Agentforce Is Enabled by Default in Winter '27: The Pre-Upgrade Check
Quick answer
Agentforce Is Enabled by Default in Winter '27: The Pre-Upgrade Check
Salesforce is enabling the Agentforce platform by default in eligible orgs on a rolling basis from early September 2026, and removing the Agentforce toggle from Setup. Nothing starts talking to customers on its own. Admins keep the Einstein Setup switch, per-agent activation, and the Manage AI Agents permission.
Last updated:
Agentforce on does not settle the model question
GPTfy runs your own model, through your own key, inside your org. Masked before the call, logged where your retention rules apply.
The Winter '27 release notes landed on 19 August. Buried in them is a change that will show up in a lot of orgs without anyone filing a ticket for it: Salesforce is enabling the Agentforce platform by default.
If you run a regulated org, that sentence probably made you sit up. Read the next one before you escalate it.
Auto-enable is not auto-deploy. Nothing in this change points an agent at a customer, publishes a channel, or changes what your users can do today. What it removes is a setup step. That distinction is the part most of the panic is missing.
Here is what is actually changing, when it reaches you, and the short check worth running before your instance upgrades.
What is actually changing in Winter '27?
Salesforce is turning the Agentforce platform on by default in orgs that already have Agentforce access through their SKU, licence, or edition. In practice that means Lightning orgs on Enterprise, Performance, Unlimited and Developer Edition with Foundations, plus anyone on Agentforce 1 Edition.
The visible change is small. The Agentforce toggle disappears from the Agentforce Agents page in Setup. Salesforce's framing is that you can build, test and deploy agents "with one less step."
Salesforce has stated the change carries no additional cost and makes no change to billing.
Worth noting: this is still marked preview in the release notes. It does not become generally available until Salesforce announces the GA date for the release.
When does this reach my org?
Two separate clocks, and people keep conflating them.
The first is the auto-enable rollout. It was originally planned for August, then moved to a rolling basis starting the first week of September 2026.
The second is your Winter '27 instance upgrade. Preview sandboxes moved to Winter '27 over 28 and 29 August. Production instances upgrade across three weekends in September and October.
Do not take your production date from a blog post, including this one. The published dates for those weekends do not agree with each other. Go to Salesforce Trust, search your instance name or My Domain, and open Maintenance. That is the only date that is true for you.
One practical consequence: if your instance is in the first production wave, the gap between sandbox preview opening and your upgrade is about a week, not the six weeks people plan around.
Does auto-enable mean agents start answering customers?
No, and this is the part worth repeating to whoever forwards you the headline.
Enabling the platform makes the building surface available. An agent still has to be created, configured with topics and actions, activated, and connected to a channel before anyone outside your team interacts with it. An agent also runs as its own user and reaches only the data that user's permissions allow.
So the realistic risk is not a rogue agent. It is a well-meaning admin with the right permission building something in a production org on a Friday, because the friction that used to stop them is gone.
That is an AI governance problem rather than a platform problem, and it is fixable in an afternoon.
The check to run before your upgrade weekend
Six items. None of them take long.
-
Find your actual upgrade date. Salesforce Trust, your instance, Maintenance tab. Put it in the change calendar where the rest of the org can see it.
-
Decide your position now, not after. Three options: leave the platform on and govern it, leave it on but restrict who can build, or turn off the Einstein setting on the Einstein Setup page, which turns off the Agentforce platform. Pick one deliberately. Arriving at one by accident is the only wrong answer.
-
Audit who holds Manage AI Agents. That permission is what lets a non-admin build agents. If it is sitting on a profile or on a broadly assigned permission set, move it to a named permission set with an owner.
-
Look at the agent list. An agent named Agentforce (Default) can appear once the platform is on. Know whether it is active, what topics it carries, and who has been given access to it.
-
Re-check field-level security on your sensitive fields. Agents inherit the running user's access. The FLS you have been meaning to tighten for two years is now more load-bearing than it was last month.
-
Test in the preview sandbox, not in production. It is already on Winter '27. Use it.
What regulated teams should look at more closely
If you are in financial services, healthcare, life sciences or the public sector, three extra questions are worth putting in writing before your upgrade.
Who signs off before an agent is activated?
Not who can. Who does. If the answer is "the admin who built it," that is the gap.
How long is agent activity retained, and does that match your own policy?
Salesforce keeps audit data for agent activity for a defined window. Check the current window in Salesforce's documentation against what your auditors expect, because those two numbers are rarely the same.
What leaves the org, and in what state?
The Einstein Trust Layer masks sensitive data before prompts reach the model and holds model providers to zero data retention. That covers the platform's own path to the model. It does not cover every other integration in your org that also sends CRM data somewhere.
Where GPTfy fits
Agentforce being on does not settle the model question, and for a lot of enterprise teams that is the harder one.
GPTfy runs inside your Salesforce org and calls your own model through your own Named Credential. You choose the provider. Sensitive fields are masked before the call leaves, and every prompt and response is logged in your org, where your retention rules apply and nobody has to request an export.
It sits alongside the platform rather than instead of it. If you turn Agentforce on and govern it well, good. The six questions above are the same either way.
Frequently asked questions
Will Agentforce be enabled in my org automatically?
If your org has Agentforce access through its SKU, licence or edition, yes. That covers Lightning orgs on Enterprise, Performance, Unlimited and Developer Edition with Foundations, plus Agentforce 1 Edition. The rollout is on a rolling basis starting the first week of September 2026.
How do I turn Agentforce off?
Turn off the Einstein setting on the Einstein Setup page. That turns off the Agentforce platform. You can also activate or deactivate individual agents in Agentforce Builder if you want the platform available but nothing running.
Does auto-enabling Agentforce cost anything?
Salesforce has stated the change incurs no additional cost and makes no change to billing. Consumption charges still apply to whatever you actually run.
Will an agent start responding to customers on its own?
No. An agent has to be created, configured, activated and connected to a channel before anyone interacts with it. Auto-enable removes a setup toggle, not those steps.
When does my production org get Winter '27?
Across three production weekends in September and October 2026, assigned by instance. Check Salesforce Trust for your own instance rather than relying on a published date, because your weekend may not be the first one.
Who can build agents once the platform is on?
Admins by default. Non-admins need the Manage AI Agents permission. Auditing who holds it is the highest-value item on the checklist above.
Sources and review date
Last reviewed 31 August 2026, against the Salesforce Winter '27 release notes published 19 August 2026 and Salesforce Ben's coverage of the auto-enable change. Winter '27 is in preview until Salesforce announces general availability, and details can change before then.
Salesforce, Agentforce and Einstein are trademarks of Salesforce, Inc. GPTfy is an independent product available on AppExchange and is not affiliated with or endorsed by Salesforce, Inc. beyond marketplace partner status.
Want to learn more?
View the Datasheet
Get the full product overview with architecture details, security specs, and pricing, with a built-in print option.
Watch a 2-Minute Demo
See GPTfy in action inside Salesforce - from prompt configuration to AI-generated output in real time.
Ready to see it with your data? Book a Demo
Explore GPTfy
Bring Your Own Model in Salesforce
Run any AI model through your own Named Credential, inside your org.
Data Masking
Field-level masking applied before a prompt leaves Salesforce.
Audit Trails and Governance
Every prompt and response logged in your org, under your retention rules.
What Is Agentic AI in Salesforce?
What agents actually are, and where the governance boundaries sit.
Open AI Architecture for Salesforce
Architecture comparison: model choice, data platform, cost structure.
Book a Demo
Thirty minutes, your org, your questions.
