Skip to main content

#Solution Architects8 discutindo

Hello Trailblazers,

I am preparing an Agentforce Solution Design for a client and would like guidance from experienced architects and consultants on how to approach the design comprehensively. 

 

The use case may involve Employee Agent,  Coworker Agent, and Out-of-the-Box Salesforce Agents

, Flex Prompt Template and I want to ensure I am covering all important aspects from business requirements through implementation, licenses, Flex Credit model, governance, and deployment. 

 

Any sample templates, reference designs, or lessons learned from real implementations would be greatly appreciated.

Thank you in advance for your guidance! 🚀 

#Agentforce #SalesforceAI #Solution Architects #AgentforceBuilder #Enterprise Architecture

2 respostas
  1. 29 de set., 08:35

    Hey Jiyaulla,

     

    Here’s how I would approach the solution design:

     

    1. Agent Boundaries & Routing

    • Split by persona: Don't build one monster agent. Keep Employee Desk (IT/HR Q&A via Knowledge), Coworker (sales/service reps on record pages), and OOTB Service Agent in clean, separate buckets.

     

    • Topics & Hand-offs: Limit each agent to 4–6 tightly scoped Topics. Write explicit "When to use" instructions so the reasoning engine doesn’t cross wires. Always map human escalation via Omni-Channel, carrying the chat summary over.

     

    2. Actions & Grounding (The Engine)

    • Actions: Use Autolaunched Flows for standard CRM updates and Invocable Apex for external API lookups. Keep JSON outputs short; feeding raw multi-page payloads burns tokens and slows reasoning down.

     

    • Flex Prompt Templates: Stick to a 4-part prompt: Role, Grounded Context, Guardrails (what NOT to do), and exact Output Format.

     

    • Knowledge & Data Cloud: If grounding with PDFs or policies, ensure your Data Cloud search indexes chunk properly. Watch Field-Level Security—if the running agent user can’t see the field, the LLM hallucinates.

     

    3. Trust, Guardrails & Security

    • Einstein Trust Layer: Decide upfront if PII needs data masking and where audit logs get retained.

     

    • Hard Refusals: Put explicit negative prompts inside each topic (e.g., "Never disclose salary bands; route user to Workday").

     

    4. Licenses & Consumption Reality Check

    • Cost control: Agentforce bills per conversation, and custom prompt calls burn credits. Don't use the LLM for things a simple Flow lookup or formula can solve deterministically.

     

    • Token limits: Heavy record grounding causes latency spikes. Keep grounding payloads minimal.

     

    5. ALM & Deployments (Where Projects Trip Up)

    • Metadata API: Topics, Actions, and GenAiPromptTemplate deploy through standard DevOps pipelines (Copado, Flosum, SFDX).

     

    • Manual Post-Deploy: Playbooks always break here. You must manually:
      1. Assign permissions and FLS to the Agent Execution User.
      2. Activate the Agent version in Target Org.
      3. Validate Data Cloud search index syncs.
0/9000

Hi everyone,

I need some architectural advice on the best way to handle report and data access for a global team without turning role management into a maintenance nightmare.

 

  • We have report folders separated by countries: Country A Reports, Country B Reports, and Country C Reports.
  • In our Role Hierarchy, we have local roles at the bottom (e.g., Sales Rep Country A, Sales Rep Country B) and a high-level corporate role at the top called Global Management.

The Business Requirement:

 

Product manager users in their Country or Regional Level role complained not being able to access reports with data related to other countries, so we moved them to the

Global Management team for them to be able to see everything

. They require full visibility to access records (Accounts, Opportunities) globally, but they also need to open and view the reports inside the local folders of Country A, Country B, and Country C. 

 

The challenge:

 

We noticed that when we move a user from a local country role up to the

Global Management

role to give them global record visibility, they immediately lose access to some of the regional reports they could see before, or the reports show up completely empty for them. 

 

My Questions:

  1. How can we avoid constantly shifting users from one role to another just so they can see cross-country reports while maintaining access to their respective records? What is the cleanest architecture to decouple record visibility from report folder visibility?
  2. What is the Best Practice in Salesforce to solve this? Should we keep these global users in a specific role and grant them report folder access via a Public Group or a specific Permission Set?
  3. Why do some reports return empty or give errors to a user right after they are moved to a higher role in the hierarchy? Is it because of dynamic filters in the reports (like "My Team's Records" or "My Role" filters) that break when their branch changes?

Thank you so much for your help! 

 

@Salesforce Administrators & Developers, @Salesforce Administrators and Developers, @APAC Architects, @Data Quality & Management

 

 

#Trailhead Challenges  #Salesforce Developer  #Reports & Dashboards  #Solution Architects  #Sales Cloud

2 respostas
0/9000

We make outbound Apex callouts from a named credential to a vendor API. The vendor has moved that API onto a private cloud network, and our callouts now fail at the network layer before auth is ever evaluated. 

