Salesforce Admins Podcast

Salesforce Admins Podcast

Mike Gerholdt
Maa Yhdysvallat
Kieli EN
Jaksot 100
Viimeisin 10.09.2026

The Salesforce Admins podcast features real-life Salesforce Admins, product managers, and community leaders who transform businesses, careers, and community with clicks, not code. This 20-minute (sometimes a bit more) weekly podcast hosted by Mike Gerholdt features episodes to empower Salesforce Admins who are implementing Enterprise CRM solutions. There may be some (digital) confetti. For more than our most recent episodes, go to https://admin.salesforce.com/salesforce-admin-podcast.

Jaksot

  • What Does the Salesforce Admin Job Market Look Like Right Now? 10.09.2026 50min
    Today on the Salesforce Admins Podcast, we talk to Maria Alvarez-Zarrilli, Founder and Principal Consultant for Throughline HR LLC, and William Walsh, Salesforce and AI Recruitment Lead at Harvey Nash. Join us as we chat about what Salesforce employers are looking for in new hires and how to get your career started. You should subscribe for the full episode, but here are a few takeaways from our conversation with Maria Alvarez-Zarrilli and William Walsh. How the Salesforce Admin job market has changed Over the past few years, the role of the admin has changed a lot. It's no longer about how many certifications you have or how many users you can manage. While those skills are still important, being a great Salesforce Admin is much more about how you put that knowledge into action to support core business processes and generate value for your organization. So how do you stand out from the crowd? That's what I wanted to talk about with Maria Alvarez-Zarrilli and William Walsh. As recruiters, they see the Salesforce Admin job market from both sides: what it's like when you're looking for a role and what employers are asking for when they hire. Increasingly, it's not just about what you can do in Salesforce, but how you can connect it to the business and make an impact. Talk about business impact The number one thing that Maria looks for in a Salesforce Admin is requirements literacy. "It's not just being able to take a set of orders and execute it, but really be able to fine-tune that," she says. "Push back, make recommendations, be in front of what's happening and have that longer future vision, knowing that so many of these runways are going to be short with AI." Showing you have that skill is tricky, but it starts with how you talk about your experience. Are you describing features, or are you talking about the benefits? Don't just list outcomes; talk about impact. You need to show that you can think bigger than what you're building and understand how it fits with larger organizational goals. The power of showing up William urges job seekers to spend real, face-to-face time in the Salesforce community. At this point, everybody has shiny, AI-polished LinkedIn profiles and resumes. But meeting someone and making a connection with them can be so much more powerful than sitting in front of your computer mass-applying to every job opening you come across. "This ecosystem is super welcoming, and everybody wants to see everybody succeed," William says. "So go to some user groups, some local events, and you'll see how quickly people around you start to root for you and start to put your resume in front of the people they know." Maria and William have a ton of great tips for interviews and navigating the Salesforce Admin job market, so make sure to listen to the full episode. And while you're at it, subscribe to the Salesforce Admins Podcast to catch us every Thursday. Podcast swag Salesforce Admins on the Trailhead Store Learn more Salesforce Admins Podcast Episode: What Skills Transfer Well Into a Salesforce Admin Career? Salesforce Admins Podcast Episode: How the Salesforce Administrator Role Is Evolving in the Agentic AI Era Admin Trailblazers Group Admin Trailblazers Community Group Social Maria on LinkedIn William on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript Mike: The Salesforce admin job market looks a lot different than it did a few years ago. So, what are employers actually looking for right now? And how do you make sure your resume, experience, and interview skills line up with that? Well, today on the Salesforce Admins Podcast, I'm talking with Maria Alvarez-Zarrilli, founder of Throughline HR, and William Walsh, who leads Salesforce and AI recruitment at Harvey Nash. We get into why certifications alone aren't enough, how industry experience can help you stand out, and why curiosity and communication matter so much once you get into the interview. So, whether you're looking for your first admin job or your next admin, we're also going to tell you about where it's worth spending your time. With that, let's get Maria and William on the podcast. So, Maria and William, welcome to the podcast. Maria Alvarez-Zarrilli: Thank you so much for having. William Walsh: Thank you. Thank you for having us. Mike: This is going to be exciting. I have not had two people on in the job space ever, so I go from zero to two, which is smart. But Maria, let's start with you. Tell us a little bit about what you do in the job recruiting, job placement space. Maria Alvarez-Zarrilli: Absolutely. Well, thanks so much for having us. My name is Maria Alvarez-Zarrilli. I am the founder and CEO and principal consultant for Throughline HR LLC. And very much in the vein of what we're talking about, this is my new solopreneurship venture launched in the last two months in response to everything that's happening in the job market. I've done every side of the recruiting, staffing, hired and being hired from doing Salesforce recruiting at Robert Half, supporting them, Protiviti, staff augmentation to going in-house with Vicasso, formerly Internet Creations, helping build both professional services and their ISV side. I worked at Salesforce directly in workforce development in Salesforce Talent Alliance under alliances and channels and helped get employer commitments to continuing to grow the ecosystem, investing in that top of the funnel Salesforce talent, building programs to help bring people in, admins, BAs, developers. And now I am working all different roles, but still very much in touch with the Salesforce ecosystem, still working with so many of the amazing partners that I've built relationships with over the years, supporting outsource hiring, staffing, job coaching, and career guidance. Mike: Wow. So, a few things. Maria Alvarez-Zarrilli: Just a couple things. Mike: William, how about yourself?  William Walsh: Yeah, I don't know if I'm as impressive as Maria, but I'll try to keep up as we go along here. But I lead our Salesforce and AI recruitment practice at Harvey Nash. So, here, what I basically do is work with companies across not only the Salesforce ecosystem, but multiple CRMs as we continue to grow. And that ranges to help them build out their teams of admins, business analysts, all the way up to architects, AI specialists, data focused people and leadership roles as well. The neat thing about what I do is I work really closely with both sides of the market. So, I'm talking to not only hiring managers for what they need for their teams, but also speaking with Salesforce professionals every day on what they're seeing in the market and where they want to take their careers next. So, I think I get a pretty unique view of the market from both the employer and candidate side.  And a big part of my job is understanding obviously where those two things line up. So, hope we can give everybody some good information today as to what employers are really looking for and how to stand out in this ever-changing job market. Mike: Yeah, I think that's why I was so excited. Shout out to Umer who was on the podcast a long time before he even joined Salesforce that connected all of us. But I love that both of you had the same but different lenses into the job market. And William, you set me up perfectly. So, I mean that's the first question on my list, which is when you look at the Salesforce job market right now, specifically for the admin role, what are you seeing? William Walsh: Yeah, I think it's definitely a more competitive market than it was a few years ago. I think there's a lot of really good admins out there. So, just being that Salesforce admin and having a few certifications on your resume isn't really necessarily enough anymore. What I'm seeing clients respond to is admins who really understand businesses behind the platform, whether it's sales, service, operations, data, which I'm sure we'll talk about a little bit more, but really admins who can show they've solved business problems in Salesforce are the ones that are standing out currently. People that can, again, not just be that general admin, but can differentiate themselves with whether it's an AI tool or a specific industry, that's kind of been the biggest thing that I've seen change. It's become a much broader role. Again, a company would just look for someone who was able to manage users, build reports, handle workflows, keep the org up and running. Now they really want someone who can be a real business partner for them, understand the data and automation integrations. So, I don't think the admin role has necessarily become much of a different role, but it's definitely, you want to add some more skill sets to just your generalist admin at this point. Maria Alvarez-Zarrilli: Absolutely agree. I think we're seeing a really important evolution and one that really follows a lot of what we've seen before in ERP and MCSC before where you're getting a role that used to be about just configuration, build this, set this up. You had a lot of single seat admins that assist admin, a lot of people didn't even call themselves Salesforce admins when I first started recruiting in this space, which is what made it so difficult. And now there's this concentrated branding and it's evolving into this governance and you really need to be able to stand out in ways that say, to William's point, this is an outcome I can provide, not here's the number of seats I can manage, but this is what I'm able to do in terms of business impact. I understand how this is going to affect what the top line is for the company, how this evolves into the mission. People need to understand the actual companies, not just the platform itself. Mike: Those are really good points, I think. And that's one thing to jump off of too is so broader, I heard partnering with the organization, not just managing. Over the last few years then, what kind of roles or skills have changed or grew in terms of what employers are looking for in Salesforce admins? Maria, I'll start with you.  Maria Alvarez-Zarrilli: Absolutely. One of the things I've seen the most is really that requirements literacy, not just being able to take a set of orders and execute it, but really be able to fine tune that, push back, make recommendations, be in front of what's happening and have that longer future vision knowing that so many of these runways are going to be short with AI. Things are going to continue to change at such an insane pace that's not going to slow down. It's not, well, after this week, after this cycle, after this next set of release notes, things are going to calm down. They're just not. And that resiliency means that when an admin has a set of requirements, they need to be able to show judgment and wisdom, not just knowledge holding. Mike: William, you mentioned in yours that there was a certain set of things you kind of look for, things that are changing. Could you expand on that? William Walsh: Yeah, absolutely. I mean, we all know AI has been the big point as of late over the last few years, and I think data is kind of the big one, right? You can have any AI tool in the world. If your data isn't clean, it's not going to work correctly for your business, right? And so, I think data's a big one, automation's a big one. And as we see AI show up more and more, you're seeing a lot more demand for admin to have the experience with your specific industry clouds as well, your specific Salesforce products. And I think that people would honestly rather hire admin to understand, again, how to use Salesforce to improve business process rather than just someone who has that long list of certifications. I think when people first get into Salesforce early on, at least back in the day, it was, "Hey, get as many search as possible." And search are great. They get you in the door, but the real world experience is kind of what gets you over the finish line. And I think that's super important for people to understand. Mike: So, we've danced a little bit on industry and William, you brought it up. I think Maria, your answers have alluded to it. If I'm a Salesforce admin or looking to become a Salesforce admin, and I have a lot of a certain industry perspective, let's say Finserv or banking or automotive, I'm picking the big categories, should I really lean into that or should I just look for an admin role in any industry because I know Salesforce administration? William Walsh: Yeah, I would say either or, right? I think it totally depends on if you surely have a true love for that specific industry and working in that industry, you can definitely stick with it, but you just have to, again, not just be a generalist admin. I think within that industry, then you have to start diving a bit deeper into, again, if it's Finserv, say specifically Revenue Cloud and more that you can do within Revenue Cloud and CPQ. And again, learning more AI integration tools that'll help your specific business within that industry. Again, it's like I said, not just being that generalist admin I think is the main part, but I also find that sometimes you can get yourself into a spot where I feel too niche, right? And when I'm looking for a role, I can only go for roles in this specific industry because that's where my experience is.  And so, I can see where people have those pain points. I think, again, if that's what you would really enjoy to do and that's your passion, stick with it and just broaden yourself within that industry. Otherwise, it's definitely, I always find being at a consultancy or being at a partner is always good because you get to have your hands on a few different platforms at once or get to be in a few different engagements to where you can really work on a Sales Cloud environment here, but then be in a Service Cloud org over here. And so, you get your hands on multiple different things and continue to grow your skill sets, not only in one specific industry, but all throughout all the Salesforce clouds. Mike: Maria, I'd love your thoughts. Should I lean into my industry first or should I lean into my admin skills and apply across the board? Maria Alvarez-Zarrilli: It's a very tricky question because ideally it's one of those, well, it depends, the lawyer answer. On the surface level, I would say yes, lead into the industry because of how that supports the differentiator of understanding the business outcomes. If you are coming from banking, if you are coming from healthcare, if you are coming from education and re-skilling into Salesforce, you're going to be able to speak more intelligently, especially at some of these, I'm going to use this phrase lightly now, entry level roles because you don't have entry level understanding of what the company is trying to do, what kind of outcomes they're looking to drive. And that's going to really support what I said about that requirements, scrutiny, the wisdom, the choices that you're making, and that's going to be an important differentiator. However, in today's job market, I would not tell somebody to limit themselves to only applying to jobs inside of their industry because there is a transferability, there is a lot of change happening inside of all of these industries, and people at the end of the day need to pay their bills. And sometimes, there just may not be enough opportunities in a given industry that makes sense for them when they're looking at jobs that are either available for remote, that are in their geographical area, if they're looking at companies that are pushing RTO, et cetera. So, if somebody really had a passion to what William and I believe you alluded to earlier about an industry that maybe they don't have deep experience in or maybe they don't have a lot of career experience at all, finding ways to stand out and deepen that industry knowledge so that you can stand out, I think is just as important as having that deep industry experience and figuring it out. Mike: Again, you set me up perfect for what I was thinking because I was kind of hovering around this question, but let's jump into this part of it. For each of you, when a candidate lands on your desk, what is it that makes them stand out versus others? William Walsh: Yeah, so I can start. I mean, like I said, I think for me, certifications matter. It shows commitment, it shows employers that they've got some confidence in your technical foundation, that kind of stuff. But what's really important to me is when I sit down, not only look at a resume, but when I speak to someone, can they walk me through three really impactful, at least three really impactful kind of projects that they've delivered? And nine times out of 10, a client is going to want to talk to someone who can walk them through really impactful projects they've been able to deliver rather than someone who's just got a list of certifications on their resume. So, I think that's super important. Another thing is having a bit of technical ability as well. Again, having that crossover, differentiating yourself from just your generalist admin, someone that can.  Again, when I say technical sales, I do not mean coding Apex, but more so building and configuring and being able to do a lot of work with workflows nowadays. And again, having some AI focused tools that you've worked with in your current role. Most clients now are using AI one way or another, and when they're hiring an admin, again, they want that person. A lot of times they are taking on the headache of trying to integrate that tool correctly, and it's probably not their role. And so, they want to have someone that they can bring in right away and understand what exactly is going to work for their business and how they can best get their platform to where they need it to get to. So, like I said, I do look for certifications, they're great, but at the same time, it's really about real life impactful projects you've been able to deliver on and what your role was in those projects. If you're able to get a bit more technical and tell me you did some of the configuring yourself, that goes a long way when you put it in front of a client rather than, again, I was just kind of creating dashboards and all the other generalist admin stuff that we would usually look at five, six years ago. Mike: Yeah. Maria, I'd love your perspective on what makes a candidate stand out to you. Maria Alvarez-Zarrilli: Yeah, I think there's a handful of things. One, just being completely candid, that they look like a real candidate. The fake candidate's a real thing now, that they have verifiable information that they are active in whether it's LinkedIn, the Trailblazer community. I'm seeing posts that look like they're written by a real person. I've seen a resume that looks like it's written by a real person, just really to start at the surface level. And that can be really tricky because I have seen profiles, LinkedIn profiles, resumes, emails, communication, LinkedIn posts that because of trying to demonstrate this very, I think, professional demeanor and best practices, sometimes it can come across so boilerplate. My spidey sense tingles for a second and I catch myself going, "Is this person real?" And that is a real risk that people run now in polishing their information off. So, I'm just going to start at that surface level.  Once we're actually interacting with a candidate and we verify this is a real person, not a bot, what really looks is that what's driving a person's? Where is the learning resiliency? Where is the resiliency within the stories that they are telling, not just the polished, "I was able to increase this by this percent and that percent." That's wonderful. Having those numbers is great. That is now the bare minimum. When somebody can say, "But," adding to the star method, that an extra R, that reflection, "But now with this new technology, I would do it differently. But now knowing how our customer base changed six months later, I would do this. But now knowing that more and more companies are going to be absorbing other companies, I would approach this slightly differently." Right? That reflection piece of saying, not just giving me the story outcome, but how they would take that into a similar project going forward, or even if they're at that level, right at that cusp of people leadership, how they would train somebody else based on their experience of going through those steps, that to me is a significant differentiator because that tells me that person has the ability to stay the long run, that they are not just looking at just having that list of facts and figures for the resume, the output, the promotions, but that they're actually looking to build both within themselves and around them. Mike: So, along those lines, thinking of where candidates spend their time, because I mean, I'm old enough to remember that I used to have to go to a bookstore to look up resume templates and go buy special resume paper. Now everything's electronic. I won't date myself, but I did in high school have to check out the internet for 15 minutes at a time. It's amazing we had anything done with dial-up back then, but we did. But you mentioned polish, and I think it's crazy that there's bots out there, but we're talking about real humans. Where are the real humans putting too much energy into either their resume or their experience or something that's not actually helping them in the hiring process?  Maria Alvarez-Zarrilli: Well, one of the top ways I think is just in their general job search. So, LinkedIn did a pretty big overhaul of their algorithm in 2025 to an algorithm called 360 Brew, and it really rewards humanity and consistency within the process, their post, their about section, their experience, the resume that's uploaded, their interactions with recruiters on the backend, et cetera. And putting everything into a ChatGPT, a Claude, a AI of choice and spitting it out is actually. I'm finding a lot of very talented people are telling me, "Oh my gosh, three years ago I couldn't open my LinkedIn because every recruiter from here to Singapore was in my DMs and now it's just crickets." And most of that is because everything is so polished and saturated and M-dashed and if not this, then that that it's getting downgraded on the algorithms. And the same things happen, and that means that they're not showing up high in the recruiter back end of LinkedIn as much as high in the results. So, really being able to have a unique voice and tone and sounds like the person that shows up in the interview, it does matter. And it's a hard line to draw because people want to present the best version of themselves, but that kind of certified human best version of themselves is mattering more and more.  Mike: Yeah. I mean, it's very tempting to feed your resume or your LinkedIn URL to AI, pick which one and have it spit stuff out. I mean, it can write how remarkable you are in some pretty punchy language that you're like, "Oh, I don't think I would've written that before." But the other half of that is everyone else is doing it, so now yours sounds less human just like everyone's. William, let's take a different angle for you. Opposite of that, what are candidates sometimes underestimating they should spend time with that hiring managers are really looking for out of candidates?  William Walsh: Yeah, I mean, I think it's tough on the resume side of things. What I would tell people is communication is the number one thing. Like you both just hit on, your resume can be great. It can look like you are the number one person that should get this job, but at the end of the day, I think, again, an admin is kind of sitting between that business and the technology team, and they need to understand how to talk to VP of sales one minute. They need to understand how to talk to a developer the next minute, and communication is key. And so, it's hard to say on paper, "Hey, what am I maybe overlooking here?" But it's really the communication aspect, and that comes from working on projects, volunteering. If it's tough to get a role, volunteer somewhere on a real project, get hands-on experience where you'll be able to explain what you really did.  Again, I think it's tough to say what people are overlooking on their resume. Again, everybody's resume can look great. It's really, once you get in front of someone, the communication aspect, because that's the differentiator at this point. Like we just said, everybody's got their resumes being made by an AI tool somewhere. They're all going to look great. What are you like when we get on the phone? And if you are really able to, again, explain what you can do for a business, the value you can bring for a business, and not just your typical reading off your resume, which a lot of folks do, a lot of folks will just rely strictly on their resume and just go into an interview studying up their resume and the bullet points that they have in there so they can just hit those soon as a question comes up. You need to be able to be a real person. People want to work with people they enjoy working with. I think that's a big thing that a lot of times people forget. You can be the best candidate for a role, but if you aren't clear with your communication, you don't seem like an enjoyable person to work with on a daily basis, there's a good chance they'll go with someone that may have a lesser skillset just because, hey, we can train this person up to be where you are and we really enjoy working with them. Again, they're clear with their communication. They can translate business needs and requirements to our technology team well. So, that stuff is what really I see matters the most once you get into that intro stage and meeting a client. Maria Alvarez-Zarrilli: And just to add to that, William, I think the asking questions, not just having answers. I think your point about having the answers, the mission statements, the details memorized is so spot on because I think the risk of that is there isn't that conversation where people are figuring it out together sometimes and showing up and saying, "I'm not sure, but here's how I think I would approach the problem." Or even just asking back, "Well, what's your internal method? Where would you start?" And then taking that from there. Sometimes even within the not knowing, how people approach that situation of not knowing, I think is really underestimated of how to show up or coming back. I had a candidate years ago who bombed a question, just stumbled and fumbled and got flustered and frustrated and 24, 48 hours later, sent me an email and said, "I looked it up. I actually didn't know about this. Here's what I learned. Here's how I would approach it right now. I actually though this was really interesting. I found a community group. They have a call here. If anybody else struggles with this question, you can send them this link and they can learn more about it." And actually gave me their references, the work that they did, and that's what comes into that learning resiliency that was... I think people underestimate the ability to come back or not know and demonstrate how that not knowing makes them someone that would be enjoyable to work with, that the team could see themselves being with. In real life, you don't have the answers sometimes when you're figuring the problems out. William Walsh: I was just going to jump in there and say, what does a good admin do? They ask questions, right? Maria Alvarez-Zarrilli: Yeah. William Walsh: You don't get told to do something and then just put your head down and do it. Usually you want to know, "Hey, why do we want to do this? What is the value for the business that we're able to do this?" Right? Maria Alvarez-Zarrilli: 100%.  William Walsh: And so, you want to know what that outcome is going to lead to, or where in that business is this going to help support if we're able to create this workflow this way or whatever the case may be. And so, a good admin asks questions and you have to have that same approach when you're going into an interview. You have to, again, not just be there with. You have no idea how many times I get feedback from a client where they say, "Hey, they seem like they're great, but they seem very robotic, right? They were just kind of reading off a sheet. Here's question, answer, question, answer." And a lot of times, clients want candidates to put them on their toes and ask questions that they might not even know the answers to. But for them, that's in their head they're going, "Oh wow, you know what? That's great. I didn't even think about that."    Maria Alvarez-Zarrilli: And that can be a small failure of the hiring process as well because the roboticness happens on both sides. You have hiring managers that have their rubrics and going through, and it's very important that we have non-biased criterion that we're hiring towards the competencies and the skill sets. And also, there needs to be room in that interview process to have that conversation and measure someone not just on their. Did they guess the answer correctly? Did they memorize the right answer? Were they able to regurgitate that? But were they thoughtful? Did they have really good questions, inviting and making enough time and room for that instead of filling every single space with call and response?  Mike: Yeah, I can't agree more with both of what you've said. I think in the times that I've been interviewing for different positions, both myself and interviewing to fill positions for other teams, nine times out of 10, I enjoy it if the candidate doesn't know the answer, but tells me their thought process to getting to an answer. I say an answer because they may not know if it's correct or not until they continue to research it, but it's understanding their thought process in that interview that I always wanted to know. At least for me, that's what I've always found valuable. William Walsh: Absolutely. And you see a lot of times, there's many different ways to do things within Salesforce, within many orgs. And a lot of times when people are interviewing, the main basis of it is, "I want to see how your mind works. I want to see how you get from point A to point B." Not to say it's wrong or right, but I'm curious. I think, again, like you just said, a lot of it is how does your mind work? And that's a huge part of what we see on a lot of interviews as well. Not necessarily it was the wrong or right answer, because usually there's a lot of right answers, but just how did you get there in your mind? How do you get from point A to B? It's always interesting for people to see. Maria Alvarez-Zarrilli: Curiosity is such an important word there because there's such a performance to the interview process and whereas the actual job requires so much curiosity. And if you can demonstrate that, I think that's going to be a significant differentiator toward and hit all the points I think we hit, making somebody be able to understand, "I understand what it's going to be like to work with this person. Maybe they didn't come to the right answer, but I feel like we could have the type of conversation that would yield the best answer, the learning resiliency, the ability to continue to develop knowledge." Mike: Yeah. It's interesting, Maria, you bring that up because on the admin relations team, we've done surveys and had some research done. More than a few times. And every single time, curiosity or curiousness is usually one or two on the list of traits. I want to jump ahead to that first job, but I want to think about it a little bit differently because for a long time in the ecosystem it was, do I become an admin? Do I become a consultant? I think it's probably changed now where a lot of companies are hiring admins. A lot of, William, you brought it up. Some people are choosing to be consultants, but I also think there's contracting work. And the bulk of the people I know do contracting work. And I kind of almost think of that as you can work for an organization, you can do consulting where you're under somebody else's shingle, or you can do contract work. And I'd be curious, what is a trait or how would an admin, a person looking to get into that job role say, "Oh, I need to work for an organization and I'll be a good fit or I'm really a good fit to be a contract admin or I really want to do consulting." How would they find that or what is something they should look at themselves to determine what path of those three to go down? Maria Alvarez-Zarrilli: I think to start, I can start on that one as I moved into the consultant contractor seat myself. I think looking at what part of the work excites you the most is important. If it's that initial gathering the requirements, figuring it out, solving the problem, meeting new people, working with new teams, if that initial part of it is not what you overcome to get to the solution that then you maintain, then you continue to build upon, I think the contracting consulting often can tend to be a path that people will continue to stay very motivated in because there is a Groundhog's Day to that type of work, right? You have to meet a lot of new people over and over again. You kind of very Sisyphean, you roll that boulder up the hill, you get to the top and boom, it's right back down at the bottom with a new project. Whereas somebody who enjoys finishing a project, scratching something off the to-do list, looking upon the Simba, everything the light touches is what you have configured landscape and then continuing to improve upon that probably is looking for more of that in-house seat, looking for more of that stability and is not going to enjoy that contract work where they're just constantly inheriting a new mess, a new series of problems and nothing ever feels finished.  William Walsh: Yeah, absolutely. I mean, I'm a big believer in contract work. I've done a lot of work with a lot of partners with contractors. I think if you're trying to break into the ecosystem, I think it's great. You get exposure to a lot of different environments like I kind of touched on before, different businesses, different problems. And a lot of it comes at a quicker speed. Again, if you were just at that solo in-house role, you're dealing with your org and at the pace that your organization wants to go with that. And from an employer's perspective, I think you're able to actually point to projects, real projects that you've studied that you've worked on rather than just saying, "Hey, I've studied Salesforce. I've gotten my certifications." And so, I think, again, people can help... What I think is always interesting is people sometimes feel like they have to completely start over if they're trying to get their start in Salesforce. And what I always try to tell people is use your previous career when you come into Salesforce, connect those dots. If you come from a sales background, you understand sales processes, right? If you come from a finance background, you understand financial processes. If you come from customer service, you understand that whole customer journey, right? And so, go into a role within Salesforce to where you can utilize your previous career and again, the business knowledge that can actually make you a better Salesforce admin is ultimately being able to... Again, the business knowledge can actually make you a better Salesforce admin because Salesforce is ultimately a business platform, right? So, if you have that experience, you can utilize that in multiple different ways in Salesforce. And whether that's with a partner, whether that's in-house, I think, again, contracting is a great way to get your foot in the door. And there's not much commitment on the client side either, so it's a lot easier where a client, it's almost, they can call it a try before they buy type of period. And it's the same on both sides, right? I think it's the same for a candidate as well, right? It's for them to try out the role without much of a large commitment as well.   Mike: I like that. I'm realizing we spent a lot of time from the admin perspective, which makes sense. It's an admin podcast, but I do want to focus at least one question on employers, and I'm going to try and go right for the heart of the main thing. In both of your experiences, what is the number one thing employers are getting wrong when they're writing admin job descriptions?  Maria Alvarez-Zarrilli: William, do you want to start on that one? I'm happy to jump in. William Walsh: Yeah, yeah, I can start on that one. I think, again, the funny part is, and Maria would probably say the same thing, I don't know if anybody writes job descriptions anymore, unfortunately. And so, I think that's a big problem is they go into, again, your ChatGPT or your clone and say, "Hey, create me a Salesforce admin job description." And you look at a lot of them, it's your basic, again, like we talked about your generalist admin kind of bullet points in there and people will apply and then they go to talk to people and then they start to realize these are all great generalist admins, but not what we need. And so, I think a lot of it comes on the employer side where they need to really have a human type up that job description, have someone who's working with Salesforce every day in the business say exactly what our pain points are and what someone can come in and help us bring value right away.  And I think that's the big issue. Like I said, most of the, I would say nine out of 10 job descriptions I see are written by some type of AI tool. And you can tell right away, you could copy and paste most of them and put them into the same job description for different companies, for different industries. They're all basically the same. So, I think that's on the employer to really be better at doing their due diligence on what we're actually looking for. And when I work with a client, we'll see it time and time again where, "Hey, we're missing the mark here, we're missing the mark here." And that's on us to do our due diligence to say, okay, what is really needed? Not just your Salesforce. I know you need a Salesforce admin, but what does your Salesforce admin look like compared to what this organization's Salesforce admin might look like? They can be totally different job titles and requirements, right? And so, employers need to do a much better job of actually describing what that role is going to look like and not just your basic, "Hey, we want someone who can, again, create flows and document requirements and all your basic kind of stuff." Right? So, I think that's what I would say is most of the stuff I see is AI written and they don't really take their time and then they find two, three months down the road, why have we still not found this person? Maybe it's because we're not targeting the right audience. Maria Alvarez-Zarrilli: 100% agree. I'll put a bold prediction that if in three to six months you go and start looking at admin jobs, how many of them are going to have completely retired certs still listed as the relevant or we had talked about it before, must have five years of experience in something that has existed in five months. There is a basic lack of understanding of what they're looking for in the job description. And a lot of time it's a speed thing, right? People want to go for, "Okay, we want to hit same as the candidates. They want to hit the keywords, they want to hit a high search, they want to show up on the right people's feed." So, a lot of times it's kind of a regurgitation, it's thrown into AI. It's dusting off an old job description from the last time they hired, whether that was three years or three months ago and reposting it.  And what employers really need to be doing, it's something that I work with a lot of employers on is looking forward in the requisition. I need somebody who is going to join us for this thing that we're doing, not just a list of what we've needed up until now, right? Showing where that investment is going to be and having that path in mind, not just, I need someone who checks this boxes and great drinking game in recruiting and hiring is hit the ground running, right? You'll be blasted. I need someone who can hit the ground running and said, "Okay, when we get to the finish line, what do they do then?" Because you have to think forward. Understanding what that rubric is and what the weighting is around things. I can't tell you what, especially in, I would say 2012 through '17, you saw the job descriptions, excellent verbal communication skills and jobs that are not client facing, right? Being clear about what the job actually requires and making sure that those requirements fit, that they're just not the grab bag of keywords that people are just used to seeing, but say looking at, "Hey, what does the data judgment look like? How good are they at requirements gathering? How are we going to actually measure that in the interview process? Why is that important? Who is it important for? What should that look like? What does success look like in the past?" But also what could success look like in the future and not narrowing it down so tightly. And then the last piece, and I'll say the kind of small kind of controversial thing is I think more companies need to pay for the work product from the interviews. A lot of times they give them real business problems and there is a very exploitative aspect of interviewing where sometimes you get a lot of knowledge from very excellent candidates and these candidates are going on a lot of job interviews. It's exhaustive. You go on LinkedIn and see, I interviewed a hundred times to get this job. I applied to 200 jobs to get this. If somebody gets to the end of the process and you are going to ask them to do a take home assignment, the best way you can get the most out of them, give them a reasonable contractor rate, give them work that you can use and get the information from them and really narrow it down because you will be really intense about who you get to that final process if you know you have to pay for that work product. And candidates would really respect, I think, being able to give work that matters, especially if they're looking for work.  Mike: Wow, I like that. That's very different than anything I've ever heard. And it would make me rethink a lot of the stuff that I've delivered because I know in the interviews I've been asked to deliver some sort of project or here's an org and here's a scenario that we gave 20 other candidates. We want to see what you do. I like that twist to be really something tangible. When I push my presenters in admin track for Dreamforce or TDX, I always say, when you get done with your presentation, think about what the person's going to do when they stand up. What do they do next? And I'm going to do the same and hold myself accountable for when we end the podcast, the listener doesn't just take out their earbuds or probably switch over to Apple Music or something and finish the rest of their dog walk. But if you were, because in my world, it would be really cool to get the three of us on stage at TDX, which is about six months from now. But if somebody was listening today and looking for an admin job, maybe they're employed, maybe it's their first job, maybe it's their third job, depending on no matter where they're at, where would you tell them to focus their energy?  William Walsh: I guess I could jump in on this one, Maria. And I would just say, I think we've hit on it a few times, but be very clear about what you actually want to be hired for, right? I think a lot of people's resumes can be a bit ambiguous in that. Make your resume and LinkedIn reflect that as well, right? Don't make a hiring manager dig through four or five pages to figure out what you can do. I'd spend a lot of time networking. I'd go to Salesforce as an awesome ecosystem. We talked about Mid-Atlantic Dreaming, which myself and Maria were at. We've talked about obviously Dreamforce coming up and TDX. And so, there's a bunch of networking events out there and obviously myself and Maria are also part of user groups. There's a ton of user groups out there that are obviously free to join, right? Be involved, network.    Again, talk to Salesforce professionals, talk to as many recruiters as you can. I know sometimes, people can think recruiters can be annoying, but I promise you, they're just getting you in front of people that you would've otherwise not been in front of. Our goal is to just introduce you to other people. And so, get as many recruiters as possible, consulting partners. The job market is super competitive, right? You can't rely exclusively on applying to jobs on LinkedIn all day long. You have to know people in the ecosystem. You have to get your name out there, get your face out there, make it known that you're a part of this ecosystem and this ecosystem is super welcoming and everybody wants to see everybody succeed. So, you get to network a bit, get a chance to get to some user groups, some local events, and you'll see how quickly people around you start to root for you and start to put your resume in front of people that they know in the ecosystem as well.  And so, that's the one thing that I think some people miss out on. They kind of really rely on just, "Hey, I applied to 20 jobs today on LinkedIn." Again, get out there, network with people in the ecosystem. This ecosystem is awesome and super welcoming. I don't know if I've ever met somebody in this ecosystem that wasn't rooting for everybody else around them. Everybody can win. So, I would say network as much as possible. There's a ton of different things out there for people that are trying to make their way into the ecosystem to get into. And again, you get in front of the right people, you get yourself, make some friends in the ecosystem and you'll see how quickly things start to move in the right direction for you.  Maria Alvarez-Zarrilli: Yeah, I 100% agree. I think the networking aspect has not changed. With everything that has changed in the last 15, 20 years in Salesforce, what has not changed is the power of community, the power of showing up, asking questions and getting connected. And that does not mean you have to be the most active on social media. You can be active in real life, but really showing up and participating in community events, the events that are available, listening to the podcast, et cetera, is so important to engage. The other thing I would say is to really look at your LinkedIn profile, your resume, your email communications, and also your networking prep and kind of filter everything through. Why are you asking? Why this person? Why this company? Why this outcome? So, what? Why does it matter inside of all of it? And then the how. So, when you're answering interview questions, when you're networking, when you're sharing your elevator pitch, really honing in on those three aspects I think are going to yield more human conversations versus just a bullet list brag show. People are trying to get so much information out. We forget that within that efficiency, it still needs to be a conversation. So, really practicing that human aspect and giving people context and understanding and not trying to be perfect, but just showing up consistently I think is going to be the most important thing that people can do. And try to un-AI your LinkedIn information. I cannot stress that enough. Your headline, your about, and your experience section should match.  It should be consistent and it should have some sort of human aspect to it because I don't think people realize how many profiles and information get passed over because of either algorithmically, it's too polished or the lead is buried.  Mike: Yeah. I mean, I think that's a perfect way to end this podcast. I couldn't think of it any better. I mean, I know the more than handful of people I've interviewed, every single one of them has come back to a user group or some sort of Salesforce event that, hey, I went to and I didn't have a job and I walked around the room and sure enough, a couple weeks later, people were calling me or an employer called me because they saw me and got to talk with me, which essentially elevated you above that stack of resumes that they were already looking at. So, I appreciate it. Maria, William, thank you for spending this time going over what is an ever-changing job market, what is constantly being invaded by AI and uninvaded by AI, I think, and helping admins try to find that niche and try to find those jobs that are really rewarding for them because I know the ones that do end up presenting everywhere and you can always just tell it in them. So, thanks for spending the time with us and thanks for helping out the admin community. Maria Alvarez-Zarrilli: Well, thank you so much. William Walsh: Awesome. Thank you so much for having us. Mike: Well, I really want to thank Maria and William for being on the podcast. It was great that I could be connected with you to talk about everything that admins are looking for in this job market and really help us make sense of what employers are actually looking for in Salesforce admins right now. For me, I think the big takeaway is that job search can't be just about adding another certification or sending out more applications. You've got to be clear about the problems you've solved, show how you think, ask good questions, and most importantly, get involved in the Salesforce community so people know who you are and what you can do. Now I want to thank you for listening and if you know a Salesforce admin who's looking for their next opportunity, share this episode with them. Until next time, we'll see you in the cloud.    
  • Security Center Essentials: What Admins Need to Know Now 03.09.2026 26min
    Today on the Salesforce Admins Podcast, we talk to Sabrina Simeroth, Product Manager on the Salesforce Security Product Team. Join us as we chat about the new Security Center Essentials feature and how to work security reviews into the rhythm of your organization. You should subscribe for the full episode, but here are a few takeaways from our conversation with Sabrina Simeroth. What is Security Center Essentials? The last time we had Sabrina on the pod, we were talking about Health Check scores. However, as she explains, that number is meant to be an assessment of your organization's security Configurables at a single point in time. But what about continuous monitoring? That's where Security Center Essentials comes in. "With Essentials, we're trying to give a broader and more ongoing visibility," Sabrina explains, with a focused set of security metrics you can monitor over time. It makes it easy to see things like what managed packages are supported, which third-party platforms have access to your data, and who in your organization made changes. In other words, Security Center Essentials gives you a map for how your org is structured, making it easier to spot potential problems and make sure your security and governance are aligned with your business goals. Two questions to ask for security reviews So how do you get started with Security Center Essentials? For Sabrina, it's all about context. Once you've run Health Check and dialed in your security settings and policies, you want to use the metrics on Security Center Essentials to get context for how things work in your organization. From there, Sabrina recommends asking yourself two key questions: What should be in my environment? Who owns this managed package? Who installed it? Who is using it? What has changed most recently? Were you expecting it? Who did it? How does it affect your business processes? Sabrina recommends establishing a monitoring cadence around regular business process milestones. If something is updated every Tuesday, check before and after to make sure everything happened as expected. As an admin, you have the best operational context to flag potential problems and bring them to your security and governance team. Why you shouldn't chase a perfect Health Check score While your Health Check score is helpful for giving you a general understanding of how your security standards compare to industry best practices, Sabrina urges you not to chase a perfect score. "Your Health Check score should begin a security review, rather than ending a review," she explains. It's there to flag areas of your org that need a closer look, so you can make decisions about how much intentional risk your business needs to carry. The most dangerous security threats are the ones you don't know about. It's OK not to have a perfect Health Check score, as long as you know why you're doing it. Make sure to listen to my full conversation with Sabrina about how to use Security Center Essentials and Health Check. And don't forget to subscribe to the Salesforce Admins Podcast so you never miss an episode. Podcast swag Salesforce Admins on the Trailhead Store Learn more Salesforce Help Docs: Security Center Essentials Salesforce Admins Podcast Episode: What Are Security Essentials for Salesforce Admins? Kate Clicks Through It: Protect Your Salesforce Org With Health Check Admin Trailblazers Group Admin Trailblazers Community Group Social Sabrina on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript Mike: Security is one of those things where it's really easy to look at a score and think, "Great. I'm done." But your Salesforce org doesn't sit still and neither does your security posture. Today I'm talking with Sabrina Simeroth from the Salesforce Security product team about Security Center Essentials and how admins can use it to understand what's connected to their org, what's changed, and what deserves a closer look. We talk about why getting a perfect Health Check score isn't necessarily the goal and how to work security reviews into the rhythms of your organization. So if you've ever opened up a security dashboard and wondered, "Okay, what am I actually supposed to pay attention to?" This episode is for you. Let's get Sabrina on the podcast. So Sabrina, welcome to the podcast. Sabrina Simeroth: Thank you. Thank you so much for having me back. Mike: Well, it's worth talking about because security is always top of mind for Salesforce admins. And the last time I had you and Laura on, we were talking about Security Center Essentials. And I think if memory serves me right, people now have that available to them and admins can start getting in touch with it, right? Sabrina Simeroth: Yeah. Absolutely. So that has been launched and it is fully rolled out. They should be able to see that in production orgs and some sandbox orgs as well. Mike: Sweet. So you're integral part of security at Salesforce and you do a lot. Refresh my memory, what's your domain and what do you handle at Salesforce? Sabrina Simeroth: Yeah, absolutely. So I sit on the product management team. I support our security center product and that also incorporates the Essentials product that we just launched and some of our other free tools like Health Check in setup. And then I actually work really closely with a few other PMs that support other features of the premium products like our agentic features and work really closely with the Shield team as well. Mike: Shield. Sabrina Simeroth: Yes. Mike: Yes. Sabrina Simeroth: All security, all the time. Mike: Our secret MCU product. So let's talk about Security Center Essentials and actually Health Check. I'd love to know, and probably admins too, we love when we get these features, but what exactly were you trying to solve with Health Check? Sabrina Simeroth: Yeah. So Health Check is a really valuable ... I would call it a point in time assessment of some of the critical settings that we find in setup. These are your security configurations. Oftentimes if you've been to any events, you hear them called configurables. So these are settings like your password policies, your session settings, some of those toggles that you can turn on and off. But with the Essentials, we're trying to give a broader and more ongoing visibility. So it's not just a point in time, this is something that extends that capability. Health Check is still really valuable and it is a collection of these configurations that are set against a baseline or a set of standards so that you can see where your posture is at at any given time. But we really wanted to extend that and allow admins the ability to see how changes in their system, how changes in their configuration occur over time, as well as broaden the view of what they're actually looking at. So not just those toggles. Mike: I always liked Health Check was like right now, here's where you're at with links to open things. So that makes sense. It's making the dashboard a little bit bigger. I think for a Salesforce admin who just opens Security Center Essentials for the first time and they have a whole bunch of different metrics looking back at them, where should they focus? I think of a car dashboard. Well, if I start my car and the fuel light comes on, probably the most important thing to pay attention to. But as an admin, depending on the level of security awareness that I have, I may not know what number is the most important number. So help me walk through those different metrics that they're seeing. Sabrina Simeroth: Yeah. You are so spot on. So I think there's a tendency to want to stack rank, which is the most important thing to look at. If I could put it very simply, so we started with a very narrow scope of, let's call it metrics. So we wanted to extend the capabilities of Health Check. We wanted to give a broader view and give admins access to what does the actual state of your org look like? What are the things that are connected to your org? What are the managed packages that are being supported? Where are your access points? Those types of things. These are all really critical things for admins to be aware of because it's basically how is your org structured? So I think that that's the key. It's not that you should focus on or stack rank immediately any one metric in Essentials. It's more around let's figure out what our baseline is and what is the actual standard for our environment. So I would resist saying one over the other. Obviously, I think the tendency is to lean towards let me look at the thing that has a score. Let me look at Health Check. I would actually say, ask yourself two questions as an admin. What looks unfamiliar to me? So look at the seven metrics. And I apologize in advance because come Dreamforce, we're extending that seven metrics to 14 metrics, but we're still keeping the scope very narrow. Mike: It's no like Salesforce to just double anything, right? Sabrina Simeroth: No. Not at all. But we're trying to bring the most critical things for you to pay attention to the forefront and just keep it narrow so that you have a really, really solid idea of what should be in my environment and then what has changed most recently. Those are the two things to be really looking at so that you can start asking yourself questions. Does this actually make sense? Should it be here? Is there an assigned owner? These are the types of questions. It's really about laying out a map for the admin to start getting the right context about how the org is configured and then start evaluating is this good or bad and does it align with the business needs? So that would be my advice using essentials. Mike: Yeah. No. It makes sense. And I think you pointed out that what's really nice is you're not just seeing today's configuration, you're seeing how things changed and that if you're a Salesforce admin, whether you're just getting started in a new org, you can watch that progression. Or if you're coming to a fresh org, if you just got hired, that was always, and I still think is top of mind for a lot of admins. "Hey, when I parachute into a new company, what do I do to look at an org that I'm inheriting?" And so I think let's apply security center essentials to that and say, "If I inherited an org tomorrow, how could I use that to see how things are changed or understand a little bit more about the org that I'm working in?" Sabrina Simeroth: Yeah. That's a great question. So if we look at the metrics that are included in Essentials, it's things like what types of packages do I have installed? What type of connected apps? So how is data interacting with third party packages? How is data interacting? And the great thing about these metrics is we're giving you visibility into who actually installed these packages? So is that normal? It's that type of context. First take inventory, see what's connected into your apps, see what IP ranges you have associated with your different profiles. What are your trusted IP ranges? Take a look at your security configurations through the Health Checkout. Are you using any baselines that were already set up? So if this is a new org did somebody already have a baseline, have they already done a security review? Check those things first and then start establishing your context. So the metrics do a really great job of showing you who may have been the owner of those, who may have installed or made specific changes at any given time. So use that as your starting point and start to do your own investigation, building context around which teams are using this? Who is the true owner at this point? Does this make sense? Is it still actively being used? That context is going to be really helpful when you start to get into the monitoring piece, which is when changes are made, then an admin can more easily flag like, that doesn't align with what I'm expecting. Does that make sense? Mike: Oh, absolutely. That whole connected apps and packages part is ... If you're working with people in a larger team or ... Boy, I got to tell you, I've done this accidentally where you set up a user and you forgot to deny them access to install packages. Sabrina Simeroth: Oh yeah. Just delete access. Mike: And I remember I had this power user. I found this whole app exchange and we can download apps. And my face just went white. Because I was like, "But you couldn't do that, right?" And they're like, "Oh no, I did totally." "Oh, well, you're not going to be able to after I finish my salad." Sabrina Simeroth: Yeah. And that's so true. It's very hard when things are scattered all over the place to maintain that. It is a very complex platform for a reason. It provides so much flexibility to the users to really align with business. The challenge then becomes like, okay, how do you make sense of that to make sure that you're doing the right things as it relates to security? And so that's the whole goal. It's let's bring some of those key elements so that you can quickly identify where those changes, those missteps, they always happen. They're not going to be able to be avoided. But how quickly can you evaluate and then shift and make changes to address any gaps or concerns or what we consider gaps in your posture? Mike: Right. Right. One thing that I loved about Health Check was it gave me a score and admins love score, got to get perfect score on everything. The idea of making it to a hundred on Health Check being perfect as a goal, is that really a goal or how should admins think about that number? Sabrina Simeroth: That is such a good question, and this is so common. So I was a part of the Own acquisition. I've been working with Salesforce security products for the past 10 years. And in that previous role, I actually helped customers implement their security programs and implement their security tooling. And we would get this all the time, customers just really wanting to reach 100. There is this- Mike: I want to be perfect. Come on Sabrina. Sabrina Simeroth: Strive for perfection. It's so common. And when it comes to risk scoring, the desire is always to reach perfection. Here's how I would look at it. A higher score is a very useful signal. A low score is a very useful signal, but 100, I would say, should not become like a trophy or the end goal without very valuable context. So context really matters. So Health Check compares settings with a standard baseline, but every organization can have very legitimate reasons for different settings or the need to actually carry some risk in their system in order to be able to operate the business. So not every setting makes sense for every customer. So the score should really begin a review rather than ending a review. It really needs to be treated more of ... We were talking about the car. It's more of a gauge. It's not like a report card that tells you you're good or bad. It is telling you where to look so that you can actually evaluate and get the right context to say, does it make sense for our business to actually secure this or remove this or lock this down, restrict this? Because there will be some legitimate reasons why you don't want to align with that. There will be impacts to the system or things that are restricted from users that need access to sensitive data in order to do their job. That is acceptable risk if it's well documented, if it's intentional, if it makes sense for the organization. So a hundred I would say is not the goal. You can always reset a baseline in-house check so that it makes sense so that you can reach that 100 state. But I would definitely use it more as a signal to review what's going on and to provide awareness of your configurations rather than the end goal. And don't ever think like I've reached a hundred, I'm perfect, I'm going home and I'm never looking at this again. A system is always changing, it's always evolving. And so a regular review is really critical. So that would be my advice there as it relates to a score. Mike: Yeah. Well, I got to ask, often admins will have governance. They'll hold monthly governance meetings or quarterly. You can refresh Security Center Essentials a lot. What is the pattern that you would suggest admins do a data refresh on that? And then part two of that, because I'll just make the question harder, how would they work that into a governance meeting? Sabrina Simeroth: Oh gosh. So now see, you're putting me in a corner because I always give a soft answer on this one, but let me try to be really practical because I want our customers to really have a clear idea of how to manage this. The cadence that we've set for in the background running these metrics is once a week. So use that as the baseline. Once a week gives you plenty of time to see actual changes in the environment, but that's not to say that you shouldn't do these manual refreshes so you can manually update these and do more targeted. What I would say is avoid just every hour, update, update, update. That's excessive. And if it doesn't align with your actual business cadences. So it's going to be different for every customer, but try to align it with known milestones or known practices. So these are things like your development life cycle. When are your planned releases? When do you traditionally install new packages? Are there large onboarding events? Do you have regularly scheduled security reviews? And this is why it's a fuzzy answer where it's like it's going to be different for every customer. But as an admin, if you know that you also have an internal regular cadence ... Maybe you're doing a security review at the first of the week every week, maybe then you do deployments on Thursday every week. I would actually align the update cadence to those known activities because then you have context. It's a starting point where you say, "This was an expected activity and here's the changes that I saw." I also saw changes outside of that activity. And so that's a really good point when you talk about bringing it into a governance meeting. When you are speaking with security folks, when you're speaking with compliance folks, it's incredible context to be able to say, "Hey, I was expecting this activity. I was not expecting anything on this date. Is there anything in your world that would indicate that this is actually an appropriate action that was taken? Should we investigate this further?" And that's a really clear starting point given the context of I'm an admin, I have a lot of the operational context of how we're operating our business and here's that context. And this from my perspective sits outside. It's a little bit anomalous to what we would expect in terms of our own personal cadences. So I can't tell you it should be every day, it should be every five hours. That's really challenging. But it should try to align with some known milestones, some known events that you have going on in the business. Mike: That makes sense. You don't want to refresh it every day if once a month you make your changes and you're getting the same number day after day like, okay, well obviously it's expected. Sabrina Simeroth: Right. And then you become numb to it a little bit. You're just like, yeah, okay. Mike: You do. And then a number of changes, you're like, wait a minute, should that have been up or down? And you forget. So I get that. Let's talk about Security Center as a whole, because Essentials is the starting point. And I think for a lot of the admin work that I've done, it sounds like it more than fills the bill. But Security Center, you've got multi-org, you've got advanced capabilities. At what point would an admin look at Security Center Essentials and say, "Not enough. We need more." Sabrina Simeroth: Yeah. Yeah. It's a great question. I think everybody leans towards it's when it's multi-org. I think that's the default. Everybody says, "Okay, well the premium products, that's for multi-org, that's for these massive organizations." I would avoid thinking that way. For me, it's more around, let's call it organizational or operational complexity, and this can mean many things. So if you are starting to have more frequent changes like adding users, your company is growing drastically and you have a lot more users that are needing access to things, the hierarchy is changing. You're having a little bit more complex structure where there's management teams and then there's people under there. Regionally, you're expanding. If you are adding a lot of applications, you are doing a lot of customization within the environments. You are incorporating more custom code or more custom applications that are third party. Anytime that the system becomes slightly more complex, that is when I would think that it is very critical to evaluate the full product where you're going to get that more advanced management, advanced monitoring, broader security controls that are in the purview. So I would base it more on when you start to feel like your org is maturing enough to a point where there is enough complexity, the full product is where you're going to see a lot of value. And it's not just about how many orgs you're managing because sandboxes are important to manage security in as well because that's the feeding point into your production orgs, but it's about the data that you're looking at, how complex are your regulations becoming in your industry, what are the standards, what are the types of controls that you actually need to manage now as an admin? And I think basing it off of that gut feeling of this is becoming more complex, that's when it's a good time to start evaluating the tool. Mike: It's almost like when you need more information behind the warning light. Sabrina Simeroth: Exactly. Exactly. Mike: We're running out of gas, but how much do we really have? Sabrina Simeroth: Yes. Mike: Can't go another 10 miles. Sabrina Simeroth: When you start to feel like security is your only focus, that is a really good time to start looking at the automation for the premium features. Mike: Absolutely. So I think thinking about that, I always love giving admins something very practical to do. And I think connecting with ... Depending on the size org that they have, it could be a security officer, it could be a person in IT. If they were to sit down with somebody at their organization and show them Security Center Essentials, in your mind, who should that person be and what should they point out to them? Sabrina Simeroth: Yeah. So every organization's going to be different. Some people do have a dedicated security team. Some of them just have a center of excellence that ensures all things related to administration and security for an environment. I would say one, if you have someone who owns internal InfoSec policies. So whether that is your compliance policies, your data governance policies, any InfoSec team, I would build a relationship with one of those connections because they're going to have context that you need in terms of what are the right policies that we need to be aligning with, but that will be a really critical relationship. If there is just a platform owner for your team, that's what I would say. The admin needs to work with a platform owner and just really establish themselves like, "Here is where we're at with the system. Does this align with your expectations? Is this where we want to head? And is there anything that you want me to focus on?" So I would say those. If there isn't a dedicated security setup in your organization, then definitely whoever is the platform owner you want to connect with. Otherwise, a security personnel building a relationship with one person in security who really understands from a business perspective what the security concerns are, that would be the right relationship to say, "And here for this system, this is what we have in terms of our security controls and configurations." Mike: Yeah. I remember how humbling it is sometimes to sit down and show them dashboards, be like, "Look at all we have." And they're like, "But what about ..." And you're like, "Let me get back to you on that." That's a really good question. And inevitably, you always learn and there's always one more thing to pay attention to. Sabrina Simeroth: Absolutely. So that's a great point. What I would love for our admins to know as well is we're learning right along with you. So we are making decisions about what we feel admins should be paying attention to, but if there's feedback, feedback is such a gift. That's what we always say at Salesforce, feedback is a gift. So if there are really large gaps or there are really problems that you are trying to solve where the tool doesn't quite hit the mark, please let us know. Send it in to your account reps, send it in to your connections at Salesforce and feed it back to the product team because we would love to start seeing how our admins are using our security tools and really becoming security professionals for their companies. And we do take that feedback to heart and we are trying to incorporate what our customers truly need. Mike: When this episode airs, it'll be 11 days, hard to believe, until Dreamforce. But you said that there's new stuff coming. Sabrina Simeroth: Yes. Mike: Without spilling all of the news, can you give us a preview of what admins can expect? Sabrina Simeroth: Yeah. Absolutely. Mike: We'll say later in September. How's that? Sabrina Simeroth: Yeah. Yeah. Yeah. So it should actually be able to be demoed at Dreamforce, and we will even actually have some additional materials. So we're working on a quick look in Trailhead for Essential specifically. But we mentioned this, I think, on our last episode as well, but we are going to be introducing a few of those critical user permissions that are going to now be a part of the required MFA enforcement and the increased restrictions on who actually requires tighter controls as a user. So those permission metrics will actually give really good insight on who are your highly privileged users in this environment? Who do you need to really focus on in terms of making sure that they have the right level of access to the right data and that there's the right controls in place, that their user credentials are protected? Mike: Wow. This is neat. This is so cool. This is all the stuff that I wish I had a hundred years ago when I was an admin just clicking around like, "I wish I could run this report now." Now, not only do you get the report, but you probably have set up with Agentforce that can help you re-permission somebody. It's an exciting time. Sabrina, thanks for coming back on the podcast and helping us out. Sabrina Simeroth: Of course. It was my pleasure. Thank you for having me. Mike: Thanks again to Sabrina for joining us. My big takeaway is that security isn't about choosing a perfect score, it's about knowing what normal looks like in your org so you can spot it when something just doesn't fit. Take a look at the Security Center Essentials, establish that baseline, and then bring what you find into the conversations you're already having about releases, governance, and access. And until next time, we'll see you in the cloud.
