Skip to content
ITECS
Data & AI ReadinessAugust 17, 202610 min read

Agentforce Coworker: Prepare for Auto-Enablement

Agentforce Coworker is rolling out automatically for eligible Salesforce users. Use this readiness checklist to control access, data, quality, and cost.

Salesforce administrators should treat Agentforce Coworker's automatic enablement as a scheduled access change, not a completed governance decision. Salesforce says eligible organizations began receiving the feature on a rolling basis on August 4, 2026. Before users rely on it, leaders should confirm who is affected, narrow what each person can search, test answers against approved records, verify credit behavior, and name the people who own quality and escalation.

Automatic availability means eligible users may see Agentforce Coworker without an administrator manually launching the feature. It does not authorize the company to expose sensitive CRM, Slack, or Data 360 content, expand a user's underlying permissions, or let an AI agent take consequential action without review. Existing access may be technically respected and still be too broad, stale, or inappropriate for AI-assisted discovery. Governance must decide what availability alone cannot.

What Salesforce is enabling

Salesforce's automatic-enablement FAQ says the rollout applies to users with unmetered user-based AI entitlements. Administrators receive an email before enablement. In eligible organizations, an in-product banner confirms activation, an Ask button appears near Global Search, and Ask and Search modes can return AI-generated answers alongside permission-aware search results.

This is not a universal Salesforce change. The FAQ excludes organizations that have disabled generative AI, organizations with multi-dataspace or multi-org topologies, HIPAA, Health and Life Sciences, and government organizations, and usage-based Flex Foundation seats without unmetered user-based AI entitlements. Administrators should verify their own contract, org topology, AI settings, and notification rather than infer eligibility from an edition name.

Users who receive eligible entitlements after their organization's automatic-enablement period do not necessarily receive Coworker access automatically. Salesforce says administrators must manually provide those users access. That makes seat changes, new hires, transfers, and license removal part of the ongoing joiner-mover-leaver process.

The Summer '26 release notes describe Agentforce Coworker as a beta capability connected to Salesforce CRM with optional connections to Slack and Data 360. They also describe action-oriented behavior such as orchestrating agents and completing tasks. Search availability and action authority should therefore be governed separately. A user who may ask about an account does not automatically need authority to update it, message a customer, or invoke another agent.

Automatic availability is not data approval

Salesforce says Coworker respects user access permissions, existing governance, and data classification. That is an important enforcement layer, but it does not prove that today's permissions are appropriate. A sales manager may legitimately have broad access for an old reporting process. A shared Slack channel may contain confidential discussions. A default Data 360 data space may combine indexed material from systems with different owners and retention rules.

AI-assisted search can make already-permitted information easier to discover, combine, and summarize. The control question is therefore not only, 'Can Salesforce enforce this permission?' It is, 'Should this user receive this answer in this business context, from these records, for this purpose?' A focused data and AI readiness audit should resolve stale roles, inherited sharing, overshared channels, duplicate records, and unclear data ownership before broad rollout.

The nine-decision readiness checklist

Use this matrix before accepting automatic enablement for a broad population. Each decision needs an accountable owner and retained evidence. A setup toggle is not evidence that the control works.

Nine Agentforce Coworker readiness decisions with the required administrator action and launch evidence for each.
DecisionAdministrator actionLaunch evidence
Eligible usersReconcile unmetered seats, access assignments, roles, and statusNamed user list, entitlement source, exceptions, and owner
Search sourcesApprove CRM objects; review Slack and Data 360 separatelySource register, data owner, classification, and retention rule
Least privilegeNarrow source permissions and keep the pilot read-onlyPermission map, role tests, revoked-access test, and review date
Opt-outEnable, defer, or disable based on unresolved control gapsDecision record, approver, open gaps, and next decision date
CommunicationBrief users and managers on sources, verification, and limitsRole guidance, acknowledgment, support path, and escalation route
Answer testingTest approved, stale, conflicting, missing, and restricted recordsFixed question set, expected sources, results, and corrections
MonitoringMeasure accepted answers, corrections, incidents, and useful workQuality sample, trend review, incident log, and change trigger
OwnershipAssign admin, data, security, business, and finance ownersRACI, disablement authority, support contact, and incident playbook
BillingVerify seat, source, Data 360, and post-license credit behaviorOrder form, license inventory, Digital Wallet check, and cost owner

1. Confirm eligible seats and affected users

Export the users with unmetered user-based AI entitlements and reconcile them to the organization, business unit, role, employment status, and actual need. Check contractors, service accounts, integration users, dormant accounts, and people scheduled to change roles. Record which users will be included automatically and which later seat assignments require manual Coworker access.

