Product
Product12 min readBy The Data Workers Team

You're on Salesforce Agentforce: Keep the Data Under Every Agent Right, From the Warehouse to Data 360

Agentforce acts on CRM and Data 360 data fed by warehouse pipelines. Data Workers keeps that data right, with approvals and receipts, and connects over MCP today.

Your service agent answers customers around the clock and your sales agent works the pipeline, all on Agentforce (Salesforce brands the wider portfolio Agentforce 360). Since Dreamforce 2026, AIforce brings Salesforce to more of the places people work: Slackforce in Slack, Agentforce Coworker in Lightning, and Claudeforce in Claude, now in beta for all customers. Admins build in Agent Builder with subagents, actions and instructions, the Atlas Reasoning Engine plans each request step by step, and the Einstein Trust Layer wraps every call with grounding, zero data retention and an audit trail. Underneath sits Data 360 (formerly Data Cloud), reading your Snowflake or Databricks tables through Zero Copy and turning them into customer profiles and context. Agentforce is where your customer-facing work runs. Data Workers is the data team behind the data it runs on.

That data travels a long way before an agent acts on it: from NetSuite or Stripe through Fivetran, into the warehouse, through dbt models, into a Data 360 data stream. When a pipeline breaks or a definition drifts anywhere on that path, every agent acts on the wrong value with full confidence. Data Workers keeps the whole path right, across the warehouse and the pipelines, with approvals and receipts.

Key takeaways

  • •Agentforce keeps its job. Agent Builder, subagents, the Atlas Reasoning Engine, the Einstein Trust Layer and Data 360 stay exactly as they are. Data Workers works on the warehouse and pipelines that feed them.
  • •Agents act on what the pipelines deliver. Entitlements, renewal dates, product usage and account health usually come from the warehouse. Data Workers catches schema changes, failed syncs and drifted definitions there, before Data 360 reads them.
  • •Every fix has an owner and a receipt. Data Workers proposes each change with its blast radius, a named approver signs off in Spellbook, and the change is applied reversibly, verified and recorded.
  • •Connected over MCP today. Data Workers connects to Salesforce over its API or MCP server today, and an admin registers the Data Workers MCP server in the Salesforce API Catalog so its tools become agent actions.
  • •One request, five levels. Autonomy is set per domain, from L0 manual to L4 autonomous, and you can step down at any time.

Agentforce is where your customer-facing work runs. Data Workers is the data team behind the data it runs on.

Salesforce built Agentforce to act. A service agent checks the customer's entitlement and routes the case; a sales agent reads product usage and drafts the renewal outreach. Both trust Data 360, and Data 360 trusts the warehouse tables it reads in place. That design is exactly why the warehouse side deserves its own crew. Here is a Monday with Data Workers watching that path. This is an illustration, not a customer case.

TimeSystemWhat happens
Sun 22:40NetSuiteFinance renames the custom contract end-date field during a billing cleanup
01:00FivetranThe nightly sync lands a new column, contract_end_dt; the old column stops filling and arrives null
01:06Data WorkersSchema-change detection flags the rename on the landed table. Blast radius: the dbt model dim_account_entitlements, the Data 360 data stream that reads it, the service agent's entitlement check and a Tableau Next renewals dashboard. 312 enterprise accounts would read as expired
01:12Data WorkersOpens an incident and proposes a dbt change that maps the new column, with a row-level preview
01:40SpellbookThe analytics engineer on call reviews the diff and approves
02:30Snowflake + dbtThe scheduled dbt build runs with the fix; Data Workers re-runs the checks on the rebuilt table, and the owner's comparison shows entitlements match Friday's, apart from 6 genuine renewals
06:00Data 360Zero Copy reads current entitlements; profiles stay correct
09:14AgentforceAn enterprise customer opens a case; the service agent sees an active premium entitlement and routes it to premium support
09:20AgentforceA service manager asks the employee agent whether last night's billing change touched entitlements; the Data Workers action answers with the incident and its receipt
Incident timeline across the stack: what Agentforce, your team and Data Workers each do, step by step

The service agent did its job well: it acted on the entitlement it was given. Without the catch at 01:06, it would have acted just as confidently on 312 wrong ones. What changed is that Data Workers was on the warehouse side of Data 360 at 01:06, and the fix went through one approval and left one receipt.

