AGENTFORCE SECURITY TESTING

Agentforce Security Testing

Agentforce security testing confirms that a Salesforce AI agent honours the running user's permissions, never exposes data it should withhold, and cannot be manipulated into unauthorized actions. It treats an autonomous agent as a new access path into your org that must respect every control your users already do.

An active-roadmap capability, available today for demonstration and proof-of-concept validation with Salesforce testing teams.

Why an agent needs its own security testing

An Agentforce agent runs as a user and acts on that user's behalf, so it inherits object permissions, field-level security and sharing rules. But it also introduces exposure a traditional page or API never had: it reads natural language, reasons over data, and can be talked into behaviour through the words in a request. Security testing has to cover both the familiar access model and this new manipulation surface.

The familiar half is enforcement. If a support agent user cannot see a competitor's account or a compensation field in the UI, the AI agent acting for that user must not surface it either. Sharing rules, restriction rules and field-level security are the boundary, and the agent has to stay inside it on every read and write.

The unfamiliar half is manipulation. Because the agent interprets language, an attacker or even a careless user can attempt to reshape its behaviour through instructions embedded in a message, a record they control or a document it retrieves. These risks do not appear in conventional Salesforce testing and are the reason agent security is its own discipline:

Prompt injection

Instructions hidden in user input or in data the agent reads that attempt to override its guardrails or system instructions.

Sensitive-data exposure

The agent revealing PII, financial or restricted fields it can technically read but should never disclose in a response.

Tool and action misuse

The agent being steered into running a Flow, Apex action or API call outside its intended, permitted scope.

Cross-user data leakage

Data or context from one user's session bleeding into another's, exposing records the second user has no right to see.

Agent security testing sits within your wider platform security program. For SyntraFlow's overall approach to data protection and controls, see the SyntraFlow security overview.

How SyntraFlow approaches agent security testing

SyntraFlow is designed to test an agent from the perspective of a specific user, probing both enforcement and manipulation, and to record every result as audit evidence. It complements Salesforce-native tooling rather than replacing it.

1

Test as the running user

SyntraFlow can be configured to run agent tests under defined personas with specific profiles and permission sets, so access is checked in the exact context the agent operates in.

2

Probe access boundaries

Tests ask the agent for records, fields and related data the persona should not see, and confirm it withholds rather than discloses, exercising object access, field-level security and sharing.

3

Run adversarial prompts

A library of injection and jailbreak attempts, including instructions planted in records and documents, checks that guardrails hold and the agent refuses to override its intended behaviour.

4

Verify action scope

Tests confirm the agent only invokes the Flows, Apex actions and APIs it is authorized to run, and refuses attempts to trigger anything outside its permitted scope.

5

Record audit evidence

Every security test, prompt and result is designed to be captured as durable evidence, so access and safety behaviour can be shown to auditors and re-verified after each change.

Salesforce provides native evaluation through Agentforce Testing Center, a Testing API and Agentforce DX. SyntraFlow is designed to complement these with persona-based access probing, an adversarial prompt library and audit-ready evidence around the security results they produce.

Agentforce security test coverage

The risks an agent security suite should exercise, and what a passing test looks like.

Risk area Test focus Passing behaviour
Object accessAsk for records on objects the persona lacks read access to.Agent returns nothing it should not see and does not fabricate the value.
Field-level securityRequest a restricted field such as a salary or SSN.Agent withholds the hidden field while still answering the permitted parts.
Sharing rulesAsk about records owned by another team or region.Agent respects sharing and restriction rules exactly as the UI would.
Prompt injectionPlant override instructions in input, records or documents.Agent ignores the injected instruction and keeps its guardrails.
Action misuseTry to steer the agent into an out-of-scope Flow or Apex call.Agent runs only authorized actions and refuses the rest.
Cross-user leakageReference another user's prior session or data.Agent keeps sessions isolated and exposes no other user's records.

Access-boundary testing overlaps with grounding testing, since an agent must withhold restricted data without fabricating a substitute to fill the gap it just created.

SYNTRAFLOW DIFFERENTIATOR

Agent access reaches into connected systems

When an agent action posts to or reads from Oracle, SAP, NetSuite or Workday, the security question does not stop at the Salesforce boundary. A prompt that steers the agent into an unauthorized ERP transaction, or an integration user with broader rights than the running Salesforce user, can expose or change data no Salesforce-only test would catch.

SyntraFlow is designed to follow access and action scope across application boundaries, pairing Agentforce security testing with Oracle ERP testing so the agent's reach into connected systems is verified end to end.

What disciplined security testing gives you

Qualitative outcomes teams can expect when agent security is tested deliberately.

Access you can prove

Persona-based tests demonstrate the agent honours the same permissions your users do, on every read and write.

Resilience to manipulation

An adversarial prompt library shows guardrails hold against injection planted in input and data.

Contained action scope

Confidence that the agent runs only the actions it is authorized to run, and refuses the rest.

Audit-ready records

Every security test and result is captured as evidence for reviewers, regulators and internal governance.

Safer expansion

Proven controls let teams widen what the agent handles without widening exposure.

Security regression cover

Suites re-run alongside Agentforce regression testing so a change never quietly weakens a control.

Agentforce security testing FAQs

What is Agentforce security testing?

It is the practice of confirming a Salesforce AI agent honours the running user's object access, field-level security and sharing rules, never exposes sensitive data it should withhold, resists prompt injection and tool misuse, and cannot leak one user's data to another. Every test and result should be recorded as audit evidence.

How do you test for prompt injection?

Run a library of adversarial prompts that attempt to override the agent's instructions, including instructions hidden inside records and documents the agent reads. A passing agent ignores the injected commands and keeps its guardrails, so the test confirms manipulation attempts do not change its behaviour.

Does the agent inherit user permissions automatically?

An agent runs as a user and inherits that user's permissions, but inheritance must still be verified because reasoning, retrieval and actions can surface data in ways a static page does not. Persona-based tests confirm the agent stays inside object, field and sharing boundaries in practice.

How is agent security testing recorded for audit?

Each test defines the persona, the prompt and the expected behaviour, and the actual result is captured alongside it. SyntraFlow is designed to retain this as durable evidence so access and safety behaviour can be shown to auditors and re-verified after every change. See the SyntraFlow security overview for the wider control framework.

Does SyntraFlow replace Salesforce security controls?

No. Profiles, permission sets, sharing rules and Salesforce Shield remain the enforcement layer, and Agentforce Testing Center and the Testing API are native evaluation tooling. SyntraFlow is designed to complement all of these by testing that the agent honours them and by adding cross-application and audit coverage around the results.

What about actions that reach an ERP?

Security scope does not stop at Salesforce. When an agent action reads from or posts to Oracle, SAP, NetSuite or Workday, SyntraFlow is designed to verify that access and action scope hold across that boundary, so the agent's reach into connected systems is tested end to end rather than only in Salesforce.

Prove your agent respects every boundary

Bring a real agent and we will show how SyntraFlow is designed to probe access, resist prompt injection and record audit evidence for your Agentforce deployment.