AI SDR & Outbound Agents
A

Agentforce Sales

Salesforce's sales product line, rebranded from Sales Cloud as the agentic layer became the headline. The Agentforce agent set includes a Sales Development Rep agent that researches leads, drafts and sends outreach and books meetings, plus a Sales Coach agent for role play and deal guidance, all running on the underlying CRM and grounded in the customer's own records through Data Cloud. Agent behavior is governed by the Einstein Trust Layer and by admin defined topics, actions and engagement rules. Consumption is priced separately from the CRM seats, at roughly 2 dollars per conversation or through Flex Credits at 500 dollars per 100,000 credits, with a published rate card.

Last VerifiedAugust 18, 2026
Compare Agentforce Sales with other vendors
Founded
1999
Headquarters
San Francisco, California, United States
Categories
ai-sdr-agents, sales-engagement, revenue-intelligence
Assessment

Capability Axes

Capability grades

17 of 17 axes rated · 13 graded A or B

AI Capability
AI CentralityAI CentralityWhether AI is the product or a feature veneer. The removal test: peel the AI label off, and does anything sellable remain?
CC on AI CentralityAI features on a conventional platform. Peel the AI label off and the product still works roughly as before.
Vendor Published

The agent layer is genuine, separately licensed and metered by the action, which is a stronger AI claim than most vendors can make. It still sits on a customer relationship platform that has been the category standard since 1999 and that works completely without it.

The rename from Sales Cloud to Agentforce Sales moved the marketing, not the architecture: Agentforce is described by its own maker as the agentic layer of the existing platform, turning existing workflows, prompt templates, Apex and APIs into agent actions. Peel the agents off and the CRM, pipeline, forecasting and reporting are untouched. The three largest incumbents in this index all land here for the same reason.

Autonomy and Oversight ModelAutonomy and Oversight ModelWhat the system does without a human. Draft for review, auto send, or fully agentic, and what contains a bad run.
AA on Autonomy and Oversight ModelThe autonomy boundary is published: what acts without review, what requires approval, what a bad run can and cannot do, and the controls that stop a batch mid flight.
Vendor Published

The most completely published autonomy boundary in the index so far. The SDR agent type carries admin defined engagement rules setting the conditions under which the agent may begin working a lead and how and when its emails may be sent, including preventing outreach to restricted leads.

Behaviour is scoped by topics, actions and instructions rather than open ended prompting, guardrails combine customer defined safeguards with vendor managed protections, and a response that violates a guardrail is withheld rather than shown. Human in the loop approval and escalation can be required by risk or sensitivity, and an audit trail captures agent actions and outputs for governance review.

AI Disclosure and Model TransparencyAI Disclosure and Model TransparencyWhat models power the product, whether AI generated outreach discloses itself, and whether scoring and routing logic is explainable.
BB on AI Disclosure and Model TransparencyMeaningful disclosure of the model stack or the disclosure posture, with one real gap, commonly silence on whether AI authored outreach identifies itself.
Vendor Published

The architecture is documented to a level competitors do not approach: a published trust layer description covering dynamic grounding, secure data retrieval, prompt defence, toxicity detection and audit logging, a separate platform security privacy and architecture document, and third party model providers named in the sub processor documentation rather than left as generic AI. Two gaps hold it below the top band.

Specific models and versions behind particular agent actions are not enumerated, and the vendor's own privacy material notes that data masking, a headline trust layer control, is currently disabled for this product.

Operational and Outcome EvidenceOperational and Outcome EvidenceMeasured outcomes with a stated basis: replies, meetings, pipeline, win rates. Logos are not evidence and prestige is not measurement.
CC on Operational and Outcome EvidenceOutcome claims are headline percentages with no stated basis, or customer logos standing in for results.
Third Party Estimated

Marketing volume is high and measurement basis is absent, and the most decision relevant evidence available points the other way. Independent 2026 reporting puts typical implementation at five to eleven months and reports that fewer than ten percent of customers have the agent layer fully scaled.

For a buyer, the question is not whether the technology works in a demonstration but what proportion of comparable deployments reached production and on what timeline, and the vendor publishes nothing that answers it. Cost modelling guidance from implementation partners is more specific about real agent behaviour than the vendor's own outcome claims.

