Agentforce’s slower-than-hoped momentum highlights a familiar security and operations lesson: AI agents do not become production-ready until data, permissions, observability, and billing are all under control.