> ## Documentation Index
> Fetch the complete documentation index at: https://docs.botshield.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Agents Ask in Agentforce

> Require a real human to confirm sensitive agent actions, approved with a passkey on their own phone.

**Agents Ask** lets an Agentforce agent take a sensitive action *only after a real human confirms it*. The agent proposes the action; the linked person gets a card on their phone and approves it with a passkey; a signed **Proof of Resolution** lands in your org as a `BotShield_Resolution__c` record. The agent proceeds only on an approved verdict — never on the caller's word.

## Add BotShield to an agent

<Steps>
  <Step title="Add the BotShield topics">
    In the Agentforce agent builder, add the packaged topics from the **Asset Library**:

    * **BotShield Customer Verification** — link a customer with BotShield (instead of an email OTP), then check the link.
    * **BotShield Approval** — require a human confirmation for an action, check it, and proceed.
  </Step>

  <Step title="Grant the agent user access">
    Assign the `BotShield_Agent_Access` permission set to the agent's running user so the packaged actions can call out.
  </Step>

  <Step title="Activate">
    Activate the agent. The BotShield actions are now available as tools the planner can invoke.
  </Step>
</Steps>

## What the agent does

The packaged **invocable actions** are the hard gate — they run server-side and are the source of truth:

| Action | Purpose |
| - | - |
| **Require Human Confirmation** | Propose a sensitive action to the linked human; returns a request to poll. |
| **Check Human Confirmation** | Read the org row first (no callout) for the verdict — approved, denied, or expired. |
| **Link Human** / **Check Link** | Pair the customer with BotShield and confirm the link. |

<Warning>
  **Topic routing is per-turn.** The verification topic must end its turn with a question so the *next* user turn lands in the working topic — otherwise a post-verification action won't fire in the same turn. Keep the "ask" and the "act" in separate turns.
</Warning>

## The approval, end to end

<Steps>
  <Step title="Agent proposes">
    The agent calls **Require Human Confirmation** with a plain-language summary of the action (e.g. “Refund order #1042 — \$168.45”).
  </Step>

  <Step title="Human approves on their phone">
    The linked person sees a card in their BotShield app and approves with a passkey — per action, every time.
  </Step>

  <Step title="Proof lands in the org">
    A `BotShield_Resolution__c` record is written with the verdict and a signed proof; the agent reads it and proceeds only if approved.
  </Step>
</Steps>

<Note>
  **MCP is reach, the package is the gate.** You can also register the BotShield MCP server so Employee agents can call these tools — but the packaged Apex actions remain the hard gate. See [MCP server](/integrations/salesforce/mcp-server).
</Note>

<Card title="Use it in a Flow instead" icon="diagram-project" href="/integrations/salesforce/flow-pause-resume">
  The same confirmation, as a Flow that pauses and resumes on the resolution.
</Card>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.