Compliance and Risk
Outreach Compliance PostureOutreach Compliance PostureHow the product handles regulated outreach: consent, DNC scrubbing, opt out mechanics, caller ID conduct, and the public enforcement record.
BB on Outreach Compliance PostureSubstantive compliance features documented in product, but material questions (litigation history, caller ID practices, where responsibility transfers to the customer) go unaddressed.
Vendor Published

Real controls exist at the point where they matter, in the agent's engagement rules: which leads qualify, when the agent may begin, and how and when it may send, with restricted lead suppression called out as a control. Role and attribute based access can gate agent behaviour by geography or compliance status. What is missing is the regulatory layer stated plainly for the agent context.

Nothing published addresses CAN SPAM mechanics, opt out propagation or consent verification specifically for agent generated outreach, which is the obligation a customer takes on when an agent sends at machine speed.

Data Privacy PostureData Privacy PostureGDPR and CCPA posture: lawful basis, data subject rights handling, DPA availability, subprocessor disclosure.
AA on Data Privacy PostureGDPR and CCPA posture documented with specifics: lawful basis stated, DSR handling described, DPA published and signable, subprocessors listed.
Vendor Published

The strongest privacy documentation set in the index so far, and it is product specific rather than corporate boilerplate. A dedicated privacy FAQ for the agent products states plainly which branded agents fall within the services definition of the master services agreement and therefore under the published data processing addendum. Sub processors are documented separately and the agent products are mapped to that documentation. Grounding through the customer's own data platform is described rather than implied. The processor boundary remains, as it must: lawful basis for the records loaded is the customer's to establish.

Data Licensing and ProvenanceData Licensing and ProvenanceWhere the data comes from and on what legal footing: licensed, contributed, public record, or scraped, and who stands behind the answer.
BB on Data Licensing and ProvenanceProvenance is substantively described but incompletely: sourcing classes named without the legal footing, or indemnification unstated.
Vendor Published

No prospect database is bundled with the product. The agent works the customer's own records, grounded through the customer's data platform instance using retrieval over structured and unstructured company data, and the origin of that material is the customer's own systems. Provenance is therefore clear by construction.

Short of the top band because the platform's wider data ecosystem admits partner sourced data and no single published statement establishes the licensing footing for enrichment that reaches an agent through those channels.

Platform Terms ExposurePlatform Terms ExposureWhether the product operates inside the terms of the platforms it touches, and the restriction risk a buyer inherits when it does not.
BB on Platform Terms ExposureThe method is described and mostly conformant, with one real ambiguity the vendor does not resolve, or conformance asserted without the partnership evidence that would settle it.
Vendor Published

Effectively none of the exposure this axis was written to catch. The agent operates inside the vendor's own platform, actions are built from the customer's existing flows, Apex and APIs, and third party systems are reached through documented interfaces and a first party application marketplace. No automation of a platform that prohibits it. No conformance position of its own is published, so the grade reflects architecture rather than a stated commitment.

AI Safety and Data StewardshipAI Safety and Data StewardshipThe cross client boundary: whether customer data trains models that serve competitors, plus retention and deletion posture.
AA on AI Safety and Data StewardshipThe cross client boundary is answered in writing: whether customer data trains shared models, with opt out or contractual exclusion documented, plus retention and deletion specifics.
Vendor Published

The cross client question is answered contractually and specifically. The vendor states it holds zero data retention agreements with the third party model providers it uses, so customer data is neither retained by those providers nor used to train their models, and the agent products are named inside the master services agreement and its data processing addendum rather than left to inference.

Toxicity detection, prompt defence and audit logging of AI interactions are documented as architecture, not aspiration. One caveat the vendor discloses itself and a buyer should carry into a security review: data masking, one of the trust layer's headline protections, is currently disabled for this product.

Recipient Disclosure and AuthenticityRecipient Disclosure and AuthenticityHow the product presents itself to the people it targets: whether automated outreach and AI agents disclose themselves, whether sender personas are real, and whether personalization is grounded in verifiable fact. Measured as known compliance with Article 50 of the EU AI Act, in force since August 2, 2026, which requires AI systems that interact with individuals to disclose that fact.
CC on Recipient Disclosure and AuthenticityNothing published on whether recipients are told they are dealing with software. For a product whose AI talks to prospects, silence here is now a regulatory posture, not a style choice.
Regulatory or Legal Record

This is the flagship case for the axis and the vendor has published no position on it. The agent researches a prospect, writes to them and follows up, under a sender identity the customer configures, and nothing states whether the recipient is told they are corresponding with software or on whose behalf it acts.