JobWhat Agentforce doesWhat Data Workers does
The customer momentAnswers, routes cases and takes CRM actions in every channelMakes sure the data behind each action is correct and current
The planThe Atlas Reasoning Engine breaks a request into steps and picks actionsSupplies governed definitions, lineage, owners and freshness as actions it can call
The contextData 360 unifies profiles and reads warehouse tables through Zero CopyKeeps those warehouse tables, and the pipelines and dbt models behind them, healthy
The breakActs on what Data 360 holdsDetects the schema change or failed sync upstream and traces it to every downstream agent
The fixRuns the actions an admin configured, on the user's permissionsProposes the change with its blast radius, routes it to a named approver, applies it reversibly
The proofThe Einstein Trust Layer audit trail records what the agent didA receipt records what changed in the data, who approved it and how to undo it

Why doesn't Agentforce just do this itself?

Because Salesforce built Agentforce to run customer work inside Salesforce, and its design choices are right for that job. Every agent request runs on the asking user's existing permissions and business rules, and Salesforce says every action "routes back through Salesforce". Data 360 reads your lake and warehouse in place through Zero Copy, deliberately, so you don't have to copy data into Salesforce. The warehouse, the Fivetran connectors, the dbt project and the Airflow schedules stay yours, run by your data team.

Repairing those systems is a different product category. A fix to dim_account_entitlements needs to know which Data 360 streams, Tableau Next semantic models, finance reports and machine learning features read that table. It needs an approval from the person who owns the model, a rollback path, a verification after the change, and a receipt that ties the change to its cause. And someone has to own the liability for a change inside tools Salesforce doesn't run. Salesforce's sensible line is to govern what agents do in Salesforce and leave writes to your data platform to the team that owns it. That is the product Data Workers is.

Focus matters too. An admin building a service agent in Agent Builder should be thinking about subagents and instructions, and shouldn't need to know that a NetSuite field rename breaks a dbt seed. Data Workers carries that knowledge, the change control and the evidence.

Every tool owns a slice. Data Workers covers the whole lifecycle

Agentforce owns one slice of the data lifecycle, and it owns it well: AI agents that act on CRM and Data 360 data, inside the Einstein Trust Layer. Each point tool adds another console, another contract and another handoff. Data Workers covers the whole lifecycle with one context, one approval flow and one audit trail, and builds on Agentforce where your teams already work.

Spider chart of ten jobs a data team does: Data Workers covers the whole list, Agentforce goes deep on its own area
StageData WorkersAgentforceWhy we scored it this way
Catalog & Context95Data 360 (formerly Data Cloud) turns records, documents and metadata into business context through the Agent Context Engine, and Tableau Semantics holds metric definitions. Data Workers keeps one governed context graph across the warehouse, dbt, orchestration and BI that feed it.
Analytics & Insights88.5Agentforce's home stage: Tableau Next and its Concierge Analytics Q&A answer from governed semantic models, inside Agentforce and over a hosted MCP server. Data Workers answers too, from governed definitions with lineage behind every number.
Data Quality83Salesforce lists data quality and classification under its trusted governance layer for AI. Data Workers writes, runs and repairs quality checks and dbt tests on the warehouse tables Data 360 reads.
Observability & Incidents8.53Agentforce Observability monitors and analyzes agent performance in near real time. Data Workers detects data breaks upstream, traces them across systems, fixes and verifies them.
Pipelines & Ingestion8.55Data 360 brings data in through 200+ connectors, MuleSoft and Zero Copy to Snowflake, Databricks, BigQuery and AWS. Data Workers builds, reruns and backfills the warehouse pipelines behind those tables, with approvals.
Schema & Migration82.5Data 360 maps incoming data into Salesforce objects and fields. Data Workers catches upstream schema changes before they reach a data stream, assesses blast radius and plans migrations in parity-checked waves.
Governance & Access8.56.5Strong over Salesforce: every request runs on the asking user's existing permissions and business rules. Data Workers proposes and applies least-privilege grants on the warehouse and pipeline side.
Security & Privacy88.5A second home stage: the Einstein Trust Layer (zero data retention, toxicity detection, secure data retrieval, dynamic grounding, audit trail) wraps every agent. Data Workers leaves a receipt on every data change.
Cost / FinOps82.5Digital Wallet tracks Salesforce credit consumption. Data Workers traces Snowflake credits to the dbt model behind them and drafts the fix for its owner.
MLOps & Models7.53.5Koa, Salesforce's first CRM reasoning model for Agentforce, is with select pilot customers, with general availability expected winter 2026. Data Workers keeps the data under your own models healthy and connects to MLflow and W&B.

