← Insights

Agentforce Goes Live in September. Are Your Controls Ready?

Salesforce is auto-enabling Agentforce for all eligible orgs starting September. There's no opt-out. Here's what operators need to close before the deadline.

What's Actually Happening

Starting the first week of September, Salesforce will auto-enable Agentforce across all eligible orgs — Enterprise, Performance, Unlimited, Developer, and Agentforce 1 Edition. The opt-out toggle is being removed. No additional cost, no opt-in required, no grace period if you're behind on governance.

Agentforce Coworker was already quietly auto-enabled for eligible customers on August 4. If your team hasn't noticed it running in your org, that's not reassuring — that's the gap.

Why Operators Can't Treat This as an IT Ticket

Most Salesforce deployments at non-tech companies have accumulated years of permissive data-access settings, loosely scoped profiles, and role hierarchies that made sense for human reps but were never stress-tested against an autonomous agent. An agent doesn't get confused by over-broad permissions. It uses them.

The governance questions you need answered before September aren't abstract:

  • Which data objects can Agentforce read, write, or act on — and is that the right scope?
  • What actions can agents take without human approval? Logging a call is different from sending an email to a prospect or updating a contract record.
  • Which users and queues can agents touch, and do those users know an agent may now be acting in their name?
  • What does your audit trail look like if an agent takes an action a customer disputes?

If you can't answer those questions in the next two weeks, you're not ready for a September go-live — and Salesforce isn't going to wait.

The Actionable Move This Week

Run a two-hour scoping session with your Salesforce admin and whoever owns CRM governance. Work through three things: (1) audit current permission sets and flag any that give broader data access than a supervised human rep would need; (2) map every automated flow or process builder rule that an agent could interact with or trigger; (3) draft a one-page agent governance policy that defines what agents are authorized to do and what requires human confirmation before execution.

This isn't about blocking Agentforce. The capability is genuinely useful. It's about making sure the first thing your agents do in a live customer environment isn't something you'll need to explain to a client or your legal team. Governance before go-live is cheaper than governance after an incident.