AI SDR & Outbound Agents
A

Agentforce Sales

Salesforce's sales product line, rebranded from Sales Cloud as the agentic layer became the headline. The Agentforce agent set includes a Sales Development Rep agent that researches leads, drafts and sends outreach and books meetings, plus a Sales Coach agent for role play and deal guidance, all running on the underlying CRM and grounded in the customer's own records through Data Cloud. Agent behaviour is governed by the Einstein Trust Layer and by admin defined topics, actions and engagement rules. Consumption is priced separately from the CRM seats, at roughly 2 dollars per conversation or through Flex Credits at 500 dollars per 100,000 credits, with a published rate card.

Last VerifiedAugust 18, 2026
Compare Agentforce Sales with other vendors
Founded
1999
Headquarters
San Francisco, California, United States
Categories
ai-sdr-agents, sales-engagement, revenue-intelligence
Assessment

Capability Axes

AI Capability
AI CentralityAI CentralityWhether AI is the product or a feature veneer. The removal test: peel the AI label off, and does anything sellable remain?
CC on AI CentralityAI features on a conventional platform. Peel the AI label off and the product still works roughly as before.
Vendor Published

The agent layer is genuine, separately licensed and metered by the action, which is a stronger AI claim than most vendors can make. It still sits on a customer relationship platform that has been the category standard since 1999 and that works completely without it.

The rename from Sales Cloud to Agentforce Sales moved the marketing, not the architecture: Agentforce is described by its own maker as the agentic layer of the existing platform, turning existing workflows, prompt templates, Apex and APIs into agent actions. Peel the agents off and the CRM, pipeline, forecasting and reporting are untouched. The three largest incumbents in this index all land here for the same reason.

Autonomy and Oversight ModelAutonomy and Oversight ModelWhat the system does without a human. Draft for review, auto send, or fully agentic, and what contains a bad run.
AA on Autonomy and Oversight ModelThe autonomy boundary is published: what acts without review, what requires approval, what a bad run can and cannot do, and the controls that stop a batch mid flight.
Vendor Published

The most completely published autonomy boundary in the index so far. The SDR agent type carries admin defined engagement rules setting the conditions under which the agent may begin working a lead and how and when its emails may be sent, including preventing outreach to restricted leads.

Behaviour is scoped by topics, actions and instructions rather than open ended prompting, guardrails combine customer defined safeguards with vendor managed protections, and a response that violates a guardrail is withheld rather than shown. Human in the loop approval and escalation can be required by risk or sensitivity, and an audit trail captures agent actions and outputs for governance review.

AI Disclosure and Model TransparencyAI Disclosure and Model TransparencyWhat models power the product, whether AI generated outreach discloses itself, and whether scoring and routing logic is explainable.
BB on AI Disclosure and Model TransparencyMeaningful disclosure of the model stack or the disclosure posture, with one real gap, commonly silence on whether AI authored outreach identifies itself.
Vendor Published

The architecture is documented to a level competitors do not approach: a published trust layer description covering dynamic grounding, secure data retrieval, prompt defence, toxicity detection and audit logging, a separate platform security privacy and architecture document, and third party model providers named in the sub processor documentation rather than left as generic AI. Two gaps hold it below the top band.

Specific models and versions behind particular agent actions are not enumerated, and the vendor's own privacy material notes that data masking, a headline trust layer control, is currently disabled for this product.

Operational and Outcome EvidenceOperational and Outcome EvidenceMeasured outcomes with a stated basis: replies, meetings, pipeline, win rates. Logos are not evidence and prestige is not measurement.
CC on Operational and Outcome EvidenceOutcome claims are headline percentages with no stated basis, or customer logos standing in for results.
Third Party Estimated

Marketing volume is high and measurement basis is absent, and the most decision relevant evidence available points the other way. Independent 2026 reporting puts typical implementation at five to eleven months and reports that fewer than ten percent of customers have the agent layer fully scaled.

For a buyer, the question is not whether the technology works in a demonstration but what proportion of comparable deployments reached production and on what timeline, and the vendor publishes nothing that answers it. Cost modelling guidance from implementation partners is more specific about real agent behaviour than the vendor's own outcome claims.

Compliance and Risk
Outreach Compliance PostureOutreach Compliance PostureHow the product handles regulated outreach: consent, DNC scrubbing, opt out mechanics, caller ID conduct, and the public enforcement record.
BB on Outreach Compliance PostureSubstantive compliance features documented in product, but material questions (litigation history, caller ID practices, where responsibility transfers to the customer) go unaddressed.
Vendor Published

Real controls exist at the point where they matter, in the agent's engagement rules: which leads qualify, when the agent may begin, and how and when it may send, with restricted lead suppression called out as a control. Role and attribute based access can gate agent behaviour by geography or compliance status. What is missing is the regulatory layer stated plainly for the agent context.

Nothing published addresses CAN SPAM mechanics, opt out propagation or consent verification specifically for agent generated outreach, which is the obligation a customer takes on when an agent sends at machine speed.