How Agentforce and Data Workers work together

Agentforce stays on top, where agents serve customers and employees and where people ask and confirm in Slack, Lightning and Tableau Next. Spellbook Data Catalog (in preview) is where the data team looks: each proposed change, who approved it, what it touched and how to roll it back. Between them, Data Context Wizard keeps one governed context graph across Snowflake, dbt, Fivetran and Airflow, the Data-Agents Swarm does the work with more than 20 specialist agents, the Autonomous Data-Conductor runs each fix end to end (detect, diagnose, fix, review, verify, remember), and per-domain guardrails hold approvals, receipts and rollback.

How Data Workers fits with Agentforce: your coding agent on top, Data Workers in the middle, your estate underneath

Two directions, both over MCP. Data Workers connects to Salesforce over its API or MCP server today, so its lineage reaches from the warehouse table to the Data 360 stream and the agent that reads it. In the other direction, Agentforce calls Data Workers: Salesforce's developer guide describes registering MCP servers in the Salesforce API Catalog "so their assets (tools, prompts, resources) become available as agent actions", and Salesforce manages those servers through a central MCP server registry with authentication, access controls and rate limiting.

Setup. Every Data Workers agent is an MCP server. To try the tools locally, start the agents from the open-source repository as the client setup guide documents (clone the repo, one start-agent.sh entry per agent). Agentforce calls over HTTP, so it connects to your Data Workers deployment's remote MCP endpoint (Streamable HTTP), which authenticates every call with an API key sent as a bearer token, or with OAuth tokens from your own identity provider that Data Workers verifies against its JWKS. Then register that endpoint with Salesforce:

  • •Your Salesforce admin registers the Data Workers MCP server in the Salesforce API Catalog (the API Catalog Connect REST API covers registering, tracking and managing it).
  • •Expose the read tools first: search_across_platforms, trace_cross_platform_lineage, resolve_metric, get_quality_score and get_incident_history.
  • •In Agent Builder, add those actions to one employee-facing agent, such as a service operations agent, with instructions for when to call them.
  • •Test in the builder: ask "is the entitlement data for Acme current?" and check that the action returns lineage, quality and open incidents.
  • •Later, add the proposal tools (assess_impact, diagnose_incident) and, one domain at a time, remediate.
Example: registering Data Workers for Agentforce
Agents:        dw-context-catalog, dw-schema, dw-quality, dw-incidents
Endpoint:      https://<your-data-workers-host>/mcp      (Streamable HTTP)
Auth:          API key as a bearer token, or OAuth tokens from your
               identity provider, verified by Data Workers via JWKS
Registered in: Salesforce API Catalog, tools become agent actions
First actions: search_across_platforms, trace_cross_platform_lineage,
               resolve_metric, get_quality_score, get_incident_history
Later:         assess_impact, diagnose_incident,
               remediate (one domain at a time)

One request end to end, L0 to L4. The request: "Why did the service agent route Acme to standard support?" The autonomy ladder is set per domain.

The autonomy ladder: L0 manual, L1 observe, L2 propose, L3 act reversibly, L4 autonomous
  • •L0 manual. A service manager files a ticket; an analytics engineer traces Data 360 back to the warehouse by hand.
  • •L1 observe. The employee agent calls Data Workers read actions. The answer: Acme's entitlement row has a null end date since 01:00, caused by a Fivetran column rename, with lineage to the dbt model and the Data 360 stream.
  • •L2 propose. Data Workers opens an incident and proposes the dbt fix with its blast radius. Nothing reaches production until the model owner approves in Spellbook and CI passes.
  • •L3 act reversibly. For change classes with a proven record, such as rerunning the dbt build for affected partitions, Data Workers applies the change, re-runs the checks on the changed tables and records the undo for the owner. The receipt is linked in the agent's answer.
  • •L4 autonomous. For a scoped domain like entitlement freshness, Data Workers fixes overnight, and the first agent to read the table in the morning reads correct data.

