You are here:
Limitations for Autonomous AI on Experience Cloud Sites
Review the mandatory constraints for search and orchestration features to make sure your Experience Cloud site functions as intended and maintains a secure guest user experience.
Required Editions
| Available in: Lightning Experience in Enterprise and Unlimited editions for an additional cost. To purchase, contact your Salesforce account executive. |
| Available in: Aura Experience Cloud sites that use Build Your Own Template |
| Available in: LWR Experience Cloud sites that use Build Your Own Template |
Data Model Object Constraints
Harmonized Citations: Standard content (such as Knowledge articles) successfully routes to the intended detail page. Non-Harmonized Citations: References to specific, raw record data trigger a login wall or an authorization failure. This behavior disrupts authenticated community members, forces guest users to a Salesforce Login screen, and can expose internal record IDs in the browser URL.
- Experience Cloud sites support only Enterprise Knowledge Harmonized Data Model Objects.
- The search engine can’t retrieve or summarize data from non-harmonized Data Model Objects within the site context.
- Citation Inconsistencies: If a search profile includes non-harmonized objects, citations
appear inconsistently for all user types (both authenticated and unauthenticated guest users).
- Harmonized Citations (such as Knowledge articles) go to the detail page successfully.
- Non-Harmonized Citations (referencing specific record data) trigger a login wall. This forces the guest user to a Salesforce Login screen and can expose internal record IDs in the URL.
Security and Access Limitations
- Guest User Experience: To maintain a consistent experience, do not include internal-only records in a search configuration available to guests. If a record is internal-only, the autonomous AI should not present a clickable citation link to a guest user.
- API Permission: Salesforce admins must assign the API Enabled permission set to all portal users. Without this permission, the Actionable Smart Search tool returns empty results.
- Guest User Context: For unauthenticated guest users, the agent runs in the context of the Bot user. This user must follow Default External Access org-wide defaults to protect sensitive data.
- Deployment Version: Agentforce Orchestrator requires a V2 Embedded Service Deployment. V1 deployments do not support the Concierge Agent Actor.
Did this article solve your issue?
Let us know so we can improve!

