Home / Products / AgentForce Shield
Proprietary · Salesforce & AI governanceAgentForce Shield
Know your Salesforce environment before attackers do.
AgentForce Shield builds a complete picture of your Salesforce organisation—from permissions and sharing rules to connected applications and governance controls—so you can identify critical risks, understand their impact and prioritise remediation with confidence.
The problem
A Salesforce org is rarely misconfigured on day one. It drifts.
A profile cloned under deadline. A sharing rule widened for one report and never narrowed. A connected app that outlived the project it was built for. None of these are incidents. Together they are your attack surface.
Audit domains covered continuously
Configuration monitoring
Manual permission reviews required to keep it current
Read-only connection to your org
Complete visibility into the security of your Salesforce organisation.
Every configuration setting contributes to your security posture. AgentForce Shield analyses the entire Salesforce environment—not just individual controls—to reveal how permissions, data exposure, integrations and governance combine to create risk.
Platform Governance
Core platform configuration, governance controls and administrative settings reviewed to ensure the organisation, not the platform, defines security.
Identity & Access
Profiles, permission sets, permission set groups, roles and privileged access analysed to enforce least privilege without disrupting operations.
Connected Applications
Connected apps, APIs, OAuth grants, integrations and third-party access reviewed to identify unnecessary trust relationships and excessive permissions.
Data Protection
Sharing rules, object and field permissions, encryption, exports and data visibility assessed to reduce unauthorised access and data exposure.
Monitoring & Detection
Audit logs, security events, login activity and detection capabilities reviewed to improve visibility, investigation and response.
Compliance & Assurance
Controls mapped to GDPR, ISO 27001 and internal security requirements, with evidence structured to support governance, audits and continuous improvement.
How AgentForce Shield connects
Standalone or inside an advisory engagement. Either way the sequence is the same.
Connect your org
Shield connects to your org through a scoped, read-only integration. It reads configuration; it does not change it.
Understand today's posture
A first full audit across the four domains produces the baseline: current score, misconfigurations, excessive privilege, exposure.
Watch the drift
Configuration is re-evaluated continuously. What matters is not the score on day one but the change on day ninety.
Know what to fix first
Dashboards for governance, alerts for change, and remediation guidance attached to each finding rather than a bare list.
Capabilities and fit.
Key capabilities
- Continuous monitoring of Salesforce security configuration
- Detection of excessive permissions and risky access patterns
- Compliance tracking aligned to GDPR and ISO requirements
- Security dashboards and reporting built for governance and audit
- Alerts on configuration changes that move your security posture
Ideal for
- Salesforce-first organisations needing ongoing compliance assurance
- Teams that must evidence governance and visibility, not just claim it
- Environments where customer data exposure is the primary risk
What it replaces
- An annual manual permission review in a spreadsheet
- Discovering drift during the audit rather than before it
- Trusting that the sharing model still matches the one you designed
- A point-in-time audit that is already outdated when delivered
A Salesforce environment that stays secure and compliant — with far less manual review and operational overhead.
What clients ask first.
Does AgentForce Shield change anything in our org?
No. The integration is read-only. AgentForce Shield reports and alerts; remediation stays in your hands, with guidance attached to each finding.
Is this a Salesforce AppExchange product?
AgentForce Shield is our own software, connected to your org through a scoped integration. We own the source, the roadmap and its security.
What does it produce for an audit?
Posture history, evidence per control domain and change alerting — the three things an auditor asks for and that a point-in-time review cannot give.
Can we run it alongside our existing Salesforce security review?
Yes, and most clients do at first. AgentForce Shield is what keeps the review true between two engagements.
Salesforce Security
The advisory side: permission model review, secure integration design, Apex and Lightning code review.
More products built for security teams.
See AgentForce Shield in action.
Explore the platform directly, or talk to us about assessing and continuously monitoring the security posture of your Salesforce environment.