Share this on:
What You'll Learn
Read the blog to understand how Salesforce and Informatica work together to enable effective AI agent governance for regulated industries.
Whether an AI agent can resolve a claims dispute or approve a credit line adjustment is not something that concerns a financial services CISO. They ask a narrower question first – can you show, field by field, what the agent saw, why it acted, and who is accountable if it got it wrong? Until that question has a concrete architectural answer, the agent does not go near a customer record. And that is the starting line for AI agent governance in regulated industries like financial services, healthcare, and life sciences.
From copilot to autonomous agent: What changed with CLAIRE in 2026
An agent that can read a customer’s full record, reason over it, and take an action is only acceptable once three conditions are architecturally true:
- The agent's data access is scoped to exactly what the task requires and enforced at the platform level
- Every field the agent touched, every source it drew from, and every action it took is logged in a form an examiner can read.
- A named system owner can explain the decision path after the fact, without reconstructing it from application logs.
This is why “governed autonomy” is a more accurate term than “responsible AI” for this space. The goal is not to make the agent polite. It is to make its behavior provable, bounded, and reversible.
This is the same bar regulated enterprises already apply through their broader enterprise data governance program to any system that touches customer data.
Two Layers: Salesforce Trust Controls & Informatica Governance
Regulated enterprises need two governance layers working together:
- Salesforce-native trust controls that govern the agent at the point of use
- Informatica governance, catalog, and lineage that govern the data before the agent ever sees it.
Most architectures stop at a single layer, and that is where the coverage gap appears.
Salesforce’s own trust stack is real and substantial. The Einstein Trust Layer masks selected PII and PCI data in prompts before they reach a model. This layer also holds zero-retention agreements with model providers and logs every masked interaction to an audit trail. Data 360’s policy-based governance layers field, object, and record-level enforcement on top of that. It is a strong first layer.
But that coverage holds only as far as what has been ingested into, or federated through, Data Cloud. It says nothing about the state of the source system the data came from. Whether that record was accurate, or how a change to a customer’s consent status six systems upstream should propagate into what the agent is allowed to see today.
Enter Informatica. Master data management resolves which record is authoritative. Data catalog declares what every field means and who owns it. And lineage traces a value back to its origin across every system it touched on the way to the agent.
The architecture regulated enterprises need is not “pick Salesforce trust controls or Informatica governance.” It is both, deliberately connected:
- Informatica IDMC masters and governs the record before it reaches Data 360
- Data 360 enforces policy-based access at the point the agent actually queries the data
- The Einstein Trust Layer masks and logs at the model boundary, the last line of defense, not the only one
- MuleSoft governs the API and integration layer connecting all of it. So the same policy holds whether the agent is inside Salesforce or calling out to a core banking or EHR system.
PII in practice: Automated masking in Data 360
The architectural detail that matters is not “does the platform mask PII.” It is where the masking happens and whether it is dynamic. Salesforce’s Data 360 architecture applies dynamic data masking at query time and combines it with attribute-based access control. A field like a Social Security number or a diagnosis code is obfuscated based on the requesting user’s role and context, without altering the underlying stored value. A support agent working the same account does not see the SSN at all, even though the record is identical underneath.
This matters for agent governance specifically because an AI agent inherits the access of the user who invoked it. Plus whatever attribute-based rules apply to the task. If the underlying masking is