← Insights

Agentforce Auto-Enable Is Coming. Your Permissions Aren't Ready.

Agentforce goes live in Winter '27 whether you've configured it or not. Here's the security model you need to understand before Dreamforce announcements land.

Salesforce is auto-enabling Agentforce in Winter '27. That means if you haven't pre-configured your agent security model, you won't be opting in — you'll be retrofitting controls onto a live deployment that's already touching your production data.

Dreamforce opens September 15. The announcements coming out of it will accelerate Agentforce adoption timelines further. The time to get this right is now, not after your inbox fills with recap posts.

The Three-Layer Security Model You Need to Know

Salesforce Ben's breakdown is the most practically useful resource on this right now. The architecture has three distinct layers:

Agent User object — Agentforce agents run as a dedicated Agent User, a licensed user type that sits outside your standard profile hierarchy. If you haven't created and scoped these yet, your agents will inherit more access than intended.

Named Credentials — these govern what external systems an agent can call. An agent with unconstrained Named Credential access can reach your connected apps, integrations, and data sources in ways your security team hasn't reviewed.

Topic and Action permissions — this is where you define what an agent is actually allowed to do: read, write, execute. Getting this wrong doesn't just create a compliance problem; it creates a customer-facing one if an agent takes an action a rep would never take.

Why the Timing Window Matters

The operational risk here isn't theoretical. Auto-enablement means the feature goes live on Salesforce's schedule, not yours. Organizations that haven't pre-configured Agent User profiles and permission sets before Winter '27 will face one of two outcomes: unsanctioned agent activity in production, or a scramble to disable features your users are already depending on.

The Dreamforce keynotes — particularly the Benioff and Anthropic session on Claudeforce — will almost certainly expand what Agentforce agents can do. New capabilities announced this week will start shaping your Winter '27 org before your admin team has finished reading the release notes.

The Actionable Takeaway

Before September 15, your Salesforce admin should be able to answer four questions:

  1. Have Agent User profiles been created and scoped to minimum necessary access?
  2. Are Named Credentials locked to only the integrations agents legitimately need?
  3. Have Topic and Action permissions been reviewed against your actual business processes?
  4. Is there a monitoring plan for agent activity post-enablement?

If the answer to any of these is