A Salesforce administrator is building an Agentforce Agent to assist customers with product recommendations. The agent must use a large language model to generate personalized suggestions based on customer purchase history. The administrator wants to ensure that sensitive customer data, such as credit card numbers, is not exposed to the external LLM. Which feature should the administrator configure?
The Einstein Trust Layer is designed to securely handle data sent to external LLMs. It provides data masking, zero-data retention, and audit trails. By configuring masking rules for sensitive fields like credit card numbers, the administrator ensures that such data is replaced with placeholder tokens before being sent to the LLM. This protects customer privacy while still allowing the agent to generate recommendations based on non-sensitive data.
Why this answer
The Einstein Trust Layer is the correct feature to prevent sensitive data from being exposed to external LLMs. It allows administrators to define masking rules that replace sensitive information with placeholders before the data is sent. This ensures that the LLM never sees actual credit card numbers while still enabling the agent to generate personalized recommendations based on other data.
Exam trap
The trap here is confusing data-at-rest encryption or field-level security with data-in-transit masking for LLM interactions, which is uniquely handled by the Einstein Trust Layer.