Agentforce Hits IL5 Without Claude
The Department of Defense authorized Agentforce 360 at Impact Level 5 on Wednesday, and Army Human Resources Command is the first organization to deploy it. To clear the bar, Salesforce attested that Anthropic's models were switched off.

[Salesforce Government Cloud Plus](/terms/salesforce-government-cloud-plus) Defense has been running workloads at Impact Level 5 for a while. What changed on Wednesday is what you are permitted to run inside that boundary. The Department of Defense authorized Agentforce 360 at IL5, and the agent layer moved from outside the line to inside it.
That is the whole story in one sentence, and it is bigger than it sounds. Until now a defense customer could hold data at IL5 and still not point an autonomous agent at it. The compliance boundary covered the records, not the reasoning. As of August 5 it covers both.
Two press releases landed the same morning. One announced the authorization. The other named the first customer: U.S. Army Human Resources Command, the first Department of War organization to deploy Agentforce Public Sector inside the IL5 environment.
The Line Agentforce Just Crossed
Impact Levels are the Defense Department's classification for how sensitive the data in a cloud service is. IL4 covers Controlled Unclassified Information, which is the enormous middle category of government data that is sensitive but not classified. IL5 adds higher-sensitivity CUI and unclassified National Security Systems data. IL6 is where classified workloads start.
Salesforce's tiers map onto that ladder. Government Cloud Plus carries FedRAMP High and supports IL4. Government Cloud Plus Defense is the physically isolated instance authorized for IL4 and IL5, built on AWS GovCloud with US-persons-only operations. We walked through the full tier structure in the Missionforce guide if the naming is unfamiliar.
What moved inside the IL5 boundary is a named list, and reading it as a list matters more than reading it as a headline. Agentforce 360 is the agent runtime and governance layer. Agentforce Public Sector brings prebuilt agent templates for government use cases. Data 360 provides zero-copy data interoperability. Tableau Next covers predictive analytics. Agentforce Marketing handles recruiting pipeline work.
Salesforce also describes a "develop low, deploy high" path, where work built in the IL5 environment can be promoted to Top Secret networks. That is a deployment pattern, not an authorization, and the difference is worth holding onto.
When the Air Force signed its first Missionforce work in May, the open question we flagged was exactly this one: the press release named no Impact Level for the Agentforce pilots, and the accreditation step was what would convert pilots into production. That step closed on Wednesday.
The First Deployment Is a Personnel Desk
Army HRC is a good choice for a first reference, and probably a deliberate one. It is high volume, high visibility, and about as far from a weapons system as a defense deployment gets.
HRC serves 9.2 million people: soldiers, veterans, Army civilians, and military families. Roughly 3,000 analysts and HR professionals staff it. Its Digital Front Door, the consolidated cloud platform that replaced a set of legacy HR systems, currently resolves about 600,000 cases a year.
Agentforce is being added on top of that existing platform rather than replacing it, which is the part most architects will recognize. The agent layer sits on a data model somebody already did the hard work of unifying.
The projected numbers are large: 1,500 or more cases supported daily through automated summarization, more than 55 million agent conversations a month at full scale, and about $6 million in annual savings from reduced manual processing. Treat those as targets rather than results. They are forward-looking figures in a launch announcement, and the deployment went live this week.
The number worth anchoring on is 600,000 cases a year, because that one is current-state and measured. It is also the honest denominator for judging the 55 million conversation figure later.
What the Agent Is Actually Allowed to Decide
The scoping in the HRC announcement is more conservative than the volume suggests, and this is the design detail to copy.
The agents answer routine inquiries, summarize case histories, and surface policy and career information from approved Army sources. Complex benefits determinations route to human specialists, who keep decision authority. The agent handles retrieval, summarization, and triage. It does not adjudicate.
That split is the reason a personnel command could clear an authorization review at all. An agent that only retrieves from a governed source set and hands off on judgment calls has a much smaller blast radius than one that writes decisions. If you are scoping an agent for a regulated internal customer, this is a cleaner reference than any commercial deployment currently in the wild, and it is public.
Anthropic Is Switched Off
Here is the detail that did not make the press releases.
DefenseScoop reported that to reach IL5, Salesforce attested to the Pentagon that generative AI models and capabilities supplied by Anthropic were disabled in the environment. The reason is not a technical one. The Defense Department and Anthropic have been in an escalating dispute since February over the military's use of Claude, which produced a supply-chain risk designation, litigation in two federal circuits, and a set of rulings that have gone both ways.
Salesforce's position is that the platform is model-agnostic and the exclusion is a policy-driven toggle, liftable if the department's stance changes.
Notice how much that single toggle is carrying. Salesforce took a $5 billion stake in Anthropic in June, shipped Claude into Slack as a tagged participant, and has spent a year making Claude a visible part of the Agentforce story. In the federal environment, that entire layer is off, and Salesforce had to say so in writing to get authorized.