The European Commission's final Article 50 guidelines, published 20 July 2026 for obligations in force from 2 August, apply the disclosure duty wherever contact with a person is reasonably foreseeable and expect an agent to identify both its artificial nature and the party it acts for, with the marking obligation resting principally on the provider of the system rather than the customer deploying it. Exposure runs to 15 million euro or 3 percent of worldwide turnover.

Integration and Deployment
Ecosystem and Integration DepthEcosystem and Integration DepthDocumented depth of CRM and stack integration: objects, sync direction, API surface, marketplace presence that matches the claims.
AA on Ecosystem and Integration DepthDeep, documented, bidirectional integration with the systems of record: named CRM objects and sync behavior, a public API with real docs, and a marketplace presence that matches the claims.
Vendor Published

The deepest integration surface in go to market software, and documented to a level nothing else here matches. A public application marketplace with thousands of listings, comprehensive published API references, and an agent model that converts a customer's existing automations, prompt templates, Apex classes and API endpoints into callable agent actions without a separate integration build. Grounding runs through the customer's own data platform, which itself carries documented connectors into external systems.

Deployment Model and Data ResidencyDeployment Model and Data ResidencyWhere the product runs and where customer data lives, including residency options for EU buyers.
BB on Deployment Model and Data ResidencyThe deployment model is clear and residency options are partially specified.
Vendor Published

Multi tenant cloud on the vendor's own infrastructure platform, with prompts processed inside that platform before being forwarded to a model provider over a contracted connection, which is a clearer account of the AI data path than any peer publishes. Regional deployment is available across a substantial set of countries.

Short of the top band because the residency picture for the agent layer specifically, as distinct from the underlying platform, is assembled from architecture documentation rather than stated as a residency commitment a buyer can read in one place.

Security Certifications and Trust CenterSecurity Certifications and Trust CenterVerifiable security posture: enumerated current certifications and a trust center an outsider can actually read.
AA on Security Certifications and Trust CenterA live trust center with enumerated, current certifications (SOC 2 Type II and peers), audit recency visible, and security practices documented beyond the badge.
Vendor Published

A long standing public trust site with compliance documentation, real time service status, and a product level security privacy and architecture document that names the agent products explicitly. Platform security practice is described in operational terms rather than as badges: security testing, site reliability, disaster recovery, least privileged access, role and attribute based access control, and audit logging of AI interactions. All of it is readable by an outsider before any commercial conversation.

Commercial and Operational
Commercial TransparencyCommercial TransparencyWhether a buyer can budget without a sales call. Published pricing graded on completeness, not on the price itself.
BB on Commercial TransparencyPartial pricing published (entry tiers real, enterprise opaque) or pricing published with load bearing exclusions.
Vendor Published

Unusually good disclosure at the agent layer and a load bearing exclusion underneath it. Published: roughly 2 dollars per conversation, Flex Credits at 500 dollars per 100,000, a rate card giving 20 credits for a standard action and 30 for a voice action, per user licensing from around 125 dollars a month, a free tier with included credits, and a usage wallet for tracking consumption. What is not published is the dependency that dominates the bill.

The agent layer leans on the vendor's data platform for grounding, and independent guides consistently report that line as the largest and least predictable component, with entry list prices in the tens of thousands of dollars a year growing into six figures. Buyers price the agent and are surprised by the data.

Exit and Data PortabilityExit and Data PortabilityWhat happens when a customer leaves: completeness of data export, rights to enriched or licensed data after termination, deletion commitments, and auto renewal mechanics, graded from published terms and documentation.
BB on Exit and Data PortabilityReal export capability documented, with a material exit question unstated in public terms, commonly post termination rights to licensed or enriched records.
Vendor Published

Export capability is real and long documented: scheduled data export, bulk APIs and a large partner tooling ecosystem for extraction, and the underlying records are the customer's own CRM objects rather than a proprietary derived store. The master services agreement is published rather than behind a sales process.

What is not published in a form a buyer can plan around is the agent layer specifically: what happens to conversation logs, audit trails, agent configurations and consumed credit entitlements at termination, and whether grounding artefacts in the data platform leave with the customer.

Deliverability and Sending DisciplineDeliverability and Sending DisciplineThe operational craft of sending: warmup, rotation, volume governance, spam rate monitoring, and what happens when reputation degrades.
CC on Deliverability and Sending DisciplineDeliverability is invoked as a benefit with no documented mechanism. For senders this is the axis where marketing most outruns evidence.
Vendor Published

The gap that matters most for this product category. An SDR agent researching accounts and sending sequences at machine speed puts a customer's sending reputation directly in the hands of an autonomous system, and nothing published describes warmup, volume governance, rotation, spam rate monitoring or what happens when reputation degrades under agent driven volume.

