NewsTradingSentimentCalendarCommunityBriefing
Tech

AI shifts focus for Salesforce security governance

By Tech Desk · 2026-09-11 · 3 min read
A digital shield protecting a network of connected nodes
Illustration: Tradingbird

Traditional security checks on user logins are no longer enough as AI agents join the workflow. A new framework argues that organizations must now map and govern the trust relationships between these automated systems and enterprise data.

The rise of artificial intelligence in enterprise environments is fundamentally altering how security teams must approach governance. For years, the primary focus of protecting platforms like Salesforce has been on static elements: user identities, permission sets, and access controls. However, as AI agents begin to perform tasks and interact with data autonomously, these traditional boundaries are becoming insufficient. The core challenge is no longer just preventing unauthorized access, but understanding how trust is established and maintained between humans, software, and automated agents.

According to a new paper from WithSecure, titled 'Navigating Trust in the Modern Salesforce Ecosystem,' organizations need to shift their attention toward the dynamic relationships that drive business workflows. This means looking beyond who can log in to what information is being used, how it moves between systems, and what outcomes are produced by automated actions. The report suggests that without a clear understanding of these trust relationships, companies face blind spots where security risks can hide in the gaps between connected services.

Defining trust in automated workflows

In this context, trust is defined as the reasonable expectation that a person, system, or piece of information will behave as required for a business process to function. When AI agents are involved, this trust extends to APIs, integrations, and external platforms that the AI relies upon to execute tasks. Each of these relationships has a specific scope and boundary, defined by the responsibilities assigned to that entity and the assumptions made about its reliability. If an AI agent is trusted to analyze customer data, that trust is bounded by the specific permissions it holds and the conditions under which it operates.

The problem arises because these relationships often span multiple tools and processes, especially when automation handles tasks without direct human oversight. A single workflow might involve a salesperson, an AI assistant, a database, and a third-party application. If the trust in one part of this chain is compromised or if the boundaries are not clearly defined, the entire workflow becomes vulnerable. Making these relationships visible is the first step in determining whether they are still appropriate for the organization's current security posture.

Five domains for assessing risk

To help organizations manage this complexity, the report proposes a Trust Mapping Framework that examines five specific domains. These are entities, information, connections, actions, and system outcomes. By breaking down a workflow into these categories, security teams can identify exactly who or what is participating, what data is being processed, and how that data is moving through the system. This structured approach applies to various modern Salesforce features, including AI-driven agents and headless integration models, as well as third-party applications that interact with the core platform.

This framework allows for a more granular assessment of risk. Instead of asking a broad question like 'Is this integration secure?', teams can ask specific questions about each domain. For example, is the information being used by the AI agent still reliable? Do the connections between systems stay within their intended limits? And are the outcomes of the automated actions aligned with business intent? This level of detail helps identify where trust may have drifted or where assumptions about system behavior have become outdated.

Governance requires continuous assessment

Once these trust relationships are mapped, the next step is governance. This involves assessing which relationships require attention and whether they still serve their original purpose. The process includes checking visibility, ownership, and monitoring capabilities. Organizations must verify that the right people and systems have the appropriate authority and that any changes in permissions or behavior are justified. If a relationship no longer aligns with business goals or introduces unnecessary risk, it can be modified, restricted, or removed entirely.

This assessment is not a one-time event but a continuous process. It draws on evidence such as security incidents, audit findings, threat intelligence, and monitoring data. As AI models evolve and business processes change, the trust relationships that supported them yesterday may no longer be valid today. By actively governing these relationships, organizations can ensure that their security measures remain effective in an environment where automation is becoming increasingly prevalent. The goal is to create a security posture that is as dynamic and adaptive as the AI systems it protects.

Based on reporting by GN technics/ai (en-US), compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories