BotShield_Resolution__c record. The agent proceeds only on an approved verdict — never on the caller’s word.
Add BotShield to an agent
1
Add the BotShield topics
In the Agentforce agent builder, add the packaged topics from the Asset Library:
- BotShield Customer Verification — link a customer with BotShield (instead of an email OTP), then check the link.
- BotShield Approval — require a human confirmation for an action, check it, and proceed.
2
Grant the agent user access
Assign the
BotShield_Agent_Access permission set to the agent’s running user so the packaged actions can call out.3
Activate
Activate the agent. The BotShield actions are now available as tools the planner can invoke.
What the agent does
The packaged invocable actions are the hard gate — they run server-side and are the source of truth:The approval, end to end
1
Agent proposes
The agent calls Require Human Confirmation with a plain-language summary of the action (e.g. “Refund order #1042 — $168.45”).
2
Human approves on their phone
The linked person sees a card in their BotShield app and approves with a passkey — per action, every time.
3
Proof lands in the org
A
BotShield_Resolution__c record is written with the verdict and a signed proof; the agent reads it and proceeds only if approved.MCP is reach, the package is the gate. You can also register the BotShield MCP server so Employee agents can call these tools — but the packaged Apex actions remain the hard gate. See MCP server.
Use it in a Flow instead
The same confirmation, as a Flow that pauses and resumes on the resolution.
