient, which is why checklists built only on data cleanliness miss containment risk entirely.

Which edition do I need for Agentforce?

Salesforce restricts Agentforce Service Agent to Enterprise, Performance, Unlimited and Developer editions, and the add-on license required differs by agent type. Professional Edition is absent from that list. Confirm both the edition and the specific add-on inside the org rather than relying on an order form.

What is SalesBleed and does it still affect Agentforce?

SalesBleed is the name Zenity Labs gave to three vulnerabilities it disclosed on 24 September 2026, which chained a prompt injection hidden in a Web-to-Lead submission to data exfiltration through a rendered HTML image tag and a DNS lookup. Salesforce has fixed the issues. The structural lesson stands: any agent reading externally submitted records, rendering links, and holding tool access to sensitive data carries the same combination of ingredients.

How many checks should an Agentforce readiness audit have?

The count matters less than whether each check has a pass bar and a blocking status. Published checklists range from five to twenty items, and most state no threshold for passing, which makes them discussion prompts rather than controls. Four blocking checks and eight degrading ones is a workable split.

Can agents read records created by anonymous users?

Yes, if those records sit within the agent’s query scope. Web-to-Lead, Email-to-Case, guest user write access on Experience Cloud, chat transcripts and survey responses all create records that an internal user can then ask an agent about. Enumerating those paths is the first check for that reason.

Does Agentforce support every language Salesforce supports?

No. Agentforce publishes a locale list separate from the Salesforce platform’s, and twenty-five of its locales are at Beta rather than general availability. Hindi is generally available while Bengali, Gujarati, Kannada, Malayalam, Marathi, Punjabi, Tamil, Telugu and Urdu are Beta, as are Russian and Ukrainian. Spanish is listed as es_ES and Portuguese as pt_BR, so Latin American rollouts inherit European Spanish. Check the Agentforce list specifically before committing to a regional rollout.

About the Author
Amit Choudhary
Amit is a tech entrepreneur and investor, currently the Co-founder & CEO of GetGenerative.ai, an AI-native Salesforce consulting platform. He previously co-founded saasguru, helping over 100,000 learners build careers in Salesforce, and SaaSfocus, APAC’s largest Salesforce boutique acquired by Cognizant. With a global background in sales leadership and $750M+ in TCV, he brings deep expertise in scaling tech ventures.