Agentforce Coworker setup, security and routing within AIforce
Agentforce Coworker is presented as one of three pillars of AIforce, the interface layer announced at Dreamforce ’26 that sits on top of Agentforce, Customer 360 and Data 360. Its purpose is to reduce swivel-chairing between applications and to act as a router for a growing agentic workforce, so users do not have to know which agent handles which task. It offers three interaction modes: Find for natural-language queries across CRM, Slack, files, knowledge bases and 270+ connected sources; Catch Up for proactively surfacing changes that occurred while the user was away; and Plan and Act for outcome-level instructions that Coworker orchestrates across agents.
The article describes the trust model as reusing the existing Salesforce metadata-driven security: Profiles, Permission Sets and Sharing Rules still apply, so the agent operates under the same least-privilege constraints as users. Setup requires Data 360 to be enabled first, since it indexes CRM data and enforces governance, then assigning the Agentforce Coworker Admin Permission Set, enabling the feature through Salesforce Go, optionally granting additional data sources under Manage Data, and finally assigning the Agentforce Coworker User Permission Set to end users. The author cautions that orgs need clean data and properly configured permissions before enabling it, and notes the user-facing entry point is a new Ask button next to global search in Lightning Experience, with availability also in Microsoft Teams.