For the full safety model, read is it safe to let AI agents change production data; for where data and credentials live, read where does our data go. If your warehouse is Snowflake, Data Workers on Snowflake covers that side. The same server serves every assistant your company runs: see you're on Microsoft Copilot Studio, you're on ChatGPT Enterprise and the hub, AI assistants are rolled out, now what.

What changes for your team

Agentforce gave the business a digital workforce. Data Workers gives the data team a crew, so the questions those agents raise don't land on the data team as tickets.

Six jobs that run on autopilot with Data Workers next to Agentforce, with a concrete example of each
  • •Incidents. Breaks on the warehouse side of Data 360 are traced, fixed and verified overnight, before an agent acts on them.
  • •Data quality. Every break that could have reached an agent becomes a check or a dbt test on the table Data 360 reads.
  • •Cloud spend. Snowflake credits are traced to the query and dbt model behind them, and each fix goes to its owner drafted.
  • •Access. A request for a Snowflake table behind a data stream arrives as a scoped, time-boxed grant proposal for the data owner.
  • •Audits. The Einstein Trust Layer records what each agent did. Data Workers records the other half: what changed in the data, who approved it, why, and how to undo it.
  • •Migrations. A warehouse move runs in approved, parity-checked waves while Data 360 keeps reading the same tables.

Keep Agentforce, or consolidate?

Keep Agentforce if you love it; Data Workers works with it from day one. Many teams consolidate once Data Workers runs that slice too.

For almost every Salesforce customer the answer is to keep it: Agentforce is where customer work runs, on the CRM, permissions and Trust Layer your admins already trust. What teams consolidate is the stack around the warehouse: a separate observability tool, a data-quality tool, a catalog nobody keeps current and the scripts each team wrote to watch its own tables. If you are weighing whether to build this layer yourself on Agentforce's MCP support, read build it ourselves with Claude Code and MCP servers first; the MCP endpoint is the easy part, and the context graph, approvals and rollback are where the work is.

The case for your CFO

The outcome: the company invested in Agentforce so agents can serve customers and run sales and service work at scale. Data Workers makes sure the data those agents act on is correct, current and auditable. When an agent routes a case, quotes a renewal or skips an upsell, it acts on a warehouse value, and an agent acts on it every time, at every hour.

The risk story is plain. Salesforce governs what agents may do in Salesforce. Data Workers governs changes to the data underneath: autonomy per domain on the ladder from L0 manual to L4 autonomous, each change routed to a named approver, applied reversibly, verified downstream and recorded in a receipt with who approved it, what it touched and how to undo it. Zero migration: Salesforce, Data 360, Snowflake, dbt, Fivetran and Airflow stay where they are.

Why now: agents act without a human reading the number first, so a broken pipeline turns into wrong customer actions within hours. The first win is a schema-change and freshness watch on the tables behind your Data 360 data streams, plus read actions on one employee agent. What stays the same: Agent Builder, the Trust Layer, Salesforce permissions, warehouse permissions and your dbt review process. For the numbers, see the ROI of agentic data operations. Start with a pilot (pricing); the pilot is credited in full against the first year.

The sentence to repeat upstairs: "Agentforce runs our customer work; Data Workers makes sure the data it acts on is right, and fixes it with an approval and a receipt when it isn't."

Getting started

Start with a pilot. Pick the tables behind one Data 360 data stream that an agent acts on, such as entitlements or product usage, turn on dbt manifest schema-change checks and lateness baselines, and register the Data Workers read actions on one employee agent. Run it for a few weeks, then enable the first write class in one domain. The pilot path and plans are on the pricing page, and the pilot is credited in full against the first year.