  • What Does the Salesforce Platform App Builder Certification Prove Today? 27.08.2026 32min
    Today on the Salesforce Admins Podcast, we talk to Alexis Kingma, Senior Certification Developer at Salesforce. Join us as we chat about the newly updated Salesforce Certified Platform App Builder exam and the best way to prepare for certifications. You should subscribe for the full episode, but here are a few takeaways from our conversation with Alexis Kingma. The Salesforce Platform App Builder Certification gets a refresh The Salesforce Certified Platform App Builder exam has been updated, and the process is more complicated than you might think. This week, I'm talking to Alexis Kingma from the Salesforce Certification team to find out what's changed, why it matters, and how to best prepare for an exam. Whenever Alexis and her team are doing a refresh for an exam, they start by interviewing a range of subject matter experts working in the real world. For the Salesforce Certified Platform App Builder exam, they're trying to answer a simple question: "What is the industry saying is most important if somebody's looking to hire an app builder?" Alexis encourages you to think of a certification exam as a validation of your knowledge. In other words, it's proof that you have the expertise to build cutting-edge apps and implement them in your organization. Shifting the focus to Flow and Agentforce So what's changed? The focus is on automations with Flow and Agentforce. As Alexis explains, if you're looking to hire an app builder, you're looking for someone with a deep understanding of Flow. Do you know which flows are best for which situations? Can you troubleshoot them? Can you maintain and monitor them? They want to make sure that anyone who passes the certification exam has the Flow expertise they need to hit the ground running. The other change is including Agentforce as an automation tool for app building. While you don't need to be a power user (there's another certification for that), Alexis and her team want to make sure that you have it as an option in your toolkit. How to prepare for Salesforce certification exams According to Alexis, every Salesforce certification serves as a gauge for your practical, on-the-job skills. This means if you are currently building applications for your company, you are already ahead of the curve. To support the recent updates, her team has curated a specialized Trailhead trail that features interactive badges, allowing you to practice directly within a sandbox environment. Alexis also highly recommends taking a close look at the exam guide for any certification you're going for. They're written very intentionally, she explains, to give you a very specific idea of what level of understanding they're asking for on each topic. Words like "create" or "configure" are asking for much more in-depth knowledge than "describe" or "understand." Finally, if you're attending Dreamforce, Alexis wants to remind you to schedule your free certification exam. Make sure to listen to the full episode for more about the Salesforce Platform App Builder certification exam. And don't forget to subscribe to the Salesforce Admins Podcast to catch us every Thursday. Podcast swag Salesforce Admins on the Trailhead Store Learn more Exam Page: Salesforce Certified Platform App Builder Trailhead: Prepare for Your Salesforce Platform App Builder Certification Dreamforce: Guide to Certification Exams at Dreamforce 2026 Admin Trailblazers Group Admin Trailblazers Community Group Social Alexis on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X   Full show transcript Mike: This week on the Salesforce Admins Podcast, I'm talking with Alexis Kingma from the Salesforce certification team about the newly-refreshed Salesforce Certified Platform App Builder exam. We're going to get into exactly what changed, why Flow now has a bigger role on the exam, and where Agentforce fits into the app builder skillset. So whether the Platform App Builder is your next certification or you just want a better sense of where admin skills are headed, this episode is worth a listen. Now, before we get into it, be sure to subscribe and share it with any other admin who's thinking about their next certification. So with that, let's get Alexis on the podcast. So, Alexis, welcome to the podcast. Alexis Kingma: Thank you so much for having me. I'm excited to be here. Mike: Well, I am a huge fan of our exams and certifications. And you can take one, you don't have to have the other, and I like to have both. But I love that we have a lot of exams and we redo them, we update them, we refresh them, at least we try to. I feel the product now is changing super quick. But before we get into all of that, Alexis, tell us a little bit about your history and how you came to Salesforce and what you do at Salesforce. Alexis Kingma: Absolutely. So I am on the Salesforce certification team. We are a team of Salesforce employees who are solely dedicated to creating and updating the whole suite of Salesforce exams. So, historically, I come from a certification industry background. I've done software certification my entire career. And I came to Salesforce about two, two and a half years ago and just hit the ground running. I joined the team updating and creating new Salesforce certifications. So I actually started with the Tableau certifications and have since moved over into my latest, which is refreshing the Salesforce Certified Platform App Builder exam. Mike: Ooh, yes, app builder, that's something all of us admins are near and dear to our hearts on. And that's cool. I mean, I guess there's enough tech out there in the world that there's enough people that need to write certification exams for all of it. Wow. This is one of those ideas of, I bet 20 years ago, that job maybe didn't exist, but it exists now. Alexis Kingma: It's funny, certification is such a rich industry, it's one of those jobs that I feel like nobody knows it exists until you have that job. Nobody grows up saying, "I want to write tests," but now it's all of our favorite things to do. Mike: No, I mean, you're exactly right, nobody sits down and, "What do you want to do when you grow up?" And it's, "I want to sit down and write really hard software questions for people about a cloud-based platform that they can configure declaratively." Alexis Kingma: Right. Mike: I think if you would've answered that, your teacher would've been, "And you're an astronaut today." Alexis Kingma: But it is interesting, the same principles that we use to write Salesforce software certifications are the same principles that are used for the medical boards, for firefighting certifications, for airline certifications. And so when we come together at certification industry events, it's a whole gamut of industries coming together to talk about the same certification principles. So you get to meet a lot of interesting folks. Mike: I mean, you don't ever think of that, but that is really... Wow, I bet that's really interesting to sit across the table from people that write certifications to be a rocket scientist. Alexis Kingma: Absolutely. Yes. A lot of these certifications, like for a professional roofer, that's a high-stakes certification, or an architect. So it's interesting to hear how all these different industries approach the same problems. Mike: Yeah. Well, we're still high stakes too. Alexis Kingma: Absolutely. Mike: So you mentioned Platform App Builder exam. It got a refresh, which it's probably needed, I mean, every few months, right? But I think before we get into that, what does it mean to refresh an exam? Alexis Kingma: So the Platform App Builder exam has been around for over 10 years. It predates me at Salesforce by far. We're actually in our 11th year this year, which is awesome. And so it's been around for so long and the role changes and evolves so much in that time. And so it's important for us to look at the role, look at the requirements in the industry, what are admins doing, what are app builders doing, what are architects doing, what is the most important knowledge that those roles need, and how does our exam align to that? And making sure that the things that we're testing out on the exam are actually things that are the most important for these roles in the real world. Mike: Yeah. I mean, that was always one of the hard parts, I remember, when I first got one of my certifications. At the time, we didn't use a lot of Service Cloud, Agentforce for Service, I think now, but I had to go out and learn it because it was part of the certification. And I thought, "Oh, why should I have to learn that?" And I thought, "Well, just because you don't use it or your company doesn't use it, doesn't mean it shouldn't be part of that certification as well or that exam." Alexis Kingma: Absolutely. And so when we approach doing a refresh like we did with app builder, we try to include subject matter experts from a whole range, internal Salesforce employees, external Salesforce users, a wide breadth of roles, admins, people who are solely app builders, architects, to try to say, "Okay, Salesforce might say these topics are most important, but what is the industry saying is most important?" If somebody's looking to hire an app builder, what does that person expect the app builder brings to the table and what knowledge should they already have when they start the job? And so we rely on our subject matter experts to say, "What are those most important concepts, and how do we make sure that they're reflected on the exam?" Mike: Makes sense. I mean, that's the part of getting dialed in, to me, that I think is the most important is, one thing for Salesforce to think this is important, but where does that fall in terms of your responsibilities and what you're seeing day to day? Well, let's talk about this new exam, because Platform App Builder, I believe if you said it was been around for 10 years, then I've been at Salesforce when it was launched. What did it originally... Not originally, back in the day have, but what were you refreshing from and really refreshing to? Alexis Kingma: I'll say the biggest change between the previous version of the exam, which had been refreshed maybe one or two years ago, to this new version of the exam is really increasing the emphasis on Flow on the new version of the exam. In talking to our group of subject matter experts, hearing from the community, we just continue to hear Flow is such an important piece of being an app builder and being able to do that role, that it needs to be tested. And we actually added it to the exam with quite some depth, not only testing can you create flows, can you choose which flow for which situation, but also can you troubleshoot flows? Can you maintain and monitor them? Really asking the app builder to get deep into flows and making the assertion that flows are a key piece of being an app builder at Salesforce. Mike: I mean, that makes a lot of sense. It's funny, I'll ask you later, but I'll be curious to see your answer on it. I mean, when I think of app building, it's a collection of stuff and then there's that automation piece. But also, really diving into Flow like you did really helps set the admin up for being an agent builder as well, right? Alexis Kingma: Absolutely. And that's another change we made to the exam is adding Agentforce, specifically how you can use Agentforce as an automation tool on the exam. So I don't want to say you must be an Agentforce superuser to be able to take that exam. That's absolutely not the intention. We have an Agentforce specialist exam for that. But really just more about knowing that Agentforce is a tool in your tool belt that's available, and when might it make sense to reach for that tool. Mike: So I'll come to that question now that I get asked, and you can decide if you want to answer it or not. But I was asked last week, do admins still build apps? Alexis Kingma: Yes. I'll say, from what I've heard, yes. We, as part of this refresh, go through the roles that this exam most aligns to, and Salesforce admin was the number one. So when we got our group of subject matter experts together and asked, "Who is taking this exam? Who should be taking this exam?" Salesforce admins was the number one thing that people said. Mike: Yeah. No, I agree. I think it's interesting to live in the time we do now where, I mean, I had somebody send me a link the other day of a dashboard that an agent had coded for them. And it was kind of temporary. It wasn't meant to be any kind of source of truth. But when you think about it, sometimes the permanency of the app, I think that's where that question was going. And I still very much believe that it's the agent that jumps in and adds the additional layer that perhaps goes across apps. Alexis Kingma: Agree. I hear from our community over and over that knowing how to get in there and actually build the flows and customize and all the checkboxes, and what they do and what they mean and what they cause is so important and continues to be important even with the new agentic world that we live in. Mike: Right. And you mentioned part of the refresh process is also gathering a lot of feedback from not just admins, but customers and employers that hire admins. What were some of the things that they pointed out as admins still need to understand these things? You refreshed it for Flow and Agentforce, but that's not the whole exam, right? Alexis Kingma: Correct. And you'll see, it's funny, we still kept Salesforce fundamentals and we still kept user interface. And the funny part is that I was actually looking at much older versions of this exam through this refresh process, and those are the same topic areas that have been around, I don't want to say since the first version, but that have been around since the beginning. And it's because they continue to still be important. Every refresh, we pressure test and say, "Okay, do you still need to know object record and field access? Do you still need to know reports and dashboards?" And the answer continues to be yes. And so those will continue to live and be tested on this exam because they continue to be important. Mike: Yeah. Now, from your advice, if a Salesforce admin's listening, maybe they don't have a certification yet or they haven't taken any of the exams, what would you advise in terms of preparation to get ready for this exam? Can they come out of the gate and take it or is there kind of understood prerequisites to this? Alexis Kingma: All Salesforce exams are designed to test your hands-on experience. And so they're designed so that, yes, you can read documentation, but they're testing that you have some hands-on experience going into the exam. But, that said, that's where Trailhead becomes a huge asset if you may not have had access to actually get into a sandbox and play around with all these different topics. So exciting for this refresh, we created a brand new exam prep trail. We had existing prep trail badges before, but those have been retired in favor of this new exam prep trail. And what's most exciting is it does prioritize the hands-on badges available on Trailhead. So there's opportunity within each section to get in there, spin up an org, and actually play around with the types of topics that are being tested on the exam. So if you don't have the opportunity to get hands-on experience with every single thing tested, this trail is an excellent opportunity to still be able to prepare for the exam and take the exam regardless. Mike: That makes sense. I mean, I think that's always the biggest question I get asked when I'm at user groups or at an event is, "What should I do to prepare for this?" And it's one part just learning. You don't want to study for the test, as they say. You want to study to learn it and understand it. I think that's why the practical hands-on part of it, really what can they build is important. Alexis Kingma: And I'll say too, a tip that all of us on the Salesforce exam development team share when we can, is every exam, this one included, has the exam guide, and there's really a lot of information and clues within that exam guide. We list all of the exam objectives, what we call them, all the different content areas tested on the exam. And they're really written very intentionally and with a lot of detail in mind. So thinking about if an objective says, "Create and configure flows," we're not just asking you to describe them or have a high-level understanding of what they are or when to use them. We're really asking, can you get in there, get your hands dirty, create and configure them? And so that's kind of a clue, "Hey, I should be getting in there. I should be clicking around. I should know what each of these buttons, each of these checkboxes does," because that's the kind of question that's going to be asked on the exam. Whereas something like describe or understand, maybe that is more of a high-level just, "Hey, can you explain or describe, but maybe not necessarily get in there and do?" So I think paying attention to that can help direct how you study for each of these objectives. Mike: One thing I thought of, and this was back when I was getting my admin certifications, was describing the value of it to my manager and to my users. And I won't tell you my answer because I want to hear your answer first, but if you were to put yourself in the seat of a Salesforce admin listening to this podcast that's like, "I really want to go and take that exam. I really want to get that certification." How do I justify that or how do I make that case to my employer and to my users that this is worthwhile and worth my time? Alexis Kingma: It's such an important question, right? Because that's the big question is how can I get buy-in to study for this, to get support to take this? I think the biggest one is that a certification at its core is a validation of knowledge. A certification is a statement that you possess the knowledge and have the skills and abilities that are tested on this exam. And so for Platform App Builder, these are the knowledge, skills and abilities that not only Salesforce, but the industry in the group of subject matter experts that helped develop this, this is what the industry is saying is most important for an app builder to know and be able to do in the market right now. And so by earning the certification and saying, "Hey, I have the knowledge, skills, and abilities that are most important for an app builder," you're bringing a lot of value to your team. You're bringing a lot of the learning that you gained through studying. You're bringing a lot of expertise to your team to be able to bring back and show what's the latest and greatest that Salesforce is doing now, and actually be able to implement it. Mike: No, spot on. I would also just add one word, confidence. Alexis Kingma: Yes. Mike: I walked on water the day after I passed my admin certification, because I finally felt like everything that I thought I knew, was verified. I don't know what the right word is. Verified comes to mind, but it's probably not the right word. And I was like, "Yes, that feels right to me." We talked about the prep trail, which I think is important because, boy, for a while there, preparing for a certification was reading some sample questions and hoping you kind of had your bases covered. I think that prep trail is really, really good to help get you hands on. Now, I'll say this because I think I know the answer, but I want to make sure. Even if I complete that prep trail, that doesn't mean I'm going to pass the certification exam, right? Alexis Kingma: I'm so glad you asked. Mike: Yeah. Alexis Kingma: The prep trail is one piece, but I think there's no guarantee, to be honest. There's no way to say with 100% certainty, "I will pass this exam." I think the prep trail is one piece. Like I mentioned, the hands-on component or experience is really important. And so, in addition to the prep trail, I think the best way to assess your level of readiness really is to go through that exam guide and those objectives on it, and just kind of do it a little self test, "Hey, let me read this objective. Is this something I'm familiar with? Do I feel like I can explain what this means and explain how I do this in my day to day? Or is this something I need to take a second and read some help documentation and get a little bit deeper on?" So I think those two things combined, the prep trail and the exam guide are your best bet to make sure that you're ready, but it is definitely not a one for one. And no Salesforce certifications are finish the prep trail, pass the exam. We want to add a little extra rigor. Mike: Yeah. Well, and that makes sense because I feel when you complete the Trailhead module that the exam should test on, okay, so you knew the answers. Did you know why those are the right answers? And I always felt like the exams pushed that limit for me because it was one thing to know what to do, I think it's another thing to know why to do it. Alexis Kingma: Absolutely. Mike: We'll talk about one thing in general, and then we have Dreamforce coming up. In general, I'm a Salesforce admin, I listen to this podcast and like, "You know what? I got the green light, I'm going to go get my app builder exam." What should I bring? What do I bring to the... Do I go to a testing center? Can I take it at home? How should I do that outside of just the regular preparation part? Alexis Kingma: We offer a lot of flexibility in this process, so it's totally up to you if you prefer to go to a testing center or if you prefer to test at home. I know for me, right now, looking at my desk, there's six drinks and about a million Post-it notes. And looking around my office, I'm embarrassed at the state. So for me, I typically go to a testing center, because when you take the exam at home, you are asked to make sure that your workspace is clean, your cat's not walking in, like mine just did. All the things. So you have the choice to take it at home or in a testing center. If you do take it at home, I just encourage everybody to run through the system checks that are part of the Pearson exam process. That will just make sure that your computer is able to take the exam. Some work computers or VPNs can need to be shut down first. So run those system checks, read the information that Salesforce has on taking an exam. Or if you go to a testing center, you'll show up to the testing center, bring your ID. Salesforce has documentation on both that will make sure that you're ready and have exactly what you need either way. But we offer our exams almost any time, any day. So you can, when you go to register, obviously, testing centers have hours, but there's a whole breadth of days and times available for you to choose to take your exam. So you can sneak it in before Dreamforce. Mike: There you go. I mean, I really admire the people that take it at home. And I know some people just have to logistics wise. For me, I can get into the mindset of I'm here to take this exam if I have to go somewhere. I think it's the whole process of getting up, getting outside, having to go to a location, it feels very purposeful. And then, I guess because of that, it keeps me focused, right? I don't feel like, "Okay, well, it's 2:15. I guess I'll take the exam now." It's like, nope, my appointment's at this time. I got to leave early, I got to put my shoes on. Alexis Kingma: I agree with you, but I'll say the other side of that coin is that the stress of, okay, now I have to fight through traffic or I have to wait on transit, and then I have to show up and hope that the check... So I think offering both is a huge benefit because it totally depends on each individual person. Mike: Yeah, no, absolutely. So I asked that because I also wanted to kind of sneakily, if that's a word, sneakily, work in the fact that you can get your certification at Dreamforce if you attend, correct? Alexis Kingma: Correct. We are very excited, Salesforce certification will be onsite at Dreamforce. And really exciting, not everybody, I think, realizes who attends Dreamforce, but everybody who attends Dreamforce gets one complimentary certification exam while they're at Dreamforce. So a huge opportunity there in having a free exam that you can take onsite and actually earn a certification while you're at Dreamforce. Mike: Wow. And that's not just limited to app builder, it's any of our certifications. Alexis Kingma: It is any of our certifications, including the architect certifications, which is exciting. Mike: Wow. Alexis Kingma: And I will say, just a shameless plug for everybody listening too, if you're interested in taking an exam at Dreamforce, I highly recommend adding that exam session to your agenda. That way, that secures your space to take an exam at Dreamforce. Otherwise, if you don't have it added to your agenda, you'll have to show up in the standby line, which we ask that you join an hour before the exam. Mike: [inaudible 00:25:49]. Alexis Kingma: Yes. We get very crowded, so it saves a lot of time to add the exam session that you'd like to attend to your agenda, we have them Monday through Thursday, to make sure that you're prepared and you have a spot to take your exam. Mike: I mean, why you would leave Dreamforce without one more certification is beyond me. Alexis Kingma: Especially when it's free. Mike: I mean, it's part of your ticket. I also get, you know what, you could fail. I will say this, there has been exams that I've studied for and went in and failed, and that's okay. I mean, it just helped me really understand what I had digested and understood, and the parts that I think I had glossed over or maybe felt I had understood, and that the exam brought that out and told me that. No harm, no foul if you go to take an exam and you don't pass. The expectation isn't that you'll pass or fail, it's that it tests your knowledge. And I think for me, leaving and having that understanding of, "Okay, I passed, great, but did I feel good about how I passed or should I really keep going to build on that knowledge?" Or maybe I didn't pass, and you know what? Now I have an inventory of where I can pay attention to and gaps in my learning. Alexis Kingma: One of the certification developers on our team, Melanie, always says, "We don't use the word fail, we use the word learn. You didn't fail, you learned." And I think that's absolutely how we approach it. Failing is not a failure. It doesn't mean you don't know Salesforce, you don't know your job. It's a learning opportunity. And we tell you the areas to work on in the exam results, and it's just one more opportunity to learn and dig in and try again. Mike: Yeah. That's a very positive note. I want to ask your advice. I mean, as somebody that has been writing software exams and helping people understand, what is, in your opinion, one method or one tip that you give people in terms of how they should approach preparation for this and preparation for other exams? Alexis Kingma: The biggest one is what I was alluding to earlier about really paying attention to the level of knowledge or skill that the exam is asking for. Is it asking for you to be able to do that thing? Is it asking for you to be able to troubleshoot that thing? Or is it just asking you to know and have awareness and be able to explain it? Because when we're writing exam questions, that's what we're looking at to write our questions, is do these questions need to be to the depth of somebody who's actually configuring and troubleshooting or is this just more let's test on the awareness? So that's always my biggest tip. And then I will share my own personal tip when I take an exam, is I sit down and I take three deep breaths before I get started, and that's always helped me. So that's my more practical logistical tip. Mike: Yep. Calm and center yourself. Alexis Kingma: Yes. Mike: Be present where you're at. I'll be honest, sometimes that's the best part about going somewhere is it's always nice and quiet and it's very easy to just stay focused because of it. Alexis Kingma: Absolutely. Mike: Alexis, I think we covered a lot. I'm excited for the refresh. I know our admins will be and our architects and developers. I mean, app builder is applicable to a lot of people in our ecosystem, not just Salesforce admins. But I love that it got refreshed and really reflects what the product can do and where the product is, and also what admins and app builders should think about. So thanks for coming on the podcast and sharing that with us. Alexis Kingma: I'm happy to be here. I am so excited. Like you said, this exam is applicable to so many people in so many roles. I heard so many times throughout working on this exam from folks saying, "This is my favorite exam because it's just so relevant and applicable across the board." So it was such a blast to be able to work on it, and I'm super excited to hear the feedback, hear from folks who take it and pass it. I hope to hear from everybody on LinkedIn after they pass. So super excited to have this out in the world. Mike: I want to thank Alexis again for joining us and giving us a look into what's changed with the Platform App Builder exam. I think this is a big takeaway for admins as certification is more than just knowing the features, it's about validating that you can apply those skills in the real world. So from Flow and configuration, to understanding when tools like Agentforce make sense. Take a look at the exam guide, get hands on, and use those objectives to figure out when you're ready and where you can learn more. And, of course, if this episode helped you, be sure to subscribe, share it with another Salesforce admin. And until next time, we'll see you in the cloud.
  • How AI Could Change the Way Admins Set Up Salesforce 20.08.2026 23min
    Today on the Salesforce Admins Podcast, we talk to Khushwant Singh, SVP of Product Management for the AI Application Development Platform at Salesforce. Join us as we chat about how rethinking the Salesforce stack for AI with Headless 360 will change the way admins set up complex systems. You should subscribe for the full episode, but here are a few takeaways from our conversation with Khushwant Singh. Opening Salesforce to AI agents AI is changing more than how we find information or generate content. It could also change how Salesforce Admins configure the platform itself. I sat down with Khushwant "Khush" Singh, to learn about Headless 360 and the work happening behind the scenes to make Salesforce accessible to both humans and AI agents. "Headless 360 is about bringing Salesforce to wherever you need it," Khush says. In a headless platform, he explains, the frontend is separated from the backend. So you can use Salesforce data and visualizations on your website without changing the design, or change records in Slack without having to open an extra tab. But Salesforce Headless 360 is about more than portability. Khush and his team are translating the entire platform into a set of model context protocols (MCPs), skills, and metadata that can interface directly with AI agents. And that opens a world of possibilities for what admins can do with conversational tools. What if setting up Salesforce became a conversation? "For the last 27 years, layers that make up the Salesforce platform have been put in place for a human," Khush says, "so we're trying to open this up for both a human and an agent, so the agent can do that work on behalf of the admin." Setup with Agentforce, which streamlines configuration for admins with the help of an AI assistant, is a great example of what Khush is talking about. You can use natural language prompts to create objects, Lightning pages, and flows; manage users and user access; and troubleshoot formulas. Headless 360 lays the groundwork for a future where setting up Salesforce becomes a conversation about your business goals and processes. No coding required. Admins still stay in control None of this removes the admin from the process. Khush is quick to point out that the goal is for agents and admins to work together, with humans still initiating actions, validating results, and providing governance. His advice for admins right now is simple: try Setup with Agentforce and start getting familiar with what this new way of working feels like. Because the biggest shift may not be AI helping you use Salesforce faster—it may be AI changing how you build Salesforce in the first place. Listen to the full episode for more from Khush about Salesforce Headless 360 and how AI could change the way we set up our orgs. And don't forget to subscribe to the Salesforce Admins Podcast to catch us every Thursday. Podcast swag Salesforce Admins on the Trailhead Store Learn more Salesforce 360 Blog Post: Introducing Salesforce Headless 360. No Browser Required. Salesforce Admins Podcast Episode: Solving Sharing Mysteries with Setup with Agentforce Salesforce Admins Podcast Episode: Setup with Agentforce Makes Salesforce Admin Tasks Easier Salesforce Help Article: Setup with Agentforce (Beta) Salesforce Admins Blog Post: Setup with Agentforce Is Now Generally Available: Built With Admin Feedback at the Center Salesforce Admins Blog Post: What Is MCP? A Simple Guide to Model Context Protocol for Salesforce Admins Trailhead: Salesforce Headless 360: Quick Look Admin Trailblazers Group Admin Trailblazers Community Group Social Khush on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript   Mike Gerholdt: This week on the Salesforce Admins Podcast, I'm joined by Khushwant Singh to talk about what happens when Salesforce stops just being a destination and starts becoming part of every system your business already relies on. That's right, from Headless 360 to Setup with Agentforce, Khush breaks down how admins are moving beyond configuring features and into orchestrating how data, AI agents, automation and people work together across the business. Now, we're going to dig into what Headless actually means for admins, why governance and trust matter more than ever in an AI first world, and how Salesforce is building toward a future where setting up complex systems really becomes more of a conversation than a checklist. This episode is really about systems thinking, how admins can connect experiences without forcing teams to rebuild everything from scratch. So if you've been trying to figure out where AI fits into your role or how your role is evolving alongside it, I promise you this episode gives you a practical look at what's already happening and what's coming next. So be sure to hit that subscribe button. Share this episode with your favorite architect or admin friend, and let's get Khush on the podcast. So Khush, welcome back to the podcast.   Khushwant Singh: Thank you for having me back, Mike.   Mike Gerholdt: I say that because I had to look and it was 2022 back in the day you were talking Experience Cloud when we last had you on. You've since moved on, moved up, had your hands in a lot of things, did an admin keynote with me. So let's start there and let's kind of catch everybody up on some of the products you've been working on, and then we're going to talk about the newest one that we launched at TDX this year.   Khushwant Singh: Yeah, happy to. And again, great to be back. I think back in the day, started obviously with Experience Cloud. Experience Cloud really was building a product that is external-facing and again, it's built on the same platform. And again, as we looked at the product portfolio, it just made sense to start to bring things together. So we've actually sort of rolled and morphed into the application development platform, obviously within the platform organization, everything pro-code, low-code, desktop, mobile. And so there've been quite a few products leading up to here, anything from our delivery on mobile, mobile offline, the Salesforce mobile app, all the way to Agentforce Vibes, the Agentforce Experience layer, obviously a fair amount of work on the Headless side of things. So yeah, it's been quite a journey to this particular point, Mike.   Mike Gerholdt: Yeah. I mean, it's actually hard to point out things that aren't admin-friendly that you've had your hands on because you've always kind of championed everybody being able to build on our platform. So let's talk about TDX this year because we launched Headless 360.   Khushwant Singh: Oh yeah, we did.   Mike Gerholdt: By the way, in case you forgot.   Khushwant Singh: Yeah, it was a massive announcement. I think, look, as you think about what's happening in the market right now, you've got customers engaging through many different surface areas. We've got customers on ChatGPT, on Claude, on Gemini, Teams. At the same time, you've got developers also using a variety of different tools, different IDEs, different coding agents. And so I think Headless 360 really is a testament to acknowledging this change in the market in the industry and trying to meet the customer where they are. The customer being an end user or the customer being a developer and admin, just meeting them where they are in whichever tool, whichever interface they might be.   Mike Gerholdt: Yeah. I mean, do you recall ever a time in technology when it was, I hate to use the euphemism, but like the Wild West where I feel like there's so many choices for what you can do just in regards to AI?   Khushwant Singh: There is. And there is obviously a good side to it. There's also a downside to it. The good side is really your [inaudible 00:04:31] for choice. There is innovation that is helping you drive productivity day in, day out. The downside of this is you just have to be really careful about quality, about trust, about governance. And you have to ensure that while you're going fast, you're not sort of compromising on that trust aspect of things. And that's what we're trying to do here at Salesforce and just trying to be a little bit more thoughtful in our approach over here.   Mike Gerholdt: Yeah. So my developer friend, Josh Burke, who comes on the podcast, usually has to explain things to me every now and then. I think developers are very familiar with the term headless.   Khushwant Singh: Yes.   Mike Gerholdt: I'm not sure outside of Headless flows, which I know what those mean, I'm not sure admins could understand or could confidently buzz in on a game show and answer what is Headless 360. So can you help them kind of understand what is Headless 360 if they had to tell their manager?   Khushwant Singh: Yeah, sure. So one way to think about it is, let's say you're a customer and you've got your own website, it's built out of React, it's not built on the Salesforce platform, but there is so much of your goodness and investment that you have within the Salesforce platform that you want to be able to easily reuse in the context of this other website that you have, portal that you have, mobile application that you have. All of that may not be built on the Salesforce platform. You want to be able to reuse your investment seamlessly. And so Headless 360 really is about how do we empower you, the customer, to be able to easily use those assets, those investments within the Salesforce platform in that surface area that you've got that may not be on the Salesforce platform. So it's really about giving them that flexibility so that they can easily reuse their investments in all of these various surface areas and just meet their customers wherever they are versus bring their customers into Salesforce.   Mike Gerholdt: Yeah, I think it makes sense. I mean, I was a customer way back in '06 when I remember it was like transfer and move to Salesforce, and everything was "have it on the platform, have it on the platform." And then shortly thereafter it was kind of like almost the realization that we had was, "Well, it's a lot of friction to constantly move platforms. What if companies just integrate and we become that connector to everything?" And I feel the same way with this.   Khushwant Singh: 100%. And you know what? Look, I think the one example is if you go into the Williams Sonoma website, right? Williams Sonoma website, it's not built in Salesforce, but if you use their sous chef AI, I think... I'm not sure what they call it, but-   Mike Gerholdt: I'm sure it's something really, really snappy and small.   Khushwant Singh: Olive. Olive. There you go.   Mike Gerholdt: Olive. Yeah. See?   Khushwant Singh: A snappy name right there. That agent is an Agentforce agent, right? So that's on example where Salesforce is being used in whichever head that you'd like us to be in. And so in this particular case, the Salesforce agent is in the Williams Sonoma website. So that's just one example where we are trying to make it easier for this integration to happen through the Headless 360 platform. Now that's one view. And that's the view, I would say, an easy way to try to understand what it means for Headless 360.   Mike Gerholdt: Yeah, because then as an admin, as a developer, you're not having to sit down and say, "Okay, well, if we move to the Salesforce platform, we have to deprecate everything that we just spent the last two years building on our site." Marketing's like, "No, no, we just got the site pixel perfect the way we want it. Now we can integrate best of everything that we want." For admins who aren't thinking of maybe websites, how does Headless 360 play into other integrations that they may talk to IT or internal stakeholders about?   Khushwant Singh: Yeah. So for example, when admins are chatting with their other internal team, they may have a custom application that they already have in place and they want to be able to have Salesforce data, Salesforce visualizations surface in whichever application they may have already, right? That's one example. So again, it is about bringing Salesforce to wherever they may already have. So for example, an admin may have a business application that already runs within ChatGPT. So ChatGPT, for example, it allows companies to create bespoke applications. And if you want to be able to integrate Salesforce into that application, that's doable as well. It doesn't have to be in ChatGPT. It could be in any other existing non-agentic application as well. But it's about that, look, you don't have to rebuild everything. Wherever you are, you've got an existing application, we'll find a way through Headless 360 to be able to bring Salesforce to it.   Mike Gerholdt: Yeah. No, it totally makes sense. I mean, in that way we can really think about how are we making sure that the departments have the software and the tech that they want, but also access to all of the information that they need to do their jobs the best.   Khushwant Singh: Mm-hmm.   Mike Gerholdt: So Headless 360 is a big thing we talked about. I also know I saw you in some True to the Core and True to the Core Deep Dive stuff. Was there some features you were talking about in that that possibly play into what admins are going to be working on for the rest of this year?   Khushwant Singh: Well, yeah. I mean, a few aspects as we think about Headless 360 that would be of interest to admins. So first and foremost, you've all seen the stack diagram of the Salesforce platform. You've got those four layers. You've got your layers of engagement, you have layers of context, you've got the sort of our data foundation, et cetera. So you've got those layers that make up the Salesforce platform. For the last 27 years, those layers have been put in place for a human, right? And now what the product teams and the engineering teams are doing are going back and saying, "How do we now open this up both for a human and an agent so the agent can do that work on behalf of the admin when the admin sort of wants a task to be done for that particular reason?" And so what that means is that we're translating our entire platform into a set of MCPs, a set of skills, a set of metadata that is grounded so that these agents can do the work on behalf of the admins. So one good example is the setup with Agentforce, which is so far so good. We've gotten great feedback on it. Now behind the scenes is a set of skills, a set of MCPs that are firing off to be able to get their tasks done. And so that's one thing that I think our admins can look to benefit from. The other piece is I know we have some admins who are familiar with some of these IDEs that we have out there. They use Cloud Code quite a bit. They use Vibes quite a bit. It may not be the entire admin audience, but for those audiences, again, the ability to be able to use all of these MCP skills in these development environments is another thing that our admins can really look forward towards. Now the other thing that we've also worked on is, over the last few months, the foundation for these skills, these MCPs, this Headless 360 foundation has been very sort of focused on how do we unblock these pro-code use cases, whether that's in Cloud Code, whether that's in Vibes, et cetera. But this is the same foundation upon which as we speak in safe harbor, I share that we are building what we call our no code offering as well. So how do you go about in an unintimidating sort of type of interface, have this conversation with an agent, which behind the scenes is interacting with that same Headless 360 layer to help you build out your agents, your applications, to help you augment your existing agents and applications, help you set up provision, configure Salesforce from a zero to one point of view, because we all know how setting it all up is quite a taxing task for our admins? So that's the potential I see for Headless 360 for our admin personas.   Mike Gerholdt: Yeah. I mean, to go back on some of the stuff that you were mentioning, I remember the first time I thought, "Hey, I could have ChatGPT rewrite ChatGPT's instructions." And I remember thinking like, "I'm so far ahead of the curve, man. I'm making AI rebuild AI." And then it was only a few weeks later that Cheryl was demoing Setup with Agentforce and I thought, "Oh, that makes so much more sense because all of the things that you were having that setup agent do are things that not necessarily admins don't like doing. It's like paper cuts." It's the little things that take 20, 30 minutes out of your day when you really wanted that solid hour to build that application kind of start to finish.   Khushwant Singh: Indeed. Indeed. So we really viewed Headless 360 as the foundation upon which agents can work on behalf of the admins. And again, look, this is agents and admins working together because again, we've got to have the human presence to be able to validate, to be able to interrupt, to be able to initiate any actions that are performed by the agents. And if these agents can help drive greater productivity, then it's a win-win while at the same time having governance by humans over it.   Mike Gerholdt: Right. Absolutely. Do you envision us being at a point where all of setting up Salesforce could just be a conversation with an agent based on the business and what they're trying to accomplish?   Khushwant Singh: We are trying to do that. We are trying to do that. Now, I'll give you a view into our approach over here. We're taking a steel thread approach here where just trying to, for example, set up a customer service agent. That cuts across Service Cloud, cuts across platform, cuts across Agentforce, cuts across Data Cloud. So we've got to take a system view, an end-to-end view versus a feature view because that's what our admins go through. That's what a practitioner goes through. They look at it from a steel thread point of view, and that's what we as product teams have to do. And so as we think about using agents to go ahead and help provision, set up, get Salesforce up and running really quickly, that's the new strategy that we are taking over here, a steel thread view so that we can look across the board and say, "Look, which MCPs are missing? Which skills are missing? Which APIs are missing? Which metadata needs to be grounded? How do we ensure that across entire steel thread, quality is being ensured, governance is being woven into?" So we are starting that way and we want to scale that way as well. So my hope is that come Dreamforce this year, we'll be able to at least have a sizable number of steel threads that we feel really, really confident about on Agentforce really helping and agents helping in this particular side of things. So yeah, that's the approach we're taking, Mike.   Mike Gerholdt: Wow, that's going to be amazing. Every time you think, "Oh, we've probably invented everything," technology just comes along and pulls the rug out from underneath of you and says, "Haha! There's new stuff. You got to figure this out now." I'd be curious, you're so ingrained in a lot of things that admins do on the platform, a lot of things developers do on the platform and then also having to keep up with AI. What is a piece of advice you could give people for how you personally keep up with the newest news and innovation on what's going on with AI?   Khushwant Singh: Wow, that's a good question. I think first and foremost, I spend a lot of time just looking at reading publications like what's on TechCrunch, what's on Techmeme, trying to just understand how are technology providers adapting, how are companies using AI. That's one. The second one is actually you learn a lot via speaking with others in the community, right?   Mike Gerholdt: Mm-hmm.   Khushwant Singh: You talk to customers, you talk to other admins, you talk to other developers and you get to understand there are use cases that they're working through and some of the very many innovative workarounds or users of AI that they're applying. And then you're thinking about this that, "Wow. There's a trend here, there's something that we should be backing up and maybe providing out of the box within the product." And so I think that community piece speaking with other customers, with your peers, your colleagues from different companies, that sort of brings a very practitioners and practical view to things. So I think if you combine it with some of these ... So if you take a combination of both, what's being published out in the internet, what sort of bleeding edge and all of these various publications and then you sort of marry that and juxtapose that with the practical aspects on how it's implemented in all of these various by your peers in different companies, that's kind of how I ... That's at least the approach that I've taken. And I've seen it help even with some of my teammates who use a similar approach as well, Mike.   Mike Gerholdt: Yeah, I would agree. I mean, coming fresh off of being at a conference, just even talking with people, you find more resources than you think you could find and it exposes you to different levels of thought. As we kind of close things out, I'd love to know I'm always big, especially when I'm coaching people for events, for TDX, for keynotes, because I've been in keynote with you. I feel like when people are done listening to something, I always want to give them something very actionable that they should do when they get done listening to a session or they get done listening to a podcast like this. So if you are a Salesforce admin listening to this podcast, what is one thing you think you should do right after you listen to this podcast?   Khushwant Singh: Good one. It's a tricky question. I would say that, look, I would encourage everyone to go ahead and use and try and give Setup with Agentforce a run, right? Take it out for a spin. It's available in an open beta. And I would encourage all of you all to give it a try, please. We've gotten so much great feedback. We are a stone's throw away before we make it generally available. And this is our first approach to using Agentforce, using AI to help improve the productivity and quality of life of our admins. It's not our last, but it is definitely our best foot forward right now. And we'd love to get your feedback. Like I said, we are in the final mile and your feedback is much appreciated, so try it out.   Mike Gerholdt: I love it. Khush, you've always been a fan of admins. And I am so grateful to have you back on the podcast and even more thankful that you are constantly helping Salesforce innovate for everybody in the tech industry to be successful. So I appreciate you spending a little time with us today.   Khushwant Singh: No, of course it's my pleasure. Admins are the lifeblood of Salesforce. You're out there, you're representing our products, you're using our products, you're championing our products, you're giving us tough love. And we can't be more appreciative. And so this is an honor to be here on this podcast to speak with you, Mike, and to speak with all of our admins.   Mike Gerholdt: And a big thanks to Khushwant Singh for joining me and sharing how Headless 360 and Agentforce are reshaping the way admins build and manage systems across the business. My big takeaway? Well, the future admin isn't just configuring Salesforce. They're designing trusted systems where automation, data, agents, and people all work together for better outcomes. And as Khush said, trust and governance will still sit right at the center of all that work. So if you haven't already, take Setup with Agentforce for a spin and start exploring what human plus agent collaboration can look like in your org. And of course, be sure to subscribe, leave a review. And as always, I would love it if you share this episode with your friends. Until next time, we'll see you in the cloud.
  • Stop AI Hallucinations with Better Salesforce Metadata 13.08.2026 36min
    Today on the Salesforce Admins Podcast, we talk to Skye Tyler, Principal Solution Consultant at Beyond the Horizon Technology. Join us as we chat about why clean metadata is crucial for getting the most out of AI. You should subscribe for the full episode, but here are a few takeaways from our conversation with Skye Tyler. Why metadata is your training manual for AI You've done it, I've done it. Sales wants a name changed on a report, so you just change the field label rather than create something new and mess with the integrations. Or maybe you have four different dates, but your marketing team knows which one they're actually looking for. What's the big deal? The problem is that while humans can get by on institutional knowledge, AI agents need a bit more help from your metadata. As my guest this week, Skye Tyler, explains, you should think of AI like an overenthusiastic intern with short-term memory problems. It really wants to answer your question, so if it sees four different dates, it's going to take a guess. Think of metadata like an onboarding manual for AI. With clear field descriptions and help texts, you can point your agents in the right direction and prevent hallucinations. How to get started with metadata cleanup Obviously, cleaning up your org's metadata is easier said than done. However, Skye has some great tips for how to get started. If your business has busy periods and slow periods, you might be able to schedule time specifically to work on your metadata. But for the rest of us, Skye recommends a clean-as-you-go approach. Any time you update an object, set aside some time to review all of the related metadata and update the description. Similarly, any time your organization is building a new business process that includes AI, you need to clean up any metadata an agent could interact with. As Skye points out, while you don't necessarily have time to deep clean your house every week, a little spot cleaning can go a long way. Skye's Salesforce journey and the value of sharing what you know We also took some time to talk about Skye's career path from nonprofit arts and what advice she has for folks who are new to the Salesforce ecosystem. AI is changing things fast, and that means there are more opportunities. "With all of these newer technologies and tools, anybody who's looking to come into the space today is learning the same things that I'm learning, having been in the space for a decade," she says. The Salesforce community is incredibly supportive, and Skye recommends putting yourself out there. You never know who you'll meet at an event, and where those connections could take you. "No matter where you are in your journey, you know something that other people don't," she says, "put yourself out there, and I guarantee you someone's going to appreciate it." Listen to my full conversation with Skye for more on how to clean up your metadata and stop AI hallucinations. And make sure you're subscribed to the Salesforce Admins Podcast so you never miss an episode. Podcast swag Salesforce Admins on the Trailhead Store Learn more Salesforce Admins Podcast Episode: How Should I Clean Metadata for Salesforce AI Agents? Salesforce Admins Podcast Episode: Use Metadata To Empower Salesforce Agents Salesforce Admins Blog Post: Metadata Is Your Admin Blueprint for Building Better Agents Admin Trailblazers Group Admin Trailblazers Community Group Social Skye on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript Mike: This week on the Salesforce Admins Podcast, I'm talking with Skye Tyler about the part of AI readiness that, well, it's easy to overlook. That's your metadata. We all know that clean data matters, but agents also need clear field descriptions, documentation, permissions, and context to understand what your business actually means. Skye explains why metadata acts like onboarding for an enthusiastic new employee and why a confident answer isn't always a correct one. We'll also talk about practical ways admins can improve metadata without trying to clean the entire org overnight. So give this episode a listen, subscribe wherever you get your podcasts, and of course share it with an admin who maybe has prepared their platform for Agentforce. And with that, let's get Skye on the podcast. So Skye, welcome to the podcast. Skye Tyler: Hi, thanks for having me back. Mike: I'm excited. Going through everything that we're doing to prepare for Dreamforce and admins are preparing for the agentic future, which is coming faster than eve, I stumbled across your session. And I thought, hey, before we get into Dreamforce, maybe we can dive into all of the stuff that you might not be able to cover in your 40-minute breakout session. So we'll talk about that because it's data related and data related is agent related. But before we get started, can you just refresh everybody on how you got started with Salesforce and what you do in the ecosystem? Skye Tyler: Oh, I'd love to. So I've been fortunate enough to be working in the Salesforce space with the nonprofit industry for a little over a decade now, and started off doing implementation work with nonprofit arts organizations, doing ticketing and donation. And then I've moved in and through the consulting space. Again, focusing primarily on nonprofits with a little bit of dipping into education along the way. And over the course of that decade, I've been fortunate enough to meet some amazing folks, yourself included, that has given me an opportunity to have the chance to share not just my journey, but my experiences, my struggles, successes, failures. And some of those avenues have included things like coaching and mentoring with super moms and the Salesforce military program, and then also just being really honored to be able to speak at community dream and events and events like Dreamforce and Trailblazer DX. Mike: I mean, that's a great answer. You know what's funny is so many people ask me, "How do I get started in the community," or, "What should I do?" And I feel like now I'm just going to point back to your answer because what you said was just perfect. Well, don't be afraid to share what you've learned, or what you're learning, or how you've learned it, or things you're working on because that's what people love to see. They love to see how you're doing it so that they can get an idea for how to do it. So thanks for answering a question I didn't have. Skye Tyler: Yeah, absolutely. I also just want to throw in, and I say this at many of my live sessions, that no matter where you are in your journey, you know something that other people don't. And everybody learns more when folks show up, and are vulnerable, and are willing to share those things. So definitely just give it a try. Put yourself out there and I guarantee you someone's going to appreciate it. Mike: Yeah, absolutely. Plus the thing I add to that is there's probably somebody out there like you that really needs to see somebody like you on stage. Skye Tyler: Yes, absolutely. Mike: So we talk a lot about data with agents and cleaning data, making sure your data's up-to-date, making sure your data's fresh, which every time I use the word fresh, I always think of how that plastic comes off an iPhone. I don't know why, but that's where my brain goes, because agents and AI and LLMs do a really good job of consuming a vast amount of information and giving it back to you in what you asked for. I think one of the things that we talk less about and that I want to talk to you about is your metadata, because I'll be honest, I pay attention to my metadata for five seconds when I'm creating the field. Skye Tyler: I'd say that's four seconds more than most people. Mike: Right, because all you got to do is click outside the box and it fills in the developer name, so I'm good. And description, ah, fill it in later. Skye Tyler: Yeah. And for the longest time, that's been really standard. And again, working across several consultancies and with lots of different works, people assume, well, we know what this field means. You give it a field name, the team knows what this means. I don't need to fill in description. I don't need to fill in help text. It's fine. And again, for the longest time, that institutional knowledge was enough of a stopgap that it was fine. Nothing was going to break or go horribly wrong if you left the description field empty. But all of that changes when you start introducing agents. And an example I may reference a couple times on this podcast is, I don't know if you've ever heard this, but the idea of thinking about your agent as a really enthusiastic intern with short-term memory problems. Mike: Like memory of a goldfish. Skye Tyler: Yes, exactly. So if you've got a new intern and they don't have deep industry experience, or they don't have longer term institutional memory within your organization, and they come on site, they're excited to be there, they're energized, they're probably young and enthusiastic, and they're going to sound really confident. You're going to ask them a question. They're like, "Yeah, absolutely. I can absolutely do that." But there's a difference between sounding confident and actually knowing the answer. And where AI gets really tricky is not only does it sound confident, it usually has a certain level of fluency to it with the amazing jumps in natural language processing over the past few years, it sounds both confident and right because it's just a well-structured sentence. And there's a huge gap between the structure of the sentence and the actual understanding of the data behind it. Mike: Right. It reads to us as so confident in its own answer that we would be silly to think it's wrong. Skye Tyler: Oh, absolutely. It would be a waste of time to go back and check it because look at how confident it is. Mike: Yeah. And look at all the part that I always think of is look at all the information it gave me. I asked it two sentences and it gave me four paragraphs of an answer. It must be right. Skye Tyler: Yes. And of course, don't forget that at the beginning, it also flattered you and said, "Oh, Mike, that's a great question. Let's dig into that." Mike: Yeah. You sound just like my AI. Skye Tyler: Exactly. Mike: "Of course it's a great idea, Mike. You should totally do that. Everything's a great idea." So when we think about that though, why is it making those mistakes? Because if we're paying attention, and I mean, I was even working on some content today that's like, got to keep your stuff fresh. If you're going to do call notes or have a summary agent, then make sure your salespeople are doing call notes and keeping it up to date or keeping the data up to date. Then why is it so confidently giving us, I don't want to say the wrong answer, but confidently providing us with information that it thinks is correct, but isn't? Skye Tyler: Yeah. So a big part of this comes down to the difference between how humans think and form answers and how the large language models do it. And one of the real risks around this false fluency framework is that you pose a question, you ask a question, and first there's the basic understanding that the agent, whichever model or system you're using, their goal is to accomplish the thing that you asked. So the first thing is getting really careful about how you ask your questions so that you're not sort of setting it up to just affirm the thing that you have asked. But then beyond that, the way that these LLMs, these large language models work, is it's basically a really complex pattern completing process. And so you mentioned peeling that plastic off of your new iPhone. How many times are you typing a text message on your iPhone and it has that auto recommend that comes up right above your keyboard? Mike: Yeah. Skye Tyler: So that's a good example of a simple version of this. So depending on how often you type in "Oh my," and then it's going to recommend a couple of different things that often come after "Oh my" in the training data. When we're thinking about this in the context of asking an agent something in Salesforce, the way that it identifies what to propose for an answer is not looking at just the data in the field, it first has to go look and see what information is available and that's when it dips into the metadata. So if you've got four different fields that have very similar field names, but have no metadata to tell the agent field one means this, field two means that, field three means this, and field four means this completely other thing, it's just going to guess. Mike: So if you had four dates on a record that were, I don't know, draft dates because it ties to a contract or something, and it's draft one, draft two, draft three, draft four, and you know as the user, those are the dates that you completed those drafts, but your metadata just shows four draft dates and there's no explanation for the agent. So the agent's like, "Here's when all the drafts were completed." Skye Tyler: Right, it's going to guess. And because it's non-deterministic, it might guess right the first time you ask it a question. It might guess right the second, third, fourth, fifth, 20th time, and then the 21st time, it guesses wrong. Mike: But confidently. Skye Tyler: But confidently wrong. Mike: Confidently. Right. Skye Tyler: Right. And so when we're thinking about how to support our agents, if we go back to that analogy of the over-enthusiastic summer intern, the metadata is effectively the onboarding process for that new intern or a new employee. It's the manual about what your data means, and it's the context that the agent can use to give you more consistently reliable, correct answers. Mike: Love it. So I remember, I think it was TDX two years ago, we were talking kind of on this subject. And whenever we roll out a new feature, it's here's the things you need to do to prepare. And I remember getting up and talking with a lot of people of like, "Hey, it's more than just the data that's got to be cleaned because there's a lot of data cleaning services and hopefully you have a lot of validation rules and stuff in place, but also your metadata needs to be cleaned as well." And I looked over in the audience, I felt this guy just shrug his shoulders and just kind of turn a lighter shade of pale, I'll say. And I walked up to him afterward and I asked him, I was like, "Are you okay?" And he's like, "Yeah, your words just hit me really hard. I was thinking of all the metadata I have to clean up." So obviously it would be awesome if every day people woke up and you cleaned your whole house. But let's be honest, you don't have to wake up every day just to live in your house to clean your whole house. What is the approach that an admin should think of in terms of getting their metadata to that next level and to prepare for an agent force implementation? Skye Tyler: Yeah, I love the analogy of cleaning your house every day because I'll tell you, I do not wipe my baseboards every day. Mike: oh, man. I would pay somebody to come once a week to do my baseboards. It would be awesome. Skye Tyler: Yeah. So there's a couple of ways that you can look at this. The first one is figuring out within your workflows, your day-to-day and annual workflows, where you can build metadata maintenance into your process. And so what this might look like for admins is the next time someone on your team asks for an update on an object, whether it's a page layout, or some new fields or what have you, taking and building some extra time into however long you budget or allocate for that task to include reviewing related metadata. Every time you need to update a flow because the business process has changed and you say save as new version, as soon as you click save as new version, update the description of the flow. That's the first thing that agents are looking at to be able to figure out what automations do I call, what automations are related to a process, et cetera. So building it into the workflow of what you already do is one avenue to consider. If you have an amazing organization that lets you do proactive maintenance, working that into your project plan and saying, "Hey, this is a usually kind of quiet time of the year for new admin requests. Let's go ahead and block two weeks or three weeks and do a more thorough or a deeper dive into updating the metadata." If you work at one of those organizations, let me know, because I've heard they exist. I haven't encountered one in the wild. But then lastly, when you have any new agent related process, it should be considered mandatory as part of that project to do a metadata review of every aspect of metadata that that agentic process is going to interact with. Because one of the big challenges that organizations have been seeing is they're putting a lot of time and resources and money into creating agentic solutions, but the research and the data is just not showing the level of return on investment or the level of success that people are expecting. And one of several underlying factors is you're not setting your agents up for success. You've got this new employee, this new agent employee, but you didn't onboard them. You didn't provide them with adequate institutional knowledge and training. You gave them some direction. But if you think about it, Mike, when you've got a new employee that comes on and they go to that podcast or that blog record for the first time and they see your four review dates and they don't know, they stop and ask someone. They ping you on Slack and be like, "Mike, can you explain these four review dates to me?" Your agent can't do that. So set them up for success with that onboarding through the metadata updates. Mike: And I think that also, I mean, I really like how you approach that. I think that's also a funnel or a pathway that you could flip. So you don't have to think of, I have to tackle everything and clean all my metadata first, as opposed to, well, if we're going to roll out an agent and it's going to touch these three objects and these 15 fields, then that's where you start. Skye Tyler: Absolutely. Mike: Because then that will help you set up a plan for here's how we're going to tackle this part of it. And then as the agent responsibilities or you build additional sub-agents expands, then you can tackle two or three more objects that maybe that sub-agent has to talk to as opposed to, okay, we're going to wake up at 3:00 AM, clean the whole house just to live in it, which is a good idea. I think sometimes readiness to the extreme can feel overwhelming. Skye Tyler: Right. And if it's overwhelming to the point where you don't make any progress on it, then it's not useful either. So definitely thinking about what's within scope. Where I would challenge that a little bit though is unless you have put very firm guardrails on your agent, there's always the possibility that it's going to get creative. So you might intend for that agent to only look at these four fields, or these 15 fields, or these two objects, but if you don't actually instantiate that guardrail or that limit into how you build the agent, it could start to be like, huh, I wonder if this related record might impact me being able to answer Mike's question better. Let me just go take a look at that. And that's where we could get into some of the more deeper technical things, but the idea that authentication is not the same as permission. And so making sure that each of your agents has very clearly defined, and that ties in with the metadata too, because all of those settings in Agentforce and Agentforce builder are set up, the sub-agent descriptions, the scope, all of those things are metadata around your agents. Mike: And I think there's downstream effects to this that are also positive too. I'm thinking of all of the reports that you're dealing with that will suddenly get better because I know you're always building reports, sometimes not off of the report label. So help me through this. You've got an implementation and you have an integration with another system and you change metadata descriptions or field names. How do you need to approach that? Because obviously you need to identify that early in your discovery. Skye Tyler: Yeah. This is a little bit of a catch-22. Let's just say that we've got five fields on, I'm going to just call it the case object, that are updated through some form of integration. Maybe it's a form submission, maybe it's an external data source, whatever. But there's five fields that are tracked and interact outside of Salesforce, and you're going to set up an agent that does something that impacts those five fields. When you set up the previous integration, if you didn't put in the description somewhere on those five fields that this field is part of X integration or this field is populated via X external data source, one, past you did future you no favors by not putting that in there. Mike: Man, when the DeLorean gets out of the shop, I'm going to go back and really tell myself. Skye Tyler: Exactly. So again, going back to that idea of you've got a new project, you've got a new request, you've got a new thing that you're building. Taking the time to do that slew thing and to really investigate what are all of the things that touch this piece of data or this particular metadata. The simplest sort of way to address that is whatever else you're changing, don't change the API name. Mike: Smart. Skye Tyler: Now where that kind of gets, I've seen more orgs than I can count where the field label is something completely different from the API name because it had some kind of external connection or integration, and if you try to change it would break it. So they just changed what referenced to the human. That's going to be a problem for your agent. If you are expecting interaction around review date one and the API name is something completely unrelated and there's no description to give the agent more context, they may not even look at that field. They might not even recognize it. Mike: Oh man, I am so guilty as charged. Skye Tyler: We've all done it. We've all done it. Mike: I mean, businesses change process and I was like, I can just change the field label. If it says this on the screen, are you happy with that? Mostly because I didn't want to ... It always happened where I didn't want to have to create a new field, move the data over just because they wanted a different name. Skye Tyler: Yeah. Yeah. Well, and if you are an admin that does not do Apex, which most admins don't, right? Mike: Not me. Nope. Skye Tyler: They're differentiated roles for a reason, and you have Apex that's running against those custom fields, you can't just go in and change the API name. You are going to break things. And so this is where that cascading effect can come into play and you say, okay, well maybe this one quick fix that the marketing team was asking for isn't actually a quick fix because we do want to get the org as ready as possible for future agentic improvements. Mike: I love how you set me up for my next question there because I was just going to ask you. So I could see somebody's listening to this and hopefully they got this far and they're like, "That was a fun podcast, but we're not really getting ready to deploy Agentforce, so why should I care about my metadata?" Skye Tyler: Yeah, this is one of those things, and I'll admit early in my consulting career, this wasn't as emphasized. It was all about the user's experience. Does the page layout make sense? Can the user click through and do the things they need to do? And the stuff that's behind the scenes, the admins can cope with that or the consultants can deal with that, and it just wasn't as important. But even things like as flow gets more complex and now, I mean, we're talking about moving to this whole headless experience, the system itself has just matured to a point where if your top or only priority is the UI, the user experience and the user interface, you are limiting the capacity of what your organization can do on Salesforce. Mike: Very true. Very true. I feel like as an admin that did focus very much on the UI, would bounce back and forth on trying to make Salesforce the one-stop shop for everybody. I remember way back in the day, do you remember when we used to be able to build web tabs? Skye Tyler: Oh, yes. Oh, those days. Mike: And so I remember we had a travel system, and I put it in a web tab because I need my users not only to sign in, but sign in and update their opportunities and update the accounts and stuff. And so I asked the salespeople back then, "What is the number one thing you check almost every day?" And they're like, "Our travel thing," because they're traveling and they need to book things and stuff like that. And I said, "Cool. I can do that." And so I put it in as a tab, but it was like a simple I-frame. It's just there. And I had one user, when I showed it to them, they were like, "Oh, this is amazing, but I booked my travel and it didn't sync with my calendar." And I was like, right, because it's literally a pane of glass that I'm giving you into another system. But your whole conversation about this made me think back to when I would try to bring all of my users together in Salesforce, and then when I would try to make it so that they didn't have to pay attention to the UI in Salesforce. And I feel like I tried to make both, because you brought up headless. And headless in theory is you use a tool and then you just at Salesforce or something, you can bring all of that knowledge in. Skye Tyler: Well, I mean, you and I have both been in the space long enough that we remember the days when the mantra was, if it's not in Salesforce, it doesn't exist. Mike: Oh, yeah. I mean, I still say that. Skye Tyler: Right. But the reality of the world now is there's a lot of data and there are a lot of processes that don't exist in Salesforce. They can be surfaced there or they can be represented there, but they live somewhere else. And that's where, going back to my previous comment that the platform, the system itself has just matured beyond that. You have to log into Salesforce, you have to create a record or update a field in Salesforce for it to count. And that's not the case anymore. And even things like using experience cloud sites to be able to allow external partners or site guest users to be able to get information into Salesforce, all of those connections, all of those disparate data points are potentially accessible by agents, and then if you move into a headless environment from a headless perspective. And so taking whatever time and resources you have at this moment and making whatever improvements or whatever cleanups you can make is just going to help future you, future admins who manage the system, be more successful in doing that. And I know right now in the nonprofit space, there's lots of conversations for folks who are considering moving from the nonprofit success pack to Agentforce Nonprofit. And when I talk to folks who are considering the move, one of the things, even before Agentforce Nonprofit, moving from a different data system into Salesforce, really doing an audit. And we were talking about cleaning houses. I have this great story from one of the times we moved when I was a kid and my mom was real stressed out, she ended up packing the trash can full of trash. And by the time we got around to unpacking that box, you can imagine how pleasant that was. So when you're packing up your house, when you're packing up your data house or your data system and you're planning to move, don't pack your trash. Go through and do a data audit. Go through and update your metadata. Make sure that you're moving into your clean new house with just the things that you want, and they're going to be easier to access and more effective. And then your over-enthusiastic summer intern of an agent is going to be much more likely to give you a coherent, fluent, and accurate response, not just a confidently wrong one. Mike: I like that. Packed your trash. It is odd when you move because there's stuff that lives in the world that when you move, you have to figure out what to do with it. Skye Tyler: See, I can't relate. Having been associated with the military for a decade, I can now fit my entire house in a U-Haul. Every time I move, it's a purging process. Mike: Sure. Yeah, I can understand that. I'd love to end on that, but I have one other thought, which is, this doesn't just apply for Salesforce. When we're working with our IT colleagues or people in the organization that own other platforms, a lot of the power comes not only from Agentforce being able to bring in Salesforce information, but to be able to consume other information. And I have to believe that we have to sit down and do the same kind of audit when we're looking to integrate with another platform. Skye Tyler: Oh, absolutely. And this is where, I mean, the kind of highest level way to think about this is it's the context. You have to have some mechanism in Salesforce, it's primarily metadata, but you have to have some mechanism for the agent to understand and to have the context of what you're actually asking them to do. So these large language models have been trained on the entirety of human knowledge that has been encoded into the internet. Well, that's not helpful for your specific question or your specific query. So having systems in place, whether it's knowledge articles, whether it's Jira tickets, whether it's Confluence folder structures, having mechanisms that give the agents the proper level of context for them to be able to support you in solving the problem, designing the solution, answering the question, whatever your purpose is, this is transferable across any touchpoint of agentic work. Mike: Yeah, totally makes sense. I always push the speakers that I work with for Dreamforce, or TDX, or any event to think about what happens when the person stands up after your presentation is over. And so I'll ask you the same thing. So what happens when somebody presses stop on the podcast and goes about their day? What's the one thing they should do after they listen to this? Skye Tyler: Well, obviously keep listening to the other podcast episodes. Mike: Right. Just continue on to the next episode. Skye Tyler: I think the takeaway that's sort of bigger than just data or metadata or even agentic work, is keep learning. All of these systems and all of these tools are evolving so quickly. And while that can be a challenge and can be maybe intimidating, it's also potentially very democratizing. And when we think about your comment earlier about people trying to get into the ecosystem, for a while it got very hard. There was the age of the accidental admin when Salesforce was young enough that just if you were good at fixing the printer, you became a Salesforce admin. And then we moved into a period of time where it had matured enough that organizations wanted people with deep experience. With all of these newer technologies and tools, anybody who's looking to come into the space today is learning the same things that I'm learning having been in the space for a decade. So my call to action for anyone listening to this podcast would be find other avenues of learning. And then if it's in your wheelhouse or your interest, offer what you've learned to other people and share that experience. Mike: I think that's great. I mean, that ties right in with the podcast I did with Gene Velonis, which was open up a Trailhead org and just start playing around and- Skye Tyler: Just try it out. Mike: ... don't be afraid to break things. I think there was a point in time when I would work with a lot of community members and they were always afraid, "But what if it doesn't work?" And I'm like, "Cool." And then we know we have to go back and get to tinker with something. Skye Tyler: Yeah. Mike: That to me is half the fun. Skye Tyler: If it works the first time, then it means you weren't trying something hard enough. Mike: I know. Yeah. Yeah. That or I'm worried when it's going to stop working, because if it worked the first time, then I didn't get to troubleshoot stuff. Skye Tyler: This is true. This is true. Mike: Skye, it's always a pleasure to have you on the podcast. And in the ever-changing world of AI, and metadata, and data, and everything else, it's good to have you kind of keeping us honest and keeping us on our toes. Skye Tyler: Well, I don't know if I want to bear that responsibility, but I'm happy to try. Mike: You're one of many people. Skye Tyler: Great. Thank you so much, Mike. Mike: Big thanks to Skye for joining us and making metadata feel practical, useful, and well, a lot less overwhelming. My key takeaway was for admins, it's really simple. Agents can only act reliably when Salesforce clearly reflects what the business means. So build metadata review into the work you're already doing. Maybe pick one active process and document the fields and the automation it depends on, and give the future you and the future agents the context they need. Now, of course, you should subscribe to the Salesforce Admins podcast wherever you listen to podcasts, and be sure to keep learning and trying something new in your org. Until next time, we'll see you in the cloud.
  • From Inbox Requests to a User Management System 06.08.2026 38min
    Today on the Salesforce Admins Podcast, we talk to Michelle Wolfe, Platform Engineer. Join us as we chat about how she built a Flow-powered user management system to handle requests, approvals, user creation, permissions, communications, and even onboarding. You should subscribe for the full episode, but here are a few takeaways from our conversation with Michelle Wolfe. Streamlining change requests with screen flows It's a good thing when your organization is growing, right? For Salesforce Admins, however, new hires need new accounts, and that means approvals, permissions, and onboarding. My guest this week, Michelle Wolfe, found herself in exactly this situation. She turned to Flow to build an automated user management system with no code, and she's here to tell us all about it. Michelle's company was bringing in 80+ people per new hire class, but the account creation request process was a mess. Managers would email a random member of the three-person admin team, and then they would manually create the account. So the first step was to wrangle the business process with a screen flow to get the correct information into Salesforce and create a case. But Michelle was just getting started. Now that everything was in Salesforce, she knew that she could use Flow to automate the rest of the process. New account creation with autolaunched flows Once the new user's information was approved by their manager, Michelle set up an autolaunched flow to spin up the account. This took care of data validation, configuring the correct permissions, and creating a username. Finally, a second autolaunched flow would close out the case and send two email actions: one to confirm the request, and one to welcome the new user. With help from Flow and Einstein Copilot, Michelle transformed a complicated manual business process into something streamlined, simple, and scalable. Partner with your training team for a fresh perspective on your org Michelle credits her success with how closely she works with her training team on enhancements. "Because they interact with new employees, they see things differently than someone who's been here for years and knows how we use our Salesforce," she explains. That fresh perspective helps her identify improvements she might otherwise miss. Listen to my full conversation with Michelle for more on how she used Flow to automate user management—we really get into the weeds. And make sure you're subscribed to the Salesforce Admins Podcast so you never miss an episode. Podcast swag Salesforce Admins on the Trailhead Store Admin Trailblazers Group Admin Trailblazers Community Group Social Michelle on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript Mike: This week on the Salesforce Admins Podcast, I'm joined by Michelle Wolf to talk about what happens when user onboarding stops being a string of emails and becomes a real platform process. So Michelle built a Flow-powered system that handles requests, approvals, user creation, permissions, communications, and even offboarding, while keeping the admin team in control. We're going to talk about the automation behind it, but also the process decisions that make it accurate, secure, and useful for her business. Now, because when admins design access and onboarding well, they're not just saving time. They're protecting trust and helping people get productive faster. So listen in, subscribe, share this episode with an admin who has one too many user requests sitting in their inbox. I'll tell you who doesn't have too many user in requests sitting in their inbox, and that's Michelle. So let's get Michelle on the podcast. So Michelle, welcome to the podcast. Michelle Wolf: Thank you for having me, Mike. Mike: I think this is exciting because I can't recall the number of times I've had people on about onboarding users. And I think it's because whatever cool tool we have come out, it's the second thing people do. They're like, "Oh, I could do this, and I need to figure out how to do X, Y, and Z when I onboard people." Because it was like that with Flow. There was stuff with Chatter when that came out, "How do I onboard people and add them to groups?" And Jennifer Lee was at your session at Midwest Dreaming, and she thought it was just phenomenal. So I had to have you on the podcast to talk about it. But before we get into that, tell me a little bit about yourself, how you got started with Salesforce and what you do. Michelle Wolf: Yeah. So my journey started as a lot of ours as an accidental admin. I was working for a small family-run business who had Salesforce, and they were paying a consultant to basically be their full-time admin. And one day my manager walked into my office and said, "I don't want to pay them anymore. I need you to learn this." And I was like, "Okay." Mike: "I suppose." Michelle Wolf: Yeah. Why not? So yeah, that's what started my journey. And I skilled up on Trailhead and I was on it two, three hours a day trying to figure out how to be an admin in Salesforce. And this was back at the initial transition from Classic to Lightning. Mike: Ooh, fun. Michelle Wolf: So half of my early batches are on Classic. There just wasn't a ton of Lightning stuff out there yet. So I would build a lot in Classic and then flip it over to Lightning to see what it looked like because they did like the Lightning interface, which was great. So that started my journey. And then when I decided to part ways with that company, I took a different position and paused my admin career. And then about five years ago or so, I had an opportunity to be a product SME for Salesforce. And I was like, "Yes, I miss this product. I miss doing this. I miss being able to make things better with just the click of the button. So let's go do this." And I jumped in both feet and never looked back. And so I've been an active admin for a little over five years now. And I'm a Flownatic. Anything I can automate, I am doing it. Mike: I love it. Active admin as opposed to passive. Michelle Wolf: Exactly. Mike: I don't know. So I love when you started because I remember those times and the reason there wasn't enough Lightning things is we were all writing it as fast as we could. Michelle Wolf: Yeah, I know it. Mike: It's kind of like learning to drive with a manual. And then they're like, "Oh, well, here's an automatic." And you're like, "Oh, I already know how to drive with a manual." I mean, if you knew how to do things in Classic, then doing stuff in Lightning was just that much easier, in my opinion anyway. Michelle Wolf: Yeah. I agree. I agree. And the user experience was better for my users. They liked the layout and the feel. It jived with their personalities better instead of that very formal grid-looking everything. Mike: I mean, that was the internet at a certain period in time. And then it grew up and it was like your eyes don't have to squint with white space. Michelle Wolf: Right. Mike: Every field just went from tight polyester pants to sweatpants. And it was like, "Yay." Michelle Wolf: Exactly. Mike: Let's talk about being a Flownatic because I've talked with Jen. I know Jen said she was in your session. I really think, I mean, outside of just it's so incredibly powerful, the amount of things that you can do on the Salesforce platform without writing a single line of code. Flow is one of those. And I remember it was 100 years ago that I saw Flow for the first time at Dreamforce when I was a customer. And I think they called it Business Process Management or something. And it was an app you had to download, and then you had to upload schemas to it. It's since graduated into a much more robust tool. But the nice thing is once you know that, I mean, caveat emptor because AI runs off of all the flows. I mean, if you're good at Flow, there's very few things you can't make Agentforce do. So tell me a little bit about why you built onboarding with Flow. Michelle Wolf: Yeah. The company I was with found themselves in a really big period of growth, which was really amazing. But the new hire classes were like 80 people. And I just could not bring myself to want to spend a week of my life just filling in these boxes to make new users. It was really so time-consuming. And one typo here, one missed field here. My validation rules didn't check out. It was just a pain. It's just very mind-numbing. And I was like, "There has to be a better way." And I went through the different variations of the Add Multiple Users. It's an out-of-the-box function, except I couldn't put my custom fields on there, which means I couldn't save my users because we had validation rules in place. And then I experimented with a bulk upload, but it was such a pain because if I would typo a field, I would mess up my entire formula. Mike: Yeah. Michelle Wolf: And I was like, "There has to be a better way. There just has to be a better way." And- Mike: Plus then all you're doing is just creating the user. Michelle Wolf: Exactly. Mike: With Flow, you can do so much more. Michelle Wolf: Exactly. So by converting it to a Flow, I had a screen. I used my screen flows, and I leveraged the fact that the onboarding team is already putting that information into an email or something. Well, just go here and put it in a case for me. Just hit this button, pull out the fields. Now I don't have to do this. And then I used that screen flow to make a case so I can track my productivity, when the requests are coming in, when the requests are due by, who's doing the request. We started with just managing cases manually and making the users off the cases. And we had built in the approval process to make sure that someone else was double checking the inputs. Did they spell their name right? Did they put in the email right? Because I don't know these people. They're not going to be reporting to me. I'm not part of the onboarding team. I'm just making a user. So we had the managers do the approvals and make sure all that information's correct, make sure they're requesting the right... We use a field called Team Name that we made custom to make sure they're getting put on the right team, the customer service team or senior customer service team, whatever. So someone else is double checking it and then approving it. And I was like, "From here, I have to be able to automate something because the information's already in Salesforce." And that's when I got into utilizing that approval flow to trigger an autolaunched flow to actually make my user and create the alias and create the username and update the profile based off of what was entered on the request form in my screen flow, and just physically make my user. Mike: Wow. We spent a lot of time talking about the tech part of it. I want to dive in because I feel like you conquered a lot, but you probably had to sell it. Maybe you didn't. Tell me about all the non-tech stuff that you had to sell. Who did you have to go to, and what were the people you met with in order to say, "Here's how I'm going to onboard users moving forward"? Michelle Wolf: So the onboarding process had already been moved to our team. And it was just that it was coming to us in a very casual way. We're getting an email request. So it was part of the struggle was they started emailing us individually. We were a team of three, and they would just pick which admin they wanted to work with. Well, if I'm out of office or I have to leave unexpectedly and forget to put my out of office on, then their stuff's getting delayed. And so that was the first big conversation of how do we take out that portion? How do we get them to just put it in so we can decide who does the work? Because if I'm heads down on a project, I don't have five minutes to go make a user. I need to be heads down on my project. Mike: Right. Michelle Wolf: So this allowed us to divvy up work more easily and really even just check our own productivity of handling these types of requests and making sure it's not one person that always gets stuck with the work because they're the one that's always being emailed. So that was the first thing. And so the three of us, we were a really tight-knit group, and we're all very aligned with not wanting to be the only human that was pinged or emailed. And so it was like, let's just get it to a centralized place. And so we just went to our manager and said, "We're going to build this. We need this to be more productive." And they were like, "Yeah, makes sense. Do what you need to do." Mike: I mean, that's awesome. Michelle Wolf: Yeah. Mike: Sometimes when I was an admin would happen and sometimes it wouldn't. But I do think some change has to happen that way of, "No, here's how I'm going to be more productive, and here's what I want to set up." Michelle Wolf: Yeah. Mike: So then were there... I guess what I'm getting at is, for admins that hear this and like, "Oh man, this is me," were there other checks that were already in place that you didn't have to deal with? There was already a check with HR or the person in payroll in terms of onboarding these people. You didn't have to go and say, "Can you..." Because I was the same way, to be honest with you. I would find out when I was an admin, "Oh, so-and-so needs a Salesforce license," two days after they started when HR sent out the announcement of the new hires. And I was like, "Hey, there has to be some process that you onboard these people to the company. Can I be part of that?" And I kind of had to unwind HR and figure that out because they didn't know that Salesforce was a part of this department and they didn't know that people need to be onboarded for it. You sound like you didn't have to deal with any of that. Michelle Wolf: We did not. That onboarding process was already handled by a team. And so when the hiring manager said, "Yes, we're going to offer," and they accept, they already knew what systems, what equipment they need, what systems they need access to, and then what types of permissions they would need to ask for from Salesforce. So like what team they were going to, so that that request could be put in. All that hard legwork was already done. So to those who might not have that, I think the biggest selling point could be onboarding experience. A lot of companies are focusing on what that hiring process, what that onboarding experience is. And as someone's starting a new job, I want to prove myself early on. I want to say, "I'm here, I'm ready to work." And if I can't access my systems, even though it's fully out of my control, I still feel like I'm not doing my best as an employee, as a new employee. So you can leverage just even the onboarding experience that they have, the equipment they need, they have the logins that they need on day one, on the day that they need it. Mike: Yeah. And you don't have to go into detail, but what are the key, I guess I'll call them, milestones in your onboarding flow that the new people get sent? Do you have training materials, or do you have a video that's Michelle being like, "Hi, I'm your Salesforce administrator"? Michelle Wolf: If only. Mike: I know. I always say that and everybody's like, "Oh, that'd be a great idea." Michelle Wolf: It would be. It would be. Mike: "It's just 4,792 on my list of things to do." Michelle Wolf: Exactly. When I have that free minute, I will absolutely get to that next. Mike: Yeah. And also my other two admins, because it can't just be me. Michelle Wolf: Right. "Here's your Salesforce team. We're here to support you." Mike: Yep. Michelle Wolf: So what we built into our process was, in my Flow automation, there was actually a second autolaunched flow that would close out the case. And this did a couple of things. One, it closed out the case so they had a complete close of the loop and updated the reason as completed by automation because a human didn't have to touch any part of this request. Mike: Ooh, that's cool. Michelle Wolf: Yeah. Mike: I like that. Michelle Wolf: Clean reporting. Who doesn't like that? Mike: I mean, for a while, I remember doing approvals or something and somebody asked me, "Well, did you actually do this or did Salesforce, the Flow do it?" And I was like, "Well, the Flow did, but the Flow ran as me." Then it marks that. But I like that you added that completed with automation. Michelle Wolf: Yeah. But we also added two email actions. And one was to the requester. So the individual that opened the case through the screen flow, it sent them an email telling them that the request had been completed. And then the second thing was, when the user record was created, it then updated the Requested For field, which was just a custom field we made on the case for a user lookup with the new user that we'd made. And we sent a welcome email to them and said, "Welcome to Salesforce. Welcome to our company. Here's how you access our org." And it had the link for the SSO. Yeah. Mike: Because at the point that the person's creating the case for you to create the user, they've already had an email assigned to them. Michelle Wolf: Correct. Mike: I like it. That's pretty sweet. Michelle Wolf: Yeah. It was just a nice clean way to close multiple loops that ended up getting started. Mike: So then, not to dig into it, and this is where I wish I should have seen your presentation, do you also have a process for adding them to... I don't know if you guys have Slack or different things like that. How, outside of maybe that user emailing you, do they have not necessarily an open loop, but at least a channel to ping back the admins and say, "Oh, hey, I got everything except this doesn't work, or, "I'm not seeing X," or, "How do I upload a profile picture?"? Michelle Wolf: Yeah, absolutely. So for our new hires, basically all of that was handled in their new hire training, a lot of that initial setup support. However, in our screen flow, we actually made it a full-service utility where when you went to launch the screen flow, you could say, "I need help with Salesforce. Something's broken." Or, "I need a new user." So it was this full access path to us where they could put in multiple requests depending on what they needed. Mike: I like that. And I'm assuming it's not Michelle, but you have people in the organization that do training. How much do you have to keep them updated in terms of, "Here's what the new user experience is like for Salesforce"? Michelle Wolf: As far as? Mike: Just anything. Anything that would change or anything that they may encounter, new features. Michelle Wolf: Oh, yeah. So anytime we would build any type of enhancement, we worked very closely with our training department. We knew if we're going to help make starter material for an announcement for the call center for X, Y, Z enhancement, training's also going to need that material and probably a deep dive hands-on demo so that they can incorporate it into their training materials. So any new builds like that, our training department was really involved even from early-on stages of the development because they interact with new employees, and they see that interaction differently than someone who's been here for five, 10, 12 years and knows how we use our Salesforce. Even just how we design and where we put things on the Lightning page, they would often give us input from a new hire perspective to ensure that we're building good things. Mike: Now, just because we're nerdy here, did you have a way of capturing that? Was that a case as well? Michelle Wolf: That was just conversations. Mike: Oh, okay. Michelle Wolf: Yeah. It was, "Hey, we have this thing. We want a demo for you. Give us feedback," type of stuff. Mike: I didn't know if you were capturing that in terms of tech debt or things we need to build, things we'd like to build, and things we need more money to build. Michelle Wolf: Yeah, depending on what it was. It was just good old-fashioned scope creep. Mike: Okay. Yeah, that usually happens, unfortunately. Michelle Wolf: Yeah. Mike: I've talked about Flow and AgentForce. I've been around now. I remember from 2006 when we finally had drag-and-drop WYSIWYG page editors to now we have... Well, I've seen agents build apps now. So I feel like I'm coming full circle. If you haven't already, if you were to bake some AI into your Flow, are there things that you would change or things you'd want to change and do different? Michelle Wolf: I don't know yet because I spent so much time getting it to do what I wanted it to do with all my magic formulas in that Flow. I don't even know if AI could have helped. Now, AI did help me make those formulas. But I don't know how I might leverage AI to improve this process even more. Mike: Yeah. No, that's fair. I mean, I have friends, and they always razz me a little bit because I work for a tech company, and they're like, "What'd you put AI into today?" And I think that's a call that admins need to make is, "Where do I need to add it?" Not just for the sake of adding it. I think we always talk about internally when we're creating content, "Well, don't AI wash everything." You don't have to include AI in it if it doesn't make sense because for yourself and your other two admins, that's one more thing you have to update or keep track of. And if it doesn't need it and you could do it somewhere else more effectively, then you should. Which sounds crazy, but it should be in the right places for the right interfaces, as opposed to, "Well, I included it because I could include it everywhere." It's like putting frosting on everything. The bacon cheeseburger doesn't need frosting just because you're a frosting company. Michelle Wolf: Yeah, exactly. And I think maybe the next iteration that could include AI would just be on the initial request, especially for individuals wanting help with Salesforce. Maybe leveraging an FAQ-type of document for the things we do get commonly asked questions about. But for the user management, I'd really have to sit down and think of how that could apply. Mike: Yeah. Or even an agent to serve up, "Here are three questions everybody asks and here's links. Do you have any other questions besides that?" And be a little proactive in terms of FAQs and stuff like that. Michelle Wolf: Yeah. Mike: So outside of email and stuff, does that seem to work okay? Or are you more leaning towards if we had Slack or anything different, we can maybe change things? I always worried when execs were like, "And then I want it to email me." I'm like, "You do know you have 10 salespeople. And if they have to close four deals a day, that's 40 emails on top of the eight billion you already get." You didn't have any executives with concerns on email velocity when you're onboarding 80 people? Michelle Wolf: Oh, no, because of the 80 people, the emails from the requesters were really going back to the onboarding team. And so it was a way for them to check off the list that that system is done. So just like they would do it for other systems or other access for Jira or their Microsoft Teams access and all that stuff. It's just closing that loop with the onboarder. We did have one concern when one of the managers was new, and so 20 of the new hires was theirs. Mike: Oh. Michelle Wolf: But that's not the norm. You know what I mean? It's not necessarily that all the time you're going to be hit with all of the approvals, but it did happen. "You're new, you're getting a full class of newbies. Good luck." Mike: "Congratulations. You now have 20 more emails." Michelle Wolf: Exactly. Mike: When you presented this, I'm curious, fresh eyes, sometimes you can sit in silence and between you and your other admins, you're like, "This is boss. I can't wait to show people." And then you show people, and they have a lot of questions. Is there questions that people had that maybe caught you off guard or you didn't think they would ask you about? Michelle Wolf: I don't think any questions really caught me off guard, but the types of questions that came up were, "How did you come up with your approval process?" I was lucky that my approval process was already established within my organization. You get a new hire, it's the direct manager that approves it. Other organizations, it's the system admin that approves that this position and title in human deserves and needs access to do their job function. So it just depends on how your organization slices that cake, but someone should be approving access to an org. Mike: And you know what's funny is, I probably asked you at the beginning of the podcast, but those are always the questions that I try to get out of people because especially when me and my team are building demos, the process behind what we're building, we just don't even think about. It's like, here's how the tech would do it. But the tech is only there to support the process. And nine times out of 10, everybody in the audience watches your presentation like, "Got it. Now I know how to build it. It's going to take me three months to get this process ironed out because either there's a lack of one or there's a shared understanding of how people think things work." And those are the questions to really ask. Are there questions that they came up with that your company hadn't figured out yet? Michelle Wolf: No, of course not. I had all the answers. Mike: Perfect. Michelle Wolf: No, I don't think so. Because my solution covered 80% or more of the situations. Even in the event of your admins, say your admins are responsible for giving an individual an access to the org, but then they're also responsible for giving them access to some connected program that integrates with your org, but your admins are responsible for providing that access. My Flow included that if a manual comment is added or if a checkbox is selected that they need this access, it adds a comment to the case using the case comments and then leaves the case in an open status, like in progress, so that your admins can go in and finish that process. Mike: Oh, cool. Michelle Wolf: And then when they close the case, it just still does the rest of that email magic to tell everybody that it's all done. So we left openings for those situations where manual changes would be necessary to complete the full onboarding from our team. Mike: That opened up a host of questions in my head. So can you create a user without going through your case and Flow? Michelle Wolf: Manually. Yeah. None of that's turned off, but we do prefer them to use the Flow. Mike: Right. I didn't know if you flagged it as, "This went outside the Flow," or something. Michelle Wolf: Yeah. The only situation where it wouldn't... No. No, we stopped making users manually because the user would still get created. It would just leave the case open. So no, it's physically possible. We do not make users manually. Mike: Nice. Michelle Wolf: Yeah. Mike: That warms my heart to know that. Well, it's always, you build the coolest solution and then the process goes around. And I remember having a manager tell me that. He's like, "Nobody's going to use Salesforce as long as they can put orders in on spreadsheets." Michelle Wolf: That's fair. Mike: Yeah, that was the truth. So the opposite of that, do you have an offboarding process? Is it like a similar Flow where if an employee decides to leave, does somebody create a case and that triggers your team to shut down the license? Michelle Wolf: Yeah. We actually built in a deactivate. We called it remove because our business calls it remove users, but it deactivates the user. When you choose that option in the flow, you get to use the lookup to deactivate the user. And then we also had a freeze, and I call it thaw instead of unfreeze. So we had a freeze and thaw process. Mike: I like that. That's awesome. Michelle Wolf: So yeah, we did a freeze and thaw process and we also had an update permission. So if somebody was changing teams, so somebody got promoted from customer service to sales, you can just put in the change request and once it's approved, off it goes. Mike: See, that's what differentiates what you built from everything else, because nine times out of 10, an admin will, "Okay, I'm going to build an onboarding thing." You're building a user management system, and you have the organization bought into it. "This is how we do this for this system." And it keeps a chain of custody, and it keeps a nice record for you as well. Especially the permissions update stuff, that's got to be handy. Are you ever asked to report out people whose permissions have changed or, for whatever reason? Michelle Wolf: I don't know that we were ever asked to report that. And the company that I built this for actually had an Apex that did all of the permission and groups assignments. It was built out with metadata and permissions because when they built that out, user access policies didn't exist. Mike: Gotcha. Michelle Wolf: So when I built it for my demo, I'm not a developer, I'm not going to build out that Apex solution, but I used the user access policies for providing those permissions and assignments for that portion of the automation and access. Mike: Yeah. I have a million more questions. I think one that people would ask. Usernames. So I don't need to know usernames, but did you put in a way to make sure that the person submitting the case doesn't have to think about the username and it's still for- Michelle Wolf: Yes. Mike: Okay. Michelle Wolf: Yeah. So I use a [inaudible 00:32:21]. Mike: So you knew the answer. Michelle Wolf: I did. Mike: It took me longer to put the question together and you're like, "I already know the answer, Mike. Spit it out." Michelle Wolf: So they only gave us their first and last name, their email address, and then the identifier that we used for our SSO or Federation ID, and then what team they belonged to. So we knew what permissions and then who their manager was so we could get the right approval. Everything else was done through the formulas. And that's the tricky part. That is one of the ways in which the automation can fail. And it's the unique username and the unique alias. Because when you're on the new user record, Salesforce does all that magic for you. They do all the hardlifting to figure it out. And so instead of a one in four, because it uses the first initial, the first name, and the first four of the last names, so instead of a one in four, I made it a two and four for the alias to increase my chances of not having a duplicate. Mike: Right, because there could be a lot of Susan Smiths out there. Michelle Wolf: Exactly. Mike: Yeah. Michelle Wolf: And so what I did was I also built in on a fault path, essentially a loop. So if it failed, I would add a digit to the end and then have it try again. Mike: Oh. Would it incremental the digit? Michelle Wolf: Yes. Yeah. Mike: Well, that's smart. Michelle Wolf: And that way I could... I'd still have a chance that it's going to not work. Mike: I mean, if that poor guy hired 20 John Smiths, we're going to work that formula. Michelle Wolf: To the bone, for sure. I used Flow. I used the power of Flow to really be as hands-off as possible with it, up to and including, we wanted to keep a minimum of 10 licenses available. We always wanted 10 emergency licenses available. So before I create a user, I have it go get my org data to make sure I have 10 Salesforce licenses at least available. And if I don't, then it won't make the user. It just leaves a note on the case and leaves the case open. Mike: Saying, "You're at your minimum of 10." Michelle Wolf: Yeah. So we built in some of those custom safeguards that were special to us. We wanted that. So we put that customization in there. Mike: I like that. That's really cool. Michelle, you've enlightened me. I'm excited. I want to go build a Flow and onboard people and make perm sets a thing. I don't know. I feel like you probably have some solid time with an AI writing a lot of formulas. Michelle Wolf: Yes. Copilot and I got real buddy-buddy. Mike: Yeah. I mean, AI is really good at writing formulas, so thank goodness for that, right? Michelle Wolf: Yes, yes. I can do them, but those complex ones were a little on the edge of my capability. Mike: Oh, yeah. I can do with validation rules and stuff, and it requires parens. Once we get past one set of parens, I'm done. I'm cooked. Michelle Wolf: Yeah. Mike: That's it. Nope. I bow out early. I can't swim in the deep end of that pool. And I've seen people work with 15 nested statements. I'm like, "I'm exhausted reading this. How do you even know what it's doing?" Michelle Wolf: Right. Mike: Well, thanks so much for coming on the podcast and telling us about this. I think it's really cool. I hope you have an opportunity to share that onboarding Flow with more people and present it at more user groups. Michelle Wolf: I had a suggestion to make it a hands-on training. Mike: Yeah, it sounds cool. Michelle Wolf: Yeah. Mike: That sounds really cool. Maybe you should suggest it for TDX next year. Michelle Wolf: Yeah. Mike: Because that's a very technical, hands-on... People would love that. Michelle Wolf: Yeah. Well, they didn't pick it up this year, but I'm not sure I sold it very well. So we'll try next year. Mike: I mean, it's all in how you sell it sometimes. Michelle Wolf: Yeah. Mike: And also whether or not places have space for stuff like that. Not every track gets certain kinds of... It's a thing. That's a whole other rabbit hole within a rabbit hole that we could go to. I could do a whole series of podcasts on it, and nobody would listen to it, but I would think it would be interesting. And five people who write submissions would. Michelle Wolf: Yeah. Mike: Awesome. Well, thanks so much for being on the podcast. Michelle Wolf: Thank you so much, Mike. It was a pleasure. Mike: A big thank you to Michelle Wolf for sharing how she turned user onboarding into a thoughtful, scalable Salesforce process. My takeaway for admins is simple. Flow can automate the clicks, but your understanding of approvals, access, permissions, and business context is what makes the process work. Now be sure to subscribe to the Salesforce Admins Podcast and share this episode with somebody who is ready to get their user management out of their inbox and into Salesforce. Until next time, we'll see you in the cloud.
  • Solving Sharing Mysteries with Setup with Agentforce 30.07.2026 19min
    Today on the Salesforce Admins Podcast, we talk to Nikita Kothari, Senior Member of the Technical Staff at Salesforce.  Join us as we chat about using Setup with Agentforce to understand and manage record access. You should subscribe for the full episode, but here are a few takeaways from our conversation with Nikita Kothari. Setup with Agentforce simplifies sharing Why can't I see this record? It's a simple question but, as any admin knows, finding an answer can get complicated quickly. If you've ever found yourself digging through Setup pages and running SOQL queries to troubleshoot permissions and record access issues, this episode is for you. This week, I'm talking to Nikita Kothari, a Senior Member of the Technical Staff at Salesforce. She's here to tell us how Setup with Agentforce can help solve sharing mysteries. Using natural language questions, admins can trace access across org-wide defaults, role hierarchies, sharing rules, groups, and manual shares to figure out what's really going on. Troubleshooting permissions and record access issues As Nikita explains, permissions and record access issues are so complicated because they are affected by many overlapping configuration settings. Small changes can accumulate over time, especially in a reorg. Setup with Agentforce was built to help you detangle these issues with simple natural language prompts. You can put your questions about permissions and record access to an agent, instead of having to wade through 1,300 pages of Setup to figure it out on your own. Once you've got a handle on what the problem is, you can use Setup with Agentforce to help you implement changes and get everything sorted. And it's built with trust in mind: every write action requires your explicit approval, the agent is bounded by your permissions, and every configuration change is captured in the Setup Audit Trail. Plan permissions for your org If you're trying to figure out where to get started, Nikita recommends starting small. "It's very difficult to go back and fix something," she says, "so I would highly recommend trying any changes in a sandbox with the minimum set of users to see if it is working as expected or not."  And because Setup with Agentforce makes looking at permissions and record access so much easier, Nikita recommends taking advantage of it to conduct a monthly permissions review. Again, these issues accumulate over time, so an ounce of prevention is truly worth a pound of cure. Make sure to listen to my full conversation with Nikita for more on Setup with Agentforce and how to get sharing straightened out in your org. And don't forget to subscribe for more episodes of the Salesforce Admins Podcast. Podcast swag Salesforce Admins on the Trailhead Store Learn more Salesforce Admins Blog Post: Mastering Your Org's Sharing Configuration with Setup with Agentforce Salesforce Admins Blog Post: 5 Use Cases To Get Started With Setup with Agentforce Salesforce Admins Podcast Episode: Setup with Agentforce Makes Salesforce Admin Tasks Easier Admin Trailblazers Group Admin Trailblazers Community Group Social Nikita on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript Mike Gerholdt: Today on the Salesforce Admins Podcast, we're talking with Nikita Kothari, Senior Member of the Technical Staff here at Salesforce, about using Setup with Agentforce to understand and manage record access. Sharing can be one of those invisible parts of the platform until someone can see a record they shouldn't or can't see one they need to. Nikita explains how admins can use natural language questions to trace access across org-wide defaults, role hierarchies, sharing, rules, groups, and manual shares. We also discuss why validation, permissions, testing, and human approval remain essential when AI helps make configuration changes. So give this episode a listen, click that subscribe button, maybe share it with another Salesforce admin who's ever asked, "Why can this user see this record?" Let's get Nikita on the podcast. So Nikita, welcome to the podcast. Nikita Kothari: Thank you, Mike. It is amazing to be here. I'm from the engineering team, so you'll get my lot of perspective on how we are building Setup with Agentforce on sharing. Mike Gerholdt: Yeah, that's exactly what I wanted to talk about. Let's first get a little acquainted with you. What do you do at Salesforce, and what are some of the things that you've worked on? Nikita Kothari: So it's been close to two years I'm working with Salesforce. And currently, I'm working with access control and sharing space. What pulled me in is the realization that sharing is one of those invisible infrastructure layer. When it works, nobody thinks about it, but when it breaks, it actually breaks the customer trust. And you know how customer-centric Salesforce is, its number one priority is trust. So there is lot of critical issues that we are dealing with and we are trying to make the sharing as the best place for the admins. And we love our admins and we are trying to make things better for them. Mike Gerholdt: I love our admins too. I used to be one for a while. I'd like to still think I am, but we'll see. Well, let's get into it. So I read your article and I'll link to that in the show notes. Tell me, I mean, before Setup with Agentforce, what did an admin have to do to answer a question of, why can this user see this opportunity and this user not? Nikita Kothari: Oh, good question. So it's the simplest way of dealing with solving the sharing's toughest problems. So just to enable the Agentforce, you don't have to do anything. It comes along with the Agentforce. So go to the setup page, search for the Agentforce agent and enable your Setup with Agentforce, and then you can start writing those questions. You don't have to know anything beforehand, that's the best part of the Agentforce setup. And sharing is the challenging domain, I won't deny that. It is very, very complex. So answering even the simplest question that you ask, like, "Who this person is having access for this thing," it requires to look into a lot of different domains like OWD, role hierarchy, sharing rules, sharing groups, manual shares, to see which layer actually give that access to that particular user. And looking that information, sometimes it's easier with the UI, but most of the time user has to run lots of SQL queries to get the correct answer. And previously, admin was spending hours of work and sometimes even the afternoons just to deal with that single questions. And with Setup with Agentforce, it just a minute of work. You just give prompt to your chatbots and it'll give you the correct answer within seconds. Mike Gerholdt: Yeah. I mean, boy, it used to be a lot of archeological digging. I think you called it that in the article. I know I used to have to feel like I was going through a checkbox, but tell me, I mean, walk us through a real investigation where an admin discovers that a user can see a record, they probably shouldn't. How would they use Setup with Agentforce to trace where that access came from? Nikita Kothari: Yeah, great question. So while building these actions, we particularly divide it into two different segments. First segment is the read action and the second segment is the write action. Just to keep it, things untangled, read actions will help you to investigate. When you ask a question like, "Why Nikita has access for these things?" So our agent will go into the background, it will do all kinds of research and it will come up with the best answer. "Okay, Nikita is part of this group, and these groups provide the access to this particular record." And what a write action on the hand will do, it will help you to solve that problem. Now you know Nikita is part of the particular group. You can go ahead and ask your write action, "Can you please remove Nikita from this group?" And your write action will help you to remove that particular user from that group and boom, your problem is solved within a few minutes. It's reliable, it's fast, and I'm sure admin can save a lot of time with these two things. And you don't need to know which action or which thing you need. You just write the plain natural language and our LLM will be able to guess where to navigate and how to solve that problem. Mike Gerholdt: Yeah. No, I hear you. I think you walked us through what a good sharing investigation looks like. But for you, is there a sequence admins should follow so that they don't just jump straight to changing configuration? Nikita Kothari: I would say I would highly recommend admin to start playing with the read action. There is no particular sequence, I would say, but mostly how the sharing is defined is like first we have the OWD, which provides the base access to the records and to the objects. And then comes the role hierarchy, then comes sharing rules, then we have public groups and queue and we have the manual shares. So at each level, sharing opens up the door for more access. So if you're going below the hierarchy, sharing will provide more and more access to the user. And if you want to close that access, it's not easier that one sharing rule will open up the access and then you create another sharing rule to close the access. It's not how it works. So in that case, you need to spend a strategic amount of time thinking how you can revoke that access. And sharing is accumulation of the small, small, small decisions over the time. Sometimes adding someone to the group, for the reorg, you have to do lot of things with the sharing, and every decision gets compound. So I highly recommend our admins to at least spend 30 minutes a month to refresh and reanalyze their sharing configuration to avoid the future problem. So this is basically the flow looks like, but I would say there is any of sequencing which admins should follow. It's pretty much open and admin can ask any question to our agent. Mike Gerholdt: No, I think you're right. I mean, Setup with Agentforce can do a lot in terms of explaining the configuration and then help change it. I think you really touched on that last answer of just slowing down for a second, verifying what the answer is to make sure that you're staying in control. My question to you would be, how should an admin validate what the agent tells them? Nikita Kothari: Oh, that's a good question. So for the read action, the information, we have mostly the links added to our prompts. We call it as a clickable link. So if investigation is saying that Nikita is part of this group, actually, there is a link of that group. So you can go to that group by clicking on that link, and you can actually see I'm a part of that group if you want to re-verify the stuff. So, that will give you more confidence that you know how admin is investigating the information or if admin is saying, "Nikita is part of the sharing rule and you'll have the link for the sharing rule." So you can actually go and verify whether that sharing rule contains the group or the users where it is providing that access. And with the write action, I think more critical is the right action. I mean, you don't want somebody, AI is coming to your system and randomly making changes to your system. So to do that, we have the validation layers. The first validation we generally come up with is for every write action, we explicitly ask for the approval, approval from the person who is making the changes. And we also have the permission boundaries, and if particular user doesn't have the permission to edit OWD, the agent won't be able to edit OWD for that person. And then the last part is the accountability. Every change we are logging into the setup audit trail saying that whether the AI agent did it or actual person did it. And then admin can verify it, whatever changes is made by the AI agent are trustable or not. So we will always advise admin to go and do as much as possible testing on the sandbox before making changes into the production. And another backup system is the Einstein Trust layer. We always say trust is our number one priority. So, Salesforce has built trust everywhere to make sure that we are not blindly making any changes, and as this is a very, very critical domain to our customers. Mike Gerholdt: No, that's great. You talked a lot about sharing, and I always feel like making a change with sharing, you want to make sure that you're doing it right. In your opinion, what is the most important thing an admin should review before making a sharing change? Nikita Kothari: So I would say, as I said before, we have some of the steps that I also wrote in my blog, that we have OWD sharing rule, rule hierarchy, and everything opens up the more access. So to close that access, it's very difficult to go back and fix something. So, I would highly recommend whenever our admins are making the changes, try it out first thing on the sandbox if it is working as expected or not. Or have some verification system or another set of eyes whenever you create some rule hierarchy or you're providing some access to the rule, rather than giving access to all of the user, first try with the minimal set of the user. Try with the one user and see if that user are getting right access to the right record. Because even if you fail to provide a single user a wrong access, that means that you're leaking your data. So having those, another, just starting with a small and then going into the bigger and bigger data, that would really help admin to build the reliable system. Mike Gerholdt: Yeah, absolutely. I think it can do a lot and I've seen it do a lot, but what is something that Setup with Agentforce can help with today that maybe admins may not realize? Nikita Kothari: I feel like still adoption, it's tricky because people are quite a lot thinking that Setup with Agentforce will replace their job. But I would say rather than replacing, it will provide you a lot of capabilities and it will remove a lot of overhead from your day-to-day work life, rather than going and looking into the SQLs or doing everything by yourself, just give it a try. And then you can see how much opportunity it is opening up for you to save time. And that time you can actually use for building a more structural, and because structure mattered a lot when it comes for sharing. How your roles are getting access or how your groups are getting access. And if you're just blindly following the steps and not thinking much, then you are in a trouble. So you can spend more time and thinking about, how can you better make a structure for your organization? And you can get more time to think about your business. And I feel like most of the troubleshooting cases we have covered into the Setup with Agentforce flow. Yeah. Mike Gerholdt: Yeah. You mentioned a lot, admins should get out and use it and try it, and I'm a big proponent of that. So I'll end on this question. What for you is one kind of low risk question that an admin could ask Setup with Agentforce today to better understand their sharing configuration? Nikita Kothari: I think my one of the favorite action among all of it is record access, to ask why this person is having access to this record. And you see how much it can do, it will give you the whole list of the OWD configuration for that particular record, or it will look for the sharing role, it will look for the group membership, it will look for the manual shares. And it will do all kind of investigation for you just when you type a one single natural language to your agent. So you can always think about someone which is having more knowledge about the setup. It's sitting with you and helping you to deal with all of the setup configuration. Because setup, again, we have like 1,300 setup pages, which is lot. And going through all and learning the capabilities of each setup action, it's difficult. So, that's why we built the Setup with Agentforce, which will give you the capability that you don't have to learn everything on the go. And you can start asking question to our bot. If it won't be able to answer, it will guide you in the right direction to help and analyze your queries or your concerns. Mike Gerholdt: Yeah. I am so glad that we have Setup with Agentforce. I feel like I could have used it 20 years ago. I know I had a lot of questions and would have to dig through my notes on org-wide and sharing and group sharing and all kinds of that stuff. So, I appreciate it. And I appreciate the article and you taking time out of your day to talk to admins and share your knowledge about sharing and setup and how we can do things better. Nikita Kothari: Yeah. I think admins are always on the top of our list. I would love to hear from our admins how they like this Setup with Agentforce, specifically with the sharing, how it is helping them or what they are looking forward to, because I feel like most of our critical projects and best solution came up with the admin feedback. And we really want to make admin life easier. We always have meetings internally, our engineering team, our product is always so much focused about thinking about our admins, thinking about the newer way to introduce some more features to make their lives easier so that they can focus on building a reliable solution. So, it was great talking to you. Mike Gerholdt: Yeah, no, I'm glad you could share your knowledge with us today. Thanks so much. Nikita Kothari: Yeah, thank you so much. And one more thing, we will be at Dreamforce. Larry Sherrill is our Product Manager. They're having a lot to share at Dreamforce. So, feel free to stop at user access booth. I'll be there too, so come and say hi and share your feedback. We would love to hear back from you. And we keep making a lot of progress on Setup with Agentforce, so stay tuned, follow our blogs, and it will be something will be really helpful in future for you guys. Thank you so much. Mike Gerholdt: Thanks again to Nikita for helping us understand how Setup with Agentforce can make sharing investigations faster without taking judgment out of the Salesforce admin's hand. And the takeaway is just really simple, use AI to uncover the source of access, validate what it tells you, and test changes carefully before they reach production. Now, if you enjoyed this episode, and I bet you did, I hope you did, you should subscribe to the Salesforce Admins Podcast. Share this episode maybe with your team, fellow team, user group. Oh, I like that, if you'd share it with the user group, that would be awesome. And then, how about this? Start with one low risk question about your own org sharing configuration and ask that to Setup with Agentforce. Until next time, we'll see you in the cloud.
