Salesforce MVP Hall of Fame · Certified Partner since 2010
Controls on the agents you actually ship.
The first week is in the org, reading what already exists. Regime mapping is the floor. Policy lives on Flex Gateway: identity, field, row, action. Semantic checks at the edge, not in the prompt. The honest no: if the work is a software factory with a named delivery date, we are the wrong partner.
Certified Partner since 2010 · MVP Hall of Fame · 200+ agents in production · UAE and US desks
Regimes
Mapped to the agents, not to a poster.
Gateway
Four policy families. Living on the hop.
If these only exist in a document, you do not have governance. You have a poster.
- 01
Identity
On-behalf-of · No shared service account · Business group per caller
- 02
Field
Which attributes leave the system · Masking at the gateway
- 03
Row
Which records this identity may touch · Sharing still applies
- 04
Action
Read · Write · Refuse · Escalate to a person
- 05
Semantic
PII detection · Denied topics · Leave this out of the prompt
Mermaid source
flowchart TD
A["Identity: who is calling"] --> B["Field: which attributes"]
B --> C["Row: which records"]
C --> D["Action: read, write, or refuse"]
D --> E["Semantic: PII and denied topics"]Your agent surface
Every connector, MCP server, and approver, named.
Integrations
HR and ops into Salesforce, still governed.
People, payroll, and tickets already live somewhere. The gateway still sits on the hop.
Questions
What we actually say.
- Is MCP a security model?
- No. MCP is how an agent reaches a tool. Identity, least privilege, and audit still sit in your IdP, Salesforce sharing, and the gateway.
- Do you sell a monthly governance retainer as a published product?
- No. We write the controls and keep them as the rules change. The brief sets the work.
Next
What to read next.
The brief · one email
Tell us what is already running.
We will mark which agents have no policy family, and which should not exist.