WithSecure Maps Trust Relationships in Salesforce AI Environments
New framework addresses governance challenges when AI agents and integrations extend beyond traditional identity and access controls.

A governance framework for connected Salesforce workflows
WithSecure has released a framework for mapping trust relationships in Salesforce environments where AI agents, third-party integrations, and automated workflows operate with limited human oversight. The approach addresses a gap in conventional security practices that focus primarily on identities, permissions, and configurations.
According to the paper "Navigating Trust in the Modern Salesforce Ecosystem," organizations need visibility into what information their systems rely on, how trust extends across connected platforms, what actions are performed autonomously, and what outcomes those actions produce. The framework applies to Salesforce processes, Agentforce, Headless 360, third-party SaaS applications, and AI-assisted workflows.
How the framework defines trust
WithSecure defines trust as the belief that people, systems, information, and connected services will behave as expected within a business workflow. Each trust relationship includes a responsibility, scope, and boundary that describe what is being relied upon, where that trust applies, and its limits. These relationships are supported by assumptions about the conditions that make the reliance possible.
The Trust Mapping Framework examines five domains: entities (who or what participates), information (what data is used), connections (how trust is established or extended), actions (how trust is exercised), and system outcomes (what results the workflow produces).
Discovery and governance in practice
The framework operates in two phases. Trust Mapping Discovery identifies the relationships that enable a business workflow to function, defining their responsibilities, scope, boundaries, and supporting assumptions. The paper illustrates this through three scenarios: a salesperson using Claude through Headless 360 to analyze Salesforce data, a customer support request handled by Agentforce and reviewed by a human agent, and a discontinued Salesforce integration whose credentials remain active.
After Discovery, the Governance phase assesses which relationships require attention and whether they still serve their intended purpose. Organizations examine whether the right entities have appropriate authority, whether information remains reliable, and whether connections and actions stay within intended limits. Based on this assessment, a relationship can be maintained, modified, restricted, or removed.
Why it matters
As AI agents and automation take on more tasks in Salesforce environments, trust relationships extend beyond traditional user access patterns. Governance questions like "Is this secure?" or "Should this integration exist?" assume these relationships are understood. Without visibility into how trust flows through connected systems, organizations face risks from unused credentials, excessive access, outdated information, and AI-generated recommendations accepted without validation—what WithSecure calls "trust drift."
An ongoing process
Trust Mapping is designed as a continuous practice because relationships change when organizations introduce integrations and AI agents, replace vendors, move employees between roles, or retire projects. The approach complements existing practices such as security posture management, threat modeling, and identity governance by adding a workflow-level view of dependencies, boundaries, and assumptions.
The details were first reported by WithSecure in their paper on navigating trust in the modern Salesforce ecosystem.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call