3.1 When to Use an Employee Agent or a Service Agent

Key Takeaways

  • Agentforce Employee agents assist internal employees, run in the logged-in user's context, and are assigned to users through permission sets or profiles.
  • Agentforce Service agents support customers on messaging, email, and voice channels and run as a dedicated agent user unless a site user is authenticated.
  • Employee agents deploy to the Agentforce panel in Lightning Experience, the Salesforce mobile app, Slack, and Enhanced Web Chat on Experience Cloud sites.
  • Creating and managing Service agents requires the Manage Agentforce Service Agents permission set, which includes the org-wide Manage AI Agents permission.
  • Agentforce (Default) stopped receiving new features on June 17, 2025; Salesforce recommends migrating to the Agentforce Employee agent.
Last updated: September 2026

3.1 When to Use an Employee Agent or a Service Agent

Quick Answer: Choose an Agentforce Employee agent when the users are your employees working in Salesforce, Slack, or an employee portal. It runs as the logged-in user and respects that user's access. Choose an Agentforce Service agent when the users are customers or the public on channels such as web chat, messaging apps, email, or phone. It runs as a dedicated agent user with least-privilege permissions and escalates to human reps through Omni-Channel.

The Spring '26 objective asks you to identify, given a scenario, "when to use an Employee or Service agent." Salesforce offers other agent types, but the exam focuses on these two because they drive different security, channel, and licensing decisions.

Side-by-Side Comparison

DimensionAgentforce Employee agentAgentforce Service agent
Primary usersInternal employeesExternal customers (and anonymous visitors)
Runs asThe logged-in userThe agent user (EinsteinServiceAgent User), except for authenticated Experience Cloud site users with credential-based verification
Data access governed byThe user's profile, permission sets, FLS, and sharingThe agent user's profile, permission sets, role, FLS, sharing, and internal OWD
Who can use itUsers you grant access through permission sets or profiles (Agent Access page)Anyone on the connected channel. End users need no special permissions
Typical channelsAgentforce panel in Lightning Experience, Salesforce mobile app, Slack, Enhanced Web Chat on an Experience Cloud siteEnhanced Chat (web and mobile), other enhanced messaging channels such as WhatsApp or Facebook Messenger, email, voice
EscalationTransfers supported on Enhanced Web Chat. Not supported from the Agentforce panel in Lightning Experience or the mobile appTransfer to reps or queues with an outbound Omni-Channel flow on enhanced messaging channels
Final response validationNot part of the documented runtime journeyChecks grounding, scope, and prompt-injection risk before replying
Build and manage permissionManage AI Agents or Customize ApplicationManage Agentforce Service Agents permission set (includes Manage AI Agents) or Customize Application
Agent Script configdefault_agent_user optionaldefault_agent_user required

Agentforce Employee Agents

Salesforce designed Employee agents for internal employees: finding information, completing tasks, and getting personalized support. Key points:

  • They run in the logged-in user's context, so an employee sees only records they could already see.
  • You assign each Employee agent to specific users with permission sets or profiles. In Agentforce Builder, use the Agent Access page. In Setup, edit Enabled Agent Access on a permission set or profile. Only Employee agents appear in that list.
  • Activating an agent makes it available in the Agentforce panel and mobile app for users who have access. Users with access to several agents choose one from the Agent Picker, which lists only active versions.
  • On an Experience Cloud site, an Employee agent runs as the logged-in site user. Because many site users share one profile, Salesforce recommends granting access through a permission set assigned to specific users.
  • Employee agents require Flex Credits.
  • Agentforce (Default) is retired: no new features since June 17, 2025, and it isn't available in new environments. Migrate to the Employee agent.

Agentforce Service Agents

Service agents intelligently support customers with common inquiries and escalate complex issues. Key points:

  • They connect to channels that aren't restricted to logged-in users, so they can't rely on an end user's user record for access control. Instead they run as a dedicated agent user with minimal default access that you expand by least privilege (section 3.2).
  • End users don't need permissions to chat with a Service agent.
  • Service agents deploy to Enhanced Chat, other enhanced messaging channels, email (Agentforce Service Agent on Email), and voice (Agentforce Voice).
  • They escalate through the Escalation subagent and an outbound Omni-Channel flow, transferring the conversation history to a rep or queue.
  • Before sending a reply, they run a final response validation for grounding, scope, hallucinations, and prompt injection.
  • Salesforce warns that Manage AI Agents grants org-wide management of all agents, not just one agent type. Assign the Manage Agentforce Service Agents permission set only to people who need that scope.

Other Agent Types (Know They Exist)

TypePurpose
Lead Nurturing (formerly SDR)Engages leads with personalized content and schedules meetings
Sales CoachGives reps feedback on pitches and role-play sessions
Service AssistantHelps service reps resolve cases with summaries and step-by-step guidance
Setup with AgentforceHelps admins with Setup tasks (replacing the retired Agent for Setup)

If a scenario describes reps inside the Service Console needing help, an Employee agent or Service Assistant fits better than a customer-facing Service agent.

Loading diagram...
Decision path: Employee agent or Service agent

Scenario Practice

ScenarioCorrect agent typeWhy
Sales reps want to ask for their open opportunities and draft follow-up emails in the Lightning sidebarEmployeeInternal users, Lightning Experience channel, results should respect each rep's sharing
An airline wants 24/7 web chat for rebooking with escalation to human repsServicePublic channel, agent user security, Omni-Channel escalation
HR wants an assistant in Slack that answers benefits questions from the employee handbookEmployeeInternal Slack users; access follows each employee's Salesforce permissions
A utility wants to handle inbound customer emails about outage creditsServiceAgentforce Service Agent on Email is a Service agent capability
A partner portal where logged-in partner users need help with their dealsEmployee on an Experience Cloud site with Enhanced Web ChatLogged-in site users. The agent runs as the site user, so restrict access with a permission set
A bank wants phone callers to check card statusService (voice-enabled)Voice-enabled agents are created from Service agent templates

Exam Traps

  • "Customers" almost always means a Service agent. "Employees" or "reps in Lightning" usually means an Employee agent.
  • Don't give end users special permissions for Service agents. The agent user carries the permissions.
  • Employee agents don't use a dedicated agent user for their normal channels. They respect the logged-in user's access.
  • Agentforce (Default) isn't the recommended answer for new employee use cases; the Employee agent replaced it.
Test Your Knowledge

A company wants service reps working cases in Lightning Experience to ask an agent for account summaries that respect each rep's record access. Which agent type fits best?

A
B
C
D
Test Your Knowledge

An insurer wants anonymous website visitors to get quote information and be transferred to licensed agents when needed. Which configuration is appropriate?

A
B
C
D
Test Your Knowledge

How do you give specific employees access to an Agentforce Employee agent?

A
B
C
D
Test Your Knowledge

Which statement about the Manage Agentforce Service Agents permission set is accurate?

A
B
C
D