  • Salesforce Superbadge Cohorts Build Skills Through Community 23.07.2026 26min
    Today on the Salesforce Admins Podcast, we talk to Jean Velonis, Senior Technical Program Manager at Salesforce. Join us as we chat about the new Superbadge Cohort Learning pilot program and how you can get involved. You should subscribe for the full episode, but here are a few takeaways from our conversation with Jean Velonis. Improvements to Superbadges I have to confess, I've always found Superbadges to be a little intimidating. They're locked behind requirements, without clear step-by-step instructions for how to work towards them. That's why I sat down with Jean Velonis, a Senior Technical Program Manager working to improve the Superbadge experience. The first thing Jean wants you to know is that they've overhauled the Superbadge UI. Instead of being locked behind a list of requirements, Superbadges now have a Recommended Learning section. These Trailhead modules and badges are organized into units, giving you a much clearer path to work towards your goal. What is the Superbadge Cohort Learning pilot program? In addition to the UI changes, Jean and her team are launching a new pilot program called Superbadge Cohort Learning. These sessions let you connect with other learners and subject matter experts to work towards a Superbadge together, guided by a facilitator. For now, the pilot program is focused on two of the most popular Superbadges. For admins, the Data Quality and Validation Superbadge gives you the knowledge you need to prep your org for AI. And if you're a dev or looking to improve your coding skills, there will also be groups for the Apex Callouts Superbadge. They're running both in-person and virtual versions of these sessions, so look out for them at a Dreamin' event or community group near you. Volunteer as a subject matter expert or facilitator If you already have these Superbadges, Jean highly recommends volunteering as a subject matter expert or a facilitator. When you're working with new learners, you'll run into questions and situations that deepen your understanding of the topic more than you ever thought possible. The other thing about students is that they keep learning. Teaching is an incredible opportunity to make strong connections that will last throughout your career. As Jean explains, two of her former students are now her go-to people when she has code or Flow questions. Make sure to listen to the full episode for more from Jean about the Superbadge Cohort Learning pilot program. And make sure you're subscribed to the Salesforce Admins Podcast to catch us in your feed every Thursday. Podcast swag Salesforce Admins on the Trailhead Store Learn more Sign up to be a subject matter expert or facilitator: Superbadge Cohort Learning Pilot Session Salesforce 360 Blog Post: How to Stand Out in the AI Era with Superbadges Admin Trailblazers Group Admin Trailblazers Community Group Social Jean on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full Transcript Mike: This week on the Salesforce Admins Podcast, I'm joined by Jean Velonis to talk about the Superbadge Cohort Learning Pilot and what happens when admins stop learning alone and start solving problems together. We're going to dig into these cohorts and how they bring experts, beginners, and everyone together in the same room to work through real challenges, build confidence, and get comfortable being uncomfortable. Because for Salesforce admins, knowing how to troubleshoot, test, fail safely, and ask better questions matters just as much as knowing where to click. And as AI and agents become part of everyday platform work, well, those fundamental skills help admins validate what is correct, keep data reliable, and make sure that the platform reflects what the business actually needs. So listen in, subscribe and share this episode with an admin who learns best by rolling up their sleeves and figuring it out. Let's get Jean on the podcast. So Jean, welcome to the podcast. Jean Velonis: Thank you so much for having me. I think this is the second time I've been here, but it's been a while. Mike: I know. Well, when you do the podcast for almost 14 years now, I try not to have guests back, only if they're important like yourself. Jean Velonis: Ooh, thank you. Mike: We were Salesforce MVPs together a hundred years ago when the internet was still tubes and wires, and now we're both at Salesforce. And you're on, I would call, what, the curriculum side, the learning side? Jean Velonis: Yeah, I would categorize that. It's more Trailhead, right? So long story short, certification was my jam for so long, and superbadges were part of that. But over the last couple of years, we've decoupled from certification. We're still with Trailhead and we're still considered an assessment, but we don't have all the guardrails of certification on us anymore, which is really exciting. Mike: Gotcha. And just for reference, if anybody thinks they might have met Jean at a Dreaming event or a Salesforce event, you tend to usually have purple hair and a bedazzled Ranger hat. Is that an accurate description? Jean Velonis: These are facts. These are facts. I've had purple hair probably since six months of coming into Salesforce. And if anybody knows the famous Chris Duarte out there, she taught me everything I know about bedazzling. So I made a Ranger hat. Mike: Yeah. A lot of people bedazzle now because of her. Jean Velonis: Yes. Mike: Well, let's talk about this new Superbadge cohort learning pilot that you've kicked off because I think you're trying to bring the best of both worlds together. Jean Velonis: Absolutely. This isn't a new concept either. I'll just throw that out there. We had some amazing trailblazers before the pandemic and even through the pandemic doing Salesforce Saturdays or Salesforce Sundays and they would get together in person or virtually and work on Trailhead. So this is kind of piggybacking off that concept and really bringing some of the community magic to superbadges because I think we can all look at a superbadge and be like, oh, that's kind of intimidating. There's no step-by-step instructions. This looks really hard. There's multiple steps to it, and that just looks hard and I don't want to do it. But the cohort learning brings a facilitator, like a community group leader or a Dreamin event person to come in and help bring people together virtually or in person and work on a Superbadge together. And we've been running a couple of pilots of these. We did one at TDX and WITness Success in Indi. And it's been really successful in person just because you can pair experts and newbies together at a table and make people really uncomfortable, and then they start talking to each other and learning from each other. And I think that's what gets really excited about doing this cohort learning. And then we've done a couple of virtual events as well where we've brought community group leaders, kind of like train the trainer of like, here's how you should run this virtually to be successful, because that virtual is a little bit different beast. It's really easy to hide and stay on mute and turn your camera off where we really try and get people excited to share their skillset with each other. Mike: Yeah. No hiding in the dark corners. So I really like the idea of this. I've always really enjoyed Trailhead because I'm the type of learner that likes to do it at my own pace. Sometimes I even crazily go back and redo a badge just because I feel like if I've rushed through it, did I really learn it or was I just trying to get it done? And when I'm really trying to learn it, I really take my time. I will agree with you, I've written superbadges. I also enjoy the freedom. They're kind of like, "Here, go, do. " And you're like, "Oh yes." It's almost like the days of driver's ed when you get out from behind the desk and you finally get to drive the car in the real world. It's a little more of trying things out. So are these cohorts that you're doing now, are they open to any superbadge or are they just specific ones? Jean Velonis: That's a really good question. We looked at our whole library of Superbadges and we wanted to pick one for admins and one for developers. And that doesn't mean it's just if you have that skill set. It's more of like, here's two of the main roles we see in the community. So we have data quality and validation, which is really for anybody prepping you for this agentic ecosystem that we're in, cleaning up your org. Mike: I mean, to be honest with you, that's what we've needed to do this whole time. Even before AI, it's sweeping the floors, you know? Jean Velonis: Yeah. I mean, it's been that way for a long time. I think I made my whole Salesforce admin career of going in and cleaning up orgs, to be honest. So that was a great place for us to start. And then now we've started looking at the developer side of it and we picked Apex Callouts superbadge for all of our developers. And I was very intimidated by trying to put together a superbadge in a box for that cohort because I'm not a developer. But going through this process, I'm like, "You know what? I think I can actually do this," And that's because of all the great learning badges on Trailhead and being able to go at your own pace. Because that's a whole nother skill set for an admin to try and figure out, right? Mike: Right. I've often thought of, this is just how Mike's brain works. If I had children, I would for sure name one of them Apex because then you just gave them a shout-out. Jean Velonis: That's hilarious. I would've never thought- Mike: That's how I work. My brain today is like, "Oh yeah. Hey, did you hear you were mentioned on a Salesforce podcast?" "Of course I was. I'm an Apex Callout." Jean Velonis: I'll tell you a weird secret. I do put my children's names in superbadge content. All of us over here under the superbadge team put little- Mike: Easter eggs? Jean Velonis: Easter eggs, yeah- Mike: Yeah, I love it. Jean Velonis: ... out there. It's either in the org or it's in the content. We're all moms over here, so we would like to give our kids a shout-out. Mike: Well, I will see your Easter egg and I will call your Easter egg. In almost every admin keynote demo, we have put our pets' names. Jean Velonis: I love that. Mike: So you can go back and figure out whose pets were whom. The only time, the only exception was we had Einstein Voice rollout and my dog's name was yet to be used and we couldn't use it because it wouldn't recognize it. It was too hard to say. And so we had to go with something easy and punchy with hard consonants in it. So anyway, yes. I think there should be, I'm sure there is somewhere, a whole forum of Easter eggs found in Trailhead material. Jean Velonis: 100%. And I think that's what Trailhead is, where it's the weird, it's the hanging out, it's the learning something new, it's the being uncomfortable. Because it really is, learning can be really uncomfortable. Mike: I mean, it exposes a weakness and people don't like feeling weak. It's also the thing I always think about whenever I was doing training because you're changing something. And the person that told me how to do training gave me a very well-rounded, concise piece of advice, which is people don't like to go to work and feel stupid. And when you change something, even in a CRM, that's what that comes from. And people don't like to feel stupid. And I feel that way. You change something, you're like, "Oh, this was here yesterday. Why isn't it here?" And you blame yourself and that's not the point. You do a lot of training. So let's go through just some scenarios of I'm a new Salesforce admin. I stumbled across this podcast. Also, hello. You have a lot of episodes to catch up on. That's okay. You have a lot of time. What should they do to prepare to come to one of these learning cohorts? Jean Velonis: I mean, the easy answer is get on Trailhead and start earning badges, that's number one. Step two is take a look at the new look and feel for superbadges and that will bring you to our recommended learning. It used to be required to unlock the superbadge, but we've just now come onto what I would say the Trailhead UI. Superbadges are put into these units now where the first unit is like, let's get ready. Let's get your developer org. Let's do the recommended learning. Let's connect it to your superbadge now. That's all a little bit different than what we used to do with superbadges. You had to unlock it and then you had to go down all the way to the bottom of the page to hook up your org. Now it looks like a regular module or badge, which is nice because as somebody who struggles with reading and keeping my place on Trailhead, this new guy is really going to help with that. But also doing the recommended learning I think is key even though it's unlocked now and you don't have to do it. I will tell you I am the first person to start doing something and being like, "Oh, I have no idea what I'm doing with this. Maybe I should have done-" Mike: I should have done those recommended modules. Jean Velonis: Yes. And then I will have to go back and learn and figure things out. I did that with the prompt template superbadge. I thought I knew what I was doing. Mike: No. Jean Velonis: I did not. And that's falling, that's failing forward. That's realizing I don't know what I'm doing. Let me go figure this out and then come back to it. So I think that's step number two. Go and read through the superbadges, look at them, look at the recommended learning. And then if you see that there is a Dreamin event or a community group doing one of these superbadges, join them. Even if you've done the superbadge, that's okay. You can go help the other people that are there. Mike: Oh, I almost think that would be the next best thing after doing a superbadge is going and volunteering to help train. Because never will you ever learn more about something than when you have to train somebody about something or walk around the room and answer questions. You're like, "Hey, I didn't run into that when I was doing mine, but let's figure it out." And it's super fun because then you're like, "This wasn't a problem for me, but now it's a problem that I get to work through." Jean Velonis: Yeah. I mean, bringing you all the way back to SABWA. Mike: Oh, sure. Jean Velonis: Call out, Mike. I mean, geez. Yeah, that is my favorite thing to walk around, especially I live in these superbadges every day. Our team builds them. We maintain them. We have to deal with all the product changes that are very quickly changing and trying to keep up with everything. So being able to walk around the room and see how trailblazers are doing things, that not only helps me figure out, okay, here's some of the common pitfalls or where people are getting stuck and I can write some hints to help, but also maybe we don't do that in the next superbadge or maybe we call it out in a different way or let's go update the help article and call this piece out if somebody's getting stuck somewhere. So it's super helpful. But also you get to meet a ton of different people, which we do virtually every day, but it's easy to hide behind the keyboard again. And to be able to connect with somebody and see their aha moment of where they're like, "Yes, I figured this out," that's super gratifying. Mike: Oh, that's almost the time that you make a friend. Jean Velonis: A best friend. Mike: Yeah. I mean, because you're always going to be like, "Well, let's continue chatting while you work through this." And then the next thing you know, they're building Apex Callouts, and you're like, "Oh, I didn't get that far." And then they're teaching you stuff. I promise you it'll happen. Jean Velonis: It will happen. I can say 100% certainty it will happen. I have two people that I call on all the time or that I met through a conference or doing something, and I'm like, "Okay, I know this person knows code and I know this person knows flow. I'm not good at those things, but I can text or call or Slack and be like, I'm stuck." Mike: Right. So I mean, I have a thousand questions, but let's go to the opposite end of that where if you're a community member, maybe you're a user group leader or a Dreamin event person and you're like, "This sounds like a super fun thing for me to include in my agenda," What would their steps be for possibly including, I know it's in a pilot, but for including this or what's your vision for it moving forward? Jean Velonis: Yeah. We have a facilitator signup forum- Mike: Sweet. Jean Velonis: ... which I'm sure you would be happy to put that in the bio or the show notes. Mike: It is in the show notes as we speak. Jean Velonis: Perfect. But yeah, just signing up to raise your hand to be a facilitator is huge. Because I'm going to have this superbadge in a box ready very quickly for people to take to a pilot. I have two Dreamin events that are already wanting to do this in August and a community group that also wants to bring it to their local people. So signing up to be a facilitator and doing this on your own, love that. And I wish I could go to every one of them, to be honest. I looked at a couple of them and I'm like, "I might be able to make this work and just show up." But there's also a piece in that form too to sign up to be a subject matter expert and help if there's somebody locally that wants to do this. And selfishly, I put that in there that if you want to help us build superbadges, that would be awesome too. Mike: Right. And this sounds rhetorical, but it is honest. They should have probably already completed that superbadge that they want to facilitate or host. Jean Velonis: I mean, I'd advise it. And with the new UI, you can redo a superbadge. You can retake it now. So you can do the superbadge over. Mike: To refresher, because maybe you haven't done it in a while and want to see what's new. Jean Velonis: I mean, the facilitator that did WITness Success told me she still had her notes when she originally did the Apex Callouts in 2017. Mike: Wow. Jean Velonis: Right? Mike: I probably have notes from somewhere of 2017 I have nowhere. That's awesome. Jean Velonis: No, that notebook's gone. Mike: Yeah. I always think of admins listening to this and I don't want it to be a pitch session for your cohort, but this is really a neat way to get involved with the community. From all of your work, and this is just stepping out of your role and what you're doing in this superbadge cohort. Out of all of the work that you've done at Salesforce and what you create for Trailhead, what are some of the biggest themes that you run into that really, when that light bulb turns on for an admin, they suddenly just become, I don't want to say instantly become successful, but they really start to click and feel confidence and have that aha moment? Jean Velonis: I think being a Salesforce admin for such a long time, being able to fail and problem solve is probably the best skill you can have. You can learn any technical skill. I can go into a dev org and break things and figure out how products work. But if you don't know how to problem solve through something, getting to that aha moment is going to take you a long time if you're too afraid to break something. And I have broken things. And I think I've told you, I've deleted records from an org before and went, "Uh-oh, how do I get those back?" So that is one of my favorite things is to go into a playground or dev org and just break it, pull things apart, see how it works and be like, "Okay, I know where I want to go, but how do I get there? And I don't know how to get there, but if I go in and break everything, I'm going to learn a lot more than if I follow step-by-step instructions of how to do something." Mike: Right. If it works out perfect the first time. Jean Velonis: Yeah. What did you learn? Oh, I know how to do that. Okay. Well, what's next then? Mike: Do you find that you have to remind people that it's okay to fail when building and it's okay for things to not work the way you want them to the first time? Jean Velonis: Yeah. And I mean, that's how we build superbadges. I mean, we have all these SMEs and we look through different use cases and we go into an org and build it out and we're like, "Well, that's not going to work for this unit," or, "That's not going to work for this use case," or how do we find those different tasks to lead the witness basically in the challenge to get to where we want them to go, but without telling them? And you can do it 97 different ways. There's not necessarily always a right way to get there. Mike: Right. I know I've sat down. We used to have, it was Dreamforce long, long time ago. And I was paired up with Josh Birk and we were helping a customer through a situation. And it was interesting because both he and I came up with a solution. Both he and I came up with a very different path to the solution. Mine was using, at the time, Flows, and his was using some code and some triggers. And the customer's like, "But which one's right?" And we're like, "Both of them." I mean, never could you ever run into a situation where both solutions are equally correct. It's based on what you want to maintain and your knowledge. Jean Velonis: 100%. And now you also have this agentic thing that will try and tell you the right path to go and you can be like, "Well, I don't want to do it that way." And it's like, "Oh yeah, you're right. Let's try it this way." So I think even having that fundamental base of an admin or a dev is really going to serve you well in this ecosystem. So problem solving, having a foundational skill set, and then also knowing where you want to go and problem solving your way to get there. Mike: Right. So let me ask you, you've brought up agents and AI sometimes intentionally, sometimes unintentionally, but I mean, it's definitely something that it's our every day now. From your perspective as building a lot of content and in the learning space, what is the most important thing you think admins should learn about AI and agents? I Jean Velonis: I think the most important... Well, there's two. Learning when to trust that the AI is telling you the right thing and knowing how to ask the prompts and the questions. Because you may not know where you want to go, but if you have your fundamental base of the system, you can ask it the right questions to get you where you're going. And as somebody who struggles with writing content, I know where I want to go, I know what the tasks are for the superbadge. And I can say, "Okay, now help me write an error message," or, "Help me write a hint for a help article that's going to help them get unstuck." And you can ask AI that too. You're like, "Hey, I'm using this Flow element. I'm trying to go here and make this system do this. It's not working. Help me untangle this." Mike: Right. Help me. Teach me, don't tell me. Jean Velonis: That's key. Teach me, don't tell me. I don't need step by step. Mike: I do that all the time with Wordle. Don't tell me the answer, just help me figure out what this word is. I'm stuck. Jean, last question because I know you have to go. It's 2030 and the Superbadge Cohort Learning program is out of pilot. What does it look like? Jean Velonis: It looks like all of our trailblazers getting together, helping each other learn something new, experts and newbies and everybody in the middle taking something away from that hour or that day that they spent with each other and everybody having their own aha moment. Whether it's I helped somebody get unstuck or I got a new superbadge or I made a new contact or I'm out of a job and I made this whole partner and I handed them my resume, those are the things that make the community go round. Those are the things that makes learning so important. And it's okay to break things. Mike: Right. Very well. Very well said. Thank you, Jean, for being on the podcast. Jean Velonis: Thanks, Mike. Happy to be here. Mike: Big thank you to Jean Velonis for joining us and reminding us admins that getting stuck is not the end of learning, it is usually where the useful part begins. Now, whether you join a cohort, you facilitate one, or you know what, you simply just help another Salesforce admin work through a challenge, teaching and problem solving are powerful ways to strengthen your platform judgment. Be sure to subscribe to the Salesforce Admins podcast. Share this episode with somebody who is ready to learn and really earn that next aha moment. Until next time, we'll see you in the cloud.
  • How Can Admins Reduce MFA Friction in Salesforce? 16.07.2026 32min
    Today on the Salesforce Admins Podcast, we talk to Jay Hurst, Senior Vice President of Product Management, and James Ferguson, Senior Director of Product Management, at Salesforce. Join us as we chat about MFA step-up authentication and what it means for Salesforce Admins. You should subscribe for the full episode, but here are a few takeaways from our conversation with Jay Hurst and James Ferguson. Step-up authentication protects sensitive actions Starting next week, Salesforce is requiring all users to use Multi-Factor Authentication (MFA). If you're a privileged user like, for example, an admin, you'll need to use a phishing-resistant MFA. That's why I sat down with Jay Hurst, VP of Product Management, and James Ferguson, Senior Director of Product Management, to talk about why these changes are vital to protect your org's data. The first thing to know is that AI is making it easier than ever to launch targeted phishing attacks at scale. So while the MFA requirements provide a good first layer of protection, we want to make extra sure you are who you say you are before you're allowed to perform certain actions, like downloading a large number of records or running a big report. Phishing-resistant MFA uses a passkey, like a fingerprint or facial recognition biometric, to verify that it's actually you and not just someone with access to your email account. Balancing security with user friction As Jay and James acknowledge, these changes will add some friction to your users' experience. However, with the pace at which these kinds of attacks are evolving, it's more important than ever to get serious about your security posture. "We're trying to introduce a little more friction right now so that people start to think," Jay explains, "and start to build those habits of understanding when they're doing something that potentially could be considered a malicious attack, such as downloading that All Opportunities report." They're also building out compensating controls that should make things easier in the future, allowing you to trust users from a certain IP range, for example. Security is a journey, not a destination The most important thing to realize is that these requirements are about more than just jumping through some extra hoops. Phishing and man-in-the-middle attacks are growing more and more sophisticated, and you need better protections than "Well, that hasn't happened yet." Instead, James and Jay recommend viewing this as an opportunity to partner with other stakeholders in your org to develop a comprehensive security plan. As Jay says, "Security is a journey, not a destination. What is 100% secure today is not as secure tomorrow." The trick is to develop a security-focused mindset throughout your business that will protect you now and in the future. Make sure to listen to my full conversation with Jay and James for more on step-up authentication and how admins can reduce friction for users. And make sure you're subscribed to the Salesforce Admins Podcast so you never miss an episode. Podcast swag Salesforce Admins on the Trailhead Store Learn more Salesforce Admins Podcast Episode: What Are Security Essentials for Salesforce Admins? Salesforce Admins Blog Post: Securing Your Org: From Reactive to Proactive Salesforce Help Article: Prepare for the upcoming Step-up Authentication requirements on Report Actions Salesforce Help Article: Prepare for MFA Enforcement for All Employee Users Salesforce Help Article: Prepare for Phishing-Resistant MFA Enforcement for Privileged Users including Admins Salesforce Help Article: Security-Related Product Updates to the Salesforce Platform: User Identity, Data Protection, and Access Controls Admin Trailblazers Group Admin Trailblazers Community Group Social Jay on LinkedIn James on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript Mike: This week on the Salesforce Admins Podcast, we're talking with Jay Hurst and James Ferguson from Salesforce Product Management about MFA step-up authentication and what it means for Salesforce admins. As you know, security isn't just a front-door login decision anymore. It's about protecting sensitive actions, understanding risk, and designing systems users can trust. So Jay and James are going to help us unpack phishing-resistant MFA, compensating controls, IP ranges, SSO, and why these changes matter in a world where data, automation and AI are all working together. For us Salesforce admins, this is a chance to think beyond features and really look at how we steward the entire system. So listen in, click that Subscribe button, and of course I would love if you could share it with fellow Salesforce admins or, hey, you know what? Let's make some friends in that security team. So with that, let's get Jay and James on the podcast. So Jay and James, welcome to the podcast. Jay Hurst: Thanks for having us, Mike. James Ferguson: Great to be here. Mike: Absolutely. Jay, let's start off with you. We kind of want to get to know a little bit about you, and James, we'll call on you second, but before we get into our topic today, can you just tell me a little bit about how you got to Salesforce and what you do? Jay Hurst: Sure, yeah. So I have been with Salesforce for almost 22 years now. I started in our customer support department, one of the first 12 phone support reps here at Salesforce. Did that for a couple years and helped found our Tier 3 organization in support. Eventually moved over to our customer-centric engineering department, stayed in there for a while. And then in 2012, had an opportunity to join the product management group for platform, and I moved over and ran a team called Force.com Canvas. And for the last, I guess, 12-ish years now, I've been kind of weaving my way upwards through platform. Currently, I lead our platform services subcloud, so all of the core foundational pieces of platform that you might think of are schema and metadata, APIs, eventing systems, connectivity systems, and also our identity area, which is what brings us here today to talk about MFA. Mike: Yeah. Boy, flashback. You called it the Force.com platform. Jay Hurst: Well, that's what it was called back then. Mike: I know. I know. Jay Hurst: And I can't remember all of the names we've had for it. Mike: Oh, that's okay. I'm sure there's a website that tracks all of them. Jay Hurst: I'm sure there is. Mike: James, fill us in. How'd you get to Salesforce, and what do you do here? James Ferguson: Well, I am, I guess compared to Jay, one of the newer members of the team. I've only been at Salesforce for about 16 and a half years, almost 17 years. Pretty much entirely on the platform product management side, working on various things people know and love like sharing and big objects and event monitoring and those things. And most recently I've taken over responsibility for the identity product team, responsible for all the login and auth and SSO and all of the wonderful things we'll talk about today. Mike: Oh, wow. Okay. So then just to be clear, I'm actually the newest person on this call. I've only been at Salesforce for a little over 12 years now, so I guess I still have my rookie stripes. Jay Hurst: Combined we're almost at 40, or just over 40. Mike: Yeah, combined. We almost get our AARP discount, right? Jay Hurst: Yeah, exactly. Mike: Jay, let's kick off. I know I did a podcast ... and I'll link back to it ... not that long ago with Laura Pelke talking about some of the new things that were coming out, and of course security is always big on admins' mind. She did a wonderful job of explaining step-up authentication to me, which was basically the airport analogy of you have to show your ID to get in and then you have to show your boarding pass to get onto the plane. I thought that really made sense to me, but let's talk about the new authentication that's coming out, if you call it that, and the new step-up concerns that Salesforce admins have. Jay Hurst: Sure. So I think as we move into the continued proliferation of agents and AI across the industry, security is obviously top of mind for a lot of our customers and for Salesforce as well, specifically because we have to help protect our customers. And so when we're thinking of that and how we ensure our customers' data is protected, with step-up authentication, it's really focused around in that same analogy, making sure you're providing your boarding pass at the right times when you're doing things. So just like you need to show your boarding pass when you go through the TSA gate and when you're on the plane and probably to the gate agent after you're on the plane, when you're doing certain things within Salesforce, we want to make sure you are who you actually are and your session hasn't been compromised. So when you're doing certain higher sensitivity-type actions such as I want to download 10,000 records out of my system, maybe run a report, putting that end user through another verification of, "Hey, is this actually you? Prove it with your step-up," so that we have that confidence that we can release the records. And so this kind of helps prevent some of those man-in-the-middle phishing attacks where somebody gets you to log in and then steals your credentials or steals your session in the background. So it's kind of that second or third or fourth level of protection in the runtime. Mike: Wow. James Ferguson: I think that's an important shift that's worth calling out, because it's no longer about just putting a stronger lock on the front door and making sure somebody has better passwords, or even the later stuff, the more recent stuff with verification. But it's when sensitive things happen, we need to do a little extra even once you're inside the airport, if we want to continue that analogy. And so it's a shift from that front door to moving forward. Mike: Yeah. James, help me understand that a little bit more, because I think one of the things that admins always fight is user friction. How hard is it to do something? And now we're introducing something when it could disrupt their flow of work, but it's for a good reason. James Ferguson: Exactly. I would say that we are constantly balancing that. We're constantly balancing the need for security with the friction it does. And so we aren't expecting to do every click, for example, but just when you're exporting data from a report, which is potentially pulling a large amount of data out, we want to make extra sure. We're looking at some other things in the future around maybe when you're an admin changing some security configurations, we want to make sure you are who you are. And frankly, you see this more and more even in consumer websites where sometimes you're asked. If you're going to change a phone number, change a thing, you need to go back and sort of double-proof who you are. But it is a trade-off. It is a trade-off. Mike: Yeah. It's like once you're logged in, it's, "Oh, if you're going to change." I was trying to order tacos the other day through an app and I needed to update my credit card. And then right after I did that, they're like, "And you need to put your password back in." I'm assuming that was kind of the same situation. James Ferguson: Kind of the same situation. Jay Hurst: Yeah, exactly. Exactly. Yeah. And the other thing I'll add to this too is on the friction point. We always have to balance that. Like James said, we don't want people to become overly frustrated and not want to use Salesforce because it has too much friction. But the reality is over the last 20 years, we've edged so far on the line of not causing any friction that we've led admins down the path of not having that understanding of what their users are doing, and really not getting into that proper security-conscious mode. So we're trying to rubber band a little bit back on the other side, introduce a little more friction right now, so that people start to think and start to build those habits of understanding when they're doing something that potentially could be considered a malicious attack, such as downloading that all-opportunities report. So starting to get customers to think through that while we are continuing to build out what we call compensating control. So the end goal here is not to provide friction and it's not to force you to do these one-time passwords for everything you need to do in the system. It's to give admins that layered capability of saying, "Well, if I have these five or six different controls I can put into place, then they can kind of compensate for one another." So where the most friction might be having to open up your email to get that one-time password to do the step-up, maybe we can compensate that through things like having a trusted IP range or already having a phishing-resistant authentication put in, or other controls that we will layer in. So we ultimately get to a posture where the admin can both reduce friction while choosing the proper set of controls for their needs. Mike: Yeah. No, that makes sense. You mentioned phishing-resistant MFA. Can you help me explain that if somebody's never heard that before? Jay Hurst: Yeah. So maybe I'm going to try and wiggle this airport analogy in. If we think way back in the day when you had your IDs, before REAL IDs and all of this, you didn't actually have good authentication on them. You might have a really bad picture, or in some cases IDs didn't have any pictures on them. They just had your name and your information, but they were accepted. Now, the problem with that is anybody could steal it if it doesn't have your picture, and they can pretend to be you. So phishing-resistant MFA is kind of that same thing. Where a normal MFA might be a one-time password on your phone where you get that push notification that says, "Hey, your code is 123456, enter that code in," that's great because it means you have to have your phone in order to get that one-time password, but it's not as secure because it's sent over SMS. It doesn't really verify that you are who you say you are. It's only that you have access to that phone. Phishing-resistant adds another layer on top of that, so it's not just over SMS or in an app. It would be through what are called passkeys or other more cryptographically secure passes. So think of your face ID, your touch ID, some of those passkey-type implementations that you might see, where it's not just getting a code, but you have to unlock a vault that has your information in it and then you provide that information out. So it's taking it from that ID that anybody can use if they just happen to steal your wallet into more of a REAL ID that also has some biometrics attached to it. So you can actually guarantee it's not just that you have the thing, but you have the thing and you are the person that should have the thing that identifies you. And so that's what we're implementing today that's starting to roll out tomorrow in production. We've already started pushing it into sandbox for admins where we want all of our administrative users across the system to enroll and use these phishing-resistant MFA capabilities, so that they're more secure. Mike: Yeah. I never even thought of that. All the time there's apps I log into and they send me a one-time passcode and I'm like, "Well, of course I have access to it." Never did I think that, "Oh, what if somebody already has access to my email, requests that code, and now they're essentially spoofing me?" And it never dawned on me until you think of, well, they're not really verifying that it's you, Mike. They're just verifying that whoever requested that code also has access to your inbox. And you're like, "Oh." Jay Hurst: Exactly. And that may not be a nice person. Mike: Right. So James, what are some questions that admins are asking online that we can kind of help answer for them, or equip them for when they get this rolled out to them? James Ferguson: They're certainly asking questions about phishing-resistant MFA versus regular MFA and the different sort of authenticators that are out there. I'll shift this around a bit. One of the things they aren't asking about, it's actually something that Jay mentioned in passing, which is the alternate controls. And for things like step-up, if you have login IP ranges on the org or on the user profile, or there's some session settings which force you to always be coming from the same IP address in your session, which is the case for most of us who are at a laptop at work or whatever it is. Those avoid step-up entirely because we have more certainty about who you are and where you're coming from. If your session's bouncing between Eastern Europe and Middle East and North Carolina and keeps hopping around, we start worrying more. So you can do some things around IP ranges, which takes that friction away from the user altogether, and so those are some of the things that I would encourage admins to look into. Now, sometimes it doesn't work because of mobile providers or other network infrastructure, but it's also potentially a low-calorie way of really sort of avoiding at least the step-up part. They'll still have the MFA requirements. Jay Hurst: And one thing I'll add to that. When we add these types of controls to ... admins are human like the rest of us and we always want to make it as frictionless and easy as possible, but we don't want to trade off the security for it. So IP ranges specifically have been a little bit of our bane for the last six months, because we have a lot of customers who have said, "Well, I will just put in the entire internet range of IPs and go 000 to 255, 255, 255, 255. And then no matter where I'm coming from, I'm not going to get challenged and it's going to be great." And that works, or worked, but it's not secure. And so we don't want to trade off security for just checking the boxes. There are reasons for us doing this. Now, with that one specifically, we have put in changes in place where we won't let you use such a broad internet range to get around it in that respect, where you actually have to put though into like, "Well, what is the internet range that I'm actually coming from and using?" And we have some friction still with that, I would say, with admins using very global deployments or salespeople that travel around a lot and using different VPNs. So we're working through that as one of those compensating controls rather than the primary control. But again, it is up to all of our admins to really think through. We don't want you to just do the check the boxes that we're telling you to check because we want you to check a box. We really want you to think about these changes and what it means to your organization, why we're actually trying to implement these, and ultimately determine what makes the most sense for you and your company. And include your security officers and your CISOs to really validate what meets the requirements that your company has, so that everybody is protected both from a security perspective and ultimately a legal perspective as well. Mike: Yeah. No, absolutely. I mean, we did a security day at TDX, our team did, and we had a CISO in there and a Salesforce admin as one of the kind of breakout topics, and they were in lockstep with each other, and I've always said that. I remember the instance I was managing, once it grew beyond 10 users, I was like, "I really need to figure out what our security posture is and who's in charge of this, who sets password complexities," at the time and stuff like that, and it's not adversarial. It's you want to be in alignment with what the rest of the company's doing and also fall in line if there's a SSO requirement. Boy, I was quick to jump on that, because it also made logging in simpler for my users. Jay Hurst: 100%, and that's the other side of this. All of these things do play with SSO. If you have implemented SSO that has phishing-resistant capabilities already built into it, great. We will take advantage of that from the Salesforce side. We'll trust your provider. We'll trust that your security team has already set up what is needed for your company and we'll let you log in. So we don't want to add these additional duplicative type of controls for you, but we also recognize that a lot of our customers, maybe they're smaller customers, maybe they're not the enterprise size of Salesforce and don't have as structured of a security posture. So in those cases, we want to partner with our customers and really help them define what this should look like when they're thinking about internet security and their data in the cloud. Mike: Jay, I'm going to continue with you because James brought up a really good point. I was thinking of, "I'm going to ask him the common questions that admins are asking online." And James, you flipped the script, and it's, "Well, here are the questions that worry us that they're not asking." Jay, I'd ask kind of the same question to you, is you've seen a lot of the questions that our community's asking online. What are the questions they aren't asking that you really hoped they would ask, or you're there to provide an answer for? Jay Hurst: Yeah, I think the biggest ones, James talked about the compensating controls. That's a good one. I think a lot of our customers, as they're approaching it from the first standpoint is really they're looking at this as a Salesforce tax. They're really looking at it as like, "Oh, gosh, this is another thing Salesforce is putting me through. I don't know why. Why don't you just let me get my job done?" That type of attitude, which is completely understandable, but I do think one of the things our admins aren't seeing at that first cut is really the threat landscape that exists out there. I think if you haven't been attacked, if your org hasn't been compromised, it's very easy to fall into complacency and just think, "Everything's perfect, I'm secure, nothing's going to happen." And like everything, security and protection is a spectrum and it's a journey. You are never 100% perfectly ready for every outcome, and you also can't assume that what worked yesterday will continue to work tomorrow. So what I would love to see more of our admins and customers look through is how do I build the security and the continuing advancement of my security posture into my day-to-day, into my development scenarios, into my admin scenarios, where the first thing we should always be thinking about is, "Is this change I'm doing helping or degrading my security posture? And if it's degrading, how do I increase it? What do I do to make it better?" So I would love to get to a point where our very wonderful and vocal admins out there are also pushing us to do even more things to help protect them. What are the other controls that they're seeing across other enterprise systems that they want to take advantage of? How can Salesforce make it easier for you without lowering that security posture? How can we make it so that the friction can be lowered faster because you acknowledge the acceptance of the controls, or something like that around really getting back to a true partnership with more of our customers that I wouldn't say we've lost, but it's easy to forget about when you're focused on the headless 360s of the world or how can I get more agents into my system. And we also still have to think about, "And how do I keep it protected and managed?" Mike: Right. Yeah. I mean, it's more people in your house, but also making sure that everybody shuts the door and locks it. Jay Hurst: And wipes their feet. Mike: Right. Takes shoes off. James Ferguson: I think Jay also touches on what maybe I would consider the elephant in the room, because I think, when going back to the original question you asked in terms of what are admins asking, most of them aren't asking the why. Most of them acknowledge the value of these things and the need to do it, but they do push back on the why immediately and why under these compressed timelines and why, and sort of those kind of questions. And I will acknowledge that the rollout of some of these controls has not been as smooth as we all would've hoped, and so there's been some schedule things bouncing around from a timing perspective, and so we're definitely working on all of that. But it does play to that level of risk, and these are the things we really felt we needed to roll out sooner rather than later, and so that's why some of these timelines are compressed. I will add another, the flip side of that, to your point about what should admins be doing. We do find when we give notice, of like advanced notice of asking people to change things, they tend not to do it until the week before the enforcement date. Mike: Imagine that. Procrastination? Come on, now. James Ferguson: And so that's sort of, when our executives are looking at adoption rates or whatnot, it's sort of blunted. The desire to extend those out is blunted because, well, people are just going to wait anyways. But that said, I don't want to sort of ... We are pushing fast. We acknowledge that. We are making people a bit even uncomfortable, I would say. And we acknowledge that, but this is something, again, in the balance of the security posture we feel is important for the overall trust in the Salesforce platform and product. Mike: I mean, the one thing that I've always learned through all of the work that I've done with various teams at Salesforce is for every time you roll something out, another lock, there's always 10 people there trying to pick it, if they haven't already picked it. And so you both have mentioned that unfortunately it's compressed timelines, but it's timelines because we need to make sure that you're building locks and putting that stuff in place before people just have it to where they can blow through it, you know? Jay Hurst: Absolutely. The best defense is a good offense, I think is a very adequate app saying in this instance. We want to continue to make sure everybody is at a baseline security level, which is the phase we're in right now. It's this horizon zero of how do we get everybody to the minimum baseline, where we feel very comfortable that your data is going to be protected on the Salesforce platform? And it is painful, and it will be painful for the next couple months as these changes really roll out. Once we get there, we start thinking about what's our horizon one and our horizon two look like where we can start to add in the extra controls, give customers more levers to pull for their specific use cases, really focus on the experience around this, because I will also fully admit and not try and gloss over the fact that sometimes the wordings of things in the UX that we provide you to turn them on and turn them off is confusing and it's not as easy as it should be, and we're sacrificing some of that ease of use right now for speed of deployment. But the efforts that we have with the Salesforce Trust platform, which is an expanded group that we now have here that is purely focused on how do we not just get everybody secure, but continue to add more and more security features to make sure that Salesforce is the premier example of how an enterprise SaaS company secures their customers' data. So that is the journey we're on, and we're taking our customers with us. And as painful as it is, James and myself and the whole team here, we are looking for active feedback. We're engaging with the community on a day-to-day basis just to try and sand down these rough edges as much as we can until we can get the front door built, locked, and then we can really talk about how do we decorate our house now. Mike: Yeah. But also you mentioned, well, we're doing it and it's going to be painful. I guess I'm on the flip side of that, thinking, "Boy, if I had other applications and they're not going through this as well, that actually is more of a red flag to me," because then now I'm thinking like, "Well, do they not care as much about making sure all of my data on their platform is as secure as possible?" Jay Hurst: Absolutely. Like I said, it's a journey, not a destination. What is 100% secure today is not as secure tomorrow. With all of the new attack vectors that come out and these capabilities like Mythos and Fable and all of these really, really smart and frankly scary AI capabilities, we have to double and triple down even harder to make sure that we stay as far ahead of that as we can. Mike: Right. And as I've been reminded, security isn't always about being scary. Security is about being informed and making the right choices so that you have that protection and that understanding, which is really good. James Ferguson: It's risk management. It's risk management. Mike: Yeah, absolutely. James and Jay, I want to thank you guys for coming on and walking us through some of this. I know anytime that we offer anybody in our community, whether it's developers or architects or admins, a change, it's always extra work. But I feel like you're right there in answering the questions and helping through some of the hard parts, because I'll be honest, there's not a day that goes by that I don't learn something in security, at my current job and even when I was a Salesforce admin. Jay Hurst: Absolutely. And thank you, Mike, for helping amplify the message. One of the challenges I think we have at the product side is making sure our customers understand and get the information. We have our blog posts and our help documentation and we send out emails, but any extra we can do to megaphone this and get people aware is definitely valuable, so thank you for this opportunity. Mike: You bet. James Ferguson: And thank to all the admins who are out there who are also helping amplify this and helping support the rest of the community. It's one of the great things about Salesforce from the very beginning. It's the huge community support that exists. We couldn't do it if it was just the six PMs on my team. We need everybody involved. Mike: Yeah. And I think the part of that you take away is while I'm glad there's so many questions online that we had the idea to do this podcast, because that means there's so many people that are engaged and caring, as opposed to rolling something out and, "Hey, did anybody have any questions," and it's crickets. The reverse of that would also be kind of scary too, is there's questions because people care and because they want to understand. And also I think the one thing that I always had to do as an admin was I had to translate all of that from whatever the document said, or the podcast like this or the blog posts, to my users and to my executives, and it's a lot different once you have to take something in and digest it and then be ready for a Q&A. So there's always more to learn, but thank you guys for coming on. We'll definitely have to have you back on. Jay Hurst: Sounds great. Mike: Talk more security. James Ferguson: Appreciate it. Looking forward to it. Mike: Big thanks to Jay and James for helping us understand MFA step-up, phishing-resistant authentication, and the role admins play in protecting business systems. Now, of course, we know security is a shared responsibility, and admins are right in the middle of making it real for users, executives and, well, everybody in the organization. So be sure to listen, subscribe and share this episode out, and work through those security changes. You got this. Don't worry. Until next time, we'll see you in the cloud.  