The architectural read is more interesting than the political one. A platform that can drop a model provider through configuration and stay authorized is demonstrating something specific about how its abstraction is built. It also demonstrates that "model-agnostic" stopped being marketing language the moment a compliance regime made it load-bearing.
If your own agent design assumes a particular model, this is a reasonable prompt to go check what it would take to swap it. Not because Anthropic is going anywhere in commercial orgs, but because a regulator, a customer procurement team, or a data-residency requirement can produce the same demand with no notice.
GovSlack Is Still at IL4
One line in the announcement gets skipped in most coverage. GovSlack remains authorized at IL4, not IL5.
Salesforce has spent this year positioning Slack as the front door to the agentic enterprise. Agents surface in channels, work gets handed to them in conversation, and the interface is where the value story lives. In an IL5 defense environment, that front door does not reach the room. Agents run at IL5, the collaboration layer stops at IL4, and the two cannot be collapsed.
For a federal architect this is a design constraint on day one, not a footnote. The interaction surface for IL5 agents has to be the Salesforce application layer or a purpose-built front end, and any pattern that assumes Slack as the entry point needs a different answer.
For everyone else, it is a useful demonstration of something the front-door narrative tends to blur. Slack and the agent runtime are separate products with separate boundaries, and boundaries do not have to move together.
What This Means Outside a Federal Org
Compliance references travel. That is most of why Salesforce pursues them.
An architect at a bank or a hospital who gets asked whether autonomous agents can be trusted with sensitive data now has a public answer that is not a whitepaper: the Defense Department authorized this agent stack for unclassified national security data, and here is the personnel command running it at scale. That does not resolve the question, but it changes the starting position of the conversation.
The commercial timing is not accidental either. Salesforce confirmed on August 5 that second quarter fiscal 2027 results land on Wednesday, August 26, after market close, with the webcast at 2:00 p.m. Pacific. Agentforce adoption has been the sore point in the last two quarters of analyst coverage, and a federal authorization plus a named 9.2 million-user deployment is a durable proof point three weeks ahead of that call.
Two other dates sit in the same window. The Winter '27 preview sandbox instances come up on August 28, which means any sandbox you want on the preview instance has to be created or refreshed before 6:00 p.m. Pacific on August 27. Production upgrade weekends follow on August 29, October 3, and October 10.
What To Do This Week
If you work in or near a federal org, pull the current authorization boundary document rather than trusting the press release. Salesforce distinguishes between authorized products, which sit inside the boundary, and interoperable products, which merely work in Government Cloud. That distinction has caught out designs before, and a five-product IL5 list means the sixth product you assumed was covered probably is not.
If you are designing an agent for any regulated internal customer, copy the HRC scoping before you copy the ambition. Retrieval from an approved source set, summarization, and triage, with a hard handoff to a human on anything requiring judgment. Write down which decisions the agent may not make, and put that list in the design doc rather than in the prompt.
And go look at how tightly your agent design is bound to one model provider. Salesforce could turn Anthropic off through policy and stay authorized. Whether you could do the same, on a week's notice, without rewriting your instructions and re-testing your evaluations, is a question that gets much more expensive to answer after somebody asks it.
Then put August 27 on the calendar next to all of it, because the sandbox refresh deadline does not move for anyone.
About the Author
Dipojjal Chakrabarti is a B2C Solution Architect with 29 Salesforce certifications and over 13 years in the Salesforce ecosystem. He runs salesforcedictionary.com to help admins, developers, architects, and cert/interview candidates sharpen their fundamentals. More about Dipojjal.
Share this article
Sources
- Missionforce National Security Unveils IL5-Authorized AI Agents and Apps (Salesforce, August 5 2026)
- U.S. Army Human Resources Command Deploys Agentforce to Deliver 24/7 AI-Powered Support to 9.2 Million Soldiers, Veterans, and Military Families (Salesforce, August 5 2026)
- Salesforce previews plans to deliver newly authorized 'AI agents' across DOD (DefenseScoop, August 5 2026)
- Salesforce Secures IL5 Authorization for Agentforce, Army HRC First to Deploy (MeriTalk)
- Salesforce Announces Date of Second Quarter Fiscal 2027 Earnings Release and Webcast (Salesforce Investor Relations)
- Salesforce Government Cloud (Salesforce)
- Pentagon-Anthropic Dispute over Autonomous Weapon Systems: Potential Issues for Congress (Congressional Research Service)
- Salesforce Winter '27 Release Date and Preview Information (Salesforce Ben)
Related dictionary terms
More news

Air Force Fleet on Missionforce
The Air Force's 441st squadron went live on Missionforce to run its $13.5B, 84,000-vehicle fleet across 389 sites. MELRAT cut contingency lookups from days to minutes. Here is what is live and what is still a pilot.

Air Force Picks Missionforce, $72M
The Air Force awarded Salesforce a $72M enterprise license for Missionforce National Security on May 13, executed as a task order under the existing $5.6B Army IDIQ. Agentforce pilots are part of the deal.
Comments
No comments yet. Start the conversation.
Sign in to share your take on this article. Your account works across every page.