Home / Companies / P0 Security / Blog / Post Details
Content Deep Dive

Agentforce and Cortex aren’t SaaS features, they’re agent runtimes

Blog post from P0 Security

Post Details
Company
Date Published
Author
Neha Duggal
Word Count
1,001
Company Posts That Month
2
Language
English
Hacker News Points
-
Post removed?
No
Summary

Agentforce and Cortex are agent runtimes within SaaS platforms, not mere features, and their operations are invisible to traditional network-layer security tools, which are not designed to monitor internal platform activities. These agents, often created by business users through low-code builders, inherit the privileges of the roles that invoke them, allowing them to access sensitive data without crossing the network boundaries typically monitored by security systems. As companies increasingly deploy these agents, with projections indicating a significant rise in their usage by 2028, there is a growing concern about governance, with only a small percentage of organizations confident in their ability to manage such access effectively. Security challenges are highlighted by incidents like ForcedLeak and PipeLeak, which exploited vulnerabilities in Agentforce and Cortex, respectively, demonstrating the risks associated with their privileged access. To address these challenges, organizations are urged to treat in-platform agents as named non-human identities, applying strict role-scoping and lifecycle management practices, conducting thorough security reviews before activation, and monitoring agent activity as part of their identity governance processes.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 3 7,668 844 209 +8%
AI Agents 2 6,119 1,396 266 +24%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.