Back to insights

Agentforce, RAG & Knowledge Architecture

Agentforce grounding is a data pipeline—not a prompt setting

JSBC Labs8 min read

Grounded does not automatically mean correct

Retrieval-augmented generation gives an Agentforce agent relevant enterprise content before the model produces an answer. Salesforce Data Libraries can automate much of the connection from sources through Data 360 indexing and retrieval. That removes setup friction, but it does not certify the source, guarantee the right passage was retrieved or prove that the response interpreted it correctly.

The JSBC Labs position is that grounding is an operated data product. Its output is not a search index; it is an answer used by a customer, employee or downstream action. The architecture therefore includes content ownership, ingestion, parsing, chunking, indexing, retrieval, permissions, prompt behaviour, citations, evaluation and incident response. Treating the library as an attachment to a prompt hides most of the risk.

Define the authority before ingesting content

A shared drive may contain approved policy, obsolete drafts, regional variants and notes written for internal interpretation. Indexing all of it makes every document equally retrievable even when the business does not consider it equally authoritative. The agent can then produce a fluent mixture of incompatible rules while technically citing available content.

Create a source register for each use case. Name the content owner, audience, jurisdiction, effective date, approval status and retirement rule. Decide which system wins when Knowledge, a website and an uploaded file disagree. Exclude drafts and superseded material at ingestion rather than expecting the prompt to recognise them. Trusted grounding begins with an explicit hierarchy of evidence.

Freshness is an end-to-end service level

An updated article is not useful to the agent until the change has moved through ingestion, mapping, chunking, indexing and retrieval. Teams often measure when an editor clicked Publish but not when the new passage became searchable. During that interval, the agent can confidently return the previous rule even though the visible source already looks correct.

Set a freshness objective by content class. Product help may tolerate hours; safety instructions, eligibility or pricing may require a much shorter path or a different real-time data action. Record source timestamps and indexing status, then test retrieval after significant changes. If the service cannot prove that a critical update is available, the safe behaviour may be escalation rather than an answer.

Structure content for retrieval, not only reading

Documents designed for humans can depend on page layout, headings, tables, diagrams and references such as ‘the exception below.’ A parser may separate the exception from the rule or strip the relationship between a table heading and its values. Salesforce's website-grounding guidance recommends tuning parsing and chunking choices to the content format and page structure.

Write self-contained sections with descriptive headings, explicit subjects and enough context to stand alone. Repeat essential scope—product, region, audience or effective period—inside the relevant section instead of relying only on a document title. Test tables, lists and long pages after ingestion. The ideal chunk is not a fixed number of characters; it is the smallest passage that preserves a complete, unambiguous business meaning.

The retriever is a decision system

A search index makes passages available; the retriever decides which of them enter the model's context. Its fields, filters, search strategy and result count shape every answer. Salesforce documents that customised retrievers should return the fields most useful for grounding and citations. A weak retriever can miss the correct article even when the library contains it.

Build a retrieval test set from real vocabulary, abbreviations, misspellings and customer phrasing. Include near-duplicate policies and questions that should return nothing. Inspect the passages, not just the final prose: did the authoritative section rank highly, did filters preserve the right region, and did irrelevant chunks crowd out evidence? Prompt changes cannot reliably repair content that never reaches the model.

Permissions must survive the pipeline

Grounding can bring protected enterprise information into generated text, so access control is part of retrieval. Salesforce notes that field-level security and Knowledge article access limit grounded Service responses. Architects must still validate the complete identity path: the human user, agent user, data space, source permissions, retriever and channel where the answer appears.

Test two users with different access, including unauthenticated or external audiences where relevant. Confirm that restricted passages are neither returned nor indirectly summarised. Separate libraries or retrievers when one index would create complex, fragile filters across business units. Avoid sensitive fields that are unnecessary for the answer, and log identifiers and decisions without copying confidential grounding text into operational telemetry.

Design for conflict, absence and abstention

Enterprise knowledge is rarely clean enough to assume one matching answer. Two valid sources may apply to different dates, products or customer tiers. A relevant passage may also be missing because ingestion failed or the question sits outside the approved scope. In both cases, generating a plausible answer is worse than acknowledging uncertainty.

Define precedence in metadata and content, not only natural-language instructions. Require the response to distinguish rules from exceptions and expose sources when the experience supports citations. Specify when the agent must ask a clarifying question, decline to answer or hand off to a person. An abstention is a successful outcome when the evidence is insufficient; it protects trust and creates a useful backlog signal.

Evaluate retrieval and generation separately

A final-answer pass rate can conceal opposite failures. The retriever may return perfect evidence that the model misstates, or retrieve the wrong passage while the model happens to produce an acceptable answer from general knowledge. Without separating those stages, teams tune prompts for indexing problems and rewrite content for instruction failures.

Score retrieval relevance, authority, scope and freshness before scoring answer correctness, completeness, citation support and safe refusal. Maintain expected passages for high-risk questions and run them after source, index, retriever, prompt or agent changes. Include adversarial wording and historical incidents. Salesforce's development lifecycle guidance supports continuous improvement of the knowledge base from real-world queries; that feedback must remain governed rather than becoming automatic truth.

Measure the questions the library cannot answer

Production monitoring should capture which queries retrieve nothing, which sources dominate, which passages are repeatedly ignored and where users escalate or correct answers. Look for growing indexing lag, stale citations and low-confidence clusters by topic. These signals reveal knowledge gaps and retrieval drift that a generic agent-success dashboard will not explain.

Route each gap to a named content or platform owner. Some require a new article, others better structure, a synonym, a retriever filter or a transactional action instead of RAG. Do not solve every miss by adding more documents; library volume can increase ambiguity and consumption while reducing precision. Curated coverage is more valuable than an indiscriminate enterprise dump.

Operate grounding like a production service

Publish a service map showing sources, owners, ingestion schedules, data objects, indexes, retrievers, agents and channels. Version material changes, retain test evidence and plan rollback for the content and retrieval configuration—not only the agent definition. Give support teams a way to inspect source status and reproduce the passages returned for a reported question.

Agentforce Data Libraries simplify important platform configuration, and that is valuable. Their automation does not remove architectural accountability. Reliable grounding comes from authoritative content, measurable freshness, meaningful chunks, scoped retrieval, enforced permissions, supported citations and continuous evaluation. When that pipeline is owned end to end, the prompt can do its real job instead of compensating for invisible data debt.

Official references

Continue reading