Data Privacy PostureData Privacy PostureGDPR and CCPA posture: lawful basis, data subject rights handling, DPA availability, subprocessor disclosure.
AA on Data Privacy PostureGDPR and CCPA posture documented with specifics: lawful basis stated, DSR handling described, DPA published and signable, subprocessors listed.
Vendor Published

The strongest privacy documentation set in the index so far, and it is product specific rather than corporate boilerplate. A dedicated privacy FAQ for the agent products states plainly which branded agents fall within the services definition of the master services agreement and therefore under the published data processing addendum. Sub processors are documented separately and the agent products are mapped to that documentation. Grounding through the customer's own data platform is described rather than implied. The processor boundary remains, as it must: lawful basis for the records loaded is the customer's to establish.

Data Licensing and ProvenanceData Licensing and ProvenanceWhere the data comes from and on what legal footing: licensed, contributed, public record, or scraped, and who stands behind the answer.
BB on Data Licensing and ProvenanceProvenance is substantively described but incompletely: sourcing classes named without the legal footing, or indemnification unstated.
Vendor Published

No prospect database is bundled with the product. The agent works the customer's own records, grounded through the customer's data platform instance using retrieval over structured and unstructured company data, and the origin of that material is the customer's own systems. Provenance is therefore clear by construction.

Short of the top band because the platform's wider data ecosystem admits partner sourced data and no single published statement establishes the licensing footing for enrichment that reaches an agent through those channels.

Platform Terms ExposurePlatform Terms ExposureWhether the product operates inside the terms of the platforms it touches, and the restriction risk a buyer inherits when it does not.
BB on Platform Terms ExposureThe method is described and mostly conformant, with one real ambiguity the vendor does not resolve, or conformance asserted without the partnership evidence that would settle it.
Vendor Published

Effectively none of the exposure this axis was written to catch. The agent operates inside the vendor's own platform, actions are built from the customer's existing flows, Apex and APIs, and third party systems are reached through documented interfaces and a first party application marketplace. No automation of a platform that prohibits it. No conformance position of its own is published, so the grade reflects architecture rather than a stated commitment.

AI Safety and Data StewardshipAI Safety and Data StewardshipThe cross client boundary: whether customer data trains models that serve competitors, plus retention and deletion posture.
AA on AI Safety and Data StewardshipThe cross client boundary is answered in writing: whether customer data trains shared models, with opt out or contractual exclusion documented, plus retention and deletion specifics.
Vendor Published

The cross client question is answered contractually and specifically. The vendor states it holds zero data retention agreements with the third party model providers it uses, so customer data is neither retained by those providers nor used to train their models, and the agent products are named inside the master services agreement and its data processing addendum rather than left to inference.

Toxicity detection, prompt defence and audit logging of AI interactions are documented as architecture, not aspiration. One caveat the vendor discloses itself and a buyer should carry into a security review: data masking, one of the trust layer's headline protections, is currently disabled for this product.

Recipient Disclosure and AuthenticityRecipient Disclosure and AuthenticityHow the product presents itself to the people it targets: whether automated outreach and AI agents disclose themselves, whether sender personas are real, and whether personalization is grounded in verifiable fact. Measured as known compliance with Article 50 of the EU AI Act, in force since August 2, 2026, which requires AI systems that interact with individuals to disclose that fact.
CC on Recipient Disclosure and AuthenticityNothing published on whether recipients are told they are dealing with software. For a product whose AI talks to prospects, silence here is now a regulatory posture, not a style choice.
Regulatory or Legal Record

This is the flagship case for the axis and the vendor has published no position on it. The agent researches a prospect, writes to them and follows up, under a sender identity the customer configures, and nothing states whether the recipient is told they are corresponding with software or on whose behalf it acts.

The European Commission's final Article 50 guidelines, published 20 July 2026 for obligations in force from 2 August, apply the disclosure duty wherever contact with a person is reasonably foreseeable and expect an agent to identify both its artificial nature and the party it acts for, with the marking obligation resting principally on the provider of the system rather than the customer deploying it. Exposure runs to 15 million euro or 3 percent of worldwide turnover.

Integration and Deployment
Ecosystem and Integration DepthEcosystem and Integration DepthDocumented depth of CRM and stack integration: objects, sync direction, API surface, marketplace presence that matches the claims.
AA on Ecosystem and Integration DepthDeep, documented, bidirectional integration with the systems of record: named CRM objects and sync behavior, a public API with real docs, and a marketplace presence that matches the claims.
Vendor Published

The deepest integration surface in go to market software, and documented to a level nothing else here matches. A public application marketplace with thousands of listings, comprehensive published API references, and an agent model that converts a customer's existing automations, prompt templates, Apex classes and API endpoints into callable agent actions without a separate integration build. Grounding runs through the customer's own data platform, which itself carries documented connectors into external systems.

