TL;DR
- Salesforce is making Agentforce agents the interface. This removes the visible controls, login, menus, and approvals. Yet agents and their access remain.
- Discover every Agentforce agent with a live inventory and a Trust Score.
- Secure agent actions with purpose-based access, runtime guardrails, and a kill switch travel every hop.
- Enforce control at the data source so the policy holds the human users accountable.
- Back oversight with full traces, replay, and an audit trail mapped to EU AI Act, HIPAA, SOX, and NIST AI RMF.
“Why should you ever log into Salesforce again?” That is Salesforce co-founder Parker Harris, quoted in a recent Salesforce Futures article on the future UI of AI. The interface is indeed dissolving. Agents reach the data and the business logic directly, and the menus, dashboards, and login prompts fade into the background.
This would make any security leader nervous.
The login screen was a checkpoint. It was where identity got established, where authorization got checked, where an approval step put a human in the loop. Salesforce’s own Headless 360 is explicit about the change. It lets an agent reach into the platform and act on a customer’s full history without going through any of the front doors.
When the interface melts, the controls that lived inside it melt with it.
Near its close, the article admits executives now face unanswered questions, including which security frameworks apply and whether people will trust an always-watching system with their data. If work is shifting to agents that act across your systems on a user’s behalf, your controls have to move to where those agents now operate, at the agent boundary and at the data layer. That is where Trust3 AI runs to secure agents built on Salesforce Agentforce.
Discover Every (Approved and Unapproved) Agentforce Agent

Agentforce makes spinning up an agent easy, which is the point. It also makes spinning one up without filing a ticket extremely easy. When the interface was a screen, an unapproved tool was at least something a person might stumble across in a menu. When the interface is an agent, capabilities that used to sit in plain sight can now hide inside whatever the agent renders.
Enterprises end up undercounting their agents by three to ten times this way. An approval gate cannot refuse what was never submitted to it.
Trust3 AI treats Salesforce Agentforce as one of the SaaS surfaces it continuously scans for agents, alongside cloud accounts and developer environments. For each agent it records the owner, the identity, the data it can reach, and a Trust Score out of 10. Any unregistered agent gets flagged on first appearance. Shadow AI gets scored too.
Secure the Action Beyond the Login
In the new model, the agent moves from system to system to finish the task. Read that as a security engineer and it is a delegation chain. One agent acts for a user, calls a tool, hands work to another agent, and reaches a data source several hops away. Every hop is a place where the originating user’s identity can dissolve and scope can quietly widen.
Most access today is static and role-based. One token opens everything the role can see with no grant tied to a purpose. That is equivalent to writing a blank check.
Trust3 AI enforces purpose-based access control, evaluated per request rather than per job title, with just-in-time grants and auto-expiring scopes so an agent holds only what the task in front of it needs. Runtime guardrails inspect each action before it executes. A kill switch can stop any agent mid-action. Identity and declared purpose travel through every hop, so scope can only narrow down a delegation chain, never expand.
The same enforcement covers the two protocols agents rely on. The Model Context Protocol (MCP) connects an agent to external tools and data at runtime. Agent-to-agent (A2A) handoffs let one agent delegate to others. Trust3 AI treats both as untrusted by default.
You Cannot Authorize the Agent Without Authorizing the Data
The agent goes straight to the underlying data. That is the entire reason an agent exists. So there is no version of agent security that stops at the agent layer.
When an Agentforce agent reaches into Salesforce records, or through Headless 360 into the systems behind them, this should be the CISO’s question: whose identity is on that query? If a delegation chain has swapped the real user for a service account by the time it hits the data, your data-layer policy is firing against the wrong principal (or not firing at all).
Trust3 AI governs data at the source. One policy, enforced natively with no proxy hop and no added latency, applies row, column, and tag-based access across Snowflake, Databricks, BigQuery, and 50 or more other sources, scoped by attribute and purpose instead of over-privileged roles. Because identity propagates all the way down, the same policy fires against the human who started the chain rather than the service account that finished it.
Oversight Requires Evidence
The article is honest that what is left for the human is supervision. The screen becomes somewhere to review, approve, and govern while the agent executes. But oversight without evidence is just a feeling.
Trust3 AI keeps full-fidelity traces from prompt to retrieval to tool call to response, with real-time detectors for PII leakage and scope drift, and the ability to replay any decision after the fact. Every action lands in an audit trail tied to the originating user and pre-mapped to EU AI Act, HIPAA, SOX, and NIST AI RMF obligations. Those frameworks require showing who accessed regulated data and why. A service-account log cannot answer that question; an identity-propagated one can. Gartner projects that through 2029, more than half of successful attacks on AI agents will exploit access-control weaknesses.
Questions to Ask Before the Interface Finishes Melting
- How many Agentforce agents are running in your org right now, who owns them, and which ones were never approved?
- When an agent acts through Headless 360, whose identity reaches the data, the user who started the task or a service account?
- Is access scoped to the purpose of a single task, or does the agent inherit everything its role can see?
- Can you replay any agent decision and prove to an auditor who did what, on whose identity?
The interface will keep receding, and more work will reach people through agents than through screens. The controls you could once see are the first to disappear. You have no choice but to move them to where the agents actually operate, at the agent boundary and at the data source, in one policy that fires in the same decision.
Let’s chat further here: https://trust3.ai/demo/
