Agentforce Sales
Salesforce's sales product line, rebranded from Sales Cloud as the agentic layer became the headline. The Agentforce agent set includes a Sales Development Rep agent that researches leads, drafts and sends outreach and books meetings, plus a Sales Coach agent for role play and deal guidance, all running on the underlying CRM and grounded in the customer's own records through Data Cloud. Agent behaviour is governed by the Einstein Trust Layer and by admin defined topics, actions and engagement rules. Consumption is priced separately from the CRM seats, at roughly 2 dollars per conversation or through Flex Credits at 500 dollars per 100,000 credits, with a published rate card.
Capability Axes
The agent layer is genuine, separately licensed and metered by the action, which is a stronger AI claim than most vendors can make. It still sits on a customer relationship platform that has been the category standard since 1999 and that works completely without it.
The rename from Sales Cloud to Agentforce Sales moved the marketing, not the architecture: Agentforce is described by its own maker as the agentic layer of the existing platform, turning existing workflows, prompt templates, Apex and APIs into agent actions. Peel the agents off and the CRM, pipeline, forecasting and reporting are untouched. The three largest incumbents in this index all land here for the same reason.
The most completely published autonomy boundary in the index so far. The SDR agent type carries admin defined engagement rules setting the conditions under which the agent may begin working a lead and how and when its emails may be sent, including preventing outreach to restricted leads.
Behaviour is scoped by topics, actions and instructions rather than open ended prompting, guardrails combine customer defined safeguards with vendor managed protections, and a response that violates a guardrail is withheld rather than shown. Human in the loop approval and escalation can be required by risk or sensitivity, and an audit trail captures agent actions and outputs for governance review.
The architecture is documented to a level competitors do not approach: a published trust layer description covering dynamic grounding, secure data retrieval, prompt defence, toxicity detection and audit logging, a separate platform security privacy and architecture document, and third party model providers named in the sub processor documentation rather than left as generic AI. Two gaps hold it below the top band.
Specific models and versions behind particular agent actions are not enumerated, and the vendor's own privacy material notes that data masking, a headline trust layer control, is currently disabled for this product.
Marketing volume is high and measurement basis is absent, and the most decision relevant evidence available points the other way. Independent 2026 reporting puts typical implementation at five to eleven months and reports that fewer than ten percent of customers have the agent layer fully scaled.
For a buyer, the question is not whether the technology works in a demonstration but what proportion of comparable deployments reached production and on what timeline, and the vendor publishes nothing that answers it. Cost modelling guidance from implementation partners is more specific about real agent behaviour than the vendor's own outcome claims.
Real controls exist at the point where they matter, in the agent's engagement rules: which leads qualify, when the agent may begin, and how and when it may send, with restricted lead suppression called out as a control. Role and attribute based access can gate agent behaviour by geography or compliance status. What is missing is the regulatory layer stated plainly for the agent context.
Nothing published addresses CAN SPAM mechanics, opt out propagation or consent verification specifically for agent generated outreach, which is the obligation a customer takes on when an agent sends at machine speed.
The strongest privacy documentation set in the index so far, and it is product specific rather than corporate boilerplate. A dedicated privacy FAQ for the agent products states plainly which branded agents fall within the services definition of the master services agreement and therefore under the published data processing addendum. Sub processors are documented separately and the agent products are mapped to that documentation. Grounding through the customer's own data platform is described rather than implied. The processor boundary remains, as it must: lawful basis for the records loaded is the customer's to establish.
No prospect database is bundled with the product. The agent works the customer's own records, grounded through the customer's data platform instance using retrieval over structured and unstructured company data, and the origin of that material is the customer's own systems. Provenance is therefore clear by construction.
Short of the top band because the platform's wider data ecosystem admits partner sourced data and no single published statement establishes the licensing footing for enrichment that reaches an agent through those channels.
Effectively none of the exposure this axis was written to catch. The agent operates inside the vendor's own platform, actions are built from the customer's existing flows, Apex and APIs, and third party systems are reached through documented interfaces and a first party application marketplace. No automation of a platform that prohibits it. No conformance position of its own is published, so the grade reflects architecture rather than a stated commitment.