Deployment Model and Data ResidencyDeployment Model and Data ResidencyWhere the product runs and where customer data lives, including residency options for EU buyers.
BB on Deployment Model and Data ResidencyThe deployment model is clear and residency options are partially specified.
Vendor Published

Multi tenant cloud on the vendor's own infrastructure platform, with prompts processed inside that platform before being forwarded to a model provider over a contracted connection, which is a clearer account of the AI data path than any peer publishes. Regional deployment is available across a substantial set of countries.

Short of the top band because the residency picture for the agent layer specifically, as distinct from the underlying platform, is assembled from architecture documentation rather than stated as a residency commitment a buyer can read in one place.

Security Certifications and Trust CenterSecurity Certifications and Trust CenterVerifiable security posture: enumerated current certifications and a trust center an outsider can actually read.
AA on Security Certifications and Trust CenterA live trust center with enumerated, current certifications (SOC 2 Type II and peers), audit recency visible, and security practices documented beyond the badge.
Vendor Published

A long standing public trust site with compliance documentation, real time service status, and a product level security privacy and architecture document that names the agent products explicitly. Platform security practice is described in operational terms rather than as badges: security testing, site reliability, disaster recovery, least privileged access, role and attribute based access control, and audit logging of AI interactions. All of it is readable by an outsider before any commercial conversation.

Commercial and Operational
Commercial TransparencyCommercial TransparencyWhether a buyer can budget without a sales call. Published pricing graded on completeness, not on the price itself.
BB on Commercial TransparencyPartial pricing published (entry tiers real, enterprise opaque) or pricing published with load bearing exclusions.
Vendor Published

Unusually good disclosure at the agent layer and a load bearing exclusion underneath it. Published: roughly 2 dollars per conversation, Flex Credits at 500 dollars per 100,000, a rate card giving 20 credits for a standard action and 30 for a voice action, per user licensing from around 125 dollars a month, a free tier with included credits, and a usage wallet for tracking consumption. What is not published is the dependency that dominates the bill.

The agent layer leans on the vendor's data platform for grounding, and independent guides consistently report that line as the largest and least predictable component, with entry list prices in the tens of thousands of dollars a year growing into six figures. Buyers price the agent and are surprised by the data.

Exit and Data PortabilityExit and Data PortabilityWhat happens when a customer leaves: completeness of data export, rights to enriched or licensed data after termination, deletion commitments, and auto renewal mechanics, graded from published terms and documentation.
BB on Exit and Data PortabilityReal export capability documented, with a material exit question unstated in public terms, commonly post termination rights to licensed or enriched records.
Vendor Published

Export capability is real and long documented: scheduled data export, bulk APIs and a large partner tooling ecosystem for extraction, and the underlying records are the customer's own CRM objects rather than a proprietary derived store. The master services agreement is published rather than behind a sales process.

What is not published in a form a buyer can plan around is the agent layer specifically: what happens to conversation logs, audit trails, agent configurations and consumed credit entitlements at termination, and whether grounding artefacts in the data platform leave with the customer.

Deliverability and Sending DisciplineDeliverability and Sending DisciplineThe operational craft of sending: warmup, rotation, volume governance, spam rate monitoring, and what happens when reputation degrades.
CC on Deliverability and Sending DisciplineDeliverability is invoked as a benefit with no documented mechanism. For senders this is the axis where marketing most outruns evidence.
Vendor Published

The gap that matters most for this product category. An SDR agent researching accounts and sending sequences at machine speed puts a customer's sending reputation directly in the hands of an autonomous system, and nothing published describes warmup, volume governance, rotation, spam rate monitoring or what happens when reputation degrades under agent driven volume.

Cost modelling from implementation partners notes that a single SDR sequence can run thirty five or more actions, which is a useful proxy for send velocity and an unhelpful one for reputation. Deliverability is not addressed as an operating discipline anywhere in the agent documentation.

Segment and Market CoverageSegment and Market CoverageWho the product actually serves, evidenced: segments, geographies, languages, and customers that match the claim.
AA on Segment and Market CoverageWho the product serves is stated with evidence: segments, team sizes, geographies, and languages, with named customers that match the claim.
Vendor Published

Coverage is comprehensive and evidenced beyond dispute: every segment from small business to global enterprise, every major industry with dedicated product and compliance material, operations and regional infrastructure across the Americas, Europe and Asia Pacific, extensive localisation, and a customer base and review corpus in the tens of thousands for the underlying sales product. The intended buyer for the agent layer specifically is narrower than the platform's reach, since it requires an existing platform foundation, and that dependency is stated.

Commercial

Pricing

Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.

No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.

GTM Tech Index

An independent reference for evaluating the software revenue teams use to find, win, and keep customers. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
August 18, 2026
The GTM Tech Index is an editorial reference, not a law firm or a regulator. Compliance postures are assessed from published sources and public records, and nothing on the index is legal advice. Figures labeled “Estimated” have not been confirmed by the vendor. See the Methodology page for evaluation standards and limitations.
© 2026 GTM Tech Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746