Common User Access for Standard Agent Actions
Learn about the permissions required for users to run many standard agent actions.
Required Editions
| Available in: Lightning Experience |
| Available in: Enterprise, Performance, Unlimited, and Developer Editions. Required add-on licenses vary by agent type. |
User Access to Agent Types and Templates
Different agent types and templates manage user access differently, depending on the channels the agent supports and your use case.
- Review the requirements
for your agent type to determine what permissions are required for
users to access your agent.
- Many agents that interact with employees are Agentforce Employee agents. You must give your users access to individual Employee agents.
- Many agents that interact with customers are Agentforce Service agents. Your users don't require special permissions to interact with Service agents.
- Determine whether whether permissions should be assigned to end users, the agent's user record, or both.
- Agents connected to channels that are restricted to logged-in users, such as Lightning Experience, operate in the context of the logged-in user and the user’s access controls are applied. If you’re creating an Agentforce Employee agent that connects to Lightning Experience, the Salesforce mobile app, Slack, or Enhanced Web Chat on an Experience Cloud site, assign permissions to individual users or user profiles.
- Agents connected to channels that aren’t restricted to logged-in users, such as Messaging channels, operate in the context of an agent user, which is a Salesforce user record with all the permissions that the agent needs to do its job. If you’re creating an Agentforce Service agent that connects to Enhanced Chat or another Messaging channel, assign permissions to the agent’s user record.
- Review the documentation for your agent template and actions for any required template- or feature-specific permissions.
User Access for Standard Agent Actions
These requirements apply across many standard agent actions.
| Feature Your Agent Uses | Required permissions |
|---|---|
| Prompt templates, including those associated with agent actions | Permission Set: Prompt Template User |
| Flows, including those associated with agent actions | App Permission: Run Flows OR Grant access to individual flows |
| Apex classes, including those associated with agent actions | Apex Class Access: Select the Apex classes that the agent uses. |
Features and actions that leverage Knowledge and Data 360, such as:
|
App Permission: Allow View Knowledge |
| App Permission: Access Conversation Entries | |
| Permission Set: Data Cloud User | |
Data Category Visibility: Select the data categories that include knowledge article data that you want your agent to use in responses. |
|
| Object Permissions: Following the principle of least privilege, grant access to the Knowledge object. |
In addition to this list, review the documentation for each action in the Standard Agent Action Reference for any template- or feature-specific licenses or permissions. Some agent actions require add-on licenses that must be assigned to each user.