Cost modelling from implementation partners notes that a single SDR sequence can run thirty five or more actions, which is a useful proxy for send velocity and an unhelpful one for reputation. Deliverability is not addressed as an operating discipline anywhere in the agent documentation.

Segment and Market CoverageSegment and Market CoverageWho the product actually serves, evidenced: segments, geographies, languages, and customers that match the claim.
AA on Segment and Market CoverageWho the product serves is stated with evidence: segments, team sizes, geographies, and languages, with named customers that match the claim.
Vendor Published

Coverage is comprehensive and evidenced beyond dispute: every segment from small business to global enterprise, every major industry with dedicated product and compliance material, operations and regional infrastructure across the Americas, Europe and Asia Pacific, extensive localisation, and a customer base and review corpus in the tens of thousands for the underlying sales product. The intended buyer for the agent layer specifically is narrower than the platform's reach, since it requires an existing platform foundation, and that dependency is stated.

Head to Head

Compared With

Editorial comparisons are published only where the index assesses two vendors as direct competitors for the same buyer. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.

Commercial

Pricing

What this vendor charges, what it commits to in writing, and where the bill can move. Figures the vendor publishes itself are labeled Vendor Published. Figures labeled Estimated come from other sources and the vendor has not confirmed them.

What it costs
Vendor Published
From $550 per user monthly on the top edition
agent actions metered separately at $0.005 per credit
$550 lowest published figure
In short
  • ›The top edition is from $550 per person a month. Several other editions sit below it, published from $100, $125, $200 and $220 per person a month, and partner access is $10 per login instead of per person.
  • ›Agent work is charged separately by the action, and this is where the company does something almost nobody else does. It publishes what each kind of action costs and then works the sums out for you.
  • ›For example, a sales request costs 40 credits or 20 cents, and it shows that twenty of those a day for a month comes to $120. A service case at 60 credits is 30 cents, and a hundred people doing three a day for twenty days comes to $1,800.
  • ›That works out at half a cent per credit, credits are sold in blocks of a hundred thousand, they are priced in four currencies, and there is a calculator on the page.
  • ›Two cautions. Every seat price says from rather than being a fixed rate, and the included credit allowances are described differently on different pages, so get both in writing.

How the price works

What you are charged for, and what makes the bill go up.

Per user editions with agent activity metered separately on a pay per action basis. The top edition is published from $550 per user monthly with the agent add on included and 2.5 million credits per organization annually. Sibling products on the same platform are published from $100, $125, $200 and $220 per user monthly, with a partner access license at $10 per login monthly and a data synchronization add on at $25 per user monthly. A further edition is described as carrying unmetered agent usage for employees together with 1 million credits and 2.5 million data credits per organization annually. Every seat figure is stated as a starting rate rather than a fixed one.

Agent consumption runs on credits sold in blocks of one hundred thousand, quoted in United States dollars, euros, Australian dollars and Japanese yen. The vendor publishes five worked action examples, each giving the credits consumed, the cost per action, the monthly credit volume and the monthly total:

A sales request at 40 credits and $0.20 per action, at 20 requests daily over 30 days, totaling 24,000 credits and $120 monthly. A service case action at 60 credits and $0.30, at 3 cases daily over 20 days across 100 users, totaling 360,000 credits and $1,800 monthly. A field scheduling action at 100 credits and $0.50, at 3 appointments daily over 20 days across 10 representatives, totaling 60,000 credits and $300 monthly. An internal employee question at 20 credits and $0.10, at 5 questions monthly across 20 new employees, totaling 2,000 credits and $10 monthly. A voice action at 120 credits and $0.15, across 300 calls monthly, totaling 36,000 credits and $180 monthly.

Every example resolves to a consistent unit price of $0.005 per credit. A credit calculator is published alongside them, and the vendor states that the examples are illustrative. Limited credit allowances are included with certain editions and additional credits are available for purchase.

The trial is 30 days with no credit card and no installation. The vendor states that most of its products run on annual contracts, that subscription terms vary by product, and that billing arrangements are settled with a sales representative.

What the contract says about your data

What the vendor commits to in writing once your data is in the product.

Not established from the pricing surfaces, and this record should not be read as a finding either way. The vendor operates one of the largest published trust and compliance programs in enterprise software, and none of it was reached from the pricing pages examined here, which carried no security, processing or subprocessing links in the material retrieved.

