Dreamforce 2026 Security Keynote: What Enterprises Need to Know About Agent Security
Dreamforce 2026's Security Keynote, "Trust Across Agents, Data, and Platforms," made one thing explicit: Salesforce is no longer positioning itself as a CRM company that happens to do security. It is positioning itself as a security company. That shift matters because the reasoning behind it is sound. Autonomous agents now operate continuously, without a human logging in, which breaks the perimeter-based security model most enterprises still run on. You cannot secure a login event that never happens.
Here is what was actually announced, organized around the three pillars Salesforce built the keynote on.
The three pillars
| Pillar | Focus | Key tools announced |
|---|---|---|
| Data Security | Protecting the data agents touch | Data 360, Unstructured Data Governance |
| Platform Security | Aggregating risk signals across the stack | Security Center, Security Mesh, Red Team Agent |
| Agent Security | Governing autonomous agents directly | Agentic Identity, Observability Center, Agent Kill Switch |
Image credit: Salesforce
Data Security
The starting position: an agent should only ever access what it strictly needs, nothing more. Data 360 combined with the new Unstructured Data Governance capability lets organizations discover, classify, and apply guardrails to sensitive data before an agent ever touches it.
This is the least flashy part of the keynote and the most foundational. Agent identity and kill switches matter less if the underlying data access was never scoped correctly in the first place.
Platform Security
Security Center and Security Mesh pull signals from across the enterprise stack, including third-party tools like CrowdStrike and Okta, into a single view. The goal is one place to see risk across the platform rather than stitching together alerts from five different consoles.
The new piece here is the Red Team Agent: an automated tool that proactively stress-tests security configurations rather than waiting for a human red team exercise or, worse, a real incident. Automated adversarial testing of your own agent setup is a meaningful shift from reactive to proactive posture, if it holds up in practice.
Agent Security
This is where the keynote answered the questions the industry had been asking going into Dreamforce. Three tools:
Agentic Identity. Verifiable access control for agents, giving each agent a distinct, auditable identity rather than a shared service credential.
Observability Center. Traces agent behavior so security teams can see what an agent did and why, not just that it ran.
Agent Kill Switch. Immediate, granular termination of a specific rogue agent, without having to shut down the whole system around it.
Granular is the operative word on the kill switch. A blunt off-switch for all agents is not a serious enterprise control. The ability to isolate and terminate one agent while the rest of the environment keeps running is what makes this usable in production.
Enterprise Trust: the Anthropic partnership
Salesforce and Anthropic introduced Enterprise Frontier Safeguards, a step beyond standard zero-data-retention practice. Rather than discarding interaction logs entirely, organizations can retain control over their own data logs while using frontier models, which allows detection of sophisticated, long-term attack patterns that a strict no-retention policy would miss.
This is worth sitting with for a moment. Zero data retention has been the default trust signal for enterprise AI for a couple of years now: don't keep the data, and there's nothing to leak. Enterprise Frontier Safeguards is a bet that visibility into long-running patterns is worth more than the simplicity of "we keep nothing." That is a reasonable trade-off for a security team, but it does shift the responsibility for governing those logs onto the organization, not the model provider. Worth confirming exactly what log retention and access controls look like before assuming this is a strict upgrade over zero retention in every scenario.
How Salesforce uses this internally
Salesforce's own security operations center runs on the same tooling, including a purpose-built SOC agent named Calli, which helps analysts triage incidents, visualize threats, and respond faster. Using your own product internally, and saying so on stage, is a reasonable credibility signal. It is not independent verification, but it is more than most vendors offer.
Image Credit: Salesforce
What enterprises should actually do with this
Start with Data Security, not Agent Security. Agentic Identity and the Kill Switch are only as good as the data scoping underneath them. If Unstructured Data Governance isn't configured correctly, an agent with a clean identity can still touch data it shouldn't.
Get the Red Team Agent details before you rely on it. Automated stress testing is only useful if it tests realistic attack patterns, not a checklist. Ask what it actually simulates.
Clarify Enterprise Frontier Safeguards log ownership. If you're moving off zero data retention, know exactly who can access those logs, for how long, and under what conditions, before you adopt it as your new default.
Pricing was not disclosed in the keynote for any of these tools. Data 360, Security Center, Security Mesh, and Agentforce pricing generally sits in existing Salesforce licensing tiers, but Red Team Agent, Observability Center, and Agentic Identity as standalone capabilities did not have confirmed pricing in this session. Don't budget against assumed cost until your account team confirms tier placement.
The bottom line
This keynote answered real, previously open questions: agent identity is now a named, purchasable capability, not a promise. Observability and kill switches give security teams actual levers, not just dashboards. The Anthropic partnership signals movement past zero-retention-as-default toward something more nuanced.
The open item is cost and packaging. Confirm what's bundled into existing tiers versus what requires new spend before you build a rollout plan around this.
As a Salesforce partner, we help enterprises connect their unified customer data with trusted AI agents that can assist, take autonomous action, and seamlessly hand off to employees across sales, service, marketing, commerce, and more.
Dreamforce 2026 Knowledge Hub:
Salesforce Dreamforce 2026 Main Keynote: Everything You Need to Know (Day 1)
AIforce: Salesforce's Big Dreamforce 2026 Announcement, Explained
Dreamforce 2026 Complete Guide
Frequently Asked Questions
-
Salesforce Guardian is the umbrella for the company's data protection tooling, spanning Data Security (Shield, Security Center), Data Compliance (Privacy Center, Data Mask & Seed), and Data Resilience (Backup & Recover, Archive). Salesforce cites 24,000 customers protected globally under this framework.
-
Discover, Classify, and Protect. Discover surfaces permission-aware data for agents to reason and act on. Classify automates sensitive data classification and unified access control across all data sources. Protect streamlines policy management with attribute-based access control across the data landscape.
-
It gives each AI agent a distinct, verifiable, auditable identity rather than a shared service credential. This is what makes it possible to trace or isolate a specific agent's actions instead of treating all agent activity as one undifferentiated stream.
-
It allows immediate, granular termination of a single rogue agent without shutting down other agents or the broader system. Granularity is the key feature, it's not an all-or-nothing off switch.
-
Not by default. Enterprise Frontier Safeguards, from the Salesforce and Anthropic partnership, lets organizations choose to retain more visibility into logs than a strict zero-data-retention policy would allow, specifically to catch long-term attack patterns. This is opt-in nuance, not a change to Salesforce's baseline retention stance.
-
Pricing for the specific new tools (Red Team Agent, Observability Center, Agentic Identity as standalone capabilities) was not disclosed in the keynote. Data 360, Security Center, and Security Mesh generally sit within existing Salesforce licensing tiers. Confirm tier placement with your account team before budgeting.
-
The identity and observability tooling matters most once you're past a handful of agents in production; that's where governance typically breaks down. If you're early stage, prioritize Data Security (Discover, Classify, Protect) first since it's the foundation everything else depends on.
Related Readings
Let’s Talk
Drop us a note, we’re happy to take the conversation forward 👇🏻