FAQ

Does Data Workers need a Salesforce connector to help Agentforce? Data Workers connects to Salesforce over its API or MCP server today, and Agentforce reaches Data Workers through the MCP server your admin registers in the API Catalog. Most of the work happens where the data breaks: in Snowflake, Databricks or BigQuery, dbt, Fivetran and Airflow, which Data Workers connects to directly.

Data 360 uses Zero Copy. Why does the warehouse side still matter? Zero Copy means Data 360 reads your warehouse tables in place, so it reads whatever those tables hold, correct or not. Keeping those tables right is a warehouse and pipeline job, and that is the job Data Workers does.

Can an Agentforce agent trigger a write to our warehouse? Only the actions an admin registers and adds in Agent Builder are available, and agents run on the asking user's permissions. On the Data Workers side, every change has a blast radius, a named approver in Spellbook, a rollback path and a receipt, and autonomy is set per domain. Start with read actions and add one write class at a time.

How is this different from Agentforce Observability? Agentforce Observability monitors and optimizes agent performance in near real time, such as resolution speed and accuracy. Data Workers watches the data those agents read and fixes it. You want both, and they answer different questions.

Does this work with Tableau Next and its semantic models? Yes. Tableau Next's data layer runs on Data 360, and Salesforce exposes its semantic models over a hosted MCP server with read-only tools. Data Workers keeps the warehouse tables under those models right and traces each metric's lineage back through dbt to the source.

Where does our customer data go? Data Workers acts on your warehouse and pipelines with the connections you configure, scoped per domain, and Agentforce calls run inside the Einstein Trust Layer. For details, read where does our data go.

Sources

  • •Salesforce, Agentforce (Agent Builder, subagents, Agent Script, Atlas Reasoning Engine, Agentforce Observability), https://www.salesforce.com/agentforce/ (checked Oct 2, 2026)
  • •Salesforce, How Agentforce Works (Einstein Trust Layer, Audit Trail), https://www.salesforce.com/agentforce/how-it-works/ (checked Oct 2, 2026)
  • •Salesforce, Agentforce MCP Support (MCP server registry, governance, AgentExchange), https://www.salesforce.com/agentforce/mcp-support/ (checked Oct 2, 2026)
  • •Salesforce Developers, MCP Solutions for Developers (API Catalog registration, hosted MCP servers), https://developer.salesforce.com/docs/ai/agentforce/guide/mcp.html (checked Oct 2, 2026)
  • •Salesforce Developers, Hosted MCP Servers: Tableau Next reference, https://developer.salesforce.com/docs/platform/hosted-mcp-servers/references/reference/tableau-next.html (checked Oct 2, 2026)
  • •Salesforce, Data 360 (formerly Data Cloud), Zero Copy and FAQ, https://www.salesforce.com/data/ (checked Oct 2, 2026)
  • •Salesforce, Data 360 Connectivity, https://www.salesforce.com/data/connectivity/ (checked Oct 2, 2026)
  • •Salesforce, Tableau Next, https://www.salesforce.com/analytics/tableau-next/ (checked Oct 2, 2026)
  • •Salesforce News, Salesforce Unveils AIforce (Sept 15, 2026; Claudeforce in beta for all customers), https://www.salesforce.com/news/stories/aiforce-announcement/ (checked Oct 2, 2026)
  • •Salesforce News, Five Big Ideas Coming Out of Dreamforce 2026 (Sept 24, 2026), https://www.salesforce.com/news/stories/five-dreamforce-2026-takeaways/ (checked Oct 2, 2026)
  • •Salesforce News, Announcing Koa: Salesforce's First CRM Reasoning Model, Built on NVIDIA Nemotron (Sept 15, 2026; pilot now, GA expected winter 2026), https://www.salesforce.com/news/press-releases/2026/09/15/koa-reasoning-model/ (checked Oct 2, 2026)
  • •Salesforce News, Agentforce 360 Powers the Future of Chess with FIDE (Sept 10, 2026), https://www.salesforce.com/news/press-releases/2026/09/10/agentforce-360-powers-future-of-chess-with-fide/ (checked Oct 2, 2026)
  • •Data Workers open-source repository (tool registrations in dw-context-catalog, dw-schema, dw-quality, dw-incidents) and client setup guide, https://dataworkers.io/opensource-docs/client-setup/ (checked Oct 2, 2026)