What can be said from what was retrieved is limited to contract shape rather than data handling. Most products are stated to run on annual contracts with terms varying by product, and payment and billing arrangements are directed to a sales conversation rather than published.

The custody question for the agent product specifically is different from the platform it sits on and worth naming. An autonomous agent acting on sales records does not merely store customer data, it reads it, reasons over it and takes actions with it, and on the consumption model described below every one of those actions is metered and therefore logged. A buyer should establish what is retained from agent reasoning and action histories, where that sits relative to the record data, and whether it is covered by the same terms. Nothing reached here addresses it, and that is a retrieval limitation rather than an absence given the scale of this vendor's published compliance material elsewhere.

Getting started

What it costs and what is included before the product is running.

Not published. No setup fee, onboarding charge, migration rate or professional services rate was located on any pricing surface reached, and for a platform of this scale professional services are ordinarily a substantial and separately contracted engagement. A buyer should assume that line exists and obtain it as a quote.

The trial is thirty days with no credit card and no installation required, which is longer than any other trial recorded in this tranche and appropriate to a product that takes real configuration before it demonstrates anything.

Contract terms are directed rather than published. The vendor states that most of its products run on annual contracts, that subscription terms vary by product, and that payment and billing arrangements should be discussed with a sales representative. For a buyer, that means the published seat figures are entry points into a negotiation rather than a checkout price, which the pricing surfaces signal by stating every seat rate as a starting figure rather than a rate.

The cost that can be modeled precisely is agent consumption, and it is the one this vendor handles best. Credits are sold in blocks of one hundred thousand, priced in four currencies, at an implied half a cent each. Every published action example converts directly into a monthly figure, so a buyer who can estimate their action volume can estimate their bill before speaking to anyone. Included allowances come with the upper editions and additional credits are available for purchase.

One further add on is published at $25 per user monthly for data synchronization and harmonization capability, and a partner access license is published at $10 per login monthly, which is a different unit from the per user rates and suits intermittent external users.

What to watch for

Where this pricing can surprise a buyer who has not read it closely.

Your brief flagged this vendor as publishing nothing usable on price. It publishes the most complete consumption arithmetic in this index.

The headline is a seat rate of $550 per user monthly for the top edition, which is a real published figure. But the interesting disclosure is the layer beneath it. This vendor sells autonomous agent activity on a pay per action basis, and rather than describing that model and leaving a buyer to guess, it publishes the credit cost of individual action types alongside worked monthly totals.

Five examples are published in full, each showing the credits an action consumes, the resulting cost per action, the monthly credit volume and the monthly bill. A sales request at 40 credits and $0.20 per action, twenty times daily across thirty days, is shown as 24,000 credits and $120 monthly. A case management action at 60 credits and $0.30, three times daily across twenty days for a hundred users, is shown as 360,000 credits and $1,800 monthly. A scheduling action at 100 credits and $0.50, three times daily across twenty days for ten field representatives, is shown as 60,000 credits and $300 monthly. An internal question at 20 credits and $0.10, five times monthly for twenty new employees, is shown as 2,000 credits and $10 monthly. A voice action at 120 credits and $0.15 across three hundred calls is shown as 36,000 credits and $180 monthly.

Those examples imply a consistent unit price of half a cent per credit, and the vendor sells credits in blocks of one hundred thousand quoted in four currencies. A calculator is published alongside them.

That is the single most useful thing a metered vendor can do and almost nobody in this index does it. The recurring failure across this tranche has been vendors publishing a credit allowance and never defining what a credit buys. This vendor publishes the allowance, the per action consumption, the unit rate, the currency ladder and a calculator, and then works three of the examples out loud.

The finding for your purposes is therefore a correction to the index's own prior view. The prediction that this vendor discloses heavily on every axis except price no longer holds for the agent product. It discloses price mechanics better than most vendors here disclose their tier tables.

Two qualifications a buyer still needs. The seat figures are all stated as from rather than as rates, so the published number is a floor rather than a price, and the vendor directs contract and billing terms to a sales conversation while stating that most products run annually. And the included credit allowances differ between editions in ways the pricing surfaces state without reconciling, with one edition described as carrying one million credits and two and a half million data credits per organization annually and another as carrying two and a half million credits per organization annually, so a buyer comparing editions on included consumption should get the figures confirmed in the order form.

The numeric field carries $550, the published seat rate for the top edition, recorded knowing it is stated as a starting figure.

Contact us

Found a vendor we missed? Have feedback on the index? We’d love to hear from you.