  • How MuleSoft Helps Salesforce Admins Build Better Agents 09.07.2026 28min
    Today on the Salesforce Admins Podcast, we talk to Mofeyi Oluwalana, Director of Product Management at Salesforce. Join us as we chat about MuleSoft, Flow, Agentforce, and what happens when agents need to take action beyond Salesforce. You should subscribe for the full episode, but here are a few takeaways from our conversation with Mofeyi Oluwalana. MuleSoft creates agent-friendly business processes Agentforce can be truly transformative for our business processes, but sometimes it's easier said than done—especially when multiple platforms are involved. That's why I sat down with Mofeyi Oluwalana, Director of Product Management for MuleSoft. As Mofeyi explains, a problem many businesses run into when they're trying to implement AI is how to enable an agent to engage with something like a process that starts on a payment platform, goes through an OMS, and then ends up with a request to a warehouse for shipping. You can't just hand them the APIs and expect them to figure out the rest. That's where MuleSoft comes in. It gives you the building blocks you need to codify your workflows into something an agent can understand. Data mapping for real-time app integration Building an agent-friendly business process begins with data mapping. What do you need and where is it located? You also need to understand the triggers that kick off each part of the process. Does it start with a Slack message, or when an order is created? Often, these types of business processes don't start in the Salesforce ecosystem. MuleSoft allows you to translate these business requirements into APIs that an agent can use to take action. How to present to stakeholders As a product manager, Mofeyi frequently gives presentations to stakeholders, so I wanted to know if she had any advice for admins. "The most important thing when I walk into any room, regardless of the stakeholder, is who are they and what do they care about? Your ability to persuade and influence is largely due to your understanding of the three things that the people that you're talking to care about and how you align what you're talking about with those three things," she says. Make sure to listen to my full conversation with Mofeyi for more about MuleSoft and mapping your business processes. And don't forget to subscribe to the Salesforce Admins Podcast for a new episode every Thursday. Podcast swag Salesforce Admins on the Trailhead Store Learn more Salesforce Admins Blog Post: How MuleSoft Helps Admins Get the Most out of Agentforce Admin Trailblazers Group Admin Trailblazers Community Group Social Mofeyi on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript Mike: This week on the Salesforce Admins podcast, we're joined by Mofeyi Oluwalana, product management director at Salesforce to talk about MuleSoft, Flow, Agentforce, and what happens when agents need to take action beyond Salesforce. Now, for Salesforce admins, this conversation matters because agents are only as useful as the data, the actions, the permissions, and the business logic they can safely reach. So Mofeyi's going to explain to us why integrations are not just about moving data from one system to another. They're about helping Salesforce connect to the real processes your business depends on. We'll talk about the questions that admins should ask when working with other platform owners, how to think about triggers and data mapping and why business context is so important when you're designing actions for humans and agents. So give this episode a listen, subscribe wherever you get your podcasts, share it with another Salesforce admin who's maybe thinking about how Salesforce could connect to the rest of their business. And with that, let's get Mofeyi on the podcast. So Mofeyi, welcome to the podcast. Mofeyi Oluwalana: Thank you so much. Mike: I'm excited. We don't do a whole lot of episodes outside a core platform. And I know my Salesforce admins ... My ... The Salesforce admins of the world work everywhere and especially now with Agentforce and agents and really just the whole bringing people together and giving a complete view of data, integrating data and working with MuleSoft and tools like that are super important. So I'm glad to have you on. I'm glad we got connected, but let's start off and learn a little bit about you. What was your path to Salesforce and becoming a product management director? Mofeyi Oluwalana: Yes. So I started at Salesforce a little over four years ago. I actually came through the APM program, also known as the Associate Product Manager Program. It's a two-year rotational program for folks coming out of university, getting their start in product. So I was able to come in through that program. I did three rotations all across Salesforce. I spent some time in Commerce Cloud working on how to run promotions on Black Friday. Mike: Oh, holy cow. Mofeyi Oluwalana: And I spent a lot of time in experience services, thinking about how we can make it easier for marketers to build nice looking emails. And I ultimately landed in MuleSoft, which is where I continued working with the MuleSoft team on how to make it easier for our customers to connect the systems that they need to, both for traditional use cases, but also for the agentic ones as well. Mike: Yeah. It's funny, for the longest time in my career, I worked retail and the day after Thanksgiving, Black Friday was always the busiest day. And then I got into tech and I was like, "I don't have to work Black Friday." Mofeyi Oluwalana: Guess what? [inaudible 00:03:17]. Mike: And then realized that like, "Oh man, I was a retail associate. There's still computers that have to be had." So I have a soft spot in my heart for all of the people that on Black Friday have to sweat it out and make sure that servers don't go down so that checks and barcodes and everything can happen on the other end. Mofeyi Oluwalana: Yeah. I never realized how complex it could mean to calculate hundreds of thousands of carts when there were promotions running on Black Friday, but certainly it's more complicated than one may think. Mike: Right. And then there's people like me that add stuff to a cart and I'll come back to it a little bit later like, no, there's somebody ... You're using up the last bit of ... I don't know. He probably doesn't know that. And then I'm also old school retail when you used to have to verify checks and put them through little check readers and now everything's a credit card or a tap or thumbprint. Mofeyi Oluwalana: All of the above. Mike: All of the above. But it's all of the above because we're integrating data and we're doing stuff with MuleSoft. So I threw together some questions, but let's start off with where should admin start when thinking about products like Flow and MuleSoft and Agentforce together? Mofeyi Oluwalana: Yeah. The journey with MuleSoft starts the moment that your agent wants to do anything outside of Salesforce. I think MuleSoft is the connector, so to speak. If you have data that your agents need to reach in your ERP, if you have actions your agents need to be able to take with your payment provider, how exactly will they be able to do that? Now when agents and agentic technology became a thing, a lot of people were of this opinion that, well, agents are smart enough to just understand platform APIs or where agents can read the specifications, figure out the commands that they need to execute and do all the things that they need to do to be successful. We very quickly realized that agents are really smart, but at the end of the day, they're limited by the information that they know and the tools that they have access to. So it's not sufficient to just give your agents a platform API spec. That's not going to cut it. Your agents need integrations and APIs that they can directly invoke that map to your business logic. They need this because not every organization operates the same. For one retail provider, creating an order is very different from other retail providers. And understanding that business vocabulary is really important when building agents that actually bring value. And that's really where MuleSoft and Flow come into the picture. You have actions that your agency to be able to take in order to execute a certain business process. Well, that action is really just an API and we serve those APIs so your agents are able to do those things. Mike: Yeah. I've always thought of Josh who's on my team keeps us in check with helping us understand stuff. And what you just described would be like as if you brought somebody new on and said, "Well, here's a phone and a phone book. And if you have problems, the phone number's in the phone book." And the agent's the same way. If you're just saying, "Here's all the specs and the APIs you can call, go figure it out." It's almost like handing them this giant phone book and just saying, "Well, you're smart. You'll figure it out." Mofeyi Oluwalana: Yeah. Exactly. And the thing is that for a retailer, creating an order may not just be creating that order record. Creating an order may be, oh, I create the order record and then I send a notification out via email that says, "Hey, this is your order." And then after that, I create an invoice. There are a number of steps that happen. And how do you codify those steps? Well, it's not enough to just give an agent, again, the phone book and the numbers. It's much better and much more reliable to give them the actual workflow or the API they can use to execute that entire process. Mike: Yeah. Now, one thing that I've run into, so back when I was doing some integrations as an admin, we had different third party tools that were being used. One thing that I didn't know to ask ... And I'm hoping you can help Salesforce admins like, here's the questions you need to ask. We had an instance and we need to connect it to our financial backend, which ran not on Salesforce. I had to find the owner of that, which I didn't know existed. The other thing I didn't know to ask was I didn't know what to ask. And so as we work through different scenarios, you brought up like, well, they want to take the cart and order the stuff. The orders could be fulfilled in a different system. There could be a warehouse system. What are some of the questions that when the admin's sitting down with a business owner and they're saying, "Here's what I want in Salesforce and I'd really like to be able to pull up the orders." And the admin's like, "Okay, now I need MuleSoft because I need to integrate another system and I got to go talk to that systems' owner." What are some of the questions they should ask and what is some of the information they need to provide so that they can start setting up that relationship? Mofeyi Oluwalana: Yeah. I think it first starts with defining what data are you actually looking for? A large part of building integrations between these two systems is I have some data in the financial system. I have my CRM data in Salesforce. How do those two things map together? So I think the first step is what data are you looking for? And what is the mapping between what you're trying to do from a CRM perspective with whatever may be happening in that financial system? So to me, it starts with the data. I think the next question to ask is what is the trigger? It starts off this process. Is it someone sending a message in a Slack channel? Is it this order being created within your ERP? What is it that triggers this process to happen? You build the trigger, then you identify what the data mapping is between the source being that financial system and the target. And that's really how you get towards that working integration. Mike: Now, when I sit down with another platform owner and I talk about using MuleSoft, we can bring ... And so this is where you're going to quickly hear Mike's knowledge run out of gas because here's where Mike's knowledge hits the wall. But we can bring that data in and it can be like a pane of glass. We can just view that data or we could actually copy that data over so that we can use it in reports. And then we could also extend that conversation with the platform owner and say, "Well, if somebody wants to change something, they could change that in Salesforce and then Salesforce with MuleSoft can push that data change back to that platform." How'd I do? Mofeyi Oluwalana: I think you're almost there. Mike: Okay. Fill me in because what I don't know is what I don't know and I feel like there's other admins that may not know this as well. Mofeyi Oluwalana: I think the best way to think about MuleSoft is that real time app integration layer. So not necessarily the data that you want to live in Salesforce. Getting that unified customer view is really important. And so you'll need the data connectors in place to get data from external systems into Salesforce. That is one use case and one that Data Cloud solves really well. The problem that MuleSoft solves really well in tandem with Agentforce is the agent needs to take real time action. Again, so let's say we're going back to the retail example where I create an order. If order management doesn't happen in Salesforce, creating an order doesn't necessarily mean starting that process within the Salesforce ecosystem. I just want to be able to kick off that process with my OMS, my warehouse, my shipping provider. Then in that case, it's real time app integration. It's using the APIs that MuleSoft has to be able to kick off that workflow and that process using your agents. So it's a little bit different than moving data just from one place to another. Mike: No. I think that's also very important because companies have spent money on those systems. And I remember when I was sitting down with our finance team, they're like, "Well, if this data lives here and in Salesforce, what's the source of truth?" And we set it up so that we were just viewing the data because we really wanted sources of truth within the organization. But sometimes the user lives and dies within one interface and where that data comes from, we don't need that exposed to them. Mofeyi Oluwalana: Exactly. And I think it's the use case for consolidating data into one place is a little bit different from the use case of making sure that your agents can take action. And so I think as part of that rationalization that admins and IT teams have to do is what data do I need to drive what? And what actions do my agents need in order to be successful? And this part of that then can separate it into those two camps and then move forward with the tools that help them do so. Mike: Cool. Now, when you connect MuleSoft with other systems, does the admin need to ask for, can you provide a certain API? That's how it's set up, right? Or walk me through it because I've never set it up and I feel like I'm completely happy being the host of the podcast that asks the questions that admins are like, "Oh, I'm so glad he asked that because I didn't know to ask that question and I didn't want to look stupid in front of my IT people." Mofeyi Oluwalana: Yeah. So I think from the business side, we set the requirements about, okay, this is what I need. This is the process that I need done. These are the steps that should happen. This is what should trigger that. You do that definition. Then you can work with the IT team or the API developer to actually make that happen. Now the API developer has access to a number of connectors within MuleSoft that enable them to build these APIs and integrations without relying on what is the API specification for my OMS system or what is the API specification for my [inaudible 00:15:07] system? There are connectors that have a ton of different actions that you can orchestrate within a MuleSoft integration to get a certain job done. So one example that I like to use is the Salesforce connector. The Salesforce connector has a ton of different triggers. Let's say when a new object is created or on when a record is modified that can trigger the integration. The Salesforce connector also has a bunch of actions or operations. So I can create a record in Salesforce. I can delete a record in Salesforce. I can create a topic in Salesforce. All of the different actions that you can execute through Salesforce APIs extrapolate it into a connector so that it's easier to build and then manage these integrations. So the API developer is in charge of translating those business requirements into the integration composed of those connectors that allow you to achieve exactly that. Mike: Gotcha. Boy, there's a lot. It feels like there's a lot to it and we make it look so simple in demos. Mofeyi Oluwalana: Yeah. I will say it's much easier looking at a screen and hearing an audio podcast of what this really is. But I like to think of them as MuleSoft gives the tools, those building blocks. You can compose those building blocks in a certain order to create a workflow. Those are the integrations that you can use and your agents can also use to take action. Mike: Yeah. I always think of it as admins are managing users and agents and agents are just like users. They have to have instructions and guardrails and guidelines for how to operate and what they can and can't do same way that people have as well. I'd love to know, so as a product manager, you got into the program. How has being a product manager helped you understand the product, but also given you a different perspective of working through explaining different customer stories or use cases? Mofeyi Oluwalana: I would say the best, and I'm obviously biased, but the best part about being a product manager is just the sheer amount of data points that you see. One of the things that I think is really important as part of being a product manager is meeting with as many customers as you possibly can because it's through those customer conversations that they're very clear themes that you can draw, not only of how people use the product, but what the product doesn't quite solve for yet. And so going through those conversations has helped me not only understand those customer pain points better, but then understand the things that we need to do in the product to make it even easier for our customers to use. Mike: Yeah. No. I often feel when I was exposed for a brief six months as a consultant that a lot of the pain points customers have always felt the same. I was like, "Man, they have the same problem that XYZ has." And at the end of the day, you'd look at all the customers you manage and you're like, "They have these five problems." And then brand new somebody would come in and you're like, "And you have completely different use case and requirements and they don't fall into those same five problems that I've been solving all day, which is nice." So I'd be curious, as admins are looking more and more at building ... They build agents and apps on the platform and they extend the platform and they use MuleSoft. What are things that you're thinking about as a product manager for, wow, I have to be a year out or two years out. How should admins be thinking about their building and management of the Salesforce platform as a product? Mofeyi Oluwalana: Yeah. I think the most important thing is not just building for where we are today, but building for what's coming. I think one thing that agents in AI technology has taught us is that the technology market is changing so fast. It's going to be a new model. It's going to be some new capability that you want to be able to leverage. And in order to do so, the foundation and the platform that you're building on has to be interoperable. It has to be able to withstand some of those changes that you want to make. The example I always like to give is if having to change a model is going to disrupt your operations, that is an issue. And we know that is an issue because LLM models, a new one comes up every day, another one is deprecated every other week. So I think the most important thing thinking about the platform is how do I make the platform resilient and flexible so that as these new capabilities come into play, I'm actually able to use them and really take advantage of them within my organizations. Mike: That's very good advice. I'm just going to guess and maybe I'm wrong and we can move on. As a product manager, you probably do a lot of presenting both to customers and probably internally. I know admins have to do that as well. What would be some advice you would have for admins that are presenting either a new solution or proposing something to their stakeholders? Mofeyi Oluwalana: The most important thing when I walk into any room, small or large, regardless of the stakeholder is who are they and what do they care about? It's easy to get lost as a product manager. It's very easy to get lost in, I actually think this is an amazing idea and I talked to 10 customers and I know it's going to be valuable for them. But your ability to persuade and influence largely due to your understanding of the three things that the people that you're talking to care about and helping them align what you're talking about to those three things. A great example is that when you talk to your COO, I will guess that it will come down to how much does it cost the organization and how much money is it going to make me? So talking to your COO is not the same conversation that you'll have with support. Who cares about, okay, is this going to make it easier for me to support my customers? Does this make us more reliable? So you need to change the delivery to really match the things that you're being evaluated on when you're presenting to an audience, when you're presenting to internal stakeholders and external ones as well. Mike: That's really good advice because I can tell you right now I'm guilty as charged of walking into a room thinking I have the answer and this is the most important thing that they're ever going to want to hear and forgetting that they probably had their own goals and I just blew right past them and kept talking about something else entirely. Bad. So one thing that I find talking with people that work in tech is we always have hobbies or things that we like to do on the side that are very tactile. I know I've interviewed a product manager that smelted pewter. Mofeyi Oluwalana: Wow. Mike: That's the extreme case. I always bring it up because it sounds interesting and who hasn't walked past some sort of pewter chessboard with its little figurines and thought that would be cool except I'm not going to pay a few hundred dollars for it. I'm wondering if there's anything interesting that you have as a hobby that you would love to share with people. Mofeyi Oluwalana: Unfortunately, I'm not nearly as interesting as the guest that you just mentioned. Mike: It's not a contest. It's not a contest. Mofeyi Oluwalana: It feels like one. Just kidding. I won't say I'm tactile as I'd like to just stay mobile. As a lot of the folks who work in tech, we sit on our butts all day looking at computer screens. So wherever possible, I like to just go outside, get some fresh air, do some movement, whether that be running, yoga or similar. That's my anchor. Again, not as interesting, but it helps me. It regulates me nevertheless. Mike: It's still super valuable. I was just talking with a coworker the other day about our grandparents and so-and-so's grandparents lived to be 89 and they were outside in the sun all day and they had bacon and eggs for breakfast. And I thought to myself, "Well, yeah. And then they probably worked it off all day because everybody was thin back then. And the worst thing they could do is sit down at a desk like I do." And so who would've thought that there was ever a need for a treadmill desk? I think that back to the future quote, "You run for fun." Mofeyi Oluwalana: Exactly. Mike: So no, that's really good. And what's great, I've had a few colleagues as well take calls while they're walking. I think the benefit of being in tech is that you can do calls like that and work through. As long as you're not working through maybe architecture diagrams for Microsoft integration, that would probably be pretty bad. Mofeyi Oluwalana: Or if it's windy outside and you don't have a great mic. I'm also a big proponent of just walking outside and taking as many meetings as I can moving. Mike: Absolutely. Yeah. No. Well, I would just say windy at all because I have yet to find a mic that doesn't make it sound like you're walking through a NASA wind tunnel. Mofeyi Oluwalana: Wait, that's the next startup. Mike: I'm telling you. The fuzzies that come on mics, there's got to be something better. There's got to be something better. Mofeyi Oluwalana: I agree. I agree. Mike: I don't need to have a big mustache just to talk into the microphone. Well, it was great chatting with you. I learned a lot. I feel like I tried to ask some of the silly questions that I know admins would want to ask. There's probably plenty of admins out there that have done some MuleSoft integrations, but I know when I had to sit down with other platform owners and be like, "I need your thing to plug into Salesforce and I don't know how to make you do that, but you figure it out." I always wanted to ask the silly questions so that when they sit down, they know what to say and can have a better relationship because in every aspect of the sense, there's other platform owners within organizations and they're all trying to do right by each other. So that being said, I appreciate you coming on the podcast and sharing that with us and we'll have to come back and talk more MuleSoft maybe after Dreamforce for sure. Mofeyi Oluwalana: Yeah. Thank you so, so much for having me. And again, I'm biased obviously, but always love talking the world of MuleSoft and integrations because it truly feels even more relevant than ever with agents and the technology. Mike: Absolutely. Big thanks to Mofeyi for joining us and really helping make MuleSoft flow and Agentforce feel more approachable. I wasn't afraid to ask the questions that you shouldn't be afraid to ask. The big takeaway for admins when agents need to act outside of Salesforce, your understanding of the business process, the data, the triggers, and the right system of truth matters now more than ever. That's how you keep Salesforce accurate, current, trusted, and useful for the business. Now be sure to subscribe to the Salesforce Admins podcast. If you haven't already, share this episode. Hey, share it with your team. And then keep asking those questions that help your org connect the right systems in the right way. Until next time, we'll see you in the cloud.
  • How Can Salesforce Admins Find Simple Agentforce Use Cases? 02.07.2026 30min
    Today on the Salesforce Admins Podcast, we talk to Kacie Molina, Salesforce Consultant at Kawaii Cloud. Join us as we chat about how admins can start small with Agentforce and still make a big impact. You should subscribe for the full episode, but here are a few takeaways from our conversation with Kacie Molina. Why you should start small with Agentforce With all the capabilities Agentforce brings to Salesforce, it's easy to dream big. Big projects, however, require major organizational investments in time, planning, and execution. My guest this week, Kacie Molina, has some simple advice for her clients who want to get started with Agentforce: start small. Go back to the basics of listening for pain points and building solutions. Once you start piling up small wins and meaningful changes, it'll be easier to get organizational buy-in for something big and bold. Admins should listen for problems users already have Agentforce solutions don't always have to be some sort of major business process overhaul. Those types of changes require layers of approvals, budgeting, and business analysis. You end up spending as much time rethinking the business process as you do worrying about executing everything in Salesforce. Instead, look for simple use cases. For example, implementing an agent summary field to help users easily see what's going on with an account without having to scroll through a bunch of records. "All of those little use cases that maybe are too specific for a flow," Kacie says, "we can solve them with Agentforce and natural language." And over time, the simple solutions add up. Keeping AI work inside Salesforce supports better security Even if you're not already using Agentforce, people in your organization are already using AI. The problem is that they're often exporting data over to their LLM of choice, which creates all sorts of security vulnerabilities. That's why Kacie recommends enabling an agent to assist your users. You can use your model of choice, and it'll be grounded in your Salesforce data and protected by your security configuration. "It shows users that there's a safe place to get the answers they want without having to worry about breaking company policies," Kacie says.  Make sure to listen to my full conversation with Kacie about how to start small with Agentforce. And don't forget to subscribe to the Salesforce Admins Podcast so you never miss an episode. Podcast swag Salesforce Admins on the Trailhead Store Learn more Salesforce 360 Blog Post: From the Farm to Flows: How One Trailblazer Built a Tech Career from Scratch Kacie's post on LinkedIn Admin Trailblazers Group Admin Trailblazers Community Group Social Kacie on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript Mike: This week on the Salesforce Admins podcast, we're talking with Kacie Molina about how admins can start small with Agentforce and still make a big impact. Kacie shares why the best AI ideas often come from listening closely to everyday user friction. The scattered preferences, repeated questions, messy exports, and those tiny gaps that slow teams down. We'll talk about building agents that are grounded in Salesforce powered by Flow and designed with trust and security in mind. Because the next generation of admins isn't just adding features, they're orchestrating safer, smarter systems where humans and agents work together. So give it a listen, click that subscribe button, share this episode with an admin who is ready to make AI even more practical for their users. And let's get Kacie on the podcast. So Kacie, welcome to the podcast. Kacie Molina: Thanks, Mike. I am super excited to be here today. Mike: Well, I'm excited to get you on. I was a rare occasion scrolling through LinkedIn and I came across a post that you had put up and it mentioned the AgentforceNow workshop that I think you were in one of mine or you'd been to one. Kacie Molina: I was in one of yours and it was done extremely well, might I say. Mike: You were. Oh, good. Well, I try hard. And you're talking about coming up with ideas and you'd had some ideas for agents and I thought, "Man, I just think we need some sort of agent brainstorm podcast." And so that's why I wanted to get you on. But we're going to talk about that. But before we get started, tell me a little bit about yourself, like how you got into Salesforce, what you do, all of the fun stuff. Kacie Molina: Absolutely. So I grew up in more rural USA, an Amish type community, so horse and buggy. Think maybe Little House on the Prairie, early 1800s. So did a lot of horse training and cheese making with my sister, tended gardens and animals. So my skills when I became an adult were fairly traditional. So as I was trying to translate, "What do I use my skills for?" I started nannying, childcare, and then I started my own sewing business. And during that phase, I was actually so bad at running a business, so I knew how to sew, but I didn't really know the business part. So keeping track of contacts and invoicing people on time was such a disaster for me. It was all little handwritten notes. So I was listening to podcasts and I heard about Salesforce. I logged into Trailhead and fell in love with the gamified learning. So it was kind of no turning back for me. I got my admin certification in about three months, landed a junior admin role shortly after. And it's been about five years and 10 certifications since then of working on all kinds of projects from in-house to consulting. And I just think like Flows, all think Salesforce. It's so much fun. And in the day and age of Agentforce, even more fun nowadays. So that's kind of how I stumbled onto the Salesforce path and it has been way too much fun. Mike: Oh man, I bet we could do a whole podcast on the skills of sewing and how they carry over to Salesforce. Kacie Molina: We probably could, although I do think Salesforce might be a little more fun. One, because you don't get poked by needles. That's a huge thing for me. I don't even like going to the doctor and getting poked by a needle and I did that for a profession. So I got poked all the time and it's much less frustrating than trying to deal with broken sewing machines. Salesforce kind of works pretty well. And when you're dealing with old-fashioned sewing machines, not so much. Mike: I could imagine. Yeah. Needleforce, that's what we'll call it. Kacie Molina: Needleforce. Mike: I bet that exists. I think that would be so cool if there was quilting or sewing at Dreamforce. Because I see people on the plane all the time with those knitting needles and stuff. I would love to have the patience to do it. Kacie Molina: It definitely takes a lot of patience. So actually, interestingly enough, when I was just getting into Salesforce, Mallory Donahue, she's such an amazing person I look up to. She was getting into Salesforce at the same time as me and she was also a seamstress. So I think there might be more sewing and needle people out there in the Salesforce world than you might think. Mike: Yep. Well, this is the diversion that Mike's squirrel brain gets on too quickly. But let's talk about ... I was so intrigued by your post, because I feel like even in the workshop that we do, the AgentforceNow workshop that I hosted, I think I'm back sometime in October because I have some vacation in July. We build an agent for Pronto, which is a food service company and it handles questions and cases and order issues. I mean, I feel like by the end of it, it's pretty complex because we've already built some Flows. There's some Apex actions that are in there. And so I feel like we're getting nitty-gritty into it, but your post kind of almost felt like a breadth mint of like, "Hey, have you ever just thought about asking your users five questions or whatever and then turning on Agentforce and giving it on action to do?" Kacie Molina: Yeah. I really like the workshop, because it gets into the more complex things and you see how the broader, the depth Agentforce can go to. But for me, when I started looking at ... Okay. So I serve multiple clients, and a lot of people are excited about Agentforce and I talk to a lot of admins about it as well, but where do you get started? For me, it was the really simple, small things where people I feel like nowadays more and more are expecting to be able to use natural language. And you don't really need to build a crazy, big agent that takes multiple sprints to complete. You can turn one on fairly simply to answer a couple simple questions and people can start to see that magic work from even a small start. Mike: Yeah. And I feel like, boy, this is me just thinking of that post, but you had really good ideas around not just what I would call the hard aspects of business, which is like invoicing and questions and emails, but also kind of like the soft aspects of business, which is just asking Agentforce to coach you that day or just kind of simple questions that you could give it that would maybe make you as a salesperson or customer service person feel better about what you're doing. Kacie Molina: Right. I do. I think it's really cool that you kind of came back to the small ideas and I'm actually very impressed you found that post because I feel like not many people see my LinkedIn post. Mike: You mentioned me in it, so I got that. But I mean, to be fair though, the small little detail, little things like that are actually kind of the bigger hooks to look for. Kacie Molina: They are in there. To me, they're everywhere. So bigger agent ideas, like there's a couple things that can be intimidating about them. One, they take a lot of time. Two, you're always looking for that big idea that is going to wow the whole company potentially. And then it also entails potentially budget and project approval, which you need to get approval for most things that you do anyhow. But the small ideas are something that you don't really need to take a whole ton of business analysis, say, to get started on it. It's something that you could know off the start like, "Oh, I see my users asking about this in a support ticket frequently." So one example recently I had was somebody who said, "We have these client preferences and they're kind of scattered in the system and they're a little hard to find. So is there any way you could summarize them?" And I said, "I think this would be a really good use case for an agent summary field." So you can build the prompt and pull things together. It's the little things like that when you're listening to details that you might not have to go build a Flow or build something so specific for. And that would be my old use cases like Flow all day, every day. But all of those little use cases that maybe are too specific for a Flow to say, "Oh, we'll grab this and explain it this way." It comes out in Agentforce as the natural language and I think that is a huge thing for users that they're looking to see something that feels like them or feels human so they can click onto a record. Say they go to a client account and then they can see at a glance like, "Oh, this person prefers this and this and they don't like this." And that's much easier than scrolling through a bunch of records. Mike: Yeah. I've been so busy building agents that I forgot about some of the other prompt builder and the grounded fields that we had. I used to call them sparkle fields, I think like that, because they have little sparkles next to it when you can automatically have Agentforce kind of fill in based on a prompt and that's exactly it. I mean, I remember rolling out chatter and I did it probably the wrong way and I turned it on for the whole company and the whole company was like 50 users, but I didn't give them any use cases. And if I was now to go back, I would've picked a team of five people and said, "I'm going to turn it on for you and here's a use case to use it for." And I feel like your post was just ... It just made me feel less burdened to come up with these extravagant big ideas to use an agent for and it was more like, "No, you can just have the agent totally answer your front door and be like, 'Hi, we're not home right now,' and that's it." And I was like, "Oh." Because I feel like admins are sometimes sitting down and thinking, "How do I make an agent that answers the questions and closes a $6 million deal?" Kacie Molina: Right. And then there's a bunch of, in my mind, you have more selling at that point. So if you're coming up with a new idea, then you kind of have to pitch it to the company. But something I like about the small ideas I've been picking up on lately is that it's kind of puts us back into our usual admin position where we're hearing problems and then we're offering solutions. So instead of coming up with a new business flow, start to finish of a new agent that can do some flashy thing, which is also extremely cool. You can also take something where somebody says like, "Oh, I export this data and ask ChatGPT about it. Anyhow, I'm already using AI." And so you can start to hear use cases where you're not coming up with something new, you're just solving something they're already doing in a more secure way. And that's another big idea for me is security within Salesforce is so much more attainable for admins. When people start exporting data and loading it up into an LLM that you don't have control over, that's a lot more scary for as an admin than if they can just use it from within the system. Mike: Yeah. I mean, when you and I talked before we pressed record, you even brought that up. If you're an admin and you're in meetings and maybe it's not even a Salesforce meeting and you hear people bring up a different LLM, what in your mind goes off and what do you think of to do as next steps if you were to help coach admins who are in that position? Kacie Molina: Something that's really incredible about Salesforce that maybe not everybody knows that they haven't played around with Agentforce yet is that you can use customized models. So it's not like you only have availability to use the Salesforce model. There's also, you can bring in different like ChatGPT if you like their open AI's model, you can use those different AI plugins within Agentforce. So that's something that goes off my head is if you like something, you don't have to totally forsake that for something new. So you can feel at home within Salesforce with the different AI models. And also, if you're using different AI models, which just like constantly goes off in my brain is that you can do that with way fewer clicks and way fewer security risks if you do it from within Salesforce without having to potentially like fudge on permissions or fudge who has access to it. So that's something that goes off in my head is like, "Oh, if you're doing this with AI already, you can just pull that into Salesforce and then you have even more data." So you are kind of limited when you export data to what the LLM can see. But when you have it within Salesforce, you have so much expansive broader options that you can use. So you can pull in different records and different things from here and there and you don't have to be so specific in one point in time. You can re-ask again in 10 minutes if you have information flowing in. So for me, it's like the different LLMs that are available within Salesforce and data availability is huge. Mike: Yeah. I mean, plus once you export that data and take it out of the platform, for many companies, you're already violating security because that data is housed in Salesforce for a reason and it's not meant to be used elsewhere. Kacie Molina: Yeah, that's a big risk I think with AI. Most companies I think are using it, whether it's an approved tool or not. So when you even enable to me a basic agent in a Salesforce or it shows users, "Hey, there's a safe place where I can get the answers that I want and I don't have to worry about breaking company policies to get the data I need." Because we are in a fast-paced world and I know some users, they really do need to get answers that maybe they can't get within Salesforce today. So they're exporting data and getting their answers with an AI elsewhere. But if they can have that easily accessible and it's safe to use, then I think that enables both admins to feel safer about their org and the users to save clicks, save time and get a better answer Mike: Absolutely. Back to that workshop, I'd love to know your perspective. So we talk about agents and subagents and even in that workshop we create a subagent to handle, I think it's returns and refunds, or order issues and refunds. I'm trying to remember it without remembering it. When you're working with customers or talking with companies about using Agentforce, do you even talk about agents and subagents, or do you just kind of like, "Here's the magic and I'm going to build everything behind the curtain"? Kacie Molina: I usually don't bring up the different agents and subagents and I guess it depends who your stakeholder is. If there's somebody who's more admin-minded and very inquisitive, I would potentially bring it up. But most of the stakeholders, I'm working with bring-me problems and expect me to be the expert and bring them solutions and they don't really care about the very cool details about agents and subagents I think are so fun to talk about. They just want to see the magic on the end. So for me, it's kind of like Flows. I kind of relate most things back to Flows when I'm learning how to code or anything. It all comes back to Flows for me because Flows are magic and they're so much fun. A lot of people don't care if you call sub-Flows or you have different components in the Flow. They just want to know when X happens, they see the screen and then magic happens in the background. And I think agents are kind of the same way where they're really cool to see the backend for people who care, but you can also talk to stakeholders at a higher level without them needing to know that detail. Mike: So you talk a lot about Flows. How important was it for you when Agentforce came out that a lot of the power behind what it could do its actions are powered by Flow? Kacie Molina: Oh, that was huge for me because it feels like it brings the control back to the admin. So I definitely wasn't the most happy, quick adopting of AI when it first came out. I was definitely suspicious and I love my Flows and I love doing things manually. So I was definitely suspicious of AI in general and I've learned to really love it. And part of that is being empowered to do tasks on the backend. So you have the agents that do all of this, we'll say agent magic in the background, but then there's also the pieces that you can build out manually in Flow so you have control over what information you're pulling, what you're feeding to the agent, that way you get the predictive and answers that you want. Mike: Yeah. And even the builder, I feel like that the new agent builder feels like Flow Builder, because, well, there's also variables in there, which still worry me. Kacie Molina: I do like the UI better. Mike: I'm still not the best at better building Flows. I don't know why my Flow confidence is low, but maybe that shouldn't have rhymed, but yeah, my Flow confidence is low. Kacie Molina: I feel like you're probably much more of a Flow expert than you're letting on. I will say though, the new UI gave me a pretty big boost. So the old UI wasn't quite as intuitive or friendly and that's something I really wanted to post on LinkedIn about as people who maybe like me, they got their certifications and started doing their Agentblazer statuses on Salesforce when it was earlier. And then when you come back and you see the new UI and ease of use and having things like variables where you feel more comfortable like a Flow, all of a sudden I was like, "Oh, I can really do this this time. This makes so much more sense." Mike: Yeah. And the fact ... I mean, we don't get into it with the workshop, but I'd love to know, have you ... So the one thing I want to do is I'd love to have an agent help me build an agent. Have you done that? Kacie Molina: Only for testing. So I haven't done a real life agent building an agent yet, but I did some demo examples just because I wanted to double down on the workshop of how it worked and it really is incredible that you can, one, even if you start, like the agent isn't building the agent yet and you hit an error. In the workshop, I think intentionally you had a couple things that would error out and we'd have to go fix. That way you get very comfortable with fixing things and throughout the agent, you can- Mike: Oh no, I think they threw that in the workshop just to make Mike sweat. Kacie Molina: They might have done that too. Mike: I know they didn't. I'm sure the people that built the workshop listened to the podcast, but I know they didn't, but let me tell you, the first time I had to go into that, I practiced for two days going into script builder. I was like, "Here we go. We're going to do code and we're going to do code in front of a thousand people." And then I forgot my quotes. And I remember half the people in the workshop were like, "Mike, quotes, and then it'll work." And I was like, "Okay, cool. So you can tell that I'm not used to this a lot." Kacie Molina: I thought personally it was intentional because it was really helpful for me, because I was kind of just playing along on the side by myself and when I hit the error, I put it into the agent and it found the error, it found the line and it told me exactly what to fix and where to fix it. I think you can even say like, "Do this yourself." For me, I wanted to get hands on and go make the change, but it can actually implement the change if you want it to if you approve that. So I was really impressed with that and I thought the error was intentional, but that was super fun to see, "Oh, it can help me when I hit errors." And also with the coding part, when you see the backend, I thought that was really comforting as well. So I'm not a coder. I don't really know Apex very well. I can kind of read it. But even with Flows, when you get, this might get a little technical, but when you get into the Headless kind of Salesforce build and you have everything pulled into an IDE and you see everything in the background, when I saw that for agents, I was like, "Oh, this makes sense." So you can see the front end, like the pretty UI, then you can go into the back end and see the code drivers and be able to change granular things. So that's another thing I really liked about the new UI is it's so easy to switch back and forth. Mike: Yeah. I'm with you. I actually, because of that workshop, I think I've gotten better at just reading. I'll equate it to a foreign language. I took a lot of German in high school and I can kind of read German or listen to German TV. I don't know specifically what's going on, but I got a general idea and I feel like I'm the same way with code. I'm like, "I don't know specifically all these lines, but I know here's the inputs and here's the outputs and here's what I'm looking for." I can navigate, but I don't delve too deep far in. Kacie Molina: Right. I want to be writing it from scratch, but I can see what's going on. Mike: Oh, no. No. If they said, "Mike, you're in prison until you can write code," I'd be in prison for a while. Kacie Molina: Me too. Me too. I've tried to learn a couple times and it is on my to-do list. It's just Flows are so much fun and you can do so much in Salesforce without knowing how to code that you can skate by for a while and not really have to learn. So that is where I'm at. Mike: Yeah. You mentioned Headless. So let's talk about that for a second. I'd love to know some of your ideas for Headless. First of all, explain Headless 360, I think that's what we call it, Headless 360 to a Salesforce admin who's never heard it before. Kacie Molina: Ooh, this could be fun. So Headless to me means you're working from Salesforce kind of from the back end instead of the pretty face of Salesforce where you're normally logging in to Salesforce and updating settings within the Salesforce browser. So Headless, you're kind of looking at a developer tool. So I think Headless has probably been around for a while if you really wanted it, but it wasn't nearly as accessible. So there's older tools like VS Code where you can pull down the metadata from the org and you can see like the backend of Flows, which is actually pretty cool. The first time I saw Flow in a code editor, my mind was blown. I was like, "What? It looks so different. This is kind of crazy." And now I can go in and bulk edit and it's very handy. So the Headless 360 is really, I think, enabling admins to do that and not needing coding skills. So you can really use natural language, kind of like I was talking about earlier, where you can enable basic prompts and people can use natural language. You can develop Salesforce, even like Flows, fields configuration from never logging into Salesforce. So you're doing it all from the back end. And of course, you want to log in at the end to make sure it looks good. But Headless is really being able to look at the metadata in its kind of raw form and update it and manipulate it and then push it back into Salesforce and boom, you have the magic happen. Mike: Gotcha. I think it's interesting. I mean, I know we're going to have a lot of really good sessions for Edmunds at Dreamforce about it. So the rapid pace of AI to me is ... I remember doing a podcast just learning about hallucinations and different terminologies like grounding and now we're all the way how far in and have agents building agents and I'm just like, "Wow, where are we going to be this time next year?" Kacie Molina: It is pretty wild. I was playing around with Agentforce, so something I really enjoy as an admin is not writing queries. So there's lots of things that I can do, but I might not want to spend the time doing tedious tests, like writing long formulas or queries. And I saw with the Salesforce inspector, you can download a prompt and I just put that into my Headless IDE and I said, "Hey, can you push this into my org so I can use Agentforce for querying?" And it took it and it had the wrong version, I think. So it updated a couple things and it didn't even need help from me. It was just like, "Oh, this is an out of date version, so I'm going to update this." And then it pushed it in and then I refreshed my page and I could ask the little Einstein Agentforce character to write queries for me. So it is kind of fun on the backend, you can do so much in so short of a time and it's just fun to see. Like you ask something and then, boom, it gets created, whereas before it could take hours. Mike: For admins that want to be in the conversation about AI with their organizations, what would you suggest they do? Kacie Molina: So I think security is one of the biggest places to start and that's where I try to start is having ... Salesforce has good documentation on the different trust layers and how Agentforce works and then cost is another thing. So usually, I'm looking at kind of the different pillars of a project, like the scope of it, the cost of it, and then security as an admin, always a big thing. So backing that up with Salesforce and just understanding that when you use Agentforce that you can keep the data secure, there's that trust layer there so you're not just bleeding out your information to the whole world like you might be doing if you put it in some random AI tool. And then with the cost as well, a lot of companies that I've talked with, they wonder, "How do I get started? Do I need to pay for something right away?" And Foundations has been a really great place to start because you get credits every month where you can try Agentforce and you can monitor your billing and it's safe to use. So that's something I always say like, "You can start really small with this. It's not something you need to implement even to every person in the org. You can have a couple super users that you trust and try small, start with Foundations." So I think the starting small is where I've really doubled down on with clients. That way it's not a big decision necessarily for the company where it's such an IT burden and they're really worried about big things. If you have a really small scope to start with, people tend to feel more comfortable. Mike: Yeah. And I mean, with all the features, we always talk about rolling them out to super users or having that kind of core group of people that helps you vet new features and what's the best use case for your organization. I'm like you, like even the smallest, if you think about it like cracks in the sidewalk, even if you patch two or three of the smallest cracks in the sidewalk, you've still made the sidewalk sturdier. Just because you didn't tackle the big gap doesn't mean you didn't improve it. And sometimes, that little bit of friction for users is what really frustrates them too. Kacie Molina: It is. It can be something even as simple as searching for a record or seeing your top account. There's some basic requests that I feel like I see that are so helpful to users, whether it's like summarizing data, like I mentioned earlier, or being able to search for something. So sometimes people get really frustrated with the search bar and they're not finding what they want and there's definitely things you can do to help with that, but I think it's really helpful when they can use that agent to use natural language and say, "I'm looking for this or I want to create a case with these details." When they can use their comfort language and they don't have to be so technically specific, for non-technical people, I think it's really helpful. Even for me, even though I love technical stuff, I still really like chatting with the agent like a human. I still say like, "Please, and thank you." And I like when it's funny back with me. So there's something comforting about that natural language I think when you enable it. Mike: Yeah, I hear you. Kacie, thanks so much for coming on the podcast. This is a fun conversation. I'm glad you posted randomly to LinkedIn and I'm glad I randomly found it and now you're a guest on the podcast. I mean, that's how I find some of the coolest conversations. Kacie Molina: I'm really happy you reached out to me about it because it's something I've been really passionate about and have some amazing colleagues I talk AI use cases with frequently. And so I was like, "Yeah, let's definitely talk about this," because you can start small and you can have so much fun with it. And my hope for every admin is that they can get hands-on with it, start to use it in their orgs and just have a ton of fun, because that's what new tools are for, right? Just like Flows. Mike: Absolutely. I agree. Thanks so much, Kacie. Kacie Molina: Well, thanks, Mike. Mike: Big thanks to Kacie, Molina for joining us and reminding us that Agentforce doesn't have to start with a giant project. Admins can create real impact just by listening for those small moments of friction and designing a secure solution while helping teams work better with data automation and AI. So be sure to subscribe, share this episode and keep the conversation going with your admin community. And until next time, we'll see you in the cloud.
  • How Do Admins Set Up Agentforce Coworker in Salesforce 25.06.2026 37min
    Today on the Salesforce Admins Podcast, we talk to Parth Shah, Director of Product Marketing, and Rikke Hovgaard, Director of Product Management for the Agentforce Coworker team at Salesforce. Join us as we chat about Agentforce Coworker and what it means for the way admins help teams get work done. You should subscribe for the full episode, but here are a few takeaways from our conversation with Parth Shah and Rikke Hovgaard. Agentforce Coworker brings AI into everyday business work AI has been a game changer for coding, but integrating it into normal business processes has proved more challenging. That's where Agentforce Coworker comes in. It's an autonomous AI teammate, grounded in your enterprise data from day one. For this episode, I sat down with with Rikke Hovgaard, Director of Product Management, and Parth Shah, Director of Product Marketing, to find out what Agentforce Coworker is and how it can help admins bring new tools to their team. Salesforce permissions remain central to trust and access Trust is central to any conversation about AI. New tools are exciting, but you need to be sure that they won't give people access to data they shouldn't be able to see. Luckily, Agentforce Coworker works around the permissions you've already configured in Salesforce. It's simple for admins, and keeps those guardrails in place. As far as configuration goes, Rikke and Parth are all about keeping it simple and transparent. While Agentforce Coworker automatically inherits the security and governance settings that are already in your org, you also have special configuration options just for the agent. Admins can connect more data through Data Cloud and Slack For Rikke, Agentforce Coworker is especially useful for summarizing her team's Slack conversations. She can quickly understand which team member is working on which issue, and where she might need to lend a helping hand. At the end of the day, Agentforce Coworker gives you a conversational interface to do more with your Salesforce data. "Coworker does the work in the background so that your team can actually focus on what matters," Parth says. Listen to the full episode for more from Parth and Rikke about Agentforce Coworker. And don't forget to subscribe to the Salesforce Admins Podcast to catch us every Thursday. Podcast swag Salesforce Admins on the Trailhead Store Learn more Introducing Agentforce Coworker Salesforce Admins Podcast Episode: How Headless 360 Helps Admins Bring Salesforce Anywhere Admin Trailblazers Group Admin Trailblazers Community Group Social Rikke on LinkedIn Parth on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript Mike: This week on the Salesforce Admins podcast, we're talking with Parth Shah and Rikke Hovgaard about Agentforce Coworker and what it means for the way admins help teams get work done. Now, this isn't just about turning on another AI feature. It's about bringing trusted business context, permissions, data, and automation together so users can ask better questions and take action faster. Parth and Rikke are going to walk us through how Coworker connects to Salesforce data, how it respects existing permissions, and how it gives admins a simpler path to roll out and governance. So, be sure to listen in, press that subscribe button if you haven't already. And I would always appreciate it if you could share this episode with a fellow Salesforce admin. And with that, let's get Parth and Rikke on the podcast. So, Parth and Rikke, welcome to the podcast. Rikke Hovgaard: Thank you for having us. Parth Shah: Thank you. Mike: Well, I'm glad we could get you both on. This is the first time I've had a product manager and a product marketing major on a podcast. Usually, one of them has something too important to do that they bail out, but I'm bringing people together. It's going to be great. So, we're going to talk about Agentforce Coworker, but first I want to learn a little bit about each of you. Parth, I'm just going to start with you because you were the first one to bug me in my Slack DMs about Agentforce Coworker. So, I'd love to learn just a little bit about how you came to Salesforce and what you currently are working on.  Parth Shah: Yeah, absolutely. Slack makes it really easy to bug my Coworkers, especially my favorite ones. I sent a lot of emojis. So, sorry, Mike. Mike: Oh, I'm your favorite.  Parth Shah: Yeah. So, a bit about me. I grew up in Ohio, was a chemical engineer in undergrad, which really I love to build things and I love to, I guess, solve complex problems. And then when I graduated, I didn't want to go work in a plant, in a chemical plant. And so, I ended up going into sales within oil and gas. Did that for about three years, really understood how to actually talk to customers and what their pain points are. And then switched over to a really early stage startup in education technology, really passionate about education. Did that for about three years, which is where I learned a lot about product marketing. Then got my MBA and then joined Salesforce. So, been at Salesforce as a product marketer for about coming up to seven years. And what's been kind of interesting is I started off on the MuleSoft side of Salesforce, so all about integrations. I really learned what it means to connect data between different systems and how developers and admins go about doing that. And that's when I switched over. MuleSoft wanted to launch a new product called MuleSoft Composer at that time, which is now Flow. So, the next level of after connecting data is like, how do you actually use that data to automate processes and make it super simple for admins like our viewers out there? So, help launch that and then moved over to our Data 360, previously data cloud business. And here, I focus on everything that is around unstructured data. So, again, the through line here, if you look at data is, now we can start tapping into the unstructured data that's all out there because of AI. But the more important thing is now that AI is coming in, how do we actually bring that data, which is full of richness in audio, video, meeting notes, et cetera? How do we bring it into AI so that AI is really grounded? And so, that's been kind of my journey. Obviously, looking back at it, everything kind of connected. I didn't know at that time, but the through line I think is my curiosity of what's next within tech has kind of propelled me to go and find out and work on the cool next product that's coming up, which is also how I land on a Coworker. Mike: Wow. I would've had no idea that you started in oil and gas. Also, what's sales like in oil and gas? Hi, do you want any? Yes. Parth Shah: Cool. Yeah. It's very old. It's a very people oriented business. Mike: Yeah. All right. Well, I had to get that joke in. Rikke, I know you're letting me say your name that way, but in all fairness, being German, there's names that we just can't pronounce. So, I'd love to hear how you got started at Salesforce and obviously you're working on Coworker now. Rikke Hovgaard: Yeah. So, originally I'm from Denmark, which is why my name is a little hard to pronounce. Believe it or not, that's actually a pretty common name in Denmark. So, Rikke is fine here, but I started out after university working for a consultation partner. So, I started implementing Salesforce randomly, started out with Sales Cloud, Service Cloud, moved over to Pardot and Marketing Cloud when that was acquired by Salesforce and ended up also doing a little bit of data and analytics there. And then I decided it was time to move on to other things. So, I joined another partner in London and I moved to London and did that for a bit. I was working a lot on analytics at that point and also marketing. And so, it was mostly focused on what we know now as CRM Analytics and I started a blog on it as well. And so, a few years into it, I joined Salesforce in the CIM Analytics product team, helping customers get the most out of CIM analytics, deescalate some of their issues, best practices, all this kind of stuff. And I think that's where I also got a lot more involved with the community. And then I joined later in Data Cloud, moved over there and about two years ago I started the team with the search team in Data Cloud and we had this idea of Coworker and I ended up working on the admin side. And today I own the Coworker setup experience as well as search manager. Mike: Oh, wow. I mean, all roads lead through Data 360, literally and figuratively. So, Parth, let's talk about that. I mean, for anybody that hasn't heard, what is Agentforce Coworker and what is it there to help with? Parth Shah: Yeah. So, Agentforce Coworker, it is your autonomous AI teammate and it's available in Salesforce and it's also going to be available in a lot of different services like Microsoft Teams, desktop, mobile, ChatGPT, Claude, and a lot more. Fundamentally, what it is is it's an AI assistant that knows your business from day one. It's already connected to all of your enterprise data, whether it's structured, unstructured, your opportunities, your cases, your accounts, all of that context that you have within Salesforce and then what's connected to Salesforce. And of course, it respects all the permissions when you do connect those systems. So, it's grounded in your context from the first prompt that you ask. Number two is it can also orchestrate a lot of your agents. It can also execute a lot of complex tasks so that way, it moves your work forward. In other ways, it takes action on your behalf and you can actually update your CRM using Coworker. And then lastly, we built that headless. So, what's really cool about this is yes, it's available in Salesforce, but now you'll be able to take that Salesforce experience and that data and the context that you've spent so many years building into wherever you work. Now a question that we usually get is like, why do we build it? What was kind of the reason behind it? What's the pain point that is really trying to solve? And I think if you look at the industry trends, what's been interesting and what's kind of been going on is you've seen AI obviously augment software engineering, right? It's writing code and it's improving their productivity, but when we think about how business users actually do their work, it's quite different than software engineers, right? Of course, AI can help write emails, it can create the docs. We're going into customer service, but it gets a bit more complex because in our day-to-day work, we're switching a lot between different applications. We're copy pasting a lot of different data from one application to the next, for example, from Slack to Google Docs and so on and so forth. And it's not adding as much value as it does for software engineering. And so, we said, "Okay, how do we bring all of that context that you have wherever you work into a product that brings in AI and actually helps you do the work so you can focus on a lot of the other things that are more important, like building your relationship?" And Salesforce being Salesforce, we said, "Let's bring in that context and we have that AI and let's put it into Agentforce Coworker, which is where also Salesforce, our users work." And the second thing that we also did on top is if you think through where most of your work actually starts, which is again, very different than how we think about agents in general, it starts from work. Anytime you have a question about a task, you go to search. And so, we said, "Why don't we turn that search into something agentic where search gets you answers and then answers can help you take those actions?" And so, fundamentally what we've done is we brought in that context and made it really easy for our users to use Salesforce and fundamentally get a lot more value out of Salesforce and all the things that it can do with the data that you have.   Mike: Yeah. I think what's cool is Coworker's not just for admins. I mean, we'll talk about that, but it's for all of your users. So, one question based on everything that you said, just to make sure that I kind of wrap my head around it as an admin, if I'm setting it up, I can permission what it can and cannot have access to in terms of data. So, if I have, let's say payroll data in Salesforce, I don't want to give it access to that so that Bob and sales can go down and be like, "Hey, I wonder what Sally makes," and then ask Coworker and get a response, right? Rikke Hovgaard: Well, we're actually using the same permissions that you've already as an admin set up in Salesforce. Mike: Oh, great. Rikke Hovgaard: So, there's nothing extra to set up. We tried to make the setup experience super simple and one of that is also, of course, knowing what you've already set up in terms of permissioning. So, if you have in your object given access to something, then the user that is locking in will be able to see that. And if they don't have access to it, they won't be able to see that data either. Mike: Gotcha. Wow, that's huge. So, it automatically just respects the user's permissions as opposed to me the admin having to go and set something up for it. Rikke Hovgaard: Correct. Yeah. Mike: Wow, that's really ... I mean, what's funny is every time I see or work through some of these new products, I'm like, "Oh, well that totally makes sense." Except I think that was probably really hard to do. So, it's always really cool when it happens. It's like intermittent wipers, I suppose. Rikke Hovgaard: Yeah. Well, we have some amazing engineers that figure out all the architecture and build this stuff. So, I can't take credit for that, but I guess from my point of view at least, as an admin, there are so many things that you have to learn with all these new features. And so, our vision was really to try and make the whole setup simple. We also wanted to be transparent around the permissioning and the governance around it. So, we've also tried to balance that, but it's also how much information do you give upfront? How much is in the documentation? So, it's a fine balance to try and make it all simple enough. Mike: Yeah. Now can we talk a little bit about the design of it too because I've seen, thankfully I've had an org and I got to play around with it and it couldn't be more intuitive. I'm sure it could be, but can you talk about what went into how you thought about what that user experience is looking like? Rikke Hovgaard: So, I think it's really down to the jobs to be done. What are you trying to achieve? And that's why the ask mode is very much focused on just asking the question and having that conversation. We wanted to make that a very clear, crisp understanding of what is it that you're supposed to do on this screen. I don't know if you had a chance to also play with the other part, which is we also introduced a new search experience and here that's more of a balance where we're trying to figure out, well, all the things that people love from the original search and how do we bring that in as well as also how do we make it a little bit more new and look a little bit more or nicer, so to speak. I think that has been a little bit of a challenge when we're thinking of all of the data that you can bring in Coworker compared to what we have in Global Search. And now I know we're going a little bit more into the admin side of things, but in order to display things correctly, we need to make sure we also have the information of the data in order to show it correctly. So, that has been an interesting challenge to look at, but yeah, really trying to make it super easy for users to know what they actually have to do, prompt them to get the most out of the tool. Mike: Yeah. I mean, it almost feels like at times there's a balance between making it super simple and having people trust it and making it a little bit more difficult just so that people trust it because you've gone through it. And if it's almost too easy, then it's like, "Hmm, but did it really do? Is it really..." I can always feel that anxiety in a user or an executive when you demo something the first time and they're like, "Yeah, but does it really do that?"  Rikke Hovgaard: Especially also when we think about AI, we're putting a lot of trust into it and allowing us to get the answers that we're looking for. And so, I think that's why the whole thinking steps that we have implemented is super important for the agentic response. So, we built a level of trust or transparency in what is it that we're actually looking and giving that information to the end user so they can see how we got to the result. Mike: Yeah, absolutely. Now trust and governance is top of mind. It's literally the first thing everybody talks about with AI. Can we talk a little bit about how that works with Agentforce Coworker and maybe some of what you're seeing in the beta version? I feel like I was on that Agentforce Coworker page and there was an admin on that page that's awfully familiar to a lot of the community that had some great quotes. Rikke Hovgaard: Mike, let's maybe start with how do you actually set up Coworker. I think that will lead into how do we control the permissions and- Mike: Yeah, let's start there.  Rikke Hovgaard: Okay. So, the vision we had with the setup page, because if we're being honest, we are using features from other parts of Salesforce. So, we're using Agentforce, we are also using Data Cloud, we're also using global search. So, the thought that we had in the beginning was that's a lot of steps and hoops for an admin to go to in order to set up a Coworker. And so, our vision was really, how can we simplify this? How can we get an admin up and running super-fast? That doesn't mean that they don't have more things they can do, but from the first click turn on to they have access to Coworker, we wanted that to be super simple. So, we have defined a bunch of steps that has to be done in order for you to use Coworker. One, for instance, we have to create the search agent. So, when you click turn on, you actually go ahead and we've automated a bunch of steps for you that goes ahead and creates the things that we need to get Coworker up and running. And in that we've created the agent, we created the permission set group that you need to give access to users and we also have enabled your Salesforce data out of the box. So, any Salesforce data, any custom object, any default or standard object that you have is automatically searchable just by hitting turn on. Now, since we are in a beta, we still need you to opt into the beta. So, there is a little step that some people might miss, which is just go ahead and opt in so you have the new search experience in the front end with the global search bar and the ask button. And then the final step in order to get a user to access and use Coworker is to assign them this permission set group. Essentially, if you're an admin, you're probably familiar with different permission sets are giving you access to different things. So, you need to have a permission set for your agent, you need to have a permission set to use some basic features of Coworker and there's some other things, but essentially we're bundling all of this together in the permission set group. And so, all you have to do is directly from the page, the setup page. You can assign your users directly from that, or you can use the permission sets or permission set group from the user setup page as well. So, that's to say that we tried our best to make everything as simple as possible and then you can lay additional features on top of that with external data, et cetera. So, this is how we are controlling whether or not you have access to it, just permission sets and permission set groups. Mike: That's very easy. So, if an admin turns it on, it's not just available to everybody. Rikke Hovgaard: No. Mike: You can choose whether or not maybe you want a small set of users to try it out first. Rikke Hovgaard: Exactly. Mike: Perfect. Rikke Hovgaard: This is all permission based. Mike: I like it. Parth Shah: Now Mike, following on that, I think if we look at trust, trust goes I think even beyond permissions. And I think one of the beautiful things about Coworkers is built on Salesforce, the Salesforce platform that we all know. And so, it automatically inherits a lot of the security and governance, the data residency controls, the access based policies, audit logging, all of that, that Salesforce has that automatically inherits that. So, to kind of give you a couple examples, when it orchestrates across agents, the agents that you've built, they all have observability and monitoring because they're built on the Agentforce platform. So, you have access to that. So, you have an understanding of what it's trying to do and then also the actions that it's taking and how it's doing it. That's number one. And then if you also look at the data itself, if we look at some of the data built into Data 360, that already has a lot of policies built into it. It also has masking built into it, right? And so, it automatically inherits those. And so, when Coworker actually gives out that response, it's not just looking at the permission sets for the user themselves, but it's also looking at the data and the agent side of governance, security and the trust that comes with the Salesforce platform. Mike: Oh, wow. I mean, that's really, really beneficial there. I was thinking, Parth, you mentioned Data 360. Ironically, both of you have worked in Data 360. Outside of Agentforce just being able to answer questions around the data that we have in Salesforce, we can also give it the ability to get information elsewhere. Can you explain a little bit more about that and kind of what an admin would be configuring and possibly doing there? Parth Shah: Yes. I can give ... Oh, sorry, Rikke, go ahead. Rikke Hovgaard: Oh, no, you can answer. Parth Shah: No, no, no, go for it. Go for it. Go for it. Well, I'll give a high level overview. You can bring in connectors to connect to external sources and then you can also ground a Coworker on the Data 360 data that you have. So, then Rikke, go on. Rikke Hovgaard: Yeah. So, we knew that we wanted to allow Admins to go ahead and take all of this rich data that they have ingested into Data Cloud and use that as well. So, when you are on the setup screen, we have a little data table as we call it that shows that you've set up your Salesforce data by default. And when you click, there's a little button there that says add more data and in here you can go ahead and add any of the data that you have already ingested into Data Cloud. So, if you have unstructured and structured data in Data Cloud that you want to go ahead and make searchable, you go ahead and go through that flow. And what we've done is very simple model where you select the DMOs that you're interested in. You then have for each one of these DMOs select some search metadata because what I said earlier, it gets a little bit tricky sometimes. With Salesforce, we already know what is the name field. We know what is a supporting field. We know how the layout is, we know the ID, et cetera. For DMOs, we don't know always know that. So, we allow you to go ahead and make those selections, finish that process and at the end we go ahead and create a search index for you that we can use both for the keyword search that appears, but also for the agentic responses that we have. Mike: Wow.  Rikke Hovgaard: So, that's how you can add that data. But I actually remembered that we haven't actually talked about getting Slack data in as well. Mike: Oh yeah. Let's talk about that. Rikke Hovgaard: Yeah. I know that you mentioned Teams, but we also hopefully have some admins out there that have Slack and we've also made that super simple. So, if you've already authenticated Slack within your Salesforce environment, you can go to that same ad data model and you just select the Slack, you click next and you click save and then you also now have Slack data just within your Coworker experience. And this is again, this is actually federated. So, we're looking at the user and you're only getting access to the data that you have access through that user connection. So, that's another really interesting thing that I would definitely use in my Coworker experience. Mike: Yeah. And it just pairs really well. That way, you know there's conversations happening in Slack that would need to be brought in. Rikke Hovgaard: Yeah. So, we use Salesforce obviously in Salesforce ourselves. We have our own engineering product engineering environment and in there we've enabled Coworker as well. And so, one thing that I ask a lot is for specific work stream that we're working on, I want to get an update that includes both the work items that I have in Salesforce, but it also includes all the Slack conversations that we're having on the side. And I get an update just by asking Coworker about what's happening. I know which engineer is working what work item and what risk or whatever else we might have that we have to, that might need my attention. Mike: How stressful were you when they turned Coworker on in that org? Because all the other product managers are just eyeballing, right? Is this going to work? I wouldn't sleep that night. You kidding me?  Rikke Hovgaard: I actually felt pretty confident in it. I can't turn it on myself. I'm not an [inaudible 00:25:12]. Mike: Oh, well, that's good. Rikke Hovgaard: But I did have very great collaboration with our admins, both on the GUS and TheOrg62 environment. And I leveraged my partner experience or my implementation experience. I wrote a really detailed walkthrough. I had amazing help from my engineers and it went pretty smoothly, and we had some check-ins every day. We watched the numbers grow and it was pretty cool to see.  Mike: Yeah, I could imagine. Parth, I know we've had some customers in the product as well because it's in beta. What have they had to say? What were some of the things they've shared back? Parth Shah: I think this is one of my favorite products to work on in my career. Mike: Oh, you say that about all the products.   Parth Shah: No, no, no. I say this seriously. I say this seriously because every time I've talked to a customer, they're so excited about it. I'll give you an example. Andrew Russo, he is currently a VP of business systems at, I'm saying it correctly, BACA Systems. And when he first heard about the product, I think Mark Benioff had tweeted about it, he heard about it. He was so excited to quote and kind of paraphrase a bit, he's like, "I felt like Santa Claus on Christmas bringing it to my team." And the use cases that he started seeing was like, start something super simple with a sales and business development team. One of the use cases he mentioned was, let's just get all of the context that we haven't reached out to.  And I think he had mentioned something along the lines of like, it was a holiday coming up and this would've taken up so much of their team's time to actually find the contacts and reach out to them. Coworker did it really quickly and their teams were able to quickly reach out to the customers they haven't been able to reach out to and they were able to engage them. And so, this just kind of shows you the power of Coworker doing the work in the background so that your sales teams can actually focus on what matters, which is building out the relationships. I think overall, when I think about the use cases and how customers have been using it, what I repeatedly hear is the use cases are endless. There isn't just one use case that kind of shines. That's really the power of AI. But what it allows you to do is it allows a person to be as creative as possible. And I think as admins or the folks that are kind of introducing it, what I've seen work really well is nurture it. Give people one or two small use cases to start with so they start to see the power of it and then the natural curiosity of that team just kind of takes over. They're like, "Huh, what if we just get more complex?" It's almost like, can you thump Coworker? And the queries and the prompts that you put in just get more and more and more complex. I mean, even internally, we were recently working on a product of like we introduced a new feature, so how do we email the customers? And part of that is we want to make sure that they have the right license. Historically, that would've taken a long time, but we're like, "Huh, I wonder if Coworker can do it." Coworker kind of became a part of natural language, I guess, that you talk about every day and you naturally go to it because you start seeing the power of it and you're like, "Let Coworker do it." So, I think that's what I've seen is seed it and then just watch it grow. And then once you watch it grow within one team, take that idea, take those wins and take the people that have used it and they will talk about it to the other teams. Mike: Well, I feel like Thursday night bowling league's going to get awkward when six of you are standing around and going, "I feel like we're missing somebody. Didn't anybody invite Agentforce Coworker?" Oh. They couldn't make it. They're stuck at the office. That's it. That's the one joke for the podcast. It never really lands and people always give it a bad review, but that you got to try every now and then. To kind of wrap things up, I always like to see what other people do. I feel having talked with a lot of people in technology, we often have very tactile hobbies or things that we like to do on the side. I'm usually pretty obsessed with my lawn. I can tell you soil levels and pH and all kinds of stuff that's not fun unless you're into lawn care. But Rikke, I'd love to know outside of making Agentforce Coworker awesome, is there a fun hobby that you have that you use to get away from Coworker every now and then? Rikke Hovgaard: I don't know if I would say hobby per se, but for me, I really like going out by the water. I actually bike quite a lot out to the beach and then I have a puppy that I just let run around and that gives me a lot of common peace. I mean, hobbies, I don't think I have anything that I'm super nerdy about except for sometimes I get a little detail with some of my own data, but I feel like that's a little bit too close to work to mention as a good hobby. Mike: Yeah. I'll take the biking thing. Boy, of all the dogs I've had, that was the best way to get them to run. Especially when you've been inside in meetings all day and they're like, "Mom, can we go for a run?" And you're like, "Yes, we can." That was about the only way I could keep up with my dogs was a good mountain bike. Rikke Hovgaard: And I trained him early enough to actually jump in, or not jump, but I put him in a basket and we go.  Mike: Oh, mine were always too big for that. They're either making or they're not. One time though, he was running and I used to live in an area that was under construction. They had a manhole cover off and he was running along just beside me and one of his feet hit that manhole and it popped out of joint and that's when I learned how heavy a 30-pound dog is to carry over your shoulder and mountain bike back to the house and call the vet. Parth Shah: Oh, no. Mike: That was the only time I carried him. No basket for me though. Rikke Hovgaard: Yeah. I'm happy I have a small dog now. Mike: Right. Rikke Hovgaard: Yeah. Mike: Note to self. Buy a small dog that's easy to carry. Parth, I mean, you've been doing a lot of things. Plus you were in the Buckeye State, so I don't know, football. Parth Shah: I watch football. I'm in New York, so go Knicks, Knicks in 5. Also, I love this question. Rikke, I had no idea that you bike. I would love to bike with you someday and obviously bring your dog. Rikke Hovgaard: I mean, it's not like a race kind of thing, but yeah, I like biking around. I don't have a car. So, that's the only way I get around. Parth Shah: Yeah. So, I live in New York and there's a lot of things that I absolutely love to do. What I've been really focusing on is one, I love going to museums. I absolutely love going to museums so much that I've pretty much checked out every single museum in New York and I'll go to them again. Part of that is just like it invokes this creativity in me, which is why I'm a marketer, just to see how other people are thinking through life and kind of portraying it. Second thing that I've been trying to get it more into is I've been trying to do a lot more of comedy. I know it's not coming through right now, but that's something that I want to work on. And then the last is yoga. Yoga because no AI is there in yoga. It's just me and myself. Mike: Not yet. Parth Shah: Not yet. Mike: Somebody will invent an AI mat. Parth, your downward dog is not doing so well. Rikke Hovgaard: There's those mirrors where you can get workout commentary on your- Mike: Oh, that kind of weirds me out.  Parth Shah: Oh, me too. Rikke Hovgaard: Yeah. Parth Shah: I can't do that. Rikke Hovgaard: I prefer my workouts to be just me and whatever I'm doing. I don't need any instructions to do. Mike: You're biking your dog. Rikke Hovgaard: Yeah. I mean, I do other things too, but I would say I don't like anybody commentary on what I'm doing. Mike: Nope. Nope. Parth, that's so cool. I love the museum part. The presentation nerd in me loves going to museums and paying for the guided tour just to see the person and how they kind of direct people through because there's often a lot. There's a lot of people to pay attention to. There's a lot of information. I don't know. I like walking through museums all by myself. Don't get me wrong, but if I can do a guided tour, I always find that kind of fun too. Parth Shah: One tip someone told me is look at the artwork and then also look at the people looking at the artwork. That itself is art as well. And I was like, "Whoa." Mike: Yes. Yes, absolutely. Rikke Hovgaard: I also find that a lot of museums are starting to have free tours with a specific theme. So, they take you on a path. I've noticed, at least when I was in Europe last time, there was a couple of museums doing that. So, something worth looking at the website all the time, because I definitely like having somebody cover a theme and take me through a journey in the museum. Mike: Yep. I've been through a few where they have an app on the phone and you can just listen to and it walks you through. And that was always kind of fun because I feel there's a lot to take in and I'll read the plaque or the information by it, but it's like they can't put everything there. I know I did a few where I think they had the artist kind of comment in addition to what the information was and just kind of standing there and hearing in the artist's own words and seeing their work, it was very powerful. So, very cool. Well, see, it's not all about AI on the podcast. Every now and then we talk about some things that are fun. I want to thank you both for coming on. I think we covered a ton of stuff and I'm excited to see the future versions of Agentforce Coworker. I'm not going to ask you what they are because it's in beta and there's a big roadmap to come, but I think it's going to be very exciting for admins.   Rikke Hovgaard: I think we have some very exciting stuff coming up. We have a lot of good ideas from customers and from what we're thinking about ourselves. So, I think you have something.  Mike: Oh, I could only imagine. And I bet we're going to see some of them at Dreamforce, right? Rikke Hovgaard: I am sure we will. Mike: Knock on wood. Great. Well, Parth, Rikke, thanks for coming on the podcast. Rikke Hovgaard: Thank you for having us. Parth Shah: Thank you for having us. Mike: Big thanks to Parth and Rikke for helping us unpack Agentforce Coworker from search to Slack to that magical moment when users ask, "Wait, it can do that." Oh yes, that's the best. Admins, this is your lane, connecting the data, guiding the rollout, and making sure AI helps the business without wandering off with the keys to the org. Now, if you haven't already, press that subscribe button, share this episode with your favorite Salesforce admin or your favorite Coworker. Maybe they're one and the same, or invite a Coworker to a bowling league. Just say it. It'd be fun, wouldn't it? I'd like to go bowling. Just don't expect them to rent the shoes. Maybe you rent the shoes. I would buy the shoes. Other people have worn those shoes a lot. You never know what could be in those shoes. Anyway, until next time, we'll see you in the cloud.  
