An architect enables a Salesforce hosted MCP server and trusts the permission model to keep every agent in bounds. Each transaction does run as the authenticated user, but by default any user in the org can authenticate through the External Client App, and that per-user guarantee does not extend to the third-party MCP servers Agentforce calls. These are the governance challenges now emerging in Agentforce and MCP architectures.
This session explores practical patterns for each one, including identity as the trust boundary, servers scoped to a single job, tool orchestration that treats every attached tool as a cost, human approval for irreversible actions, and canary fields that make observability provable. Attendees will leave with a reusable five-question governance playbook they can apply while designing Agentic Enterprise systems.