An administrator needs to ensure that an Agentforce Agent only accesses specific knowledge articles regarding internal HR policies. How should the administrator configure the agent's access?
Trap 1: Apply a Sharing Rule to the Knowledge object based on the Agent's…
Sharing rules in Salesforce govern record access for users, but they do not directly dictate the context of Agentforce retrieval. While profile-based access is a foundation, it is insufficient for filtering specific AI response capabilities without integrating the Agent Builder's specific Topic and Action configurations.
Trap 2: Configure a Permission Set specifically for the AI User with…
Granting broad read-only access to all articles fails to provide the granular filtering required for specific AI use cases. This approach lacks the ability to restrict by category or topic, potentially exposing sensitive information that the agent should not be authorized to surface to end users.
Trap 3: Update the Agent's system prompt to ignore any articles outside of…
Relying on system prompts for security enforcement is considered 'soft' security and is prone to prompt injection vulnerabilities. System prompts should be used for behavioral guidance rather than data access enforcement, as they do not provide a robust, programmatic way to restrict underlying data retrieval.
- A
Apply a Sharing Rule to the Knowledge object based on the Agent's User profile.
Why it fails: Sharing rules in Salesforce govern record access for users, but they do not directly dictate the context of Agentforce retrieval. While profile-based access is a foundation, it is insufficient for filtering specific AI response capabilities without integrating the Agent Builder's specific Topic and Action configurations.
- B
Use the Agent Builder to restrict the agent's access to specific Knowledge Data Categories.
Agent Builder allows administrators to define the scope of data retrieval by mapping Topics to specific Data Categories. By restricting the Data Category visibility within the agent's configuration, you ensure the agent only queries relevant and authorized knowledge articles during the conversation, maintaining strict organizational security boundaries.
- C
Configure a Permission Set specifically for the AI User with read-only access to all articles.
Why it fails: Granting broad read-only access to all articles fails to provide the granular filtering required for specific AI use cases. This approach lacks the ability to restrict by category or topic, potentially exposing sensitive information that the agent should not be authorized to surface to end users.
- D
Update the Agent's system prompt to ignore any articles outside of HR policy.
Why it fails: Relying on system prompts for security enforcement is considered 'soft' security and is prone to prompt injection vulnerabilities. System prompts should be used for behavioral guidance rather than data access enforcement, as they do not provide a robust, programmatic way to restrict underlying data retrieval.