3.1 When to Use an Employee Agent or a Service Agent
Key Takeaways
- Agentforce Employee agents assist internal employees, run in the logged-in user's context, and are assigned to users through permission sets or profiles.
- Agentforce Service agents support customers on messaging, email, and voice channels and run as a dedicated agent user unless a site user is authenticated.
- Employee agents deploy to the Agentforce panel in Lightning Experience, the Salesforce mobile app, Slack, and Enhanced Web Chat on Experience Cloud sites.
- Creating and managing Service agents requires the Manage Agentforce Service Agents permission set, which includes the org-wide Manage AI Agents permission.
- Agentforce (Default) stopped receiving new features on June 17, 2025; Salesforce recommends migrating to the Agentforce Employee agent.
3.1 When to Use an Employee Agent or a Service Agent
Quick Answer: Choose an Agentforce Employee agent when the users are your employees working in Salesforce, Slack, or an employee portal. It runs as the logged-in user and respects that user's access. Choose an Agentforce Service agent when the users are customers or the public on channels such as web chat, messaging apps, email, or phone. It runs as a dedicated agent user with least-privilege permissions and escalates to human reps through Omni-Channel.
The Spring '26 objective asks you to identify, given a scenario, "when to use an Employee or Service agent." Salesforce offers other agent types, but the exam focuses on these two because they drive different security, channel, and licensing decisions.
Side-by-Side Comparison
| Dimension | Agentforce Employee agent | Agentforce Service agent |
|---|---|---|
| Primary users | Internal employees | External customers (and anonymous visitors) |
| Runs as | The logged-in user | The agent user (EinsteinServiceAgent User), except for authenticated Experience Cloud site users with credential-based verification |
| Data access governed by | The user's profile, permission sets, FLS, and sharing | The agent user's profile, permission sets, role, FLS, sharing, and internal OWD |
| Who can use it | Users you grant access through permission sets or profiles (Agent Access page) | Anyone on the connected channel. End users need no special permissions |
| Typical channels | Agentforce panel in Lightning Experience, Salesforce mobile app, Slack, Enhanced Web Chat on an Experience Cloud site | Enhanced Chat (web and mobile), other enhanced messaging channels such as WhatsApp or Facebook Messenger, email, voice |
| Escalation | Transfers supported on Enhanced Web Chat. Not supported from the Agentforce panel in Lightning Experience or the mobile app | Transfer to reps or queues with an outbound Omni-Channel flow on enhanced messaging channels |
| Final response validation | Not part of the documented runtime journey | Checks grounding, scope, and prompt-injection risk before replying |
| Build and manage permission | Manage AI Agents or Customize Application | Manage Agentforce Service Agents permission set (includes Manage AI Agents) or Customize Application |
| Agent Script config | default_agent_user optional | default_agent_user required |
Agentforce Employee Agents
Salesforce designed Employee agents for internal employees: finding information, completing tasks, and getting personalized support. Key points:
- They run in the logged-in user's context, so an employee sees only records they could already see.
- You assign each Employee agent to specific users with permission sets or profiles. In Agentforce Builder, use the Agent Access page. In Setup, edit Enabled Agent Access on a permission set or profile. Only Employee agents appear in that list.
- Activating an agent makes it available in the Agentforce panel and mobile app for users who have access. Users with access to several agents choose one from the Agent Picker, which lists only active versions.
- On an Experience Cloud site, an Employee agent runs as the logged-in site user. Because many site users share one profile, Salesforce recommends granting access through a permission set assigned to specific users.
- Employee agents require Flex Credits.
- Agentforce (Default) is retired: no new features since June 17, 2025, and it isn't available in new environments. Migrate to the Employee agent.
Agentforce Service Agents
Service agents intelligently support customers with common inquiries and escalate complex issues. Key points:
- They connect to channels that aren't restricted to logged-in users, so they can't rely on an end user's user record for access control. Instead they run as a dedicated agent user with minimal default access that you expand by least privilege (section 3.2).
- End users don't need permissions to chat with a Service agent.
- Service agents deploy to Enhanced Chat, other enhanced messaging channels, email (Agentforce Service Agent on Email), and voice (Agentforce Voice).
- They escalate through the Escalation subagent and an outbound Omni-Channel flow, transferring the conversation history to a rep or queue.
- Before sending a reply, they run a final response validation for grounding, scope, hallucinations, and prompt injection.
- Salesforce warns that Manage AI Agents grants org-wide management of all agents, not just one agent type. Assign the Manage Agentforce Service Agents permission set only to people who need that scope.
Other Agent Types (Know They Exist)
| Type | Purpose |
|---|---|
| Lead Nurturing (formerly SDR) | Engages leads with personalized content and schedules meetings |
| Sales Coach | Gives reps feedback on pitches and role-play sessions |
| Service Assistant | Helps service reps resolve cases with summaries and step-by-step guidance |
| Setup with Agentforce | Helps admins with Setup tasks (replacing the retired Agent for Setup) |
If a scenario describes reps inside the Service Console needing help, an Employee agent or Service Assistant fits better than a customer-facing Service agent.
Scenario Practice
| Scenario | Correct agent type | Why |
|---|---|---|
| Sales reps want to ask for their open opportunities and draft follow-up emails in the Lightning sidebar | Employee | Internal users, Lightning Experience channel, results should respect each rep's sharing |
| An airline wants 24/7 web chat for rebooking with escalation to human reps | Service | Public channel, agent user security, Omni-Channel escalation |
| HR wants an assistant in Slack that answers benefits questions from the employee handbook | Employee | Internal Slack users; access follows each employee's Salesforce permissions |
| A utility wants to handle inbound customer emails about outage credits | Service | Agentforce Service Agent on Email is a Service agent capability |
| A partner portal where logged-in partner users need help with their deals | Employee on an Experience Cloud site with Enhanced Web Chat | Logged-in site users. The agent runs as the site user, so restrict access with a permission set |
| A bank wants phone callers to check card status | Service (voice-enabled) | Voice-enabled agents are created from Service agent templates |
Exam Traps
- "Customers" almost always means a Service agent. "Employees" or "reps in Lightning" usually means an Employee agent.
- Don't give end users special permissions for Service agents. The agent user carries the permissions.
- Employee agents don't use a dedicated agent user for their normal channels. They respect the logged-in user's access.
- Agentforce (Default) isn't the recommended answer for new employee use cases; the Employee agent replaced it.
A company wants service reps working cases in Lightning Experience to ask an agent for account summaries that respect each rep's record access. Which agent type fits best?
An insurer wants anonymous website visitors to get quote information and be transferred to licensed agents when needed. Which configuration is appropriate?
How do you give specific employees access to an Agentforce Employee agent?
Which statement about the Manage Agentforce Service Agents permission set is accurate?