 

The only working solution we've found is for the vendor to allowlist Salesforce's published Hyperforce outbound ranges from https://ip-ranges.salesforce.com/ip-ranges.json (per KB 003876184, which explicitly recommends an IP allowlist for outbound Apex callouts since Salesforce outbound IPs may not resolve under *.salesforce.com). 

 

That works, but it has two drawbacks we'd like to avoid: the ranges are shared across all Salesforce tenants on that infrastructure, so it's a weak control rather than a real identity boundary and Salesforce advises allowlisting the entire file, which is a broad and evolving surface for the vendor's security team to accept. 

 

What I'm hoping someone has solved before-- 

 

  1. Salesforce's stated preferred alternatives are mTLS and domain allowlisting, but both assume the far side is filtering at the application layer. When the block is network-level, a client certificate doesn't get you through the firewall. Has anyone actually used mTLS to solve a reachability problem rather than an auth one, or am I right that it's the wrong tool here?
  2. Private Connect / Outbound Network Connection appears to be AWS PrivateLink only. Can anyone confirm whether Azure-hosted targets are supported, now or on the roadmap?
  3. Is there any other mechanism to give an external endpoint a stable or narrower egress identity for Apex callouts?
  4. For those who've hit this: did you end up putting a relay/gateway in front of the private service and pointing Salesforce at that instead? Would you recommend it?

Any experience appreciated, we have a go-live this week, so we're proceeding with the allowlist for now and looking for something more durable after. 

 

Articles that I have already read - 

 

1. https://help.salesforce.com/s/articleView?id=003876184&type=1

2. https://help.salesforce.com/s/articleView?id=000384438&type=1

 

#Salesforce Developer  #Architects  #Solution Architects  #TrailblazerCommunity  #Security  #Integration

1 resposta
  1. 16 de set., 15:59

    Hi Piyush, 

     

    1. You're right, mTLS is the wrong tool here. mTLS operates at the application/TLS layer after a TCP connection is already established — it proves identity to something that's already listening and accepting connections. If the vendor's firewall is dropping packets before that handshake even starts, no client cert changes that. mTLS solves "who is this," not "can this even reach me." 

     

    2. Private Connect is AWS PrivateLink-based only, so it's natively usable when the target sits in an AWS VPC. Azure targets aren't natively supported — you'd need inter-cloud private peering (AWS↔Azure via ExpressRoute/Direct Connect + a transit arrangement) which Salesforce doesn't self-serve; that requires your account team and is a heavier lift. No public roadmap confirmation of native Azure PrivateLink support as of now. 

     

    3. No native mechanism gives an Apex callout a narrower/tenant-specific egress identity beyond the published IP ranges — that's the actual gap you've identified. The published Hyperforce ranges are deliberately shared infrastructure-wide, not per-org, so it's a network-layer allowlist, not an identity boundary. There's no equivalent of "static NAT per org" for outbound Apex callouts today. 

     

    4. Yes — a relay/gateway in front of the private service is the standard, recommended pattern here, and I'd recommend it. Put a lightweight reverse proxy (or MuleSoft Anypoint, or even a small managed API gateway) in a publicly reachable spot the vendor controls, with the vendor's actual private-network service sitting behind it. Salesforce calls the gateway over the public internet (allowlist-friendly, small surface), and the gateway — sitting inside the vendor's trusted network — forwards to the private endpoint. This gets you real identity-based control (API key, mTLS, OAuth — now actually meaningful since the gateway is an app-layer listener) instead of a shared-IP-range network allowlist, and it decouples you from Salesforce's outbound range changes entirely, since your callout target becomes a stable endpoint the vendor owns. This is what most orgs land on for exactly this scenario — it's a small piece of infra to own, but it's the durable fix. 

     

    Reference:

    https://unofficialsf.com/understanding-private-connect/

0/9000

Available for freelance and project work — Salesforce Solution Architect, 5x certified, Double Star Ranger 

 

One of the biggest pain points I hear from Salesforce orgs isn't what they want to build — it's that nobody fully understands what they already have. Undocumented automations, mystery Apex, flows nobody wants to touch, integrations with no runbook. If that sounds familiar, this might be for you. 

 

I offer:

  • Org assessments with full documentation of your processes, automation, and architecture
  • Process Builder & Workflow migration to modern Flow — or Apex where Flow hits its limits. If your org is still running on deprecated automation, that's a ticking clock
  • Builds, integrations, Health Cloud, Experience Cloud, MuleSoft, Apex and LWC development

15 years on the platform, PwC consulting background, currently the sole architect for a 200-user org with ERP integration and Data Cloud pipelines.  

 

Drop a comment or message me if you want a second set of eyes on your org.

 

Trailhead: https://trailblazer.me/id/egentile2

LinkedIn: https://www.linkedin.com/in/eileengentile/

 

#Freelance Project Work  #Flow  #ApexDevelopment  #LWC

#Job Postings  #Open Jobs  #Jobopportunities  

0/9000

🚀 Tickets are live for Architect Dreamin' 2026!

 

Join experienced Salesforce Architects, CTAs, and solution leaders for deep-dive design sessions, hands-on labs, and real-world discussions. 

