Agentforce and Cortex aren’t SaaS features, they’re agent runtimes
Blog post from P0 Security
Agentforce and Cortex are agent runtimes within SaaS platforms, not mere features, and their operations are invisible to traditional network-layer security tools, which are not designed to monitor internal platform activities. These agents, often created by business users through low-code builders, inherit the privileges of the roles that invoke them, allowing them to access sensitive data without crossing the network boundaries typically monitored by security systems. As companies increasingly deploy these agents, with projections indicating a significant rise in their usage by 2028, there is a growing concern about governance, with only a small percentage of organizations confident in their ability to manage such access effectively. Security challenges are highlighted by incidents like ForcedLeak and PipeLeak, which exploited vulnerabilities in Agentforce and Cortex, respectively, demonstrating the risks associated with their privileged access. To address these challenges, organizations are urged to treat in-platform agents as named non-human identities, applying strict role-scoping and lifecycle management practices, conducting thorough security reviews before activation, and monitoring agent activity as part of their identity governance processes.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.