DEV Community

Ashapura Softech INC
Ashapura Softech INC

Posted on Originally published at ashapurasoftech.com AI-assisted

Agentforce Coworker Is Already On. Audit Your Sharing Model First

If your org runs Enterprise, Unlimited or Agentforce 1, there is a fair chance Agentforce Coworker is already live in your search bar. Salesforce started switching it on automatically from 10 August 2026, and it became part of AIforce on 15 September. Most admins are treating it as an AI feature to evaluate. It is more useful to treat it as something else: the most honest audit of your sharing model you will ever get.

Why Coworker exposes your sharing model

Coworker does not bypass security. It fully honors the existing Salesforce access model. A user asks a question in plain language and gets one written answer built from every record they are allowed to see.

That last part is the problem. In most orgs, "allowed to see" and "supposed to see" drifted apart years ago. Public Read/Write defaults set during a rushed go-live. Sharing rules nobody remembers creating. A permission set handed to a whole team because one person needed it once.

Classic search hid that drift, because a user had to know what to look for and open records one by one. Coworker removes the friction. It reads across accounts, opportunities, cases, custom objects, knowledge articles, Slack and connected Data 360 sources, then summarises. Anything over-shared is now one question away from being quoted back in a tidy paragraph.

So the first question is not "is the AI accurate?" It is "what can each role actually see?"

Check this before anyone else does

1. Confirm the status. Go to Setup, search "Agentforce Coworker" and see whether it is on. Automatic enablement skipped some orgs: those that opted out of generative AI, multi-dataspace or multi-org setups, HIPAA, health, life sciences and government orgs, and Flex Foundation seats without Unmetered entitlements. Do not assume either way.

2. Audit org-wide defaults on high-traffic objects. Opportunity, Case and any custom object holding pricing, margin or HR data. If the default is Public Read Only and it should be Private, fix it now.

3. List every sharing rule and who it opens records to. Pay attention to rules granting access to "All Internal Users" or a top-level role.

4. Check who holds the Access_Ai_Search permission set group. That assignment is what lets a user in. Start with a pilot group across a few roles, not the whole org.

5. Look at your Data 360 sources separately. Sources that are permission-aware enforce their own rules. Others need governance policies you create by hand in Data 360. An unconfigured connector is the easiest place to leak.

6. Clean duplicates on the objects people ask about most. A summarised answer built from three copies of the same account is confidently wrong.

Then test it by role, not by feature

Pick one user from sales, one from service and one manager. Ask each the same questions: "What are our largest open deals this quarter?" "What did we quote Acme last year?" "Which cases mention a refund?" Compare the answers. If a rep gets a figure only managers should see, you have found a sharing problem, not an AI problem, and it existed long before Coworker arrived.

What it costs, briefly

CRM and Slack search is included at no extra fee on eligible Unmetered seats. Answers that draw on Data 360 objects consume credits, and users without eligible seats are billed on credits too. Measure credit use during the pilot before you widen access.

Limits worth knowing

Updates work on Salesforce CRM records only, and ask the user to confirm first. There is a cap of 30 language model calls per minute per user, files over 75 MB are not indexed, the beta is English only, and it is not available in GovCloud except for Experience Cloud.

The takeaway

Coworker is only as trustworthy as the permissions underneath it. Spend the first week on who can see what, and the rollout after that becomes the easy part.

The full guide, including setup steps and fixes for the common Not Enabled, 401, 400, 500 and Invalid Token errors, is on our blog: Agentforce Coworker: What It Does, What It Costs and How to Turn It On.

Ashapura Softech is a certified Salesforce partner.

Top comments (0)