 

Jan 21–22 | Scottsdale, AZ 

 

Early Bird pricing available for one week → 

https://architectdreamin.us/2026-registration?ss_source=CGL&ss_campaign_name=Reg07

 

@Susan Thayer @Marlene Guerra-Reeve @Jon Cline @Melissa Shepard @Chris Pifer @Paul Mccollum MVP @Steve Simpson @Architect Group, Los Angeles, US

 

 

#Architects  #Solution Architects  #Technical Architect  #Architecture & Solution Design  #Architect  #Integration Architect

0/9000
0/9000

Check out Be More Solution Architect with @Gordon Lee

 

In this episode we discuss the role of a Solutions Architect in the Salesforce nonprofit sector, emphasizing the importance of trust, collaboration, and soft skills.

 

Listen via the Audio Podcast Platform of your choice

Watch on YouTube 

#Salesforce #TrailblazerCommunity #MVP #SalesforceMVP #Solution Architects #CRM Configuration #Architecture & Solution Design

 

@Trailblazer Community Cove @* Salesforce Platform * @* Customer Success *  @Nonprofit Hub

4 comentários
0/9000
0/9000

Do you struggle to say NO?

 

This is a crucial skill for any Consultant, Admin, Developer, Architect, Business Analyst, Designer or Marketer and more...

 

It's not a selfish thing to do, it protects your clients/users, the quality of your work and your work-life balance.

 

Learn how to build you this skill by listening or watching Be More NO with @Tracy Keeling

Listen via the Audio Podcast Platform of your choice;

 

Amazon Music https://bit.ly/bemore-amazon

Apple Podcasts https://bit.ly/bemore-apple

Spotify https://bit.ly/bemore-spotify

YouTube Music https://bit.ly/bemore-youtubemusic

Overcast https://bit.ly/bemore-overcast

Pocket Casts https://bit.ly/bemore-pocketcast

AntennaPod https://bit.ly/bemore-antennapod

 

Watch on YouTube https://youtu.be/YytALcDQE44

 

@* Salesforce Administrators * @* Salesforce Developers * @Architect Trailblazers @Salesforce Business Analysts @Design Trailblazers @MomentMarketer Community Group @* Customer Success * @Trailblazer Community Cove

 

#BeMore #Salesforce Developer #Salesforce Admin #TrailblazerCommunity #Solution Architects #Business Analyst #DesignersMind #Marketing Cloud #Pardot B2b Marketing Automation

8 comentários
  1. 30 de ago. de 2024, 21:15

    Interesting thread... I believe that saying 'No' is a valuable skill - not just in consulting, but in life. However, when the word 'No' resonates too loudly with a client -- this compounds over time. If you say 'No' too much, at the time of your next consulting agreement with that client - you may get a taste of your own medicine with a 'No' answer reflected right back at you (i.e. 'No' consulting agreement).

     

    Rather than wrestle with the number of times you have to say 'No', I think it makes more sense to get a little more creative with your next consulting agreement with the client - and enable you to say 'Yes' more often. Then you and the client are happy. 

     

    I think the traditional SOW can have this kind of results more often. That's why I like to focus on a Consulting Services Agreement (with a range of services for a period of time) than a SOW.

0/9000

Hey Fellow Trailblazers,

 

I'm asking for advice on certs based on my org, experience and certification. I'm curious about these certifications Solutions Architect, MuleSoft Developer 1, PD2, and JavaScript Developer 1. I already have my PD1 and Platform App Builder Certs. I got them around a year into developing. I'm a little over 2 years of experience now. I'm ok with architecting or developing I currently do both.

 

Consideration/parameters for my next cert 

- What is most desirable (gets you employed the quickest)

- which is most lucrative (gets you the higher paying job or promotion)

- Which is most beneficial for my current experience and org

- Which certification translates best outside of the Salesforce ecosystem 

 

Org Overview

- B2B commerce managed package 

- Org relies entirely on MuleSoft for data (Records are well into the millions)

- Custom Scheduled Product Indexing and other custom scheduled Batchable apex classes

- Org relies on complex Sync/async transactions at runtime on the storefront to populate product pricing, deals and entitlements 

- completely custom experience site built off OOTB B2B Classic

- Tons of Extension classes built off B2B Classic including search and filter features

- 5K plus Accounts and climbing 

- Recent integration of Google Tag Manager and Google Analytics

 

Background/Experience/Development

- Recently architected and implemented completely custom Google Tag Manager use JS described below and frameworks

- Areas/features of expertise inside the ecosystem Experience Site, integrations (through B2B Classic APIS, APEX & Connected Apps both inbound and outbound) and the Salesforce the CRM

- Responsible for end-end architecting and development using languages mentioned below

- architecting/technical guidance with integrations to our ERP, Delta Service , and MuleSoft Anypoint platform

 

www.linkedin.com/in/brandon-radford-uwb1b4a21195 

 

Languages

-  JS (backbone, handlebar, underscore, and pubsub)

- Salesforce Languages Advanced Apex, VF, Lightning(Aura & LWC) & most declarative features

 

 

 

#Salesforce Developer

0/9000