The cross client question is answered contractually and specifically. The vendor states it holds zero data retention agreements with the third party model providers it uses, so customer data is neither retained by those providers nor used to train their models, and the agent products are named inside the master services agreement and its data processing addendum rather than left to inference.
Toxicity detection, prompt defence and audit logging of AI interactions are documented as architecture, not aspiration. One caveat the vendor discloses itself and a buyer should carry into a security review: data masking, one of the trust layer's headline protections, is currently disabled for this product.
This is the flagship case for the axis and the vendor has published no position on it. The agent researches a prospect, writes to them and follows up, under a sender identity the customer configures, and nothing states whether the recipient is told they are corresponding with software or on whose behalf it acts.
The European Commission's final Article 50 guidelines, published 20 July 2026 for obligations in force from 2 August, apply the disclosure duty wherever contact with a person is reasonably foreseeable and expect an agent to identify both its artificial nature and the party it acts for, with the marking obligation resting principally on the provider of the system rather than the customer deploying it. Exposure runs to 15 million euro or 3 percent of worldwide turnover.
The deepest integration surface in go to market software, and documented to a level nothing else here matches. A public application marketplace with thousands of listings, comprehensive published API references, and an agent model that converts a customer's existing automations, prompt templates, Apex classes and API endpoints into callable agent actions without a separate integration build. Grounding runs through the customer's own data platform, which itself carries documented connectors into external systems.
Multi tenant cloud on the vendor's own infrastructure platform, with prompts processed inside that platform before being forwarded to a model provider over a contracted connection, which is a clearer account of the AI data path than any peer publishes. Regional deployment is available across a substantial set of countries.
Short of the top band because the residency picture for the agent layer specifically, as distinct from the underlying platform, is assembled from architecture documentation rather than stated as a residency commitment a buyer can read in one place.
A long standing public trust site with compliance documentation, real time service status, and a product level security privacy and architecture document that names the agent products explicitly. Platform security practice is described in operational terms rather than as badges: security testing, site reliability, disaster recovery, least privileged access, role and attribute based access control, and audit logging of AI interactions. All of it is readable by an outsider before any commercial conversation.
Unusually good disclosure at the agent layer and a load bearing exclusion underneath it. Published: roughly 2 dollars per conversation, Flex Credits at 500 dollars per 100,000, a rate card giving 20 credits for a standard action and 30 for a voice action, per user licensing from around 125 dollars a month, a free tier with included credits, and a usage wallet for tracking consumption. What is not published is the dependency that dominates the bill.
The agent layer leans on the vendor's data platform for grounding, and independent guides consistently report that line as the largest and least predictable component, with entry list prices in the tens of thousands of dollars a year growing into six figures. Buyers price the agent and are surprised by the data.
Export capability is real and long documented: scheduled data export, bulk APIs and a large partner tooling ecosystem for extraction, and the underlying records are the customer's own CRM objects rather than a proprietary derived store. The master services agreement is published rather than behind a sales process.
What is not published in a form a buyer can plan around is the agent layer specifically: what happens to conversation logs, audit trails, agent configurations and consumed credit entitlements at termination, and whether grounding artefacts in the data platform leave with the customer.
The gap that matters most for this product category. An SDR agent researching accounts and sending sequences at machine speed puts a customer's sending reputation directly in the hands of an autonomous system, and nothing published describes warmup, volume governance, rotation, spam rate monitoring or what happens when reputation degrades under agent driven volume.
Cost modelling from implementation partners notes that a single SDR sequence can run thirty five or more actions, which is a useful proxy for send velocity and an unhelpful one for reputation. Deliverability is not addressed as an operating discipline anywhere in the agent documentation.
Coverage is comprehensive and evidenced beyond dispute: every segment from small business to global enterprise, every major industry with dedicated product and compliance material, operations and regional infrastructure across the Americas, Europe and Asia Pacific, extensive localisation, and a customer base and review corpus in the tens of thousands for the underlying sales product. The intended buyer for the agent layer specifically is narrower than the platform's reach, since it requires an existing platform foundation, and that dependency is stated.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.