Until now, Agentforce was something you opted into. With the Winter ’27 release Salesforce turns that around: Agentforce is enabled automatically in orgs that have access to it through their licence. Agentforce being switched on by default in Winter ’27 is therefore not a product announcement but a governance question. The feature appears in your org whether or not you had a plan for it.

What changes, and in which orgs

Salesforce enables Agentforce by default in orgs that have access through their SKU, licence or edition. According to reporting by Salesforce Ben, this covers Lightning Experience orgs with Foundations on Enterprise, Performance, Unlimited and Developer Edition, plus the Agentforce 1 Edition. New orgs are enabled at creation. Existing orgs are switched on gradually, a rollout that began in the first week of September 2026. The setting that lets you turn Agentforce off is, according to the same reporting, due to disappear later in Winter ’27.

One caveat up front: these details come from secondary reporting and from release notes that are still in preview. Check the current position for your own org in the Winter ’27 release notes before you base policy on it.

Enabling costs nothing, using it does

Salesforce states that enabling Agentforce by default carries no additional cost and that billing does not change. That holds for switching it on, but switched on is not the same as free. Agentforce usage is billed in Flex Credits, and each edition comes with its own annual allowance. Anything above that you buy separately. Our article on the new Core, Advanced and Max editions lists those allowances per edition.

So the risk is not in the switch, but in what happens after it. An agent that is live and that staff discover consumes credits.

Four things to check

Together these checks take less than an hour:

  • Access. Look at which profiles and permission sets receive Agentforce rights once the feature is on. “Everyone with a licence” is rarely the answer you want.
  • Data. Decide which objects and fields an agent may read. An agent operates within the permissions it runs under, so a broadly configured profile shows up here immediately.
  • Active agents. Check in Agentforce Builder whether any agents are active. Enabling the platform is not the same as activating an agent, but you want to know what is actually running in your org.
  • Usage. Agree who tracks credit consumption and at what level it triggers a conversation. Without an owner, you notice it on the invoice.

If you would rather not use Agentforce yet, you can switch it off through the Einstein settings and deactivate individual agents in Agentforce Builder. Bear in mind that this off switch is reportedly set to disappear later in Winter ’27. Delaying is not a policy, it buys time.

Do it before the release arrives

The difference between a controlled start and an unwelcome surprise is mostly timing here. Work through the four points above before the release reaches your org and you decide who gets access, and to what. Do it afterwards and you are reacting to something that is already live.

Would you rather not work that out yourself? Our consultancy reviews your org on access, data exposure and usage, and records which agents you do and do not want. Get in touch and we will schedule it.