Agentforce Coworker is not something you are choosing whether to adopt. It reached general availability in August 2026 and began auto-enabling on a rolling basis for organisations with eligible AI seats — no setup, no extra cost. At Dreamforce 2026 it was opened to all customers as one of the three surfaces of AIforce, alongside Claudeforce and Slackforce. For a lot of orgs, the first question is not “should we turn it on” but “is it already on, and who is using it.”
What Coworker actually is
Coworker is an AI teammate that lives in the Lightning global search bar. A user types a question in plain language and, instead of a list of matching records, gets a single written answer built from the data they are allowed to see. It reaches beyond CRM into Slack and Data 360-connected sources, and it can hand work off to the specialised Agentforce agents you have already built. Salesforce reports it crossed 100,000 active users within 35 days of launch, so this is adoption at speed, not a quiet beta.
Why default-on is the risk
Everything good about Coworker — instant answers, no training, no setup — is also what makes an ungoverned rollout dangerous. It inherits your existing permissions and business rules exactly as they are. If a user could already technically see a record they should not, Coworker will now summarise it for them in a sentence, conversationally, without them clicking through five screens to find it. The tool does not create a new exposure; it removes the friction that was hiding the old one. An over-permissive org does not feel over-permissive until an AI teammate makes its contents one question away.
Get ahead of it in four moves
First, find out where you stand. Confirm whether Coworker is already auto-enabled for any of your seats, and treat that as live until proven otherwise. You cannot govern a rollout you did not know had started.
Second, audit permissions and sharing before you publicise it. This is the real work, and it is not glamorous: profiles, permission sets, role hierarchy, field-level security, and sharing rules all decide what Coworker will say. A conversational answer is only as safe as the visibility behind it.
Third, check the data it will answer from. Coworker reasons over your records as they are. Duplicates, stale owners, and fields that do not mean what they say produce answers that are fluent and wrong — the same failure we described in clean data before you deploy an AI agent. Fluent-and-wrong is more dangerous than obviously broken, because people trust it.
Fourth, decide where actions need a human. Answering a question is low-risk; letting Coworker orchestrate an agent to change a record or message a customer is not. Draw that line deliberately — it is the whole argument for keeping a review step on AI output.
The mindset shift
With opt-in tools, governance could lag adoption — you turned it on when you were ready. Coworker inverts that: adoption can arrive before governance does. The orgs that do well are the ones that treat “it is already on” as the starting assumption and get their permissions and data in order on that basis. This is the same lesson behind moving Agentforce into production rather than proof-of-concept: the model is ready long before most orgs are.
What to measure in the first 30 days
Governance isn’t a one-off audit; it’s a habit you build while usage grows. In the first month we track four signals. Adoption by team — who is actually asking Coworker questions, and who has ignored it. Answer quality — a weekly sample of real questions and answers, checked by someone who knows the data, with every wrong answer traced to its cause: a permission, a stale record, or a field that doesn’t mean what it says. Sensitive-data exposure — a review of whether any answer surfaced information the user shouldn’t have been able to reach. And hand-offs to agents — which actions Coworker triggered, and whether each one should have needed a human. Those four signals tell you whether to widen access, tighten permissions, or clean data before rolling Coworker out further.
How we help
We run Coworker readiness as part of AI enablement: a permissions-and-sharing audit, a data-quality pass, and a clear policy for where a human signs off — delivered AI-native, with a certified engineer reviewing the configuration. The goal is simple: when your team starts asking Coworker questions, every answer it gives is one you would have been comfortable giving yourself.
Key takeaways
- Agentforce Coworker is GA and auto-enabling on a rolling basis — assume it is already live in your org.
- It inherits your permissions exactly, so a loose sharing model becomes a conversational data-exposure risk.
- Audit permissions and data, and set a human-sign-off line, before you publicise it — governance now has to lead adoption, not follow it.