  • What are Security Essentials for Salesforce Admins 18.06.2026 33min
    Today on the Salesforce Admins Podcast, we talk to Laura Pelkey, Director of Customer Security Communications and Engagement, and Sabrina Simeroth, Product Manager for Security Center at Salesforce. Join us as we chat about security essentials for the summer and how Salesforce is helping admins protect their data. You should subscribe for the full episode, but here are a few takeaways from our conversation with Laura Pelkey and Sabrina Simeroth. Why admins are a target Security doesn't take a summer vacation. And while AI is helping all of us do more things faster than ever before, it's also helping hackers deliver new types of targeted attacks at scale. And as privileged users, admins are finding themselves in the crosshairs. Luckily, Salesforce is rolling out key security enhancements over the summer to help you protect your org. I sat down with Laura Pelkey and Sabrina Simeroth to talk about what threats are out there and how you can be prepared. MFA requirements to protect your credentials Because AI makes it easier than ever to imitate someone's writing style or even their voice, the biggest threats that Laura and her team are seeing are different variations of phishing attacks. In the end, it's all about getting someone's credentials and then using that access to do damage. That's why Salesforce is requiring all customers to use multi-factor authentication (MFA), as opposed to the gentle nudging we've done in the past. However, MFA can still be vulnerable to man-in-the-middle attacks, so admins and other privileged users will need to use a stronger phishing resistant MFA. Finally, Salesforce will require step-up authentication for users attempting a sensitive or unusual action, like exporting a large file. I don't have to tell you that these kinds of changes can often be met with resistance. Laura recommends framing things in terms of what they protect your users from. Does a salesperson really want a hacker to email everyone on their contact list from their account? It's not about making you jump through hoops—it's about protecting you from real risks. Security Center Essentials and Health Check give admins a central view We also checked in with Sabrina about how her team is trying to make it easier to get a handle on essential security configurations across the platform and what settings are most critical. Coming in July, the new Security Center Essentials will let you see everything in one place instead of having to wade through a bunch of permissions and toggles. Health Check will help you prioritize which changes will get you the biggest bang for your buck, and help you track your security posture over time. "It's all about allowing admins to navigate the security space in a way that helps to reduce the complexity and provide some guidance," Sabrina says. There's a lot more from Laura and Sabrina about security on Salesforce and what's coming next, so make sure to listen to the full episode. And don't forget to subscribe to the Salesforce Admins Podcast to catch us every Thursday. Podcast swag Salesforce Admins on the Trailhead Store Learn more Salesforce Help: Security-Related Product Updates to the Salesforce Platform: User Identity, Data Protection, and Access Controls Trailhead: Use Health Check to Scan Your Security Configurations   Admin Trailblazers Group Admin Trailblazers Community Group Social Laura on LinkedIn Sabrina on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X   Full show transcript Mike Gerholdt: This week on the Salesforce Admins Podcast, we're talking security with Laura Pelkey and Sabrina Simeroth. The threat landscape is moving fast and with AI in the mix, attackers are getting better at targeting privileged users like Salesforce Admins. But in this episode, it isn't about fear, it's about readiness, trust, and the systems admins can put in place to protect our orgs. We'll cover MFA enforcement, phishing-resistant MFA, step-up authentication, and how Security Center Essentials gives admins a clearer view of the settings that matter most because today's admin isn't just managing features. They're designing secure, trusted systems that help businesses move forward. So, let's move forward with this podcast and get Laura and Sabrina on. So, Laura and Sabrina, welcome to the podcast. Laura Pelkey: Hello? Sabrina Simeroth: Thank you. Thanks for having us. Mike Gerholdt: Absolutely. Well, it's always good to talk security. I feel like I was watching the news the other day and they talk about kids when they go to school and then they have the summer off and there's that summer slump of information. I feel like maybe over the summer we kind of have a security slump because we're taking time off and we're going to water slides and watching tornadoes in the Midwest, but maybe I'm just crazy thinking about that. Laura, why don't you catch us up and tell us what's going on with security and some of the newest things in summer 26? Laura Pelkey: I would love to. And I was just going to say our catchphrase, which I feel like I repeat every time we do a podcast together and that security never sleeps even in the summer. Mike Gerholdt: Oh, yes. Right. That could also be a fun summer action film. Laura Pelkey: Yes. I would see it. Mike Gerholdt: I would. Laura Pelkey: Yeah. So, I mean, we're halfway through the year, which is crazy already. And I'd say in the last year we have seen the security landscape and the threat landscape shift tremendously. And especially, I mean, I think a lot of people at Salesforce and a lot of people who are listening are very aware of and use on a day-to-day basis, AI nowadays, which is great. It's a very powerful tool. But what we're seeing in the security landscape is that AI-driven cyber threats have emerged and hackers have really up-leveled their ability to create and execute targeted cyber attacks faster than ever before. So, it's kind of crazy the speed at which this is happening. And unfortunately, I think we're going to see their capabilities get better and better as these tools evolve. Mike Gerholdt: Well, that's not fair. We're supposed to use AI for good. Laura Pelkey: Yeah. Well, the good news is, so yes, I agree. The good news is that providers are now using the same AI models or better AI models if you're in the lucky groups to enhance the security of their platforms and products. So, now the playing field has really been evened out. Mike Gerholdt: Well, that's good. Laura Pelkey: Yeah. But we're in a really interesting time right now with cybersecurity and AI. Mike Gerholdt: I mean, I feel like everybody's trying to figure out AI and now that kind of only muddies the water of impersonating other people or the speed at which it can replicate good or bad effective use of, I don't know, text messages or different spoofing. Can you walk us through how does Salesforce leverage AI to proactively block the type of threats that you're seeing today? Laura Pelkey: Yeah. So, there are some really common threats that just across the industry we're seeing that AI is being used for. So, account takeovers and this is a really common one. This is where attacker might use AI to create a phishing campaign, which targets users and tries to get access to their account. And then once they're inside a user account, they can then utilize all of the privileges that that user has to continue carrying out their attack. So, it's really about getting credentials, finding creative ways to get around our existing solutions to get those and then get that user profile and exploit it. Mike Gerholdt: Yeah. I think one thing that you've pointed out in the past is identity-based social engineering. So, I'd love for you to kind of expand on what makes admins and some privileged users such high-value targets for that. Laura Pelkey: Yeah, that's a great question. So, identity-based social engineering is when attackers create very highly personalized phishing campaigns and this can be phishing. Traditionally, we saw that with email five years ago it was primarily email. Now we're seeing phishing campaigns and especially with the help of AI, attackers are conducting these campaigns over voice calls. So that's called vishing or voice phishing. And admins are such a appealing target for these attackers because they're privileged users, they have such a high level of privilege and they can do almost anything within their Salesforce org. And so, that persona in general is highly targeted by attackers because of their level of access. Mike Gerholdt: What would you suggest an admin listening to this do today to start just being ready for if that phone were to ring and it was a malicious actor on the other end? Laura Pelkey: Well, I mean, we always say use common sense. So, there are a lot of built-in protections that I can talk about within the Salesforce platform that will help protect admins, which is great and I'll talk about those in a minute. But if that ever happens, if you are an admin and you get a call from a number that you don't know, from a person that you don't know claiming to be your help desk or claiming to be even Salesforce in some cases and they're asking you to log into your Salesforce account for them so that they can help you do something, that's typically how these things are positioned, that kind of scenario is never going to legitimately happen. No one's going to call you or email you and send you a link and ask you to log into your Salesforce account ever. That's just not something that we do. So, look for red flags like that. And in general, whenever you're suspicious about something from a cybersecurity perspective, the best thing to do is disengage with whoever is trying to speak with you or engage with you and get you to do something and then hang up the phone, don't email back whatever it is and then call your help desk line or call your Salesforce account person in a number that you already have and that you are already confident in and that way you can verify if that interaction was real or not. Mike Gerholdt: Yeah. I think the thing that always struck me when you would bring it up or somebody from your team, Laura, would bring it up is it's that human nature side that they try to take advantage of like, "Oh, you want to be helpful and you don't want to cause a problem." And so, you just kind of go along with it and it's like, yeah, you're not causing a problem if you just say, "Let me call back the number that I trust and talk to somebody there." Laura Pelkey: Yeah. Yeah. And you can do that in any scenario. If it's like your bank, someone calls and says they're from your bank and they're reaching out to you, that probably isn't going to happen. So, what you said, Mike, is exactly right. The reason that people are exploited is because we have these human behaviors, which human behaviors are great. They make us who we are, but false urgency is one of these tactics that attackers will use and they'll try to get you to do things quickly without really thinking about it. So, if we feel like goosebumps or we kind of have a weird feeling about why is someone calling me and asking me to log into my account, we can just stop and think and that's the best thing you can do to break this cycle. Mike Gerholdt: Yeah, absolutely. Well, let's talk about some of the security enhancements that has come out over the last few years. I mean, we have MFA and we have a whole bunch of other things. Laura Pelkey: Yeah. Yeah. So, we're very aware that this threat landscape has shifted and that it's our duty to protect our customer's data as it always has been at Salesforce. We take that super seriously, trust. Trust is our number one value. And so, to better help our customers protect themselves against these quickly evolving threats, we have some new enhancements and some new requirements in our platform that will help harden our customer security posture against these kinds of attacks. So, one thing, I'll only talk about a few, but one thing, and everyone really should be using this because it's been around for a while, is MFA, like you said, Mike. And I think we had started requiring customers to use MFA back in early 2022, I think. So, it's been quite a while, but we're actually going to be enforcing that. So, rather than being contractually required, it's going to be enforced in the product, meaning you may not be able to log in if you are not using MFA. So, this is going to happen starting in June. There's a phase rollout based on sandboxes and production environments. So definitely check out the documentation for the exact dates, but it is starting now. So, soon all Salesforce customers will need to use MFA to log in. Mike Gerholdt: And I know we've done security workshops. I've seen you present a lot. One of the questions, and inevitably the person that is listening to this is like, "Yes, Mike's going to ask this question." That comes up in all of the security workshops is, "Well, we use SSO to sign in. Do I still need to use MFA?" And we just threw out a whole lot of acronyms there, so I'll have you explain them too. Laura Pelkey: Yes. So, SSO- Mike Gerholdt: Alphabet soup. Laura Pelkey: SSO is single sign-on. That's a great question, Mike. So, if you do use SSO to access your Salesforce instance, then that does satisfy the requirement, but we ask that you also use MFA on top of your SSO. SSO is great. It's a great tool to make it possible so that you don't have to remember a million passwords for all of your work apps. It's awesome. Just have to remember one, but as long as you are using MFA to access your SSO, you are satisfying this requirement as well. Mike Gerholdt: Awesome. You explained it and you used all the alphabets too. Laura Pelkey: All the letters in the alphabet. Yeah. Mike Gerholdt: It's like MFA is like bacon and SSO is like a cheeseburger. It makes it better. Laura Pelkey: Yeah, exactly. Yes, I love that. Mike Gerholdt: Because MFA is also just good on its own. I mean, I'll just eat some bacon. Laura Pelkey: Yeah. So you can either use MFA for direct logins directly into the UI or with your SSO login. Mike Gerholdt: So, this makes me think of, you talked about phishing. Oh, boy, this is where audio doesn't serve me well. Phishing and vishing, which there's the PH and the V, but because I'm from the Midwest, you can't hear the difference. Could you explain the difference between standard MFA and phishing-resistant MFA? Laura Pelkey: Yes. So, yeah, this is actually kind of a newer... Think of it as a supercharged form of MFA. So, what traditional MFA, you have two layers of verification before you can log into an account. With phishing-resistant MFA, you are actually bound to a specific site when you're logging in, which makes it harder for attackers who are trying to get you to log into those fake websites that might look real. It actually helps prevent that. So, that's why we call it phishing-resistant MFAs because that is a really common thing for phishing attacks to leverage is these man in the middle fake websites where you think you're logging into your actual tool or product, but you're logging into a fake version of it. And another thing that's great about phishing-resistant MFA is most users of this use biometrics as their second form, so like a fingerprint or a retina scan depending on the device that you're using to log in. So, that just makes it, again, harder to fake and harder to intercept. So, this is most companies are moving towards phishing-resistant MFA as it's so effective, and which is why we're actually also starting in June, so this month, we are requiring system administrators and privileged users to log in with phishing-resistant MFA. Mike Gerholdt: And why is that? Laura Pelkey: Because those are privileged users like we talked about, they're highly targeted. They're more targeted than their regular user and they have such a high level of access that if their account, especially were to get compromised like an admin, it could cause a lot more damage. And so, we want those folks to be extra, extra protected. So, phishing-resistant MFA we feel is the best thing to ensure that those accounts and those users stay safe. Mike Gerholdt: I like that. Now I know I've had to roll out different features to users and sometimes you can't do it fast enough because they love it and other times it's getting them to eat their vegetables. For admins that are worried about user friction with MFA, what would your advice be? Laura Pelkey: Well, hopefully your users are already using MFA. If they're not, we often find that if an admin holds a training, some informational sessions with their users, some kind of enablement before this change happens and also talk to them about the value that this provides to them. The last thing a salesperson, for example, would want is if their account got hacked and then their clients are getting emails that are sent from them, which are actually malicious. They don't want that to happen. No one wants that to happen. So, just there's some enablement materials that exist on the help portal that could be helpful, but really it's admins explaining and enabling their users why this is so important and helpful. Mike Gerholdt: One last thing, admins love reports and I feel like isn't Salesforce doing something to help admins set up different kind of reports or report actions to understand maybe when a user would log in that's outside of the normal behavior? Laura Pelkey: Yes. Yeah, I love that. Yeah. So, this is another enhancement that's coming this summer and it's called Step-Up Authentication and we're doing it for report actions and for anomalous report behavior. So, let's say one of your users all of a sudden wants to export a very large file or something. There's something kind of unusual about this. Anomalous is the word we use in the security community. Our platform is now able to flag that and will cause a step-up authentication toggle to happen. And if you're not familiar what step-up authentication is, it's basically like having to re-log in after you've logged in, which I know might sound annoying, but there is a really good reason for this. So, I always think of it as like the airport analogy. So, when you go to an airport, you have to show your boarding pass and your ID to get through the security line, right? Mike Gerholdt: Mm-hmm. Laura Pelkey: And then once you're through security in the airport, you have the freedom to kind of walk around, go get a coffee, go get some food, maybe go to the bathroom and you have freedom of movement because these are not sensitive actions, what we would call in security. But when you get in line at your gate and you're trying to board the plane, you have to again, show your boarding pass in order to get on the plane. And that's actually a step-up authentication. You can think of it like that. This is because getting on the plane is considered a highly sensitive action and requires additional identity verification. And so, that's what we're trying to do within the product. So, say an adversary or an attacker did get access to your Salesforce instance through a user and now they're inside and they're trying to do sensitive things or they're trying to do things that are very bad, we are now able to force them to verify their identity again, which would likely stop that action. Mike Gerholdt: Nice. Well, here's your Starbucks, but you can't board the plane. Laura Pelkey: Yeah, exactly. Mike Gerholdt: I like it. Laura Pelkey: I mean, if you lose your boarding pass in the airport, you can't get on the plane, right? Mike Gerholdt: I mean, you should- Laura Pelkey: Oh, wow. Mike Gerholdt: It also probably means I've lost my phone and the whole day is just going downhill from there. Laura Pelkey: That's a big problem. Yeah. Mike Gerholdt: I know. Laura Pelkey: But that's the thought behind that. Mike Gerholdt: Sabrina, we didn't forget about you. It's usually Laura has a long laundry list of things to talk about, but I'd love to bring you into the conversation. First of all, I think this is your first time on the podcast, so tell us a little bit about what you do at Salesforce. Sabrina Simeroth: Yeah, thanks so much for having me again. I am a product manager in our trusted services space for a product many of our admins may have heard of Security Center. Mike Gerholdt: Oh, yes, we've heard that. We like that. Yep. You should put it on T-shirts. We'd wear it. Sabrina Simeroth: Yes. And then also a lot of folks don't know that this team also actually owns the Health Check, which is available for all admins as well. Mike Gerholdt: We like Health Check too. That's a fun one to demo. You've created good demoing products. You know that? Sabrina Simeroth: Thanks. Well, we've got more actually. Mike Gerholdt: Well, let's talk about those because I think there's a Security Center Essentials launching in early July. Am I correct? Sabrina Simeroth: Yes. Yes. So, we are launching a version that will be of Security Center that will be made available in all orgs this summer and you are absolutely correct, that is going to be starting in July. So, a very fast follow to some of these changes that Laura has been talking about and really, hopefully this product will actually help alleviate some of those concerns and worries of admins who are looking to comply with some of these changes that are coming out in the security space. Mike Gerholdt: Can you just bring us up to speed on what some of those core problems or pain points were that this is going to help? Sabrina Simeroth: Yeah, absolutely. So, for admins, security configurations can kind of be really hard to navigate. They're found all across the platform and it's really kind of hard to know what is most critical. So, Laura was talking about things like MFA enabled. These are configurations that you can actually enable through certain permissions as well as toggles and setup. So, these types of security configurations is exactly what we are trying to provide visibility to admins so that they have a single place to see critical security configurations like their session settings, their MFA enablement, how are they set up to allow their users to actually enter the system, whether they're restricting it through login IP addresses and how do they have installed packages, external connected apps set up in their org. All of these things can impact their security and what information bad actors could get to depending on how they have their users configured. Mike Gerholdt: Yeah. I know you listed... This is going to be so cool, by the way. I loved when we had Health Check and we still do, and I love that this is getting available to everybody. You mentioned some of those metrics. I know there's about seven of them, I believe. If you're a Salesforce admin who's listening to this podcast and you're like, "I don't know where to start." Of the metrics that will be provided in Security Center Essentials, what do you think the biggest bang for the buck is in terms of improving their security posture? Sabrina Simeroth: Yeah, a great question. So, we're initially launching with a curated set of seven metrics. That's kind of our MVP for our rollout. We're going to have a very fast follow-on where we're expanding the number of metrics that will be very curated, very targeted to the things that they need to look at and that are probably most critical. The first one of the seven that I would say is really essential is that Health Check. So, on important thing is when we say Health Check is going to now be made visible in Security Center Essentials, Health Check contains about 44 configurations that are critical for your security. And with those configurations, Salesforce actually takes a stance on here's what we recommend is the way to configure those settings and have that set up so customers can actually take action and see if they're in compliance with that. So, the Health Check is going to probably be the biggest bang for the buck. And the great thing about pulling this into Essentials is now you can kind of track as these configurations change over time, you can see when those changes happened, how those changes occurred, and then you can take action to remediate that. So, Health Check contains those configurations around identity that we were just talking about enabling MFA, enabling SSO, how those are set up, what are your password policies and all of that information will be contained into this metric that they can monitor changes to those configurations. Mike Gerholdt: We'll play devil's advocate here for a second because I know some admins are listening and they think, "Well, that sounds cool." And the big organizations that have all the fancy bells and whistles will probably really benefit from this." Do you think smaller organizations will find value in some of these features as well? Sabrina Simeroth: Absolutely, because the things that we are talking about are the configurations, the critical items that actually impact every organization. It shouldn't really matter the size. These are the most critical things that administrators need to be aware of in order to ensure that they have an appropriate level of security, that there aren't gaps in their security posture. So, these are definitely things that impact all orgs of all sizes. And it really is allowing admins to navigate the security space in a way that helps to reduce the complexity and provide some guidance. And again, this kind of transcends whether you are in a very small environment, very few users because this is more configuration based, or you have a very large environment and many environments to manage. Mike Gerholdt: Yeah, no, that's really good. I think sometimes you forget how much there is out there and the best security is the stuff you never see because everything just works properly. So, this is great. I'm excited for it. I think come July, admins will be coming back from some PTO and have fancy new dashboards and things to look at. Sabrina Simeroth: Absolutely. Laura Pelkey: I can't wait. Also, I don't know if we can talk about this, but there's a couple of things on the roadmap that might be really interesting to admins too. Sabrina Simeroth: Yeah, absolutely. Yeah. So, like I mentioned, this isn't the end. So, the initial launch is just getting us started. As kind of a fast follow to the July launch, we will be incorporating even more metrics around providing visibility. Laura, you were talking about those privileged users and specifically there are certain permissions that are associated with administrative level permissioning. Those are kind of the targets for any users that have those permissions. That's where we want to try to find the weak spots and get in there. So, we are actually going to be pulling in our permission metrics, some related to this like export exfiltration, modify all data, those administrative permissions, exactly what's called out in this new phishing-resistant MFA enablement required for those types of users. We will have permission metrics so that admins can now monitor when there are changes to those access, who's granting that access, when is it being granted and they can take action to make sure that those permissions are limited to only the users that need those. And we'll continue to produce more metrics and visibility into some of these critical configurations and expanding that information in the months to come following the initial launch. Laura Pelkey: That's amazing. Mike Gerholdt: So there will be even more fun stuff to see at Dreamforce this year. Sabrina Simeroth: Yes, absolutely. Mike Gerholdt: I think in closing, because I could probably sit around all day and talk security, Laura knows that, but I'll start with you, Laura. And this question's for both of you. If everybody listening took only one action after listening to this podcast to prepare their orgs for the upcoming security changes, what should that single step be? Laura Pelkey: So, I would recommend immediately after listening to this going over to the help portal, help.salesforce.com and looking at our documentation where we're outlining all of the enhancements happening this summer. And there's a full list. It's going to give you all of the dates, all of the enforcement details, all of the pre-work, if there is any, to get your org ready for these enforcements that are coming out and we'll get you all set up so that it's a really seamless transition. Mike Gerholdt: That's great. Sabrina, do you have anything to add to that? Sabrina Simeroth: Yeah. No, I think Laura, her answer is perfect. I think gathering information ahead of time is so critical to ensure that you have a smooth rollout. So, definitely take a look at the help articles and then also leverage resources if there are questions around what these things are. There are so many resources on our help documents to help guide admins around what is this, what are the impacts and how do you implement these critical configurations? And I think that that's the first step. Mike Gerholdt: I know I've worked a world tour before and this leads me into my last question because I pointed out our trust and help services and where we used to have release notes. But if admins had a specific question about these enforcement changes and how they'll impact their unique org configuration, where would you suggest they go? Laura Pelkey: If they have a account success person, definitely ask them. They can also go to the Trailblazer community and we're engaging with customers there on these things. So, that's my recommendation. Sabrina Simeroth: Yeah. And I think Laura, you mentioned there are a couple of articles that have come out to help them prepare for the MFA enforcement and the specific things that we are enhancing. So, those are really great resources and those can also be found on the help.salesforce.com website. Mike Gerholdt: Yeah. And I can go ahead and link those in the show notes. Sabrina Simeroth: Awesome. Mike Gerholdt: So people can click on those. Sabrina Simeroth: That'd be great. Mike Gerholdt: Laura, Sabrina, thank you so much for coming on. I know there was a lot to cover and we could do this every month, I'm sure, and have a new fresh topic, but admins always need to be security minded. Laura Pelkey: Yes, we love that. Sabrina Simeroth: Yes, absolutely. Laura Pelkey: Always great chatting security with you, Mike. Mike Gerholdt: Absolutely. Well, I'm sure we'll do this again for the winter release or sometime before Dreamforce to get admins ready for that as well. So, thanks for coming on the pod. Laura Pelkey: Thank you. Sabrina Simeroth: Thanks for having us. Mike Gerholdt: Huge thanks to Laura and Sabrina for making security feel less scary and maybe even a little fun. We covered AI threats, MFA, suspicious phone calls, airport analogies, and why admins should absolutely know what's happening inside Security Center Essentials. Now be sure to check out the show notes for the resources we mentioned. Subscribe so you don't miss an episode. And then finally, share this with an admin who enjoys trust, dashboards, and keeping bad actors off the plane. Until next time, we'll see you in the cloud.  
  • How Agentforce Helped Build a Food Waste Solution in Days 11.06.2026 25min
    Today on the Salesforce Admins Podcast, we talk to Parth Sevak, Director of Technology and Principal Architect at Incepta. Join us as we chat about how Parth built a multi-agent system designed to connect surplus food with the people and organizations that need it the most and won the Agentforce for Good Grand Prize at the TDX Hackathon. You should subscribe for the full episode, but here are a few takeaways from our conversation with Parth Sevak. The Hackathon project focused on reducing food waste If you listened to last week's episode with Alexandra Iyer, you know that Agentforce for Good was a popular problem at this year's Agentforce Hackathon at TDX. Contestants took on big issues like nonprofit volunteer coordination and disaster relief. That's why I was so excited to sit down with Parth Sevak, whose project Harvest Bridge won the Agentforce for Good Grand Prize. Harvest Bridge is a multi-agent application that connects food donors with organizations near them. As Parth explains, food waste is a serious problem. According to the UN's World Food Programme, about 318 million people are facing acute hunger today. "In North America, 30-40% of the food that is produced never gets eaten," he says. So he decided that this would be the perfect problem to tackle for the Agentforce Hackathon at TDX.  Simple integrations and out-of-the-box tools Under the hood, Harvest Bridge features multi-agent coordination between four agents to handle donor intake, food matching, volunteer logistics, and reporting analytics. While it sounds incredibly complicated, Parth is quick to point out that 80% of the work was done in configuration with out-of-the-box admin tools. Parth needed to write some Apex to do specific things like geo-matching, which he vibe-coded with the Claude plugin for Agentforce. Crucially, he didn't have to write glue code to make everything work between Agentforce, Data 360, automations he built in Salesforce, Slack, and Tableau. "All of it just worked like a charm," he says, "five years ago, that integration story would have been months, if not years." How to get started building Agentforce solutions In just a few days, Parth was able to build an autonomous, multi-agent system that uses Agentforce, Data 360, Slack, and Tableau to match surplus food with local organizations and coordinate delivery in under 90 minutes. If you're looking to get started with Agentforce, Parth recommends jumping on Trailhead as your first step. The Agentforce Specialist certification gives you the tools you need to start building, and then it's all about getting your hands dirty. Make sure to listen to the full conversation with Parth Sevak about how he built Harvest Bridge and won the Agentforce for Good Grand Prize. And don't forget to subscribe to the Salesforce Admins Podcast so you never miss an episode. Podcast swag Salesforce Admins on the Trailhead Store Learn more UN World Food Programme Trailhead: Agentforce Specialist certification Salesforce Admins Podcast Episode: Agentforce for Good Shows the Power of Inclusive Innovation Watch the Demo Admin Trailblazers Group Admin Trailblazers Community Group Social Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript Mike: This week on the Salesforce Admins Podcast, we're talking with Parth Sevak about how a real world food waste solution went from idea to working system in just days using Agentforce. Drawing from a challenge that impacts millions globally, Parth built HarvestBridge, which is a multi-agent system designed to connect surplus food with the people and organizations that need it most. Now, this was part of the TDX26 Hackathon Challenge and what makes this conversation the most compelling isn't just the technology, it's how admins and architects can really orchestrate data automation, AI agents and human coordination together without months of integration work. We also get into what it means to design a trustworthy system where humans stay in control while AI handles scale and speed. So, if you've ever been wondering about how Agentforce changes the role of the Salesforce admin from builder to system orchestrator, this episode's for you. Be sure to subscribe, share the episode with your team, your friends, your local Salesforce admin user group and let us know what kind of real world problems you'd solve with Agentforce. But for now, we're going to get Parth on the podcast. So, Parth, welcome to the podcast. Parth Sevak: Thanks, Mike. Really glad to be here. Mike: Well, I'm glad to have you. So, if everything shakes out, the episode before this will be the episode with the Agentforce for Good People, but sometimes scheduling is what it is. But I was at TDX this year and we had Hackathon winners and you were part of the Agentforce Hackathon. And so, that's how I got connected with you. But I think before we get into that, I'd love to know a little bit about how you got started in the Salesforce ecosystem, what you do and let's go from there. Parth Sevak: Absolutely, Mike. Again, thanks for having me. So, the story of how I ended up in Salesforce is really interesting. That was not my plan. In fact, back in 2011, I was a fresh computer science engineering grade hunting for my first real tech off somewhere. And that time, the startup economy was just taking off and Java was the thing, the only thing in my perspective as far as I was concerned. And then my boss pulled me aside and said, "Parth, you are going to work on Salesforce." And I said, "Oh, what is Salesforce? I'm looking for Java opportunities." So, he made his pitch. "Apex is basically Java, you will feel right at home. And there is this thing called Dreamforce, massive event, you might get to experience it someday." And that's where you see a lot of enterprise innovation is going to come in. Basically, he sold it and 16 years later, here I am loving the challenge, loving the stretch, always finding ages I haven't touched yet and it keeps me motivated. Mike: He was a heck of a salesman. Java, here's Salesforce. It's just like Java. And if you're good enough, you might get to go to Dreamforce. That's awesome. So, go ahead. Parth Sevak: Yeah. And just to tell you what currently I'm doing. So, these days- Mike: Yeah, please. Parth Sevak: ... I'm working as a director of technology at Incepta Solutions where I lead data, CRM integration and agentic AI transformation for enterprise clients across financial services, retail manufacturing and pharma healthcare. But I make sure to keep one foot in hands-on building always. And that's how HarvestBridge happened at TDX, as you see. Mike: Yeah. So, let's talk about that. I mean, it's really cool. This isn't our first hackathon since we've come out with Agentforce. We've been doing hackathons and the early hackathons, I was a judge in quite a few and some of the really neat ideas that people were coming up with for the use of AI agents and some agentic use cases I think were really kind of interesting. I know we had that at TDX. So, I guess let's start off with the TDX Agentforce for Good Hackathon. What made you want to enter that to begin with? Parth Sevak: Yeah, to be really honest, it was again, my boss encouraged me because even I was not sure whether I would be attending the TDX in first place, but my boss was really motivated to join the party and he invited me. And then I realized, okay, if I register for TDX, there is an option to participate in the hackathon. And that's how my journey began. Mike: Oh, well, we made that awfully easy for you, didn't we? Parth Sevak: Yeah. Mike: I mean, I would like to think I'm a competitive person, but when it comes down to it, I think I really like watching competitions as opposed to competing. What made you think, "Oh, I'm going to get into this because the idea that I have is so great." So, tell me a little bit about what your idea was and what it solved for. Parth Sevak: Yeah. So, honestly, the topic I picked is not a fleshy topic, right? I picked the food waste, which is definitely not a hackathon topic. It's not a biotech, it's not a blockchain. But my heart said, pick it anyway because food is the most basic thing and somehow we managed to throw away nearly half of it while families a few blocks away are skipping dinner. And then again, I am a data guy, so please allow me to share some numbers here. Mike: Oh yeah, please. Parth Sevak: And that application for me, that 2.5 billion tons of food wasted every year, 783 million people are facing hunger. And when I read that and thought, "This cannot be right." And I check UN website, food banks' websites, and again, the numbers held up. And the on that hit really hardest is this number, which is in North America, 40% of food produced never gets eaten right here in our cities, whether it's San Francisco, Toronto, basically with our neighborhood. Mike: I mean, that's crazy. I know I've seen ... I forget the show. It was on Discovery Channel here in the US and they talked about ... I didn't know there were hog farmers out in Las Vegas, but there are and they work with the casinos. The casinos have all those buffets to get all their food scraps. I thought that was really, really fascinating. I guess you think about it and until you look at it on a larger scale, do you even understand how much food is produced and unfortunately how much is wasted? Parth Sevak: Yeah, totally, Mike. Mike: So, let's talk about your solution because it involves Agentforce. So, were you going to feed Agentforce some apples? That's a joke because you can't feed it apples. I mean, you could feed it apples maybe like an emoji. Parth Sevak: So, yeah, I think let me first of all piggyback on this one, this idea that this HarvestBridge as a idea, right? When you look at this project from the outside, it may sound like as a big AI project. We have four agents, multi-agent coordination, the whole team, but the reality on the inside is three of those four agents are about 80% configuration. And this is the Agentforce play in my opinion because I used agent builder topics, instructions, guardrails, then flow for orchestration, custom objects, validation rules, formula fields, like typical standard admin toolkit. And obviously, there was a 20% which is code, which is attacks actions for things like geo-matching. So, that also like I wipe coded with cloud plugin for Agentforce available. And what came back was the quality of a season developer with proper design patents, clean error handling, governance limit aware as I made sure to provide the right context. That is very important. So, anytime if anybody ever built a flow with a decision branch and a few validation rules, you can think the way you need to build an agent. The tools just caught up with you. Mike: Yeah. Well, actually we had a few presentations at TDX and the admin track from admins who are vibe coding and I've had a few people on the podcast talking about how they've vibe coded and just the product itself is just insane to think you can sit down and there's a plan and there's an action button. And even in the plan button, I was really impressed with how much Agentforce Vibes could give you back as an admin to really help you plan your application. Parth Sevak: Yeah, that is really empowering thing has happening just in front of eyes and not just that, but we are at the forefront of that innovation and definitely the Agentforce for Good is really the category that should motivate everybody to get their hand dirty for something to produce something really good. Mike: Yeah. So, let's talk about while you were building your application to deal with food waste, what was a point in time when you sat back and maybe learned something that you didn't know as you were building it? Parth Sevak: Yeah. So, before I answer that question, I need to tell you how I approach the build process if it is okay. Mike: Oh, please. Parth Sevak: Yeah. Okay. So, basically like Mike, to be very frank, I didn't follow a plan. I would love to say that I sat down on day one and map out a clean sprint like user stories and backlog, but that was not what happened. What actually happened is I just started building right away. So, I picked the first thing, which is a donor bot. This is the agent that talks to donors and captures surplus food. First I got that working and the moment it ran, the next question was obvious that, okay, now surplus is in the system in the Salesforce. Now where does it go? So, I built the matchmaker agent and once matchmaker was written in matches, the next question came up on its own that who actually picks the food up and delivers it? Who is the volunteer? That became logistics coordinator on Slack and by then, I had data flowing through the whole system and it was almost asking to be visualized and that become impact analyst on Tableau. So, overall, I ended up building four agents, each one revealed the next. And what made that look possible beyond Agentforce itself is that I had AI assistance alongside me the whole way, like not just for the apex spaces we talked about, but for the thinking too, like should this be one agent or two? What edge cases am I missing? Is this topic structure clean, less a solo build and a more long conversation with a partner who is read every Salesforce document kind of like ever published. So, when I started building on the Agentforce platform, I had some high expectations and let me tell you, like what really surprised me in a pleasant way is the breadth. I use Agent Builder for the agents themselves, the topics, instructions, custom actions. Then underneath, I relied on agent script for the deterministic safety rules. So, things like allergens and expiry windows are not left to the LLM to decide. From there, I brought an Agentforce voice for the call-in donation capture, which I think just became GA recently, which I think, yeah, an intelligent context handled passing food details out of photos that donor send in. All of it was sitting on Data 360, which held the unified profiles of donors, recipients, and volunteers. Here is the part that genuinely caught me off guard. I didn't write any glue code between those layers, like an agent would hand off to a flow which will call an apex action that will update the records in the Data 360 and that would trigger a Slack message. That would feed back into another agent's context and all of it just worked like a charm. And if I reflect like five years ago, that integration story would have been months, if not years and this made me possible to deliver something so amazing in just few days and that was my wow moment from the whole build. And Mike, if I just like tell you another perspective that the other thing I was nervous about going in was hallucination because I am building four different agents and then you have obviously hear the horror stories, right? But between agent builders topic structure, agent script for hard rules and clear instructions, that's how I make sure that my agent behave very well. So, food safety rules around allergens and expiry are not something that I would let an LLM to decide. I would make sure to enforce them deterministically at the architecture level and for that I leverage agent script and thank God, that agent script work really well and where I would love to see things improve is just the debugging because when an agent's reasoning across topics and data sources, tracing what it actually did is still a bit difficult. So, the tooling is getting better, but its place still I'm watching. Mike: Yeah. I do an Agentforce Now workshop every month and I always try to point out when we're building it and preview how you can go through and see what the agent is doing and how it's deploying its sub-agents. And I think with everything we're still learning what AI is and how to debug it and it's this interesting intersection because we want the intelligence and the context and the engagement of AI, but I think people got really hooked on how perfect a bot would respond and a bot would respond because it's always A, B or C and we gave it those answers. And the nice thing about AI is it doesn't necessarily have those answers, but it can think independently, but we still want that control. So, it's like building the perfect employee. Parth Sevak: Yeah, absolutely. And that's why, like as I said, Mike, the deterministic approach is very significant and particularly, I would kind of rely on agent script that really gives that control back to the human or admins or architects so that they don't need to basically do the guesswork that, okay, what will be the response of agent if I do this prompt versus that prompt? It can simply be predictable. So, that is the cool thing I would say about the agent script and what it makes possible now in the reality of governance. Mike: So, I think one thing that's really cool about hackathons is it's kind of blue sky and green field. You can come in with a solution and like in your case, it really solves a real world problem. If somebody is listening to this and thinking, "Wow, I'd really like to get started with Agentforce," what was the first thing that you did to get hands-on with Agentforce and start understanding the product to the level that you do now? Parth Sevak: Oh, I think I don't recall exactly the date and time, but I think it was I think a couple of years ago when there was already like Agentforce discussion has already began because I was active in the community and thanks to Trailhead. And I basically started my journey to equip myself about like what is this best Agentforce, right? And then I did few modules and ultimately I think last December, I got certified in the Agentforce as Agentforce specialist. So, that really gives me clarity that okay, just not about like, okay, what I can build for the demonstration purpose, but also for me, it's very important that I can actually pass on that knowledge to my team so that they can ship the products or ship the agents that is really the kind of like configurable and scalable across the systems, not just one particular cloud or system or CRM. Mike: Yeah. I mean, anytime I need to learn something for a demo or for a presentation I'm putting together, I usually turn to Trailhead first and kind of walk through it and get an idea of what the product can and do and how I can configure it. So, I'm right there with you. Even Salesforce people still learn on Trailhead. Parth Sevak: Yeah, that's amazing actually. I call it as a live report, it's always live. You never get any stale recipe or stale dishes. So, that means everybody, whether it's a employee of Salesforce, partners or customers, everybody can rely on Trailhead for the real time information for sure. Mike: So, moving forward, we have a little event in the fall that we do called Dreamforce that you mentioned. Obviously, none of us have a crystal ball. Well, I'm sure a few people in Salesforce do to know what we're going to show, but what are some of the things you would love to see this year at Dreamforce? Parth Sevak: Okay. So, as I said, I have been part of the Salesforce ecosystem for almost 16 years and what really amazing to see is that the platform never sits still. So, when I started, here is the context, Mike, what I'm talking about is when I started we were building the S controls and it came to Visualforce. Mike: Yeah, that's back when I started too, called them Superman controls. Parth Sevak: Yeah. Then Visualforce, like proper MVC, controllers, pages, then Aura framework. And my first test of real component-based DUI was that Aura and then Lightning Web components. And I remember thinking, okay, this changes everything. And now 2026, we have got React running on Lightning Web Runtime along with the Headless 360 and agents that reason and act on their own and every leap has bigger than the last, right? So, it is the one ecosystem I have worked in that's never stopped becoming more interesting. I will make sure like a kid, I always go without any expectation that, okay, oh, what I'm going to get out of this conference because I know whatever will be there, it will be super amazing, super productive and make everyone's life much better than it was before. Mike: Yeah. Wow, that sets the wheels in motion to draw the bar even higher for all the rest of us. I appreciate you sharing that. And I will say one thing that we do at Dreamforce every year is we not only have volunteering activities, but I know the entire event is very conscious about the food that we use and how it gets recycled and dispersed evenly to make sure that we have the right amount. Because conferences I'm sure are big places where a lot of stuff can go to waste as well. Parth Sevak: Yeah, no absolutely. And I couldn't be more prouder than this, particularly like I was not also that conscious about all these basic problems, but then I started volunteering. I involved with some foundations and then I realized, "Oh man, wow, we are living in a 21st century and still we are not able to figure out the solution for this day-to-day problems." And it really kind of like hurts in our heart like if we see. So, basically like my belly is full. It's not solving the problem, right? I cannot be that selfish and truly like I couldn't agree more like Dreamforce. And that's I think really set the high bar that how the conferences should be run from the humanitarian angle as well. Mike: Yeah. Well, thanks for the kind words, Parth. I appreciate you coming on the podcast. This was a great conversation. I will say this now I should be able to find your TDX video and post that in the link so that everybody can see the demo of the app that you built and see how cool it was because I know we like to showcase those winners and so hopefully it inspires other people to not only participate in the hackathon but bring those solutions back to their communities as well. Parth Sevak: Yeah. And Mike, if you permit, can I say something like I would take maybe a one minute- Mike: Sure. Parth Sevak: ... which is very close to my heart and this is like a period like everybody is going through the transition. So, what I say is like, yeah, we need to be a jack of all, but master of one. And what I mean by that is that we don't want to restrict ourselves doing the same thing for too long. It's easy to get comfortable. For example, you are good at your role, the work is familiar, but comfort is also the thing that quietly stop you from growing. And right now with where the technology is, the agentic AI is here, right? This is exactly the moment to step outside that comfort zone, not because that you have to, but because the upside is so much bigger than the downside and Agent AI use well is probably the most empowering tool any of us have had access in our professional journey at least. So, I can take you somewhere you couldn't get along, but only if you handle it right, it can. So, stay the architect, keep judgment in your hands, let it stretch you instead of replacing you. The individuals who lean into that, who do the thing that is needed most for their clients, their employers, and honestly for their own sake, those are the people I think come out of the next two or three years transformed. So, for me, what is next is more building, more sharing, more conversations like this one. And if one person listening today challenges themselves to try something they have been putting off, that is a great month. Mike: I would agree. Couldn't have said it any better than you did. Well, Parth, thanks for coming on the podcast. It was great having this conversation with you. Parth Sevak: Yeah, thank you, Mike. This was a real pleasure. Mike: Huge thanks to Parth for joining us and sharing how HarvestBridge came together at the intersection of AI, automation, governance, and real world impact. I know one of the biggest takeaways from this conversation is that the future admin isn't just configuring tools, they're designing systems that connect people, data, agents, and outcomes responsibly. So, whether you're experimenting with Agentforce for the first time or already building multi-agent workflows, the opportunity is bigger than just productivity. It's about solving meaningful problems faster and with more intention. Of course, if you enjoyed this episode, subscribe, leave a review, share it with somebody who's ready to start building what's next. And until next time, we'll see you in the cloud.
  • Agentforce for Good Shows the Power of Inclusive Innovation 04.06.2026 27min
    Today on the Salesforce Admins Podcast, we talk to Alexandra Iyer, Director of Marketing Strategy and AI Transformation, and Global EVP of Abilityforce at Salesforce. Join us as we chat about the Agentforce for Good Hackathon at TDX and what happens when technology, accessibility, and community come together to solve real-world problems. You should subscribe for the full episode, but here are a few takeaways from our conversation with Alexandra Laxmi Iyer. Agentforce for Good expands AI beyond business problems This year, we added a new twist to the types of problems you could solve for at the TDX Hackathon. We called it Agentforce for Good, and it offered participants a way to work on some big problems: food insecurity, nonprofit volunteer coordination, disaster relief, and more. That's why I'm so excited to bring Alexandra "X" Iyer on the pod. She's the Global EVP of Abilityforce, Salesforce's internal business unit for people with disabilities and their allies. They've been running an internal accessibility hackathon for years, and Agentforce for Good grew out of a desire to open it up to the community and broaden its scope. "Builders who probably never thought of themselves as social impact developers shipped working Agentforce solutions for all sorts of big problems," X says, and 62% of this year's Hackathon entries were solving for Agentforce for Good. Inclusive design creates better technology for everyone "When we are challenged with designing for the edge, you make the center better," X says. Finding challenges that force you to push tools like Tableau, Slack, and Agentforce in new ways helps you uncover capabilities that you might not have otherwise thought about. As X likes to put it, "Good design is just good design, full stop." Going forward, X and her team are looking for ways to expand Agentforce for Good beyond TDX. Consider this a call for participation, and she encourages you to get in touch to volunteer or bring Agentforce for Good to a community event near you. Lived experience is a valuable design credential "One of the main things I would love for people to take away from our conversation is that your lived experience is a credential," X says. "It's not a distraction." After all, designing around new challenges is how we come up with innovative solutions that nobody else would have thought of. Your unique perspective is valuable. Make sure to listen to the full episode for more insights from X. Next week, we'll hear from the winner of the TDX Hackathon, so make sure you're subscribed to the Salesforce Admins Podcast. Podcast swag Salesforce Admins on the Trailhead Store Learn more Trailblazer Community Group: Abilityforce Salesforce Equality Groups Admin Trailblazers Group Admin Trailblazers Community Group Social X on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Love our podcasts? Subscribe today or review us on iTunes! Full show transcript Mike: This week on the Salesforce Admins podcast, we're talking about what happens when technology, accessibility, and community come together to solve real world problems. I'm joined by X or X, who is the director of marketing, strategy and AI transformation at Salesforce and Vice President of Abilityforce to discuss the Agentforce for Good Hackathon that happened at TDX. Now we're going to find out that it started as an employee-led accessibility initiative. And has grown into a community movement bringing together admins, developers, partners, and customers to build solutions that address challenges like food insecurity, disaster relief, and volunteer coordination. We're going to talk about why designing for inclusion leads to better outcomes, how AI can help scale impact, and why your lived experience might be one of the most valuable design credentials you have. So if you're thinking about how data automation, AI agents work together to create meaningful change not just inside your organization, but in the world around it, I promise you this episode is for you. So let's get Alexandra on the podcast. So Alexandra, welcome to the podcast. Alexandra: Thank you for having me, Mike. Mike: I think it's going to be a fun conversation because we're talking about Agentforce for Good today. So let's get started to learn a little bit about you and your path to Salesforce and your path to the Agentforce for Good Hackathon. Alexandra: Absolutely. Thank you for asking. And by the way, I go by X for short, so feel free to call me X. Mike: Perfect. X: I'm the director of marketing strategy and AI transformation for our customer success and partner marketing team here at Salesforce. And I'm also the vice president for Abilityforce, our employee resource group for people with disabilities and their allies. And when we're talking about the Agentforce for Good Hackathon, this is really a moment where these two worlds actually collided. Normally, they wouldn't collide, but the hackathon is genuinely where they did. I come from 20 years of go to-market experience. I'm not a builder by background. I actually got curious in a marketing role about the products that I was marketing and how they worked. So that curiosity pulled me into the platform, into development, into force certifications that I did not see coming. And then, I went from talking about technology to building on it and that changed everything. I believe that the AI era is only worth building if it's built for everyone. That's not a tagline for me. It's a design requirement. And I truly feel that admins have always known that. Admins are the ones closest to the humans using the platform, the problems, the friction, the gaps. And I also believe they're the closest to the solution. So I think it's not a support function, it's a superpower and I'm really happy to be here. Mike: Yeah. Well, I agree with everything you had to say, X. I do agree that admins are very superpower. I also think just in general, when we think about technology, it's not how do we roll it out for some people? It's how do we roll it out for everyone? And I remember this is a long time ago, but when I first joined a company that did workplace assessments, I remember they said, "Well, when creating the test, we have to assume the person doesn't know how to use a mouse." And I remember thinking to myself, this is ... closed-minded is the wrong word, but I just was unaware. And I was like, "Well, who doesn't know how to use a mouse?" And they're like, "Well, you don't understand." And I was like, "Oh, that is a huge challenge." And sometimes until you get someone else's perspective, do you really understand like, it's not that you've been living under a rock, it's just too often sometimes people assume their world is just like everyone else's world and it's not. So there's a Mike side of I had to remember that not everybody knows how to use a mouse sometimes. X: Well, Mike, frankly, I consider that the main dish. I don't think it's a Mike side. I think that if you're designing for the default user, it's not really good technology and that when you optimize for the average, you're excluding by design. So I think it's the main dish and it's part of the reason why the Agentforce for Good Hackathon even exists. So to give you a little context, three years ago, the Agentforce for Good Hackathon was an internal-only, employee-only hackathon led by Abilityforce. I mentioned earlier Salesforce's business resource group for people with disabilities and their allies. And then, last year we said, "Why does it have to be about accessibility only and why does it only have to be for employees?" So then we opened it up to the community. We had partners and customers and employees all building on the platform, really stretching the platform, bringing us to TDX this year, where builders who really probably never even thought of themselves as social impact developers shipped working Agentforce Solutions for food insecurity, for nonprofit volunteer coordination, you name it. So when we all come together to threshold platform for everybody, not the default user, we're really shipping great technology and boy, did the admin community really show up for this. Mike: Yeah, no kidding. And just as kind of a teaser, next week on the podcast we have the winner of the hackathon to talk through their application. So that was a fun conversation, but let's dive into what some of the things that you did around the hackathon, some of the stuff that you saw and what some of the participants tried to tackle. X: Absolutely, so we had ... so a little fun fact for you is that of all of the submissions for the TDX Hackathon, over 62% of them self-selected to say, "I want to solve for the Agentforce for Good." It wasn't required. And then, 50% of the Agentforce for Good projects were participants could submit in multiple categories, but 50% of those 62% of the projects were only for Agentforce for Good. They solved things from disaster relief to supporting teams post-addiction to food rescue, truly really pushing the boundaries of the Salesforce platform. Mike: Yeah, absolutely. And I always think sometimes that we're trying to solve problems with technology where it's just how do you layer in the technology? But I do feel ... and I was there when they gave the awards, I do really feel that the integral solution for a lot of these works the technology along with the process that is also needed. There's just things you can't do without the technology that when you layer that in, wow, it unlocks a different world. X: Yeah, absolutely. I think that when we are challenged with designing for the edge, you make the center better. And so I'm sure that some of these solutions that put together Tableau and Slack and Agentforce have uncovered some capabilities that maybe we might not have thought about, whether it's for a good cause or not. So I do think it also allows very special kinds of developers and admins to come to the surface as well. Mike: Absolutely. So in your work with the community and around the community, what are some of the events that you go to? What are some of the presentations and content that you put out there that people find valuable and useful? X: Well, I mean, I'm only starting to get into the conference circuit or the community circuit, to be honest with you. I've been kind of- Mike: I like that we call it a circuit. X: Yeah. Mike: Get around the circuit. X: I mean, for me, it's something that I've always been ... and this might be a little too raw, but I am an open book, Mike, so hear me out here. I have never, ever had the ... what's the word I'm looking for? It's kind of like, I guess confidence is the right word. I've never been raising my hand to say, "Oh, I should submit and speak," or, "I should fight to attend this event because this really matters to me." And it's only recently where I've started to get my legs a little bit more to do that. I've published a couple of articles on LinkedIn, building with Cloud Code, using Slack, Slackbot, all these things. And so, I'm just starting to get out there and really getting exposed to the possibilities of our platform. I actually don't know how to answer that question, except for I'd love invites, I'd love to know what the community finds interesting and I'd love to facilitate doing good in the world, doing as much good as we are solving business problems. Mike: Yeah. I think ... I mean, you're also just taking the first step. Some people ... I'll just go, but I'll never present. And I always encourage people, even ... you don't have to go to a big conference or you don't have to present at Dreamforce, but even getting up and sharing things at your local user group, the thing I'm reminded of, somebody needs to see somebody like you presenting. X: Well, thanks for saying that. I'm actually presenting at Connections this week. Yeah. It's my first real speaking session and we're talking about how we've used Slack and Slackbot to scale top level support to our incredible partners. We have over 13,000 partners in the Slack community and we have a lot of different skills that we're using to help our partners go to market faster in a more customized personalized way. And so, we'll be talking about that. But back to the hackathon, the one thing I did want to underscore is that Salesforce has a total of 16 equality groups from Abilityforce, to Neuroforce, to Asiapacforce, to Outforce, BOLDforce. And we all came together for this hackathon and we're going to continue to do that. So likely, you'll see us at Dreamforce and at TDX again. So I would love to have the community just continue to support this and participate and start the platform. I'll say that our community is proving that intersectional volunteer-led initiatives drives higher engagement and faster product adoption than traditional top-down motions. And so, I just want to have a call to participation. If your community or your listeners want to participate, we're definitely open to having more volunteers support and would love to see these at our community events as well. Mike: Yeah. I've already been to a community event MidAtlantic Dreamin', this year in Philadelphia. And I love going to those events because it is all community presenting and really showing their perspective on giving different solutions and tackling different challenges. And it ranges from technical through just giving presentations to your executives and having the confidence to walk into a boardroom and really working through that, not all the presentations are exactly technical. And so, you can learn different skills that way, but I appreciate you bringing that up. That's always very good and good for you getting up on stage. It's okay. I do think sometimes ... I've spoke on a lot of different stages. Sometimes it's the smallest ones that are the hardest because once you get up on a big stage, there's just so many people that your brain can't absorb it. It's crazy. X: Yeah. Well, I guess my little theater session at Connections will have to do, but- Mike: You never know, there could be 200 people there and do a little theater session. X: I know, I know. My goodness. Yeah. What I'm curious about, Mike, from your perspective is why do you think ... Here I am, I'm asking you a question. Mike: Please. X: Why do you think we had such incredible participation? Because it really was humbling the amount of community support we got from folks joining the Agentforce for Good Hackathon. Mike: I thought about that too and I think it's maybe a couple of things. One, I've been a part of either on the team where people around me are planning the hackathon. I've been in the judging room sometimes for a few of the events and going through, watching the submissions and watching the integration of how did they use Agentforce and what was the solution they were trying to solve. I feel like the opportunity for solving things that really provide, I'll call it exponential value to the community, is so great. And it also kind of, in some respects, opens up the creativity because depending on how long you've been a Salesforce admin, how long you've been a Salesforce developer, you might not have all of that kind of exposure into different businesses and different processes. I know for a long time, a lot of hackathon people were tackling things in the medical world and I won't give away ... Well, I can give away the winner because we all know it. But the unique solution that they come up with, you have to think of it's not what is the technology solved for, it's what was the issue and the challenge that provided the biggest gap that technology proved out to do the most good. And I just think after talking with the winner and seeing that solution, I think a lot of people just genuinely found a lot of really satisfying things to build when it comes to solutioning ... I'll call it solutioning for good, as opposed to solutioning for profit. X: Right. Mike: Because then you're like, wow, if we can do this, this and this, because the gaps are always there and they're always huge because nobody ... For lack of a better terms, nobody is maximizing good for profit. X: Yeah. Mike: And so, the thinking of just different things around animal adoption or adoption shelters or food and food insecurity, there's always communication gaps there. And the biggest thing that AI we found and Slack, and some of these other tools, but the biggest thing that AI solves is communication. I was on Amazon the other day just not as a tangent, but kind of ... and they have this new button now you can click and it generates kind of an AI overview of the product and some of the common answers to the questions that they have. And I thought to myself, that gap probably didn't exist, but AI solved it and AI is able to communicate with us. And I think that to me for things that do good and help others, communication is always the key and it's always the biggest gap because communication at scale never happens. X: It's interesting that you say gap and it's making me think of something I'd love to share about our employee hackathon. So we are still doing our employee version of the Agentforce for Good Hackathon and this year, we're adding an AI fluency track. So we have our traditional builder track, and then we have our AI fluency track and you don't have to be building an agent to build something powerful. Mike: Right. X: And so, we want to provide an opportunity for admins and marketers and all sorts of folks to be able to confidently collaborate with AI to give our users agency to drive impact at speed and scale. And so, I think admins do a really great job at understanding human like you were saying the Amazon button and clicking that button as an admin, you kind of know why the user might click it or why they might click the wrong one because of maybe where it's placed or is it accessible or things don't get filled out correctly and you know how to create some workarounds. And so, I think the AI fluency track for us is about really bringing more of that human element back into the AI. So I'd be curious if the community would be down with participating in an AI fluency track where it's like writing ... like it's not about building something. Maybe it's like the most artful skill, Slackbot skill, or maybe it's a killer Gemini prompt or something along those lines. But I think you mentioning the gap really made me think about how I want AI for all technology that empowers everybody, but I also don't want to leave anyone behind. Mike: Right. Yeah. I mean along those lines, I was talking today with my manager and we were discussing something and she's like, "So what do you use?" Because at Salesforce we have a wealth of tools. I think comparative to ... I've talked with other friends and like, "Wow, you get to use that and that and that?" And I'm like, "Yeah, and there's probably more that I don't know about." And they're like, "Geez, we don't even have ..." So that part alone was ... I was like, "Yay. Well, I'm glad I have a wealth of resources." But she asked what I was going to use it for. And I said, "The biggest thing that I try to use AI for in looking at a lot of data on sheets or 10, 15 page documents, what are the blind spots for the stuff that I don't normally pick up?" And that to me was the greatest prompts that I could use. And back to some of your Agentforce Hackathon stuff, I think actually that's some of the biggest opportunities that admins have across their org is we always look at, well, how can the agent improve this or that? Boy, I would just love it if ... how could the agent just look at the record somebody created and be like, "Yeah, Jim, that's not going to cut it." X: Absolutely. Mike: "You left a bunch of fields blank and you know what, those fields are there for a reason. Go back and fill them in." That's what I would want. I would want a little snarcastic clippy coming up and being like, "I think you can do better." X: Yeah. Mike: But it's also not, how do I make myself perform in a greater capacity or increased speed? Yes, that's part of it, but also, how do I make myself save myself? X: Yeah. Mike: So how do I look at this, but tell me what I'm not seeing because I don't know to look for it. X: You've inspired me to share one of the main things I would love for people to take away from our conversation, which is your lived experience is a credential. It's not a distraction. So how you experience things, the type of inputs you would want. In the Agentforce for Good Hackathon, we're asking for accessibility and equity lenses that only people can have through their lived experiences of what's broken, what's inaccessible, what might be perceived as unfair in technology. That is absolutely a credential and not a distraction. And so I am happy to hear that those are the types of thoughts you have and I hope that all of us do that. All of us have the agency to think about those things in our designs. Mike: Yeah. I mean, your answer brings me back to long ago publishing days and I remember I used to work selling textbooks and I worked the sales desk set by the editors and the author's desks and we could all mix and mingle and talk to each other. I remember one of the authors for a book in New York City came over to my desk and said, "Can you read this question and tell me what the answer is?" And the question had, it was like for fifth or sixth grade, if the kid was at his window and wanted to look at the stars, what would he use? A microscope, a telescope, binoculars, or ... I forget something else. And I remember saying, "Oh, well, it's obviously a telescope." And they said, "Yeah, but you know that because you know telescopes exist. What if you don't know that telescopes exist or what if you didn't know you could see the sky?" And it was because it was based for a book in New York City where I live in the middle of the Midwest, I can go outside and see the sky. I can walk two feet outside my front door, but some people ... And I've been in parts of New York, you walk outside and the buildings are so tall, you might not ever see the sky. And I thought, wow, what an interesting perspective. And so, I use that example with a lot of AI bots that I work with to be like, here's an example of, not a blindness, but something I wasn't aware of. And can you look for something similar to that in my writing or in this thing that I'm looking at? Because sometimes if you grew up in the Midwest and you could always see the stars in the sky, you might not know that there's a sky. X: Right, right. Okay. So real talk here, did you influence any of these authors? Are there books out there tech book- Mike: There was. There was. There were No Child Left Behind Test Prep books, which I think have probably faded into obscurity, but I probably have a few in my closet somewhere that I took before I left the company, but I would like to think so. X: I'm sure there is. And that's such a good story and such a good analogy. I mean, at times I've thought to myself, well, what if you grew up every single day thinking blue was red and then somebody told you red was blue and you were wrong. Your perceived lived experience changes very basic things like that. Mike: Right. I grew up with Four Seasons because we have all of them in Iowa and some people haven't. Or the other conversation I had with the author that was working on the New York books was around green grass because the likelihood that a child might not have ever seen green grass in their life is very high in New York City. And I was like, "Wow, actually you're right." X: Exactly. Mike: And you don't think about those things when your perspective is, I can see green grass outside of my window, why can't everybody else? X: Yep, 100%. Well, at the end of the day, this conversation that we're having is exactly why the Agentforce for Good Hackathon is so important. One of my taglines in one of my recent articles is that good design is just good design, period. And it truly becomes non-negotiable when the stakes are someone's health, their safety, or their dignity. And that is what is so exciting about the Agentforce for Good Hackathon. Mike: Yep. I think that's perfect note to end things on. So X thanks for coming by and sharing with us on the podcast. And next week, we get to talk to the listener or to the hackathon winner. X: That's going to be exciting. I can't wait to tune in and thank you for the opportunity to share more about this hackathon and look forward to the next one. Mike: So that was a great conversation with X. I'm glad she could come on. And by the way, I teased it out, but just a reminder, next week on the podcast we have the hackathon winner on, to talk about their solution and what they're passionate about. It's a really great episode. One thing that stood out to me is that great solutions don't start with technology. They start with understanding people, their experiences, and their outcomes that matter most. As Salesforce admins, we're often the ones connecting systems, stakeholders, and now AI agents to solve problems at scale. So whether you're building your business, your community, or a cause you care about, there's an opportunity to design technology that works for you. Be sure to subscribe so that you never miss an episode. And you know what? If you found this conversation valuable, share it with a fellow Salesforce admin. Until next time, we'll see you in the cloud.  
  • Salesforce Admins Can Reduce Risk With Proactive Security 28.05.2026 20min
    Salesforce Admins Can Reduce Risk With Proactive Security   Today on the Salesforce Admins Podcast, we talk to Kate Lessard, Lead Admin Evangelist at Salesforce.   Join us as we chat about why security is the foundation for how data, automation, and AI work together.   You should subscribe for the full episode, but here are a few takeaways from our conversation with Kate Lessard. Why strong security is proactive, not reactive Security can often feel like the elephant in the room. Everyone knows it's important, but the amount of work needed to do it right can feel daunting. Thorny problems like accumulated tech debt and organizational inertia can make you feel like you're better off not talking about it.    That's why I sat down with Kate Lessard. This month, she ran a workshop called Security in Action to highlight the simple steps you can take to strengthen the security posture of your org. She got hands-on with an example org to demonstrate how to use Health Check to identify and fix security problems.   It's all about taking a proactive approach to security, rather than waiting for something to happen to you.  Your Health Check score is a security action plan "Health Check is no longer just a list of settings for you to review," Kate says, "it's your dynamic risk mitigation dashboard." Issues are sorted into four categories: high-risk, medium-risk, low-risk, and informational. There is also a status to rate the level of urgency for each issue: critical, warning, or compliant.   Health Check is also customizable. If your organization's security policies are different than the Salesforce Baseline Standard, you can download an XML file and tweak the criteria. You can compare your policies to what's recommended by Salesforce, and maybe identify some low-hanging fruit.   In short, your Health Check score gives you a prioritized list of which security issues need to be addressed first so you can walk into a meeting with stakeholders with a solid plan of action.   Helpful reports for user management Security and user management go hand in hand, and Kate recommends some reports that admins can run to help with governance.    First of all, the Active System Administrator Report can help you find users who might have more access than they need. This can often be an issue in older orgs where it was easier to give someone admin access than to sit down and solve the permission problem. Kate also likes to run a report on Reports, to keep track of what her users are interacting with the most.   As Kate says, it's all about making a shift towards a security model built around permission set best practices. As admins, we need to find a way to fit security seamlessly into our organization's business processes, and vice versa. There may be an upfront cost, but it's all about making security easy in the long run.   Listen to the full conversation for more from Kate about security and Health Check. And don't forget to subscribe to the Salesforce Admins Podcast so you never miss an episode.   Podcast swag Salesforce Admins on the Trailhead Store Learn more Salesforce Admins Blog: Securing Your Org: From Reactive to Proactive Kate Clicks Through It: Protect Your Salesforce Org With Health Check   Admin Trailblazers Group Admin Trailblazers Community Group Social Kate on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript Mike: This week on the Salesforce Admins podcast, I sit down with Salesforce Evangelist Kate Lessard to unpack why security is really no longer a side conversation for admin, but the foundation to how data, humans, automation and AI all work together. We're going to cover her new security workshop that she led last week, and talk about health check upgrades, permission set security models, and of course how Salesforce admins can move from reacting to security problems to proactively designing trusted systems. We do touch on a little bit of governance, user access, and why secure data is the backbone of every successful AI implementation. So if you've ever wondered how modern Salesforce admins evolve from feature builders into stewards of trust, this episode is for you. And with that, let's get Kate on the podcast. Kate, welcome back to the podcast. Kate Lessard: Hey, thanks for having me back. Excited to be here. Mike: Well, it feels like a lot of relevant things for admins are coming out of your camp lately from True to the Core Deep Dive to last week's security and action. I feel like there should be like a thunderclap after that. Security and action. Dun, dun, dun. Kate Lessard: Yeah, absolutely. Data and access. Mike: Right. Mm-hmm. Yep. Like a comic book hero. And then you got to do the comic book land. Anyway, totally off topic. Look at that. 30 seconds into the podcast, we're already in comic books. People- Kate Lessard: I mean, I am here for it. Admins are superheroes, especially when they are securing their orgs. Mike: We are. So let's talk about what that first workshop was, and what you covered, and how it went. So tell me a little bit more, tell everybody a little bit more about what that workshop was. Kate Lessard: So in the Security and Action workshop, we were really focused on data and access and using HealthCheck as our guide. So essentially we started off with some security basics knowing that much of our audience was at different levels. So we had people joining us that are brand new admins that are working on their first certification. And then we had people joining us that have been in the ecosystem and in a Salesforce role for more than 10 years. So wanted to make sure that we had a strong foundation and that we had reviewed some security foundational knowledge base points for everybody to get on the same level. And then we got hands-on in an org that just didn't have a great health check score and had some security concerns that we went through, and hands-on adjusted together until we improved our score, we better secured our org, and just increased our security posture. Mike: Cool. I didn't hear Agentforce in there and we're in the age of AI. Kate Lessard: Yeah. So I do think we didn't specifically touch on Agentforce in this first workshop. We really wanted to focus on that strong security base where it applies to all of your org. And that might mean that it applies to your users, both human and agent, but really focusing in on that prime security. And then we do have plans in the future to enhance this and take this to the next level and really expand on some of those agentic guardrails. But I think that it's just really important to have that foundation first. Mike: Yeah. I mean, all of it bases around good, clean data and secure data. Kate Lessard: Absolutely. And you're not going to have a successful Agentforce implementation without that. That is the foundation point that's going to set your organization up for success using AI. Mike: I did the Agentforce Now workshop that week, and I always emphasize the importance of filling in description and metadata fields as well. Kate Lessard: Yes, hugely important. Mike: So one of the things, it's really cool the workshop pivots all around HealthCheck. And I know having worked some of the Q&A, people were like, "Wait a minute, I thought HealthCheck went away." Kate Lessard: Yeah, HealthCheck has not gone away. It is free for admins to use and it actually recently got some pretty impressive and exciting upgrades that we spend some time on in the workbook. So it's no longer just a list of settings for you to review. It is really dynamic and serves as your risk mitigation dashboard. So you can do things like not only configure the specific settings for your org security, but you can also set up email notifications for system admins or anyone who that you would like to receive notifications when your security score changes. So maybe members of your IT team, your security team, if you work with a governance team, making sure that they get notifications because as you know, security is a team sport. I think the coolest thing that we do in the workshop and that I really want everybody to be able to take advantage of is you can actually export the standard Salesforce baseline and customize it to your own organization's security criteria. So if you have different security criteria like maybe your password policy has a minimum of 11 characters at your organization, the Salesforce baseline has eight characters. That is a change. And you want to compare your Salesforce security settings against your own organization standards, and you now have the ability to do that, which is just incredible. Mike: Yeah. And it's not like the way that you walk through it, it's not that daunting. I mean, is it an XML file that you download? Kate Lessard: Yeah, absolutely. So you don't have to start from scratch, which is the really nice thing. You can actually export the standard Salesforce baseline. It is an XML file. In the workshop, we walk through what the download looks like and how to actually make the edits. It's pretty easy to read. And even in the file, there's a link to help notes so that you know exactly what types of formatting to use when you're editing the XML. And then you can just save it as your custom, re-import it, and set it as your default. Mike: Yeah, I thought that was really cool. One other thing that you dive into is, and of course it's set up because it's a workshop, but number of admins that... Kate Lessard: Oh yeah. Mike: Or number of people that have the Salesforce admin profile. Kate Lessard: Absolutely. So everybody's favorite admin horror story that you log into an org for the first time and take a look and realize that you have just a completely disproportionate number of system admins and folks that are over-privileged just because it was easier to give them that permission than to really sort through a proper permission set model. And in our org, we have the very scary informational security setting letting us know that we have 100% of our users as system admins opposed to the typical 5% that you see in the standard baseline. So we address that and we talk about who really needs admin permissions. Mike: So I mean, let's expand upon that because we've had that idea of delegated admins as well. So they wouldn't have a system profile or a system administrator profile. Kate Lessard: That is correct. Yeah. You might have your delegated administrators that are taking certain tasks for certain teams, but that doesn't mean that they have the full system admin profile. It means they're a delegated admin and they have certain admin responsibilities that they take on, but it does not give them the keys to the castle. Mike: Very important. Very important. With HealthCheck, I think it's always one of those big discussion areas because there's different levels that we call out. We have critical. What are some of those stages? Non-critical, informative. Would you as an admin getting started approach HealthCheck as maybe it's like a topic we should bring up in governance? Kate Lessard: I absolutely think it's a topic we should bring up in governance. And it really is set up well to help you prioritize. So if you're going into a governance conversation or maybe a meeting with your security stakeholders, and you want to present different actions that you would like to take or approaches and settings that you'd like to address in your org, it's broken down by high risk, medium risk, low risk, and then informational. And then in each of those different categories, we have it called out what is a critical status, what is a warning status, and then where you're compliant. And so you might want to prioritize your high risk critical items, and then you could share that information of what your value is versus that baseline so that you can provide a really strong recommendation about where to take action to better secure your org. Mike: That makes sense. You've been doing a lot of security stuff lately. I mean, you've had some workshops. Outside of this, we had the True to the Core Deep Dive. What are one of the areas that almost consistently comes up as a theme that really maybe this year admins could address the most? Kate Lessard: That is a really great question. I think we've seen it in the True to the Core Deep Dives that we've had. We had one recently on security and user access. And I think those are two things that go hand in hand and something that comes up consistently. It was also a major discussion point at our admin day of security before TDX. We had a day zero event with several admins and that was just a common conversation as well. Really making that shift towards the best practice of having a permission set led security model, what that looks like for your organization, how to get there, what tools are available to help. I think that things like user access summaries, which we dove into in the workshop as well last week. There are just so many tools that can help admins better move to that permission set led security model. And I mean, I don't have to tell you that security and user management really go hand in hand, and oftentimes are interchangeable topics about how we can better secure our orgs and create a better user experience as well. Mike: Absolutely. And being proactive on topics that come up, one of the things that you cover that I really enjoyed, this is also, this speaks to how long I've been in the ecosystem. It wasn't until I joined Salesforce that I think you could do really in depth user reports, basic reporting was available, but one of the things that you create is the active system administrator report. I'd love to know, I mean, you were an admin out in the world more recently than myself. Were there reports that Kate always created to help her understand her users outside of just if they had a license or if they didn't? Kate Lessard: Yeah, absolutely. I think that the active system administrator report is a great one to call out, but it is looking specifically at users that have that system admin profile. And you might have other concerns about your users or things that you're checking up on them and what they're doing and what they're using. I loved to create the report on reports to get little snippets and information into what reports my users were using. I found that to be really helpful. And also there is a great Salesforce Labs report package about different administrator reports to help you get a little bit more insight into your user activity. So I think that something like that is really helpful if you don't have advanced security options to pinpoint that user activity for you. Mike: Yeah, that definitely makes sense. In addition to knowing when people log in and when they don't, it's also what are they doing? Because I remember I did an implementation and they were adamant about having a login component on a dashboard. And I had one user that I, to this day, I think all they did was wake up, check their email, and then log in and out of Salesforce because they were always head and shoulders above everybody else. They'd have 300 logins for the week. Kate Lessard: Oh, interesting. Mike: I'd be like, "Are you just logging in, updating a field, and logging out?" And they were very dodgy about their answers, but I think that's what they were. I think that's what they were doing because they liked being at the top of the board. Kate Lessard: That is hilarious. Mike: And I always had to reframe the conversation with executives of, we have to look at the entire dashboard, not just logging in because it could be meaningless. Kate Lessard: Right. They're just like logging in, logging a single activity, logging out, coming back in. Mike: Refreshing a dashboard, refreshing a report, and then that's it. Kate Lessard: Oh my goodness. Well, and then the other concern is where are they logging in from, if we're talking about dodgy behavior. When I was an admin out in the wild, one of the stories I like to tell about why security is so important. I worked for a mental health hospital system, and as you can imagine, we dealt with a lot of PHI. And I noticed some funky login IP ranges, and it turns out that someone had given a local college student access to their Salesforce credentials and was having them log their activities for them. Mike: Uh. Kate Lessard: Yeah, I know. And thankfully they didn't actually have access to any PHI because we had a good security model set up. However, obviously huge concern and something that Salesforce was able to help us identify because we were able to see those different login IP ranges, spot what was going on, and address it, and prevent it from becoming a big security concern, which I feel like that's really one of the big takeaways that I... If you asked me what I wanted people to take away from this workshop, it is to shift from being reactive about your security and just waiting to become a statistic to really being proactive and getting ahead of things and making sure that your org is secure and that you are addressing those risks versus waiting for them to happen to you. Mike: Yeah. I mean, to that point, I often look at things that are security that don't sound like security. And one of them is process management. So to me, that sounds like there's a complete separation between what executives expect in Salesforce and what the actual process is. Because the process, the technology should support the process that's needed, and here it sounds like it's burdensome to the process. And that to me is a security risk. I mean, if you don't have the process ironed out so that it feels natural, every action has a deliberate and equal technology component, then the security's going to fall apart. Much like a Salesforce admin shouldn't learn about a person being separated from a company four days after they've left the company. They need to be part of the off-boarding or onboarding process. They don't need to know why, but they need to make sure because that person should or should not have access to that system. Kate Lessard: Absolutely. I think that it is certainly a role of power and responsibility because you are getting that notification, best case scenario, to freeze that user. And again, you don't need the why or the explanation, but to have an actual process in place to be able to continue to secure your org so that after someone's left an organization that you're able to say, "Yes, this is still secure, this is not a risk." And you know you're not maybe going through a full deactivation process right away, but that ability to freeze that user and be able to take action is just so important. Mike: Absolutely. Well, Kate, I appreciate you coming on the pod and helping admins keep all of their data secure and their org secure. Kate Lessard: It is my pleasure. I mean, I love to talk about security any chance I get, and I think that we have so many brilliant people on our security team at Salesforce who I'm always learning from and happy to partner with. And this workshop was just a real labor of love, and I'm so happy that so many people were able to attend last week and glean the information and be able to take that and go use HealthCheck and better secure their actual orgs, not just our fake, very poorly-secured org that we fix and adjust in the workshop. Mike: Yeah. I mean, it works because you can spot things very easily because I think in the real world, sometimes things aren't as obvious as they should be. I know the biggest question that we can answer, and we're doing it at the end on purpose, will there be more of this content? Kate Lessard: Yes. So I can't give you a date, but we are planning to continue this on a monthly basis. I do think that there are plans to expand the content as well. And you'll also maybe catch us doing these workshops hands-on at some community conferences over the next year. Mike: Ooh. See, even more of a reason to go to community conferences besides the fact that they're super fun and held at really interesting locations. Kate Lessard: Absolutely. And get to actually really connect with the community, which I am very excited about. Mike: Yeah. Yep. I hear you. Well, Kate, thanks so much for coming on the pod. Kate Lessard: Thank you so much. I'll talk to you later, Mike. Mike: So big thanks to Kate for joining us and reminding us that security is more than just a technical checklist. It's really a mindset for Salesforce admins as we operate to bring scalable systems to our entire enterprise. Of course, be sure to check out admin.salesforce.com for the announcement of more Security and Action workshops, which are also coming to future community dream and events, and start thinking about how your own org can shift from being reactive to an intentional system stewardship even with IT. Now, if you enjoyed this episode, subscribe, share with a fellow Salesforce admin, and of course, I always appreciate it if you leave us a review. And until next time, we'll see you in the cloud.
  • Can AI Help Salesforce Admins Build Apps More Efficiently? 21.05.2026 33min
    Today on the Salesforce Admins Podcast, we talk to Nick McOwen, Senior Salesforce Administrator at Alpine Intel. Join us as we chat about his path to Salesforce and the TDX workshop he gave about the development lifecycle, sandboxes, and data masking. You should subscribe for the full episode, but here are a few takeaways from our conversation with Nick McOwen. Nick's unconventional path into Salesforce Nick is the second touring musician I've had on the show this month—I promise I'm not raiding a recording studio somewhere just to find podcast guests. He was waiting tables in between gigs when a guest called him over to ask if he might want to try something different. A chance encounter turned into an entry-level job and, eventually, an admin certification. I caught up with Nick fresh off his workshop at TDX, where he shared how he uses sandboxes and data masking to build new agents and apps for his organization. Learning better development habits and sandbox management They say every warning sign has a story behind it, and the same goes for best practices in Salesforce. Luckily, Nick had Salesforce MVP Kelly Bentubo around to show him the ropes. He learned about the importance of consistent naming practices, managing user expectations, and having a structured deployment process instead of building in production. Recently, Nick was tasked with building a new recruiting app for his organization. He was able to spin up a sandbox with an app they had already built and, using that foundation, quickly reconfigure it to meet the new requirements. Once the app was in good shape, Nick moved it up to a staging sandbox environment for testing. There, he could copy data over from production and use data masking to keep everything secure. Once everything was thoroughly vetted, it was finally ready to be deployed into production. How Agentforce Vibes can help admins collaborate with developers Recently, Nick's been taking advantage of Agentforce Vibes to work more closely with his dev team. He was able to write an Apex class and, while the code isn't perfect, he was able to go through it with a developer to learn what was working, what wasn't, and why. "It was a great launching point," he says, "something that would have taken days was written in an hour." For Nick, the most important thing admins need to do to get the most out of Agentforce Vibes is to learn the basic underlying principles of Apex and coding. It's just like using a calculator—you still need to have some way of knowing if the answer you're getting is in the right ballpark. Make sure to listen to my full conversation with Nick for more on sandboxes, data masking, testing, and why AI is a new opportunity to grow. And don't forget to subscribe to the Salesforce Admins Podcast so you never miss an episode. Podcast swag Salesforce Admins on the Trailhead Store Learn more Salesforce Admins Podcast Episode: How Headless 360 Helps Admins Bring Salesforce Anywhere Salesforce Admins Podcast Episode: Why Pattern Recognition Matters for Salesforce Admins Salesforce 360 Blog: Your AI Could Be Better: The 4 Tools You Need for Continuous Improvement Admin Trailblazers Group Admin Trailblazers Community Group Social Nick on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript Mike: This week on the Salesforce Admins podcast, I'm joined by Nick McOwen, which means now I've started a trend of having former musicians who become Salesforce admins as guests. Anyway, Nick is going to show us how he went from touring in a band and waiting tables to leading Salesforce projects that involve sandboxes, data masking, deployment processes, and AI assisted development. We talk about the early build it in production and hope for the best admin days, how Agentforce Vibes is changing the way admins approach coding and why today's Salesforce admins are becoming orchestrators of systems instead of just builders of features. There's also a little Apex talk and surprisingly deep analogy involving semi-trucks and AI because you know my analogies and a confirmation that developers will always think their code is prettier. So hit subscribe, share this episode with your favorite Salesforce admin and let's get Nick on the podcast. So Nick, welcome to the podcast. Nick McOwen: Hey, Mike, it's great to be here. Mike: Well, I was introduced to you through a couple product managers at Salesforce that are always on the hunt for finding good Salesforce admins and you were also presenting with them in the admin track. So before we get to that, let's learn a little bit about Nick. How did Nick get started doing Salesforce and be in the ecosystem? Nick McOwen: Well, it was a complete fluke. I had been touring in a band and we just kind of stopped playing music and I was waiting tables at a country club and one of the members was, "Do you want to keep waiting tables?" I said, "Not particularly." So got me a job doing the entry level position at the company and I realized I didn't want to be doing that either. So I went to the developer at the time who was also the CIO and the CTO and said, "I'm going to learn Salesforce." And he kind of looked at me in the way that an adult might look at a middle schooler who said, "Watch me hit this three point shot." And I eventually learned it after a few misses, but they decided to take a risk on me and many, many years later here I am working with Agentforce agents writing a little bit of Apex here and there. And yeah, it just didn't intend to get here, but here I am. Mike: I mean, people are going to think I went down and raided the local music festival because not but a couple weeks ago I just had Adam Stark on who was also a musician that became a Salesforce admin. So apparently it's a trend. Nick McOwen: Yeah, that's the track. That's the track line for most musicians, I guess. Mike: Yeah. I mean, let's see. Should I be like an '80s metal hair band or an admin? Nick McOwen: Oh, that's a tough call. Mike: I know, right? Let's talk about some of the stuff that you presented at TDX because you covered a lot of things in terms of development life cycle and sandboxes and I felt like you were in that area for stuff that admins are interested in and kind of that next level of their career building apps. Nick McOwen: Yes. It was a talk that focused around seeding sandboxes masking data and my experience with that and it's funny because prior to the presentation at TDX, shout out to Allie and Sam, I was talking to them and they were running a booth and they were saying how many people that they'd talked to who didn't use sandboxes or didn't quite see the value in sandboxes. And so I realized that this talk probably had a lot more impact than I thought it was going to be. My particular use case was how we had rebuilt an app that our recruiting team was using for our field agents and how we spun up a sandbox specifically for it, rebuilt everything using the foundation of the app that was already there and got to test in a secure environment, move it up to our staging environment and then production. So it was an interesting experience and an eye-opening one too, getting to talk to everybody. Mike: I mean, to be fair, I don't think when I started as an admin, I really had to pay attention to what my organization's life cycle for app development was because you're kind of, and in this case, and I don't know about your company, but you're kind of a small scrappy unit and maybe they got Salesforce for like 20 or 30 people. I mean, nine times out of 10, I was just building stuff in a dev org to make sure it worked and then literally just not even deploying it, rebuilding it in production and Monday afternoon being like, "Okay everybody, so there's a new field on the account." I think back to those days of like, "Wow, what was I doing?" Nick McOwen: 100% identify with that because that is exactly how I more or less learned when we were first starting out because like I said, it was just the developer and then me and we had to get things done because it was a startup environment, things move fast and so it was tested in the sandbox and then move it. And I didn't want to bother him so I wasn't using change sets and so I would make a field or whatever he asked me to make and then rebuild it in production when nobody was working and just, yeah, it was loose and fast. Mike: I mean, nine times out of 10 when I was building things in my dev org, I wasn't paying attention to naming. I was just trying to like proof of concept and so I never wanted to package anything up because I didn't want to move it over because I was like, "Well, when I get to production, that's when I'm going to make the names nice and shiny." Nick McOwen: Yeah, I remember we brought on Kelly Bentubo, MVP. She sat me down and was like, "All right, we're going to start fixing some of these habits," which totally warranted. And I mean, she was great at helping me understand the value in the consistent naming, the process aspect of everything. So she really elevated my abilities and my use cases and everything. Mike: So as somebody that just started, obviously went from waiting tables, which by the way, 20% tip is not excessive. It just means that you got everything good and on time, you should tip more. Thank you for attending my waiter tipping TED Talk. Just getting into this and thinking, okay, I guess these are bad habits. I bet you had the same bad habits I did. What was the first things that she kind of tackled? You mentioned some of it was naming. Did she help you set up sandboxes and kind of a deployment life cycle? Nick McOwen: So we had the sandboxes and she came on at the time when the dev team was starting to grow and the company itself was starting to grow. So we needed more organization and she kind of sat me down and helped me with these processes, like how to move it up through the environments, the value of making sure that everything is tested within the sandbox environment and then user management, which I think is something that I relied on when I first started. It wasn't necessarily that I knew what I was doing a lot, but I knew how to put on like a waiter attitude so to speak. And if somebody asked for something and I didn't know what I was doing, it was just that kind of like, "Oh, I didn't burn your steak, but let me make this better for you." And so through talking with Kelly, I kind of like refined how to shape expectations for users. If I couldn't figure something out, then she would kind of help coach me through the deployment issues or level setting and expectations with users, which that was a big one. Mike: I mean, I think that also we've talked about order taker admins before and it's very easy to sit across the desk from somebody and listen to them be like, "Oh yeah, this is totally easy to do," or, "I have no idea what I'm going to do." And then say, "Yep, let me just work on it and kind of forget that maybe there's bigger things in the organization they need to pay attention to as opposed to everything that comes in front of me right away." Let's get into that recruiting app that you built. Was that your first kind of get your hands dirty in the org per se, building something new for the organization? Nick McOwen: That was my first project that I led from start to finish. I got the specs from the higher ups. They said, "This is roughly what they're asking for, figure it out." And immediately went to the recruiting manager and said, "Okay, let's figure out how we want this to look." And we had an app that was already built and I knew that the foundation of that app was great. And so it was really a matter of building off of those blocks and reconfiguring it, re-imagining how it could be used and then future-proofing it so that it could scale as the business grew. And it was definitely a lesson in organization and communication, which is good. Always want to keep learning and growing. Mike: Yeah. So let's dig deeper into that organization communication. What organizationally, do you mean the way that you organized stuff, understanding your company's organization, a little bit of both? Nick McOwen: A little bit of both. For me, it was keeping track of everything that was getting worked on, making sure that we were trying to document the change in processes and communicating those changes to the business side so that they would know, you might not interact with this functionality, but this is what's going to happen to get you this result. And that it sounds pretty straightforward, but I think that can get lost sometimes on people, especially in larger projects where it seems peripheral and intuitive, but it might be what's intuitive to someone who built it might not be for the person that's going to end up using it. Mike: Yeah, which leads into communication. I always feel you can't communicate enough. I feel with every project I've ever worked on, you always learn more about communication. What did this first jump in kind of give you in terms of maybe some best practices that you follow now or stuff that you learned really quick? Nick McOwen: I think the accountability aspect maybe was if you presented an idea and it's kind of your child and you say, "What do you think about this, huh?" And then the end user going, "No, that's not going to work for us." There's like a little bit of an ego bruise where you think, "That was a really good idea though." Maybe it wasn't, but then kind of absorbing that critique and then using it to build something that you know is going to work and not being stuck ruminating on the fact that your idea didn't get accepted, that was kind of a lesson because prior to that it was somebody else's idea or I was building something that was given to me. It wasn't as personal, but that was the first time I got told, "Hey, I don't like that." Mike: Yeah, that can always... It's funny because you almost want your cake and eat it too, right? I don't want to take the rejections personal, but you 100% take the wins personal and it's like you can't have both. You really do though because it does feel like, "Well, no, I know how this thing works and I promise this will really work for you, but you're just not seeing it." And that can be the frustration that I always ran into. Nick McOwen: Exactly. And then even after I built it, my bosses came up and they said, "What is this object?" Oh, well, I made that because that was giving the solution to the end user and they said, "Hmm, well, why didn't you do this?" I was like, "Ah, I don't know why I trusted my gut and stuck to it." Mike: Right. Well, this is the way it is now. Let's talk about, I feel like that's always the first part. Your path into Salesforce, they always talk about individuals that grew up and like I was in high school in the 90s just to date myself, but I remember in middle school there was no internet and when I got to high school, you could go to the library and check out the internet for 15 minutes on a computer. I bring that up to say, obviously now everything's online and I don't know how I even got anything done in 15 minutes with dial-up modems back then, but apparently I did. You kind of came in to the Salesforce ecosystem at about the same kind of inflection point with AI in that there's really best practices and development aspects to learn, but then, oh, hey, by the way, now we've got a lot of new stuff coming like Agentforce Vibes. How did you kind of balance those two that learning path? Because I think it would be very easy to, "I don't need to learn this. Vibes can do it for me." Nick McOwen: I think that's something that is incredibly important in this time with the ubiquity of AI and how many people are using it. I think people need to become literate in AI. I don't mean learning how to program large language models or even write agents, but just understand how it functions. And in the context of Salesforce, I remember I first started getting into the predictive analytics for Einstein and thinking, "Oh, this is super cool." We didn't end up going that route, kind of kept my eye on everything going and then Agentforce came out and started learning that. And it feels like every couple weeks something's getting rolled out, which is exciting because there's always something to learn and I don't know, I would hate to be stagnant and have to do the same thing over and over for 20 or 30 years. So it's a blessing and a curse to have a product that constantly evolves for you to learn. So it's exciting. Mike: I think you covered Agentforce Vibes in your TDX workshop. What have you done in Agentforce Vibes? Nick McOwen: Shockingly, I made an Apex class and a test class that- Mike: Hey. Nick McOwen: If you had asked me... Mike: It's kind of what it's there for, right? Nick McOwen: Yeah. The musician that could barely string sentences together is all of a sudden writing Apex classes and test classes. I mean, if you asked me even a year ago, "Hey, Nick, would you think you could write an Apex class?" I was like, "Yeah, give me a couple years so I can write it line by line over days." Mike: Sure. Let me put an ad out on Craigslist and see if I can get a developer to do it. Nick McOwen: Yeah. I would've laughed if somebody said that and then all of a sudden this product comes out, which actually Allie and Sam, when we were doing our ... We did a webinar for the sandbox seating and data masking and they were talking to me about the Agentforce Vibes and I said I hadn't really looked into it. And so after that talk, I started to and that kind of encouraged me to look into the foundations of Apex and coding languages. So it wasn't just learning Agentforce Vibes and how to use it. It was also getting a base understanding of the underlying principles. And so through that journey, I was able to use Vibes to write an Apex class and then I could take that class to the developers and then the developers would look at it and go, "Well, my Apex is better, but we'll use yours." And corrected a couple things because... Mike: Wow, you really nailed the developer intent like mine's better, but we'll use your... Nick McOwen: It could be flawless code and still, mine's prettier. No, I do. I enjoy working with all those guys and they were great helping walk me through everything and showing me, "Okay, this is where Vibes made this. This is the intent but it doesn't quite hit. Here's how we're going to fix that. Walk me through." And it was a great launching point. Something that would have taken days was written in an hour. Mike: Oh, wow. Nick McOwen: We're not talking thousands of lines here. It was- Mike: No, but still. Nick McOwen: 150. Yeah. And then the test class on top of that, it saved us a ton of time. Mike: If you threw me in jail and said, "You're out when you write 150 lines of Apex class," I'll be like, "What's for dinner?" Nick McOwen: I've been be here for a while. Let me get some furniture. Mike: We're going to be here for a few years. Do I get a shave every now and then every few weeks to keep me from looking scruffy? I mean, I was so impressed getting the admin track ready for TDX this year with the submissions that admins had. I watched them demo vibes and just use the planning tab and really kind of have vibes spell out like, "Here's everything you need to do and here's kind of an action plan." And I felt like natively some people had that, but for a lot of people, wow, this was really helpful because I had this monster of an application but I didn't know where to start and it wasn't just, "Oh, I have to vibe code this super hard application." It's like, "No, this is actually just helping me get my steps down." Nick McOwen: I'm excited for the future of the vibes and Salesforce integration, specifically with your organization's metadata and being able to find, where are these fields referenced? What would happen if I did this? I think when that becomes a reality, it could be something that's really cool. And I imagine that's something that's possible if it's not already. I'm not a vibes connoisseur just yet, but I think something like that would be incredibly beneficial. How many times have you tried to figure out where an error is coming from on the admin side and you just go, "Well, I hope a developer has time to help me figure out this error." Mike: That, or how many times do you go to delete something and you can't because there's a dependency and then you spend the next four hours chasing all of the dependencies just to get that one thing done. I mean, the benefit the listeners have is last week on the podcast they heard from Khushwant Singh who was literally leading our Headless 360 development. And I mean, I asked him, I was like, "Do you envision a world where a Salesforce admin sits down and talks to Salesforce to build the application?" And he's like, "Yes." I mean, not forward-looking statement, not by Dreamforce, but that's the rubber band that I think everybody with AI is going to is, "Well, if we make the AI smart enough that it can actually build and rebuild the applications that it's running, why wouldn't you?" Nick McOwen: Yeah. And being on the other side of the wall, so to speak, to be frank, it can be scary on the tech side because you think, "Oh, is this something that's going to replace me?" But having talked to people, it's also an opportunity to learn and grow. And if that's something that you want to do, then you grow and you adapt. I kind of think of it like painting and photography when the photograph came out all the painters like, "Oh, that's poo, poo, poo, throw it out stinky cabbage and it's a tool." And then it kind of grew into its own path and now it's a separate form of art for most people, I'll say, but I kind of see similarities in that sort of mistrust of this new technology and maybe not everybody wants to be an admin for the rest of their life and they'll go and be an artisan baker or make candles or something. I think that's great. That's the beauty of life. Mike: Yeah. No, I mean, I've had the very same discussion too of, well, is AI going to take your job? And I think of it like I happen to think of it as you see a lot, you look out on interstate, you see a lot of big semis go down the road and is it really cheating that the guy's driving the semi to move 80,000 pounds? If he has to get some steel from California to Pittsburgh or Pittsburgh to California, it's kind of silly to think that a person would pull that. No, they're going to use a vehicle that is optimized for moving that kind of capacity and payload. And I look at the way we use AI in the same ways. It's not cheating for me to use AI. It's I'm using my skill to navigate and move and maneuver the AI to produce the product that I want the same way that the truck driver navigates the semi through traffic and road construction and busy city streets to get the product from A to B. Nick McOwen: And to that point, exactly like you said, you're using the tool to build what you've envisioned and it is a tool and I think people need to be careful not to rely on it as their brain and we need to keep learning the foundations of Apex so that if you do use Vibes to write 2020 lines or something, you can sit down and look at it and see, okay, where might this be going wrong What do I actually know about this? So using it as a tool and not your brain replacement, I guess, be- Mike: Right. It's the same way we had to, your math teacher was telling you to use a calculator. You should know the answer before it tells you. Nick McOwen: I mean, I look back now and how frustrating that was as a kid to be told, can't use your calculator and now so many years later it's, well, now that makes sense. Now I see why they said you can't use your calculator. Mike: And it does help. I think the irony is I didn't realize how much I needed a calculator until I sold shoes for a living because people always wanted to know, well, how much are these? They're 10% off or they're 25% off. And I learned the little trick of how you find 10% of anything because once you find 10% of a number, you can literally find any number. And so somebody would ask you like, "Well, they're 39.99, but they're 25% off. Well, how much is that?" And you're like, "Okay, so 10% is 390 and 20 would be 390 times two, and then 25% would be 390 times two and then half of 390." And you do the math really quick in your head, which I'm not going to do right now, but it's around what, like six, eight, 10 bucks, something like that. And you tell them like- Nick McOwen: They can work for that. Mike: "Wow, how'd you do that so fast?" And you're like, "Because I can do math in my head." Nick McOwen: This is going to turn into a math hacks podcast. Mike: No, never. It'll be a food podcast before that, but I did want to cover... So one thing you did talk about that I haven't covered on the podcast is data masking. And I feel like it's because I've never really ran into it as a use case for me anyway, but it's not that I don't understand it, but what was kind of the use case that you guys ran into for really needing to make sure that you used data mask in... I mean, you used it in a sandbox, right? Nick McOwen: Yes. So very relevant to me at the moment. We're in the process of a big build and to get prepared for that we spun up a sandbox and needed accounts and contacts and we could have made it one by one. That would've just been cumbersome. We didn't really have the time for that. So we seeded it and then masked all of the data. So now we've got dozens of contacts for each account and we needed to be able to test email deliverability, but you don't want to send a test email to your clients. Mike: No. Nick McOwen: "Why did I get this test? What test-" Mike: "Oh, it's just us testing things. Thanks." Nick McOwen: Yeah. And then all of a sudden you get a pink slip in the mail, but no, nobody wanted that for anybody. So we changed and masked all the data, removed all the personal information, made scrambled emails, phone numbers, anything that could potentially link to a client and all of a sudden we've got a fresh sandbox with no real contacts and information. We were able to go in there, test the email deliverability safely and then once we proved out our process could move it up to the larger sandbox environments and eventually into prod. So without that masking feature, we're spending time one by one creating contacts and filling out information. Mike: Yeah. And I mean, the goal is when you're building something, you always want to... I want to test it on as real of data as possible and or if I'm bringing in a consultant or somebody, they also don't need this data. They just need it to act like data. They don't actually need to understand what that data is. I think that's always incredibly valuable. Nick McOwen: And in the context of training agents, you don't want to just unleash an agent in your production environment and go, "Well, I hope this works." Mike: Oh, very true. Nick McOwen: If you start testing it in a sandbox environment but you're skewing the data or you're giving it biased data, then you're not going to get a representation of how it's going to function in the production environment. So to be able to seed it with randomized realistic data, you have a better environment to then build and train that agent to move to production. Mike: Yeah. You don't want it thinking that you have 15 random widgets that you sell. Nick McOwen: This is working great. Wow. Mike: Yeah. Look at it. It's going to build the widgets for us and then you put it in production and the agent realizes everything's a lot more complicated. Nick McOwen: Yeah. Then you're sweating. Mike: Yeah. Well, the agent's not, you are. I guess as we kind of wrap things up, if you were to go back to the Nick when he was learning Salesforce and getting into this, is there anything you would tell yourself to do differently that you wish you'd done at the beginning? Nick McOwen: That's a tough one. I think what was important for me learning was having the ability to create a sandbox in Trailhead and really just explore the things that interested me and follow the paths of the things that interested me. I mean, if I'm going to be real nitpicky, maybe spend some more time trying to learn the foundations of Apex because it can be frustrating as an admin to have this brilliant idea and then not have a developer have time to be able to help flesh out that idea although there's a product now that's kind of doing that. But that would probably be if pie in the sky, do it again, learn a little bit more about coding. Mike: Yeah. That makes sense. I mean, for as much as every application builds front end usability stuff, there's still always code running somewhere that somebody's going to have to upkeep and build more of too. Well, very cool, Nick. Thanks for coming to speak at TDX. I know sandboxes and data seating and data masking can fall farther down on people's popular list in terms of cool fun stuff to see, but it's very important. I'm glad you also came on the podcast and talked about it and gave people some tips. So thanks. Nick McOwen: It's been a blast. Thanks for having me. Mike: Huge thank to Nick for joining me this week and proving that sometimes the path to writing Apex starts with playing in a band and waiting on tables. We covered everything from the startup style deployment chaos to Agentforce Vibes, data masking, AI literacy, and the universal admin experience of chasing dependencies for a few hours just to delete one field. What stood out to me most is how the admin role is evolving into systems of thinking and understanding not just what gets built, but how humans and automation and AI all interact together. Now, if you like this episode, please subscribe, share it with another Salesforce admin that you may know or maybe spin up a sandbox before making changes directly in production tonight. Until next time, we'll see you in the cloud.  
