// verdict · checked 2026-08-11 · Agentforce 3 (legacy agent builder docs)
Agentforce
Salesforce
The word 'agent' does more work in the keynote than the product does in prod.
- CAPABILITY
- 4/5 AGENT
- PROOF
- OPERATOR INSPECTABLEYou can run it and read the steps yourself — the record exists for whoever runs it
- TRACE ACCESS
- OPERATOR-OWNEDWhoever runs it holds the record; nothing is published
- LEASH
- Not measuredno execution record scored — measure it yourself
| LOOPSruns until doneyes | Atlas Reasoning Engine runs a ReAct loop out of the box: acts, checks result, decides next step at runtime, looping until the goal is met — variable step count, up to seven loops (a ceiling, which the rule allows). |
| CHOOSESpicks its own toolsyes | Atlas classifies the utterance to a subagent at runtime, then exposes that subagent's actions as tools the LLM "can subjectively choose to run based on the current context". |
| ACTSchanges the worldyes | Update Record ships as a standard action and custom actions invoke Flows/Apex/invocable methods under a licensed agent user, writing real CRM records logged in the audit trail. |
| RECOVERSfixes its own errorsno | No retry or error-handling construct is documented; failures route to the Escalation subagent and a human. |
| UNSUPERVISEDnobody watchingyes | Docs: Service Agents resolve cases autonomously 24/7 on messaging/voice channels; isConfirmationRequired is an optional per-action opt-in, so a documented mode completes full tasks with no per-action approval. |
Capability decisions combine documented behaviour and execution evidence. The proof label on each row shows which of the two decided it, and Leash is reported separately, only when it was measured from an execution record. Primary source: help.salesforce.com. Tested against: Agentforce 3 (legacy agent builder docs). Our confidence in this dossier: 6/10.
Can you see it work?
the weakest of the five grades aboveOPERATOR INSPECTABLE — You can run it and read the steps yourself — the record exists for whoever runs it. Trace access: OPERATOR-OWNED — Whoever runs it holds the record; nothing is published.
OTLP session trace export: turns, LLM calls, actions, scores (beta, 72h)
Where we looked: Salesforce Agent API guide, then 'Export Agentforce Session Tracing Data': GET /einstein/audit/otel/{session-id} returns OTLP spans of turns, LLM calls, actions. · see the evidence →
- 2026-08-113/5 WRAPPER WITH AMBITION → 4/5 AGENTUNSUPERVISED corrected to yes: Docs: Service Agents resolve cases autonomously 24/7 on messaging/voice channels; isConfirmationRequired is an optional per-action opt-in, so a documented mode completes full tasks with no per-action approval.editorial correction — no case was filed
- 2026-08-112/5 WRAPPER WITH AMBITION → 3/5 WRAPPER WITH AMBITIONLOOPS corrected to yes: Atlas Reasoning Engine runs a ReAct loop out of the box: acts, checks result, decides next step at runtime, looping until the goal is met — variable step count, up to seven loops (a ceiling, which the rule allows).editorial correction — no case was filed
Badges
earned, never for sale
These render from the live dataset, so a badge cannot outlive the verdict it claims. If the verdict changes the badge changes with it, and an unearned one returns 409 rather than an image. No sponsor can buy one, at any price.
Think this is wrong?
bring evidence, not opinionName the criterion and link a trace, a doc, or a recorded run that shows the behaviour. A verdict changed by evidence is the best thing that can happen to this site, and the change goes on the public record with your reason attached. Vendors are welcome, and a vendor's own filing is labelled as such rather than buried.