Salesforce and Infinitus describe their sales agents the same way: a model that talks and reasons, wrapped in a layer of fixed rules that decides what the agent may actually do.
The shift: agents that act need a second layer
In our read, sales AI is moving from drafting text to taking actions inside systems of record, and that changes what can go wrong. A bad draft gets edited. A bad action lands in a CRM, a quote or a customer conversation. Two vendor statements published this week show how the sellers of these agents answer that risk, and the answers share a structure. One comes from a platform vendor that sells to every kind of sales team. The other comes from a company selling into a regulated corner of sales, where the release stresses compliance monitoring.
We covered the earlier stage of this move in Agentic AI for Sales Clears Its First Production Test. The questions now are about control rather than capability.
What Salesforce describes
In a question-and-answer piece on its newsroom, published October 6, Salesforce explains how Agentforce is built. The company says large language models are probabilistic and can deliver incorrect answers and even take incorrect actions without the right context, data and instruction. Its answer is a two-part design.
“Agentforce splits the agent brain into two layers,” said Kathy Baxter, Salesforce’s Principal Architect of Ethical AI Practice. The first layer is the language model, which handles language and reasoning. The second is deterministic, built through Agent Fabric, Flow and Apex. According to Baxter, all consequential decisions are routed through that second layer instead of being left to the agent, and they follow whatever workflow policies, procedures or escalations to humans the customer sets.
The piece lists the supporting parts. An audit trail records every action the agent takes, along with the humans’ actions. The Atlas Reasoning Engine forces an agent to explain each of its actions. A Trust Layer does toxicity detection and prompt injection detection. A Testing Center lets customers evaluate the responses their agents give. Salesforce says autonomy is granted incrementally and based on policies, and that agents must identify themselves as AI and not pretend to be human.
Baxter ties the design to a specific failure. “When an agent hallucinates, it’s not just giving an incorrect answer; it can actually take incorrect actions,” she said. In her telling, those incorrect actions can compound over time.
The same pattern in pharma sales
Infinitus, which sells AI agents for healthcare communications, announced FieldForce on October 7. Its release describes agents that support pharma sales representatives and field reimbursement managers. The agents connect with the team’s CRM to prepare information before meetings, capture notes and update systems afterward.
The rule layer shows up in how the product handles scope. The release says FieldForce is built around the distinction between promotional and medical communications. The sales agent can support appropriate promotional conversations. When a provider asks a clinical or safety question outside the sales rep’s role, the agent hands the conversation to a member of the organization’s Medical Information team along with full context. Infinitus Lens adds same-day compliance monitoring.
The release also says the agents are trained on specific data and resources provided by each pharma organization, plus Infinitus’s own knowledge graph, and that customers can measure impact through metrics such as provider coverage, interactions and cost per interaction.
What it means for the sales leader
Two vendors in different markets reach for the same device. The model is allowed to converse and reason. Anything consequential passes through rules the customer can inspect, and a person or a log can answer for the result. In our read, this is where agent buying decisions will move over the next year: away from how fluent the agent is and toward what it is allowed to do, who sets that boundary, and how anyone finds out when it fails.
That has a practical consequence for how a revenue team evaluates a product. In our read, a demo shows the language layer, and the rules layer rarely shows up in one. Salesforce’s own description explains why: the workflow policies, procedures and escalations to humans are whatever the customer wants them to be, so the buyer has to write them.
Questions to put to any sales agent vendor
- Which actions does the agent take on its own, and which pass through fixed rules you can read?
- Where does the agent hand off to a person, and does the person get the full context of the conversation?
- What does the audit trail record, and who on your team will read it?
- Which measures come with the product? Ask for one that shows whether the agent was right, beside any volume and cost measures.
Watching the agent after launch
Baxter names the gap in her own interview. In her words, one of the biggest gaps is customers who test before launch and then stop monitoring. The tooling exists in both vendors’ descriptions: an audit trail, a Testing Center, same-day compliance monitoring. Tools that record and report only matter if a named person reads what they produce.
We argued a related point in Sales Agents Get Weeks-Long Autonomy. Vendors Sell Control. The pattern holds in this week’s material. Vendors are selling control, and control has an owner on the buyer’s side or it has none.
What to do this quarter
List every agent action in your CRM and your sales engagement tools that writes data or contacts a customer. Mark each one as passing through a fixed rule or relying on the model’s judgment. For the second group, decide whether a rule can replace the judgment or whether a person should approve the action. Then assign one owner, usually in revenue operations, to review the audit trail on a set schedule and report what changed.
Source: Salesforce Newsroom

