Agentforce · Trust & Security · 2026 Connecting…

Trust & security deployment checklist

Shared team board — everyone sees the same status live. First mark which items are relevant to this project, then work through them; changes sync for the whole team.

Loading…0%
Core: 0/0 complete
Project context

Model in use: GPT-5.4 (OpenAI) — external provider

Zero data retention applies

Prompts are encrypted in transit. OpenAI is contractually barred from retaining the data, using it to train models, or having it reviewed by their staff. ZDR is built into the Trust Layer — there is no toggle to enable.

Data crosses the trust boundary

OpenAI models are operated outside the Salesforce network, so prompts leave it to be processed. “Not retained” is not the same as “never left” — state both to security reviewers.

Data masking does not apply

LLM data masking is disabled for Agentforce agents. Masking policies configured in Setup cover embedded features only. PII in grounded call transcripts — and anything a user types into chat — reaches the model unmasked.

Core — non-negotiable Verify per org / model Optional — scale by risk