Agentforce Governance & Privacy Assessment
Know what your AI agents can see, say, and do before they go live, or before someone else asks.
Agentforce agents act on your customer data, and many organizations turn them on before anyone checks what they can see, say, or do. The Salesforce team configures the agent. Legal and compliance rarely look at the org. Nobody owns the gap between them.
That gap is where the exposure sits: agents reading fields they shouldn’t, personal data flowing into prompts and logs, no documented guardrails, and no answer when a regulator, auditor, or customer asks how your AI is governed.
What the assessment covers
- Data exposure: what each agent and AI feature can access, by object and field, and whether that matches its purpose
- Privacy and consent: personal and sensitive data in prompts, grounding, and logs; consent and opt-out handling; HIPAA, CCPA, and state privacy law where they apply
- Agent guardrails: topics, actions, instructions, Einstein Trust Layer settings, and escalation to humans
- Governance: who approves new agents and changes, how AI risk is documented, and alignment with the NIST AI Risk Management Framework and ISO/IEC 42001
- Access and security: permission sets, sharing, integration users, and audit trail
What you get
- Findings report: each risk rated high, medium, or low, with the exact setting or process behind it
- Remediation plan: fixes in priority order with effort estimates; we can implement them or hand them to your team
- AI governance policy starter: acceptable-use and agent-approval policies written for how your organization actually works
- Executive readout: a 60-minute session with leadership, legal, and your Salesforce team
The assessment is an advisory review of your Salesforce configuration and governance practices. It is not a legal opinion, a formal audit, or a certification of compliance with any law or standard, and it does not create an attorney-client relationship. Consult your legal counsel on legal questions.
Timeline and price
Three weeks from kickoff to readout, for a fixed fee of $15,000. Your team’s time commitment is light: a kickoff call, read-only org access, and a few short interviews. Remediation work is quoted separately.
Who does the work
The assessment is delivered by a consultant with more than 10 years of hands-on Salesforce experience and 12 Salesforce certifications, including Agentforce and architecture, who also holds a J.D. and the IAPP’s Artificial Intelligence Governance Professional (AIGP) and Certified Information Privacy Professional/United States (CIPP/US) credentials. That means one person reviews both how your agents are configured and how they line up with your privacy and AI governance obligations, so nothing gets lost between the technical and legal teams.
Next step
Book a 30-minute call to see whether the assessment fits your organization. Use the form below or email hello@duxburytech.com.
