Share

Only 14.4% of AI agents reach production with full security and IT approval, and 91% of teams find out what an agent did only after it already executed. Those two numbers describe the same problem from opposite ends. Agents are shipping without review, and the org has no way to see what they did until the damage is already in the log.

A Flow does the same thing every time. An agent does not. That single difference breaks the assumption underneath most Salesforce test plans, because a process built to confirm that something works cannot confirm that something never does what it should not. Geraint Waters has spent 13 years building test automation for Salesforce and previously ran QA for equity derivatives at Barclays Investment Bank, and in this session he walks the four places untested agents create exposure: permission inheritance through the running user, input paths that feed user-controlled data into agent context, the gap between sandbox conditions and production, and output scope, where an agent that can read a field is treated as an agent that should return it.

The platform gives you real tooling, and this session is specific about where that tooling stops. Agentforce Testing Center validates topic classification and action selection, which is functional behavior rather than security behavior. Einstein Trust Layer guardrails fire after the agent processes input, which makes them reactive rather than preventive. Setup Audit Trail records Setup changes rather than which records an agent queried. Trusted URLs block calls to unapproved domains without validating what data leaves in a call to an approved one.

That is where the OWASP Top 10 for Agentic Applications earns its place. Four of its ten risks map directly onto how agents behave in a Salesforce org, and the OWASP AI Testing Guide structures testing across application, model, data, and infrastructure layers. The framework tells you what to test. The scenarios stay yours to write against your own data model, permissions, and integrations. Geraint closes with a real finding from a public card-servicing agent that revealed an email address, phone number, and home address to a caller who had failed two of three identity checks, and with the language to use when leadership asks why testing needs more time.

What you will learn

  • Where untested AI agents create exposure in a Salesforce org, and why permission inheritance through the running user is the first place to look
  • How the four OWASP agentic risks that apply to Salesforce translate into testable scenarios: goal hijack, tool misuse, identity and privilege abuse, and memory and context poisoning
  • What Agentforce Testing Center, Einstein Trust Layer guardrails, Setup Audit Trail, and Trusted URLs each cover, and what none of them cover
  • How to structure a test process across four stages, from written scope before sandbox through scheduled re-runs that catch model drift after deployment
  • Why an agent test plan needs a named owner, and what happens to it when nobody owns it
  • Five questions to ask before any agent goes live, and how to frame scope rather than time when you need leadership to hold a release

Resources discussed in this session

The OWASP Top 10 for Agentic Applications and the AI Testing Guide v1 are both free, peer-reviewed by more than 100 researchers, and the backbone of the approach in this session.

The OWASP AI Testing Guide project page is where the guide’s four-layer methodology and current version live.

The OWASP Web Security Testing Guide remains the reference for the application layer underneath any agent you deploy.

Salesforce AI Research published an Agentforce test skill that ties agent testing to OWASP, surfaced by an attendee during the session and worth building on rather than relying on alone.

The ForcedLeak disclosure from Noma Security documents the $5 chain through Web-to-Lead that Salesforce closed with Trusted URLs enforcement in September 2025.

Salesforce best practices for secure Agentforce implementation covers the platform side of the responsibility boundary.

Salesforce Ben on Agentforce testing best practices is the practitioner reference behind several points in this session.

Provar TrustAI ships adversarial probes modeled on the OWASP Agentic Top 10 and is where the card-servicing agent finding came from.

 

Your Salesforce data is invaluable—is it truly secure? If you are allowing users to upload files into your Salesforce orgs, you are risk of also uploaded viruses and consequential data breaches. Get in contact with us today. 

Share

Did you love this blog and wish there could be more?

It is our goal to keep you informed about everything you need to know about Salesforce security to keep your Salesforce data and company safe and secure by providing you with the highest quality of original content.

If this sounds good to you, then sign-up below to be one of the first to know when the next super awesome Salesforce security blog has been released.

Download your free guide today!

Learn if you are at risk and how to start protecting your users!

GET THE FACTS NOW