Horus Eye · Modernization & AI Readiness

What to fix before Agentforce — measured in your own org

Every Agentforce conversation reaches the same question: is the org actually ready? Horus Eye answers it the only honest way — not with a readiness score invented from metadata, but with the specific prerequisites measured as findings: retiring engines still carrying logic, identity the agent would be grounded on, access the agent’s context could reach, and the UI and API debt underneath.

Check Your Agentforce Readiness What Horus Eye is

Findings filtered to the Modernization & AI Readiness dimension in Horus Eye
The readiness queue: the Modernization & AI Readiness dimension, with the MOD-lens findings that decide how much an agent can be trusted with.

Before you put AI on top of Salesforce, know what’s underneath it

The problem

Agentforce will inherit your data, your permissions, your automation, your business rules, your integrations — and your technical debt. Protecting what comes next starts with fixing the foundation your agents will depend on.

An agent inherits the org as it is. If Opportunity automation is split across three engines, the agent’s actions land on top of execution-order behavior nobody chose. If the same customer exists under three Accounts, the agent answers confidently from whichever it hits — the failure mode that looks like success. If the agent’s user context carries broad grants, every one becomes part of its operating envelope. None of this is an AI problem; all of it is org debt an agent amplifies. The readiness work is debt work — with an unusually clear payoff.

The prerequisites Horus Eye measures

No invented score

Automation on current engines

Objects still carrying Workflow Rules and active Process Builder processes — grouped per object for migration, with managed-package automation excluded because the vendor migrates theirs. An agent’s Flow actions should compose with one automation model, not three.

Data an agent can be grounded on

Core objects without duplicate rules and the duplicate groups they let in — fragmented identity is the difference between an agent that answers and one that answers consistently.

What the agent’s context can reach

The access findings wearing the MOD lens: over-broad grants, policy-bypass permissions, profile-centric security that resists least-privilege scoping for an agent user.

Platform currency

Components below the API retirement line and Lightning pages leaning on Aura/Visualforce — the debt that decides whether the org can adopt new platform capability on Salesforce’s cadence.

There is no “Agentforce Readiness score” in Horus Eye today — it is a planned KPI, and the product names it as not yet computed rather than faking it. What ships is sharper anyway: the specific findings, each with its fix path.

MOD-lens findings including objects still carrying Workflow Rules, grouped per object

Clearing the runway

The clearing

The engine migrations are guided — Horus plans them per object so save order survives the move. The access tightening is largely executable: withdrawing grants and removing policy-bypass permissions run as reversible, per-step-approved operations. Duplicate management starts with activating Salesforce’s standard rules. And then the part Kemisoft was built for: our Agentforce practice designs the agent on the cleared org — governed architecture, grounded data, guardrails, and a 90-day pilot with outcomes measured from day one.

Frequently asked questions

Straight answers
Is my Salesforce org ready for Agentforce?

Readiness is measurable as prerequisites, not as one number: engine currency, data identity, access scope, platform debt. A scan shows where each stands in your org — and what clearing them takes.

How does data quality affect Agentforce?

The agent answers from what it is grounded on. Fragmented identity produces confidently inconsistent answers — the failure mode that erodes trust fastest because it looks like the agent works.

How do permissions affect AI agents?

The agent acts through a user context; its reachable surface is that context’s grants. Least privilege stops being hygiene and becomes the agent’s specification.

What should I fix before implementing Agentforce?

Engines, identity, access, currency — in that order of leverage. All four are ordinary org work; the agent is why they finally get funded.

Does Process Builder need to be gone first?

Not as an absolute — but agent actions compose with Flow, and logic still living in retired engines is behavior the agent can trip over and you can’t easily extend. Migrating it is runway, not ceremony.

Protected AI — the Trust Layer

Every AI read in Horus Eye is metadata-first: built from an allowlist, sanitized by pattern, made through one audited gateway and checked by an output firewall on the way back — and AI is off by default, per org. Every request carries an audit id and an AI Data Scope manifest you can open.

See the Trust Layer

Measure the runway before you build the agent

One read-only scan turns “are we ready?” into a findings list with fix paths — and Kemisoft’s Agentforce practice takes it from there.

Try Horus Eye Check Your Agentforce Readiness All Horus Eye pages