Salesforce's Coworker setup guidance identifies the AI Search permission set license and the Access_Ai_Search permission set group as core user-access controls. Confirm the exact names and assignments in your org, because product labels and prerequisites can change during beta. Removing a seat, permission set group, or license can also change access and billing behavior in different ways.

2. Review CRM, Slack, and Data 360 search scope

Build a source register before connecting optional systems. For CRM, list searchable objects, fields, record-sharing rules, knowledge content, and sensitive classifications. For Slack, review connected workspaces, channel membership, private-channel expectations, retention, legal holds, and whether messages are an approved business record. For Data 360, record the selected data space, indexed objects, source systems, ingestion method, policy inheritance, owner, and credit model.

Start with default CRM search if it clears review. Do not connect Slack or additional Data 360 objects merely because the option exists. Each connection changes the evidence available to the model and may introduce a separate permission model, data-quality problem, or cost path.

3. Apply least privilege before testing

Create a pilot group around a defined job outcome, then give it only the records and Coworker permissions needed for that outcome. Review profiles, permission sets, permission set groups, sharing rules, role hierarchy, Data 360 policies, and Slack membership. Remove obsolete access at the source rather than hiding it with instructions that ask the model not to use it.

Separate search access from action access. Begin read-only. If a later workflow can write records or invoke agents, authorize each action independently, set approval and value thresholds, retain logs, and define reversal. A governed custom-agent model should make read, draft, write, send, and transact distinct permission decisions.

4. Decide whether to opt out

Salesforce says administrators can opt out before enablement through the notification email or through Setup under Agentforce Coworker and Opt Out of Auto Activation. After enablement, the Coworker toggle can be enabled or disabled from Agentforce Coworker Setup.

Opt out when the user list is unknown, permissions are under review, required stakeholders have not approved the data scope, billing cannot be reconciled, or the business cannot support testing and escalation. Opting out is a sequencing decision, not a rejection of the product. Document the control gaps, owner, target review date, and evidence required to turn it on later.

5. Communicate the change before users discover it

Tell affected users when the feature may appear, what Ask and Search modes do, which sources are approved, what data must not be entered or exposed, how answers must be verified, which actions remain prohibited, and where to report a problem. Managers need a separate briefing on review expectations and how to handle an employee who receives unexpected results.

Make the message role-specific. A service team needs guidance on customer and case data. Sales needs rules for opportunities, contacts, and account strategy. Executives need to know that a concise answer can still omit context. Administrators need the disablement, access-removal, and escalation steps.

6. Test answers against approved records

Create a test set from approved, current records that represent common work, ambiguous questions, permission boundaries, stale data, conflicting sources, missing evidence, and restricted records. For every question, define the expected source, acceptable answer elements, forbidden disclosures, and reviewer.

Run tests as users with different roles. Confirm that the same question produces appropriately different evidence when permissions differ. Review citations or source references where available, factual completeness, record freshness, unsupported conclusions, and refusal behavior. A fluent answer is not a passed test unless it matches the approved record and respects the intended boundary.

7. Monitor usage and answer quality

Track active pilot users, accepted answers, factual corrections, source failures, permission incidents, escalations, and work completed. Pair those measures with review effort and business impact. Search volume alone can reward curiosity without showing dependable value.

Use a sampled quality review after launch. Re-run the fixed test set when permissions, connected sources, data spaces, models, or Coworker releases change. Salesforce's beta status is itself a refresh trigger. If the organization cannot observe quality and incidents, broad availability should remain paused.

8. Document ownership and escalation

Name a Salesforce admin owner for configuration, a data owner for every connected source, a security or privacy reviewer for access and incidents, a business owner for acceptable answers, and a finance owner for credits and contract interpretation. Define who can disable Coworker, remove user access, disconnect a source, preserve evidence, notify users, and contact Salesforce Support.

Set escalation levels. A wrong low-impact internal answer may require correction and a test update. Unexpected restricted data, an unauthorized action, or a material customer-facing error should trigger immediate containment and the incident process. Record the question category, user role, source, output, decision, and remediation without creating a new uncontrolled copy of sensitive data.

9. Verify billing and credit behavior

The automatic-enablement FAQ says default CRM search and optional Slack search do not use Flex Credits or Data Services Credits for users with Agentforce 1 Edition or Agentforce for Sales, Service, or Industries seats. For users with unmetered user-based AI entitlements, usage shows 0% consumption in Digital Wallet and does not count toward contracted usage limits.

Data 360 is different. Salesforce says ingesting, processing, and indexing Data 360 content uses Flex Credits or Data Services Credits regardless of billing plan. If a user loses an eligible seat after enablement, Coworker access may remain through the primary Salesforce license while billing returns to the standard credit model. Verify those behaviors against the current order form, assigned licenses, connected sources, Digital Wallet, and Salesforce account team before expansion.

A controlled 30-day rollout

During the first week, confirm the notification, eligibility, Einstein prerequisites, seats, permission assignments, source register, opt-out decision, and owners. If any material boundary is unresolved, opt out or keep the user population narrow.

During week two, communicate the policy and run the fixed test set with a small group from two or three roles. Keep Slack and additional Data 360 sources disconnected until their access, governance, and credit paths pass review.

During weeks three and four, operate the pilot in read-only mode. Review sampled answers, incidents, corrections, adoption, useful work, and billing evidence. Correct source data and access controls before tuning instructions. Do not grant action authority merely because search answers are accurate.

At the decision gate, choose to stop, extend the pilot, broaden search access, connect another approved source, or authorize one narrowly bounded action. Record why, what evidence supports the decision, who approved it, and when it must be reviewed.

Agentforce Coworker can reduce the distance between a question and the business evidence needed to answer it. Automatic enablement reduces setup friction; it does not reduce accountability. The organizations that benefit will make seats, sources, permissions, quality, billing, and escalation visible before availability becomes routine use.

FAQ

Agentforce Coworker Auto-Enablement FAQ

What does Agentforce Coworker automatic enablement mean?

It means eligible Salesforce users with unmetered user-based AI entitlements may have Agentforce Coworker appear automatically on a rolling basis. It does not approve broader CRM, Slack, or Data 360 access, and it does not authorize consequential agent actions without business governance.

Which Salesforce organizations are eligible for automatic enablement?

Salesforce says the rollout targets customers with unmetered user-based AI seats. Organizations that disabled generative AI, use certain multi-dataspace or multi-org topologies, fall into listed HIPAA, Health and Life Sciences, or government categories, or have only usage-based Flex Foundation seats are excluded. Administrators should confirm their own notification and contract.

Can a Salesforce administrator opt out of Agentforce Coworker?

Yes. Before automatic enablement, Salesforce says administrators can use the notification-email link or the Opt Out of Auto Activation control in Agentforce Coworker Setup. After enablement, they can enable or disable the Coworker toggle from Setup.

Does Agentforce Coworker expose every record a company has?

Salesforce says Coworker respects user permissions, but administrators must still review whether existing CRM access, Slack membership, Data 360 policies, and indexed sources are appropriate for AI-assisted search. Permission enforcement does not correct stale or overly broad access.

Does Agentforce Coworker use Salesforce credits?

It depends on the entitlement and source. Salesforce says eligible unmetered CRM and optional Slack search can show 0% consumption in Digital Wallet, while Data 360 ingestion, processing, and indexing use Flex Credits or Data Services Credits. Seat loss can also return usage to a standard credit model, so billing should be verified before expansion.

Preparing for Agentforce Coworker? Validate seats, permissions, connected sources, answer quality, and credit behavior before broad access. Learn about our Data & AI Readiness service or schedule a free AI assessment.

Ready to see where AI moves your business forward?

1Book a call
2Free assessment
3Your roadmap

Share This Article

Send this guide to a colleague or save it for planning.

Sources And Trust Signals

This article is based on ITECS implementation experience and the public resources below.

Salesforce's July 9 FAQ covering the rolling August 4 start, eligible and excluded organizations, user experience, opt-out controls, optional sources, seat changes, and credit behavior.

The Summer '26 release note describing Agentforce Coworker beta, its CRM, Slack, and Data 360 context, permission-based access, governance, classification, and action-oriented capabilities.

Salesforce's Summer '26 impact matrix, which marks the Coworker feature as requiring administrator setup and reinforces the need to verify the actual organization state.

Current setup guidance for administrator prerequisites, AI Search licensing, Access_Ai_Search assignments, Data 360 access, license monitoring, and user-access removal.

ITECS assessment for data ownership, access control, source quality, retention, and governance before business AI receives broad access.

About The Author

The ITECS Team

ITECS' AI consulting, security, training, and DevOps team helps Dallas businesses adopt practical AI safely, backed by more than 24 years of IT operations experience.