Permissions only help if they are correct today

Salesforce now ships agents with first names and fixed jobs, and the sentence that decides whether they are safe in your org is a conditional. Writing for diginomica on September 24, analyst Rebecca Wettemann records that Salesforce says every agent can only see what its permissions allow, then adds the condition, that this "only works if permissions are current and correct today", and consistent across Salesforce, Slack and other agents.

Two things about the source. The piece is signed analysis and opinion rather than reported news, so every judgement below belongs to Wettemann and is named as hers. And diginomica discloses that Salesforce is a premier partner of diginomica at time of writing.

The roster she names is worth learning, because each name carries a defined scope of data. Casey covers customer service, Paige covers IT and human resources, and Carter covers commerce. Hunter covers outbound sales and runs on the new long-horizon runtime, the one behind agent work that can pursue a goal for weeks. Marshall covers supply chain, Piper covers inbound pipeline management, and Fin covers customer experience, arriving through an acquisition the piece does not explain.

Every vendor in this market now offers that same assurance. Stated once it sounds reassuring. Stated by all of them, it quietly moves the burden onto permission hygiene. Most permission models were assembled over a decade by people solving one request at a time, were never designed for automated access, and have never been audited against the question of what an agent could reach.

A catalogue of agents is a narrower promise

Prebuilt agents with names and defined jobs are a retreat from the earlier pitch, that anyone in the business could build an agent for whatever they needed. Both readings hold at once. Seven agents doing known work are far easier to govern than an open building surface, because you can enumerate what each one touches. The catalogue is also a smaller claim than the one originally made, and nobody on a keynote stage will say so.

The trade favours whoever would otherwise inherit the governance problem. Reviewing a fixed set of agent definitions with declared data access is ordinary platform work. Reviewing several hundred built by departments is the cleanup that never finishes.

Wettemann offers one anecdote about how well the roster is understood, that nine out of ten customers she spoke to did not know what one of the agents did. She gives no base population and does not present it as research, so read it as her impression rather than a measurement. It still points at something familiar, that a named agent needs someone internally who can say what it touches.

Metadata stops being back-office plumbing

The sharpest idea in the piece is where Wettemann puts the value. "Salesforce is betting that value is shifting from the user interface to the metadata," she writes, and pairs it with her reading of the company's position, that "users shouldn't have to open Salesforce to use Salesforce." Both sentences are hers.

Follow that through and the consequences land on people whose job titles understate what they now control. If the agent reads the metadata rather than a page, then objects, fields, permission sets and sharing rules become the surface the product is delivered through. Whoever names a field or decides which profile sees a related list is making a product decision, whether or not anyone calls it one.

Wettemann carries the point through to the money. She argues that whoever owns control, permissions and actions determines which agent and model gets called when and how often, and becomes the arbiter of who gets the biggest piece of the token pie. Set that beside our reporting on how agent work became a billable unit and the permission owner decides both who sees what and what the org spends.

Slackforce Surfaces meets record-level access

The piece also describes Slackforce Surfaces. A user says what they need, and Slackbot assembles a live dashboard, report, deck or calculator from Salesforce data, running inside Slack. No Salesforce tab, no page layout, and no trip through the interface where sharing rules normally make themselves felt.

That is the precise point where record-level permissions meet a shared channel, and two questions follow that the piece does not answer. Whose permissions build the surface, the person who asked for it or each person who later opens it. And what happens to a live surface pinned in a channel whose membership changes next quarter.

If the surface resolves under the viewer's access each time, most of the exposure disappears. If it renders under the author's access for everyone in the channel, you have a sharing model nobody approved, sitting outside the place you administer it. Our coverage of the claim that AI would replace the CRM interface hit the same gap, and this one is worth settling during a pilot rather than an incident review.

The audit to run before you switch one on

The work here needs no purchase order. Export every profile and permission set in production, then sort for the wide ones, anything granting View All Data, Modify All Data, View All on an object, or rights over metadata. Against each, record the owner, the last review date, and who it is assigned to. Most orgs find one created for a project that ended years ago and was never withdrawn.

Do the same pass for accounts with no human behind them, the integration users, the automated process users, and anything carrying a permission set nobody present can explain. An agent inherits its reach from a record in your org, so that record is the thing to read. The mechanics sit in our Salesforce permission audit guide, and we worked through where a vendor draws that line in the Claudeforce permission boundary.

Finish by putting a name and a review date against every wide permission set, and by mapping which Salesforce access sits behind the Slack channels your team already uses. Salesforce's claim that an agent sees only what permissions allow can be tested in a sandbox in a week. Run that test before the first named agent reaches production, while a wrong answer still costs nothing but the afternoon.