  • How Headless 360 Helps Admins Bring Salesforce Anywhere 14.05.2026 23min
    Today on the Salesforce Admins Podcast, we talk to Khushwant Singh, SVP of Product Management for the AI Application Development Platform at Salesforce. Join us as we chat about what Headless 360 means for admins and how Salesforce is building towards a future where setting up complex systems becomes a conversation, not a checklist. You should subscribe for the full episode, but here are a few takeaways from our conversation with Khushwant Singh. What is Salesforce Headless 360? If you're not a developer, the idea of a "headless" platform may sound a little spooky. My guest this week, Khushwant "Khush" Singh, is here to tell us what it all means and why Salesforce Headless 360 represents a step forward into the future of the Agentic Enterprise. As Khush explains, in a headless platform the frontend is separated from the backend. If you have a pixel-perfect website that you love and you want to use Salesforce applications, or visualizations, you can do that without having to change anything. If your organization relies on Slack, your users can interact with Salesforce data and agents in the chat instead of having to open another browser tab. "Headless 360 is about bringing Salesforce to wherever you need it," Khush says. Headless 360 builds the foundation for the Agentic Enterprise One of the main reasons for Headless 360 is to rethink the Salesforce stack for AI. "For the last 27 years, those layers have been put in place for a human," Khush points out, "so how do we open this up for both a human and an agent?" To do that, Khush and his team are translating the entire platform into a set of model context protocols (MCPs), skills, and metadata that can interface directly with AI agents. This makes conversational tools within the platform, like Setup with Agentforce, even more powerful, while also allowing you to use any other outside AI model you like. And while these changes have the biggest impact on vibe coding for now, Headless 360 lays the groundwork for a future where we build agents, create applications, and configure Salesforce through a conversational interface. No coding required. Why trust is even more important with the rapid pace of AI AI is quickly transforming the way we work, and the conversation can become centered on how to move fast. But that makes trust, quality, and governance even more important, Khush explains. Headless 360 is built with trust as a core feature, so you can move quickly without making compromises. There's much more from Khush about Salesforce Headless 360 and what it means for admins, so be sure to listen to the full episode. And don't forget to subscribe to the Salesforce Admins Podcast to catch us every Thursday. Podcast swag Salesforce Admins on the Trailhead Store Learn more Salesforce 360 Blog Post: Introducing Salesforce Headless 360. No Browser Required. Salesforce Admins Podcast Episode: Setup with Agentforce Makes Salesforce Admin Tasks Easier Salesforce Help Article: Setup with Agentforce (Beta) Salesforce Admins Blog Post: What Is MCP? A Simple Guide to Model Context Protocol for Salesforce Admins Trailhead: Salesforce Headless 360: Quick Look Admin Trailblazers Group Admin Trailblazers Community Group Social Khush on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript Mike Gerholdt: This week on the Salesforce Admins podcast, I'm joined by Khushwant Singh to talk about what happens when Salesforce stops just being a destination and starts becoming part of every system your business already relies on. That's right, from Headless 360 to Setup with Agentforce, Khush breaks down how admins are moving beyond configuring features and into orchestrating how data, AI agents, automation and people work together across the business. Now, we're going to dig into what Headless actually means for admins, why governance and trust matter more than ever in an AI first world, and how Salesforce is building toward a future where setting up complex systems really becomes more of a conversation than a checklist. This episode is really about systems thinking, how admins can connect experiences without forcing teams to rebuild everything from scratch. So if you've been trying to figure out where AI fits into your role or how your role is evolving alongside it, I promise you this episode gives you a practical look at what's already happening and what's coming next. So be sure to hit that subscribe button. Share this episode with your favorite architect or admin friend, and let's get Khush on the podcast. So Khush, welcome back to the podcast.   Khushwant Singh: Thank you for having me back, Mike.   Mike Gerholdt: I say that because I had to look and it was 2022 back in the day you were talking Experience Cloud when we last had you on. You've since moved on, moved up, had your hands in a lot of things, did an admin keynote with me. So let's start there and let's kind of catch everybody up on some of the products you've been working on, and then we're going to talk about the newest one that we launched at TDX this year.   Khushwant Singh: Yeah, happy to. And again, great to be back. I think back in the day, started obviously with Experience Cloud. Experience Cloud really was building a product that is external-facing and again, it's built on the same platform. And again, as we looked at the product portfolio, it just made sense to start to bring things together. So we've actually sort of rolled and morphed into the application development platform, obviously within the platform organization, everything pro-code, low-code, desktop, mobile. And so there've been quite a few products leading up to here, anything from our delivery on mobile, mobile offline, the Salesforce mobile app, all the way to Agentforce Vibes, the Agentforce Experience layer, obviously a fair amount of work on the Headless side of things. So yeah, it's been quite a journey to this particular point, Mike.   Mike Gerholdt: Yeah. I mean, it's actually hard to point out things that aren't admin-friendly that you've had your hands on because you've always kind of championed everybody being able to build on our platform. So let's talk about TDX this year because we launched Headless 360.   Khushwant Singh: Oh yeah, we did.   Mike Gerholdt: By the way, in case you forgot.   Khushwant Singh: Yeah, it was a massive announcement. I think, look, as you think about what's happening in the market right now, you've got customers engaging through many different surface areas. We've got customers on ChatGPT, on Claude, on Gemini, Teams. At the same time, you've got developers also using a variety of different tools, different IDEs, different coding agents. And so I think Headless 360 really is a testament to acknowledging this change in the market in the industry and trying to meet the customer where they are. The customer being an end user or the customer being a developer and admin, just meeting them where they are in whichever tool, whichever interface they might be.   Mike Gerholdt: Yeah. I mean, do you recall ever a time in technology when it was, I hate to use the euphemism, but like the Wild West where I feel like there's so many choices for what you can do just in regards to AI?   Khushwant Singh: There is. And there is obviously a good side to it. There's also a downside to it. The good side is really your [inaudible 00:04:31] for choice. There is innovation that is helping you drive productivity day in, day out. The downside of this is you just have to be really careful about quality, about trust, about governance. And you have to ensure that while you're going fast, you're not sort of compromising on that trust aspect of things. And that's what we're trying to do here at Salesforce and just trying to be a little bit more thoughtful in our approach over here.   Mike Gerholdt: Yeah. So my developer friend, Josh Burke, who comes on the podcast, usually has to explain things to me every now and then. I think developers are very familiar with the term headless.   Khushwant Singh: Yes.   Mike Gerholdt: I'm not sure outside of Headless flows, which I know what those mean, I'm not sure admins could understand or could confidently buzz in on a game show and answer what is Headless 360. So can you help them kind of understand what is Headless 360 if they had to tell their manager?   Khushwant Singh: Yeah, sure. So one way to think about it is, let's say you're a customer and you've got your own website, it's built out of React, it's not built on the Salesforce platform, but there is so much of your goodness and investment that you have within the Salesforce platform that you want to be able to easily reuse in the context of this other website that you have, portal that you have, mobile application that you have. All of that may not be built on the Salesforce platform. You want to be able to reuse your investment seamlessly. And so Headless 360 really is about how do we empower you, the customer, to be able to easily use those assets, those investments within the Salesforce platform in that surface area that you've got that may not be on the Salesforce platform. So it's really about giving them that flexibility so that they can easily reuse their investments in all of these various surface areas and just meet their customers wherever they are versus bring their customers into Salesforce.   Mike Gerholdt: Yeah, I think it makes sense. I mean, I was a customer way back in '06 when I remember it was like transfer and move to Salesforce, and everything was "have it on the platform, have it on the platform." And then shortly thereafter it was kind of like almost the realization that we had was, "Well, it's a lot of friction to constantly move platforms. What if companies just integrate and we become that connector to everything?" And I feel the same way with this.   Khushwant Singh: 100%. And you know what? Look, I think the one example is if you go into the Williams Sonoma website, right? Williams Sonoma website, it's not built in Salesforce, but if you use their sous chef AI, I think... I'm not sure what they call it, but-   Mike Gerholdt: I'm sure it's something really, really snappy and small.   Khushwant Singh: Olive. Olive. There you go.   Mike Gerholdt: Olive. Yeah. See?   Khushwant Singh: A snappy name right there. That agent is an Agentforce agent, right? So that's on example where Salesforce is being used in whichever head that you'd like us to be in. And so in this particular case, the Salesforce agent is in the Williams Sonoma website. So that's just one example where we are trying to make it easier for this integration to happen through the Headless 360 platform. Now that's one view. And that's the view, I would say, an easy way to try to understand what it means for Headless 360.   Mike Gerholdt: Yeah, because then as an admin, as a developer, you're not having to sit down and say, "Okay, well, if we move to the Salesforce platform, we have to deprecate everything that we just spent the last two years building on our site." Marketing's like, "No, no, we just got the site pixel perfect the way we want it. Now we can integrate best of everything that we want." For admins who aren't thinking of maybe websites, how does Headless 360 play into other integrations that they may talk to IT or internal stakeholders about?   Khushwant Singh: Yeah. So for example, when admins are chatting with their other internal team, they may have a custom application that they already have in place and they want to be able to have Salesforce data, Salesforce visualizations surface in whichever application they may have already, right? That's one example. So again, it is about bringing Salesforce to wherever they may already have. So for example, an admin may have a business application that already runs within ChatGPT. So ChatGPT, for example, it allows companies to create bespoke applications. And if you want to be able to integrate Salesforce into that application, that's doable as well. It doesn't have to be in ChatGPT. It could be in any other existing non-agentic application as well. But it's about that, look, you don't have to rebuild everything. Wherever you are, you've got an existing application, we'll find a way through Headless 360 to be able to bring Salesforce to it.   Mike Gerholdt: Yeah. No, it totally makes sense. I mean, in that way we can really think about how are we making sure that the departments have the software and the tech that they want, but also access to all of the information that they need to do their jobs the best.   Khushwant Singh: Mm-hmm.   Mike Gerholdt: So Headless 360 is a big thing we talked about. I also know I saw you in some True to the Core and True to the Core Deep Dive stuff. Was there some features you were talking about in that that possibly play into what admins are going to be working on for the rest of this year?   Khushwant Singh: Well, yeah. I mean, a few aspects as we think about Headless 360 that would be of interest to admins. So first and foremost, you've all seen the stack diagram of the Salesforce platform. You've got those four layers. You've got your layers of engagement, you have layers of context, you've got the sort of our data foundation, et cetera. So you've got those layers that make up the Salesforce platform. For the last 27 years, those layers have been put in place for a human, right? And now what the product teams and the engineering teams are doing are going back and saying, "How do we now open this up both for a human and an agent so the agent can do that work on behalf of the admin when the admin sort of wants a task to be done for that particular reason?" And so what that means is that we're translating our entire platform into a set of MCPs, a set of skills, a set of metadata that is grounded so that these agents can do the work on behalf of the admins. So one good example is the setup with Agentforce, which is so far so good. We've gotten great feedback on it. Now behind the scenes is a set of skills, a set of MCPs that are firing off to be able to get their tasks done. And so that's one thing that I think our admins can look to benefit from. The other piece is I know we have some admins who are familiar with some of these IDEs that we have out there. They use Cloud Code quite a bit. They use Vibes quite a bit. It may not be the entire admin audience, but for those audiences, again, the ability to be able to use all of these MCP skills in these development environments is another thing that our admins can really look forward towards. Now the other thing that we've also worked on is, over the last few months, the foundation for these skills, these MCPs, this Headless 360 foundation has been very sort of focused on how do we unblock these pro-code use cases, whether that's in Cloud Code, whether that's in Vibes, et cetera. But this is the same foundation upon which as we speak in safe harbor, I share that we are building what we call our no code offering as well. So how do you go about in an unintimidating sort of type of interface, have this conversation with an agent, which behind the scenes is interacting with that same Headless 360 layer to help you build out your agents, your applications, to help you augment your existing agents and applications, help you set up provision, configure Salesforce from a zero to one point of view, because we all know how setting it all up is quite a taxing task for our admins? So that's the potential I see for Headless 360 for our admin personas.   Mike Gerholdt: Yeah. I mean, to go back on some of the stuff that you were mentioning, I remember the first time I thought, "Hey, I could have ChatGPT rewrite ChatGPT's instructions." And I remember thinking like, "I'm so far ahead of the curve, man. I'm making AI rebuild AI." And then it was only a few weeks later that Cheryl was demoing Setup with Agentforce and I thought, "Oh, that makes so much more sense because all of the things that you were having that setup agent do are things that not necessarily admins don't like doing. It's like paper cuts." It's the little things that take 20, 30 minutes out of your day when you really wanted that solid hour to build that application kind of start to finish.   Khushwant Singh: Indeed. Indeed. So we really viewed Headless 360 as the foundation upon which agents can work on behalf of the admins. And again, look, this is agents and admins working together because again, we've got to have the human presence to be able to validate, to be able to interrupt, to be able to initiate any actions that are performed by the agents. And if these agents can help drive greater productivity, then it's a win-win while at the same time having governance by humans over it.   Mike Gerholdt: Right. Absolutely. Do you envision us being at a point where all of setting up Salesforce could just be a conversation with an agent based on the business and what they're trying to accomplish?   Khushwant Singh: We are trying to do that. We are trying to do that. Now, I'll give you a view into our approach over here. We're taking a steel thread approach here where just trying to, for example, set up a customer service agent. That cuts across Service Cloud, cuts across platform, cuts across Agentforce, cuts across Data Cloud. So we've got to take a system view, an end-to-end view versus a feature view because that's what our admins go through. That's what a practitioner goes through. They look at it from a steel thread point of view, and that's what we as product teams have to do. And so as we think about using agents to go ahead and help provision, set up, get Salesforce up and running really quickly, that's the new strategy that we are taking over here, a steel thread view so that we can look across the board and say, "Look, which MCPs are missing? Which skills are missing? Which APIs are missing? Which metadata needs to be grounded? How do we ensure that across entire steel thread, quality is being ensured, governance is being woven into?" So we are starting that way and we want to scale that way as well. So my hope is that come Dreamforce this year, we'll be able to at least have a sizable number of steel threads that we feel really, really confident about on Agentforce really helping and agents helping in this particular side of things. So yeah, that's the approach we're taking, Mike.   Mike Gerholdt: Wow, that's going to be amazing. Every time you think, "Oh, we've probably invented everything," technology just comes along and pulls the rug out from underneath of you and says, "Haha! There's new stuff. You got to figure this out now." I'd be curious, you're so ingrained in a lot of things that admins do on the platform, a lot of things developers do on the platform and then also having to keep up with AI. What is a piece of advice you could give people for how you personally keep up with the newest news and innovation on what's going on with AI?   Khushwant Singh: Wow, that's a good question. I think first and foremost, I spend a lot of time just looking at reading publications like what's on TechCrunch, what's on Techmeme, trying to just understand how are technology providers adapting, how are companies using AI. That's one. The second one is actually you learn a lot via speaking with others in the community, right?   Mike Gerholdt: Mm-hmm.   Khushwant Singh: You talk to customers, you talk to other admins, you talk to other developers and you get to understand there are use cases that they're working through and some of the very many innovative workarounds or users of AI that they're applying. And then you're thinking about this that, "Wow. There's a trend here, there's something that we should be backing up and maybe providing out of the box within the product." And so I think that community piece speaking with other customers, with your peers, your colleagues from different companies, that sort of brings a very practitioners and practical view to things. So I think if you combine it with some of these ... So if you take a combination of both, what's being published out in the internet, what sort of bleeding edge and all of these various publications and then you sort of marry that and juxtapose that with the practical aspects on how it's implemented in all of these various by your peers in different companies, that's kind of how I ... That's at least the approach that I've taken. And I've seen it help even with some of my teammates who use a similar approach as well, Mike.   Mike Gerholdt: Yeah, I would agree. I mean, coming fresh off of being at a conference, just even talking with people, you find more resources than you think you could find and it exposes you to different levels of thought. As we kind of close things out, I'd love to know I'm always big, especially when I'm coaching people for events, for TDX, for keynotes, because I've been in keynote with you. I feel like when people are done listening to something, I always want to give them something very actionable that they should do when they get done listening to a session or they get done listening to a podcast like this. So if you are a Salesforce admin listening to this podcast, what is one thing you think you should do right after you listen to this podcast?   Khushwant Singh: Good one. It's a tricky question. I would say that, look, I would encourage everyone to go ahead and use and try and give Setup with Agentforce a run, right? Take it out for a spin. It's available in an open beta. And I would encourage all of you all to give it a try, please. We've gotten so much great feedback. We are a stone's throw away before we make it generally available. And this is our first approach to using Agentforce, using AI to help improve the productivity and quality of life of our admins. It's not our last, but it is definitely our best foot forward right now. And we'd love to get your feedback. Like I said, we are in the final mile and your feedback is much appreciated, so try it out.   Mike Gerholdt: I love it. Khush, you've always been a fan of admins. And I am so grateful to have you back on the podcast and even more thankful that you are constantly helping Salesforce innovate for everybody in the tech industry to be successful. So I appreciate you spending a little time with us today.   Khushwant Singh: No, of course it's my pleasure. Admins are the lifeblood of Salesforce. You're out there, you're representing our products, you're using our products, you're championing our products, you're giving us tough love. And we can't be more appreciative. And so this is an honor to be here on this podcast to speak with you, Mike, and to speak with all of our admins.   Mike Gerholdt: And a big thanks to Khushwant Singh for joining me and sharing how Headless 360 and Agentforce are reshaping the way admins build and manage systems across the business. My big takeaway? Well, the future admin isn't just configuring Salesforce. They're designing trusted systems where automation, data, agents, and people all work together for better outcomes. And as Khush said, trust and governance will still sit right at the center of all that work. So if you haven't already, take Setup with Agentforce for a spin and start exploring what human plus agent collaboration can look like in your org. And of course, be sure to subscribe, leave a review. And as always, I would love it if you share this episode with your friends. Until next time, we'll see you in the cloud.
  • Why Pattern Recognition Matters for Salesforce Admins 07.05.2026 32min
    Today on the Salesforce Admins Podcast, we talk to Adam Stark, CRM Systems Administrator at Belmont University. Join us as we chat about how his experience as a musician with learning and pattern recognition has set him up for success as a Salesforce Admin. You should subscribe for the full episode, but here are a few takeaways from our conversation with Adam Stark. From the stage to the Salesforce Admin chair I met Adam Stark at TDX, and he had such an interesting path to becoming a Salesforce Admin that I had to bring him on the show. Based out of Nashville, he's been a professional touring musician for twenty years. But when everything shut down during COVID, he spent his days on Zoom making an album, and his nights on Trailhead working towards his admin certification. Adam's experience in the studio made it surprisingly easy to jump into automations on Salesforce—they made sense to him. "As a music producer, one of the things I got really good at doing was accomplishing signal flow, like trying to get a sound source to a final, presentable stage," he says, "and that sort of signal flow process is the same with flows." Whether it's building tracks in a DAW or building solutions in Salesforce, Adam discovered that it's still the same underlying logic. How pattern recognition makes learning Salesforce easier Starting out in Salesforce can feel overwhelming because the platform is robust. But, as Adam explains, the same could be said for learning guitar, and he realized that he could draw on his experience as a music teacher and performer. A part of learning any instrument is pattern recognition. You practice scales or licks in isolation so that it's easy to find them and play them when you're performing. "The more you do it, the more familiar you get, the more you begin to recognize patterns," Adam says, "and once you see the patterns, things start to feel smaller." Over time, something that seems very big, like learning a piece of music or trying to use campaigns in Salesforce, becomes more manageable. Acing your job interview with honesty I also wanted to hear how Adam got through the interview process and landed his first job as a Salesforce Admin. His experience as a musician helped here, too, because he was already used to doing interviews with radio stations while on tour. But nerves aside, Adam feels the key to his success was honesty. "I don't know everything," he says, "but if I don't know it, I'll figure it out, and we'll find a solution." For the folks out there who are still breaking into the ecosystem, Adam encourages you to get out there and meet working Salesforce professionals as soon as you can. Go to a community group, or even TDX, and pick someone's brain. It can help you piece together what you're learning in Trailhead by understanding what Salesforce looks like in action. There's so much more great stuff from Adam about how he learned Salesforce and landed his first admin role, so make sure to listen to the full episode. And as always, make sure you're subscribed to the Salesforce Admins Podcast, and we'll see you next time. Podcast swag Salesforce Admins on the Trailhead Store Learn more Salesforce Admins Podcast Episode: How Do I Transition Into a Salesforce Admin Career? Salesforce Admins Podcast Episode: Building Salesforce Projects To Land Your Next Role Admin Trailblazers Group Admin Trailblazers Community Group Social Adam on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript Mike: This week on the Salesforce Admins podcast, Adam Stark didn't start in Salesforce. He started on a stage, building songs and touring as a professional musician. In this episode, he's going to share how that same mindset of thinking and systems, sequencing steps, and designing outcomes translated into building solutions with data, automation, and now AI. In this episode, we're going to dig into how admins aren't just learning tools anymore. They're designing how work actually gets done across people and technology. Adam's going to walk us through his journey from Trailhead to his very first admin role and what it really takes to connect those dots when you're building something bigger than just features. So if you've ever wondered how your past experience shapes the way you architect solutions today, this episode's for you. So with that, let's get Adam on the podcast. So Adam, welcome to the podcast. Adam Stark: Happy to be here, man. This is awesome. Mike: I'm glad we got connected through our architect friends. You are at TDX this year. So let's just give people an overview of who Adam Stark is and how you got started at Salesforce. Adam Stark: Yeah, absolutely. So I work down in Nashville, Tennessee. I work at Belmont University. And my journey into Salesforce is quite a unique journey. I actually was a professional musician for a long time. I was a touring artist, a professional songwriter, producer, and did that for many, many years. And then a thing called COVID hit in 2020 and really put a damper on the touring side of things, as you can imagine. So during COVID, I went through my own personal little existential crisis moment of, are we ever going to play shows ever again? This was a huge part of my income stream to provide for my family. And so I'm going through this crisis moment of what's next, what should I be doing? And a really good friend of mine who is a Salesforce developer, he told me, he's like, "Man, you should look into Salesforce. Just go on Trailhead and just poke around." And this is me not knowing anything about it. I didn't even know what a CRM was, but went on Trailhead and shout out to the Trailhead team because what an incredible resource, like unbelievable resource for people to learn the platform. Just really, really impressive. But yeah, I would spend my days working on music with my... I was a duo, if you will. I was in a band with another guy and he and I produced our records and we wrote all of our songs. And we're doing that virtually during the day during COVID where we're songwriting over Zoom, which is a complete interesting exercise to try to be creative over Zoom. And then we're recording audio files and sending them back and forth and compiling them into a record, which was wild. Doing that during the day. And then at night, I would just get on Trailhead and just start learning. And the more that I learned, the more interesting it got to me. And yeah, I got hooked and was really fascinated with what Salesforce as a platform was capable of doing and honestly how beneficial it is to businesses and organizations. Mike: Wow. Adam Stark: So yeah, I started learning. I was really determined to get an admin certification just to have in my back pocket. And then the world opened back up. And we did what artists called revenge touring because so many people were starved for entertainment at that point in time. It'd been a year, year and a half of no real public entertainment. So we got busy, went back out on the road, and I put Salesforce on the back burner for a little bit and then had more kids and talked to my wife and we just decided we're at a spot in life where being home is really, really nice. And I was pretty invested into the Salesforce journey at that point. So I went ahead and finished up, got my admin certification and I saw that Belmont was looking to implement Salesforce and went ahead and filled out an application and landed the job. Mike: So I've shown Salesforce to people. I've taken good friends of mine to user groups and I've had friends of mine even get up to Ranger status, which is a hundred badges and still be like, "Meh, it doesn't make sense to me or nothing's clicking." Something clicked for you that was like you got it and it's hard to describe, but I know what you're feeling, but what was it for you? Adam Stark: As a music producer, one of the things that I got really good at doing was accomplishing signal flow, like trying to get a sound source from one stage to a final stage, final presentable stage, if you will. And what I found was when I really started to get into some of the automation tools in Salesforce, especially flows, I realized this actually feels like a very familiar muscle to me. How do I get from A to B and what are the steps I need to take and in what order? What's the logic to get there? If I was producing music, it would be, I've got this... Say it's a vocal, do I want to EQ the vocal first or do I want to compress the vocal first? And then do I want to bus it to a different channel and affect it there with other things or do I want it to be isolated? And really that signal flow process is the same with flows. And then I just watched what it could do with data and I was like, "This is actually really fun because you're building solutions." As a songwriter, you're building songs. As a producer, you're building tracks and you're building records and I'm still building. It's just a different medium now. Mike: Yeah, that's fascinating because the next question I was going to ask you was... So I will confess, when COVID hit, I was one of those people that's like, "I'm going to learn a skill." Except I didn't do like you, I wasn't as devoted. I bought a guitar, a really nice acoustic guitar. And let me tell you why. Two reasons. One, I was like, if I'm going to learn, I'm not going to learn on some Walmart guitar level, I'm going to learn on something good. Adam Stark: Good for you. Mike: And two, if I buy something nice, then I feel like the investment will... I'll feel bad if I don't use the investment, right? Adam Stark: Mike, I'm the same way. When I told my wife, I'm going to get into cycling. It's like I need to buy a nice bike to make myself get on the bike. Mike: Right. I'm not going to buy the Lance Armstrong. I didn't go out and buy a Les Paul and spend a used car's money, but I got a nice acoustic guitar and people come over to my house, they see it on the stand. They're like, "Wow, do you play?" So here's the moral of the story. I took guitar lessons online for like a month solid and I realized, I don't know what it is, but music and math are two things that my brain's like, "Hey, that looks like I should go on the couch and sit and eat some Cheetos and somebody else will figure this out." That is exactly what my brain does. And so I would get to the point where I could learn the chords and figure out the finger and then they started to get to the point where they're like, "We're going to teach you music." And those notes on those bars, it might as well have been a foreign language. It was to me. It just didn't make sense. And I'm sitting here, during the day, I do Salesforce and we're dealing with complex flows and data validation and all this other stuff. And I'm like, "Why can't music make sense to me?" And it's funny because the reverse almost sometimes doesn't hold true. What works for you in understanding music did not work for me in taking understanding Salesforce to music. It's crazy. So anyway, so the moral of the story is I have a really nice acoustic guitar- Adam Stark: We're going to do some guitar lessons out there. Mike: ... that has sat on its stand. But I did play it for a month. Adam Stark: Well, you bring up an interesting point, and this might cross over to just some meta principles in general is the longer you're doing something, when you first get into anything, whether it's music or Salesforce for that matter, Salesforce is so daunting to get started because it's just so robust. There's so many things. It's overwhelming. It feels like this massive mountain you have to scale, but the more you do it, the longer you go about doing it, the more familiar you get, you begin to recognize patterns, right? And then once you see the patterns, things just start to feel smaller, if that makes sense. And I think the best way I could describe it is, that has been my journey with Salesforce. To get started, it felt like this massive undertaking. And the concept of campaigns, it's like, what are those for? I still don't really know why someone... There seems like there's several different angles to use campaigns, and it's just trying to get your head around it without ever being a user in Salesforce. But then you start seeing one example of campaigns, and then you see another, and then you're like, "Oh, well, now I've got some creative ideas because I recognize some patterns and I know what the functionality of this thing is." So yeah, I just think the longer you work at something, you recognize those patterns and then it's like, "All right, this actually is starting to make a little bit more sense to me." Mike: So you got your certification, you did Trailhead on and off when you weren't revenge touring, which is a fun term. I also remember that when the world opened back up and we were like, "Oh, let's do a thing." And maybe ironically, the first thing I did was I went to a Hyatt Regency and I got French fries. Adam Stark: Yes, sir. Mike: Totally boring, but man, the quality of French fries in those restaurant style fryers, nothing at home makes the same. Adam Stark: You are right. Mike: Everybody right now that's listening to this podcast wants me to ask this question, so I'm going to ask this question. Adam Stark: Okay. Mike: What was your first interview like? Because you obviously did a remarkable job of interviewing because you got a job. And I asked that question because I probably every day get a dozen or so DMs across various social networks of, I'm starting in Salesforce and I want to be an admin and how do I get my first job? Adam Stark: It is the million-dollar question, right? Mike: Right. Adam Stark: Again, going back to familiar muscles, one of the things that I was familiar with was the concept of interviewing because I did interviews with radio stations all over the country for years. So the idea of someone sitting in front of me and asking me questions, I wasn't expecting it. I was pretty nervous about it at first when I was venturing into this new career path because I was like, "I haven't had a job interview in how many years? It's been a long time." I was pretty nervous about it. And then once I sat down and started having the conversation, again, it was like a familiar muscle of like, "Oh, this is an interview just like a radio interview is an interview." So I felt pretty comfortable in the interview environment. And then it was me being honest. I really wasn't trying to put on that I knew more than I actually did. I wasn't trying to talk technical where I didn't understand it. I was honest with the idea of who I was as a person, what I'd learned. I'd achieved my certification. I have a pretty good base of knowledge for what Salesforce is and what it can do, but I don't know everything, but I'm determined to find out. If I don't know something, I'm the person that will figure it out. That's what I've always done. In my music career, where there were technical needs, we didn't always have resources to have somebody else meet those needs for. So I would be the one that would go and dive into it. I would figure out how to code lighting rigs and write DMX and program a light show for us because we needed a light show. So that's just my makeup is I'm a hard worker, I'm a learner, and I was honest about that in my interview. If I don't know it, I'll figure it out. We'll find a solution. And it worked to a point. Obviously, the organization took a chance on me because of an experience gap, but they saw something in me, I guess in my integrity and honesty, but also my drive to find solutions and not be afraid to go learn was attractive to them. Mike: Yeah. Well, from your perspective, what were you the most concerned about going into that interview? Adam Stark: I would say I was most anxious about the technical interview side of things, mainly because I have never been a front end user and I'd never been an admin before. So I was a little anxious about, am I going to look like a fool if they're asking me technical questions that I should know answers to? And there was a little bit of that. We found some limitations in that interview process, but again, I always said, "I'm happy to go learn. I'm happy to run that down and figure it out." Mike: Yeah. That's always, I feel like, the first question is, how do I get through the interview? How do I get through... I've never had a Salesforce admin job before. Aren't they going to look for experience? And to me, my first job, I didn't have a Salesforce admin certification or anything, and I just got handed that as a responsibility. I think it depends on the vision and commitment that people see. They saw something in you and said, "Hey, he can grow with us in the same way that we're probably looking to grow this platform." And also, you were a good fit culture. I think people are always like, "Well, what if I'm not smart enough?" Well, the other part of it too is, do they see themselves working with you? Adam Stark: Absolutely. That's a really good point. And I should mention, I don't think I mentioned this, I graduated from Belmont, so I went here for undergrad. Mike: A little bit of alumni. Adam Stark: I had the alumni angle coming in. So that really helped because I did understand the culture. I was here for four years. I'd know what the school represents. I knew how, at least on a basic level, how the school functioned and what some of the departments and teams were. So that was a starting point, right? But you're absolutely right. What you know is, I don't want to say half the battle, maybe more than half the battle, but there's a large percent of the battle is like, are you going to be someone we enjoy working with day in and out? And are you someone that thousands of other faculty, staff and students are going to be interacting with? Are you the person for that job? So you're right, the culture fit is a huge part of it and not to be underestimated. Mike: Yeah. What part, now that you're in it, of the job has probably been the most rewarding that you didn't anticipate? Adam Stark: Oh, it's for sure this idea of going through a journey with people. As admins, you find your users and you go through the discovery process with them and you learn about what are your pain points and you just learn about the language they speak and their staff, their workflows, all that stuff. And when you can deliver something that helps relieve those pain points for them, and at the end of it, they see that beautiful chart that they've been longing to see for two years, or they see the one-click automation that just executes perfectly and performs the need they need. When you can look at each other and high five at the end, and just it's so rewarding. I just love those wins with people. Mike: Yeah. The best part for me was always go live day. When somebody finally gets that solution and they're like, "Oh, I don't have to look at that green DOS screen anymore." God knows whatever else they were dealing with. Adam Stark: Absolutely. And then you see the spreadsheets and things that they've been managing. Mike: Oh, [inaudible 00:18:03]. Adam Stark: "Oh, Lord, this is your world." Mike: It is. But what's funny is some people, I'd say, almost get to the level of coding with the amount of cross tables and pivot tables and references that they build in these spreadsheets. You almost have a robot there. Adam Stark: You are right. You are correct. Mike: So you spent some time at TDX this year. Was that your first Salesforce event as an admin? Adam Stark: It was my second. I was able to go to Education Summit last year first, but I got to say TDX was awesome. I loved it. Mike: A lot of people that listen to the podcast don't get to go. Some people do the over under. I wish all my listeners could go to TDX, but for you, what were you going there thinking, "Here's what I need to leave with?" Adam Stark: It's a really good question. For me personally, I am not content staying where I'm at. I always have this need to grow. So as an admin, I feel like I'm getting comfortable with some of my admin tasks and I'm always looking to grow into the next stage. If that's going to be growing as a developer or a consultant or whatever that would be, I'm always looking for the next thing and eager to just up my skills. So going into TDX for me was this exciting opportunity to interact with people who are way smarter than me and way more talented at the platform and just pick their brains. The cool thing about TDX was it's so, I would say, question-friendly. You can walk up to ask the expert tables and just sit down and have conversations and really glean a ton from some of these technical architects. And there's great hands-on training... Not training, but almost hands-on demos and hands-on with certain products, which was really cool, too. I don't get to mess around with agents a lot because we don't use agents yet. So being able to go and sit and work on, build some agents and see how that's working with Salesforce was really great. But mainly the thing I wanted to do was just go have conversations and glean from those who are far ahead of me in their Salesforce journey and help determine what path am I most excited about going forward? Do I want to be a developer or do I want to go more of a consultant, like client facing route? What's the next thing for me? So yeah, that was my goal. Mike: Yeah, no, and that's what we're there for. Obviously, get you hands on with agents, but also I think to be exposed to what other roles in the ecosystem there are, or you can always just stay in admin. Adam Stark: Well, you know what I found so interesting with how Salesforce is growing and developing, I feel like the admin might be the most important and diverse role of all of them at this point because so much is being brought to the admin's table of possibilities. We can do so many things with native Salesforce tools now that, I don't know, man, the admin is such a key role that maybe I'll never move on from being an admin. Maybe I just become a super admin. Mike: Yeah, that was always one of the things when I got started with Salesforce that I found empowering was that I could configure the product using the product. And I don't recall at that time or even... Now short of a few website builders, did enterprise architecture live there. It was always, you had to plug in a development app and then you had to work in that app and then you had to shove your changes to the monolithic CRM. And if you didn't know code and you weren't a computer programmer, it was easy to really make a mess of things. And it just never made sense to me. And then when you would open up Salesforce and be like, "Oh, you can configure this and you just go into set up, here I can just configure this whole page." And it's immediate. It's right there when you press Save. I was like, wow, okay, wait, this is... I still remember, I don't know if you've built this. This makes me feel so old. The very first time I built a dependent picklist, I was like- Adam Stark: Magic. Mike: I was like, "I can run the Internet." Adam Stark: I love that. Mike: Because I just made this picklist value dependent on this picklist value. And I remember it was a little thing on our leads and it was basically just our tests were categorized in a certain way. And the previous admin, which there hadn't been one, just used one picklist value. It was a monster and it was a word hyphen, another word. And so you had to type out every variation of that and you would open the picklist and it would literally go from the top of your screen to the bottom. Adam Stark: Oh my gosh. Mike: And I remember I was like, "Well, this is just really two values." And I looked it up and I just remember my users being like, "Oh, that's amazing and I can't select the wrong one anymore." Adam Stark: I had that moment with Lightning Record Pages moving on to page layouts. When I realized the power of conditional visibility with Lightning Record Pages, I was like, "This is incredible. I'm a genius." Mike: Yeah. And I remember we rolled out dynamic record pages in a keynote and for how long as an admin, I didn't want that. Just the ability to show the field when they need to fill it in and then take it away. And I'm from the days when our account pages used to have 300 fields on it and every person used a different area of that record page and you would go to their desk and everything else would be collapsed except for that area. And I just remember thinking there has to be a way to make this only visible to them and 10 years later we can. Adam Stark: And it's so satisfying. It's just beautiful when it works. Mike: Right, absolutely. So looking ahead, agents and AI are the thing for now for a long time. We went through mobile and social and there was a brief internet of things and connected devices, but we really were headed towards this AI stuff. What are some of the things you're paying attention to that you're trying to learn and how is your musical skills or other talents helping you learn those? Adam Stark: I feel probably like most people feel because AI is just developing so quickly. I feel so behind the curve on what's happening, but TDX was definitely an eye-opening experience for me that it's here. The power of AI and agents is here. And so it's time to really start learning. Lately, what I've been doing is just trying to get my head around some of the 30,000-foot concepts of how AI even works. How do these large language models work? Like what is a vector database and the MCP connectors and how do all these things work together? Because I'm that person where I don't have confidence in what I'm doing unless I have a conceptual understanding of how the whole thing is working. So I don't like just blindly building something saying, "I think this ought to do what we want it to do. " It's like, I need to understand on a deeper level how it ticks, if that makes sense. And for better or for worse, that's just how I'm wired. And I will say AI is a behemoth. It is to get your head around it and to understand what it can do and then try to keep up with all the changes. Wow, it is daunting, but very impressive. I have been really excited since the conference and since I've been learning more about the possibilities with AI. It's starting to spark some creative ideas for me and some creative ideas for how it could be implemented in my organization. So that's side note there. But overall, I feel a sense of excitement of where we're going with all this stuff. And I encourage everybody else, if you feel overwhelmed with the idea of AI or having to implement AI tools, rather than just fighting it and putting your heels into the ground and saying, "I'm not doing it," just start learning and start seeing what it can do, what the possibilities are, and then see where your creativity takes you. You might surprise yourself. But yeah, I'm still in my infancy of learning and getting my hands on the tools, but I will say I'm excited about where we're going. Mike: Yeah. I've often heard it described as we're in the steam powered era of AI, which means, wow, it's going to be something. I guess last question, which hearkens back to your beginning, for somebody who is listening, and first of all, I don't know how they would find this podcast, but let's say somebody that's not in Salesforce finds the podcast and they're listening, is there anything you would do different when you were getting started learning Salesforce, knowing what you know now? Adam Stark: I think I would... If I was getting started now, knowing what I know, I would have made an effort to connect with Salesforce professionals sooner than I did. I stayed in my room and stayed on Trailhead and just kept completing modules. And the best way I can describe the feeling was I felt like I started putting all these dots on a plot, right? I had all these scattered dots that I was learning as I had complete each module, but I was having a hard time connecting them all. And Trailhead is so big now that if you can easily just wander off on a path of learning that you don't really know if you need it or not. And then you wonder like, "How have I found myself configuring SSO and I don't even know how opportunities work?" So I think I would have really tried to have gotten involved with community, either the Trailhead community or user group meetups locally, but just start getting plugged in with working professionals and start having conversations because again... And even TDX is a perfect example, sitting down on tables and just asking questions with technical architects. And 15, 20 minutes of that is just so helpful to connect all those dots and have that little bit of a light bulb moment of like, "Oh, all right, that makes sense now." So yeah, get involved, get in a community. I think that's going to be the most beneficial if you're just getting started. Mike: Yeah, no, that absolutely makes sense. I'm glad you pointed that out. Adam, thanks so much for coming on the podcast and sharing with us your story and your insights. I think it's always super valuable because the community continues to grow. I was at TDX this year and it used to be a thing where I would walk around and know everybody. And now I felt like I walked around. I didn't know anybody. And it was because everybody was so new. I hadn't met them yet. So case in point yourself. Adam Stark: Yes, sir. Hey, thank you so much for having me. I really appreciate it. And I have enjoyed your podcast. Side note, I'm just going to give you a little shout-out here, Mike. Your podcast was super beneficial for me getting started because it was allowing me to have an insight to what an admin does because I had never been in the ecosystem. So just the value that your podcast brought me getting started was huge. So thank you for what you do and thank you for having me today. Mike: Well, I appreciate that. You probably also learned too much about food because there's food in every podcast. Somehow- Adam Stark: You can never learn too much about food. Mike: ... everybody is always like, "I never know how you're going to work it in." But every now and then food shows up and I'm like, "We all need food. It makes it very relatable. Adam Stark: Absolutely. Mike: Adam's story is a reminder that being an admin today isn't about where you start. It's about how you think. From designing signal flow in music to orchestrating automation and exploring AI, this role is evolving into something much bigger, building systems that actually move the business forward. If this episode helped you see your work a little differently, share it with somebody in your network and keep the conversation going. Thanks for listening. And as always, until next time, we'll see you in the cloud.
  • Agentforce Grid Enables Next-Gen Admins to Scale AI Workflows 30.04.2026 25min
    Today on the Salesforce Admins Podcast, we talk to Avi Shah, Senior Director of Product Management for Salesforce AI. Join us as we chat about Agentforce Grid, a new way to coordinate data, automation, and AI agents. You should subscribe for the full episode, but here are a few takeaways from our conversation with Avi Shah. Spreadsheet-style AI workflows to simplify complex automation Salesforce Admins deal with data, automations, and AI every day. But how do you make everything work together in a way that makes sense? That's why I sat down with Avi Shah to talk about Agentforce Grid, a spreadsheet-like tool for creating AI workflows. "Agentforce Grid is, in our opinion, the fastest and easiest way to build AI workflows," Avi says. "You have columns for your data and the actions you want to take with it." Some columns are AI-based, enabling you to run prompts or agents you've built, and others are action-based, allowing you to update records or call an invokable action to send an email. Put it all together, and you can build complex AI automations that can transform your organization's workflows. Combining data and actions As Avi explains, Agentforce Grid gives you a simple, spreadsheet UI to perform powerful transformations on your data. You can pull things from Data Cloud, uploads, or even the web into a data column. Action columns give you a way to act. You can run prompt templates, agents you've already built, or inline prompts. Not everything needs to be an AI step, however—you can also perform more deterministic actions like formulas, updating records, or invoking flows. AI and non-AI actions work together in workflows All of this makes more sense when we talk about actual use cases. For example, you can use Agentforce Grid to assist with case categorization, working with a list of cases, a prompt column to analyze them, and another prompt column to look at those analyses and categorize them based on theme, priority, or issue. Avi has also seen customers take advantage of Agentforce Grid for transcript and session analysis for customer-facing agents. You can use the prompt column to analyze, classify, and extract information from transcripts to make sure that everything is working the way you want it to work. Be sure to listen to the full conversation for more from Avi on Agentforce Grid. And don't forget to subscribe to the Salesforce Admins Podcast so you never miss an episode. Podcast swag Salesforce Admins on the Trailhead Store Learn more Salesforce Admins Blog Post: How Salesforce Admins Can Streamline AI Workflows With Agentforce Grid Admin Trailblazers Group Admin Trailblazers Community Group Social Avi on LinkedIn Salesforce Admins on LinkedIn Salesforce Admins on X Mike on Bluesky social Mike on Threads Mike on X Full show transcript