Salesforce published a post on October 7 summarizing a white paper on trust in multi-agent systems, and it names shared agent memory as a place where sensitive data can leak between contexts.

What happened

Kathy Baxter, Salesforce’s Principal Architect of Ethical AI Practice, wrote in a Salesforce News post that the company convened engineers, researchers, security specialists and ethics professionals from 21 organizations for workshops, which informed the white paper. Her main recommendation is a hybrid approach that combines a model’s probabilistic reasoning with hard-coded, deterministic guardrails outside the agent’s reasoning loop.

On memory, Baxter cites researchers Miranda Bogen and Ruchika Joshi of the Center for Democracy and Technology, who call the blending of conversation history, preferences and sensitive context a “data puddle.” Salesforce says it is building deterministic mechanisms that give each piece of memory an owner tag naming the user and AI assistant that created it. Baxter’s principle is that “Storage does not equal access.”

Why it matters

Sales agents carry deal history, pricing discussions and contact notes from one session to the next. If memory is shared loosely, an agent working one account can surface another account’s details. The post also lists the moments that call for a human: significant financial transactions, low-confidence decisions, detected prompt injection attacks and repeated failure loops.

Our read

Baxter says the industry currently lacks a definitive solution to balancing human oversight with the scale agents were deployed to deliver. We looked at the vendor side of this in Sales AI Vendors Now Pitch a Rules Layer Between Agent and Action. We also argued yesterday that pre-launch testing is not a governance plan, and memory ownership belongs on that list. A practical check for any team running sales agents is to ask where each agent’s memory is stored, who owns each entry, and which actions force a handoff to a person.

Source: Salesforce News