Starting Winter '25 release, Salesforce will enforce flows initiated by a bot to run in the user context. Previously, the flows initiated in a bot ran in the system context and had permissions to access and modify all data. This change will be available for testing through the release update where it can be Enabled or Disabled by the System Admins to verify any impact.
The reason for this change is to improve security by preventing users from unintentionally allowing bots to create or modify records they don’t have access to.
To avoid any issues arising out of this change system admins need to identify the missing permissions and add them to the user profile or permission sets associated with the bot. You may need to use a custom bot user to provide necessary permissions as you may not be allowed to add certain permissions to the standard chatbot permission set.
Alternatively, if the invocable flow is already running in the system context then it should not cause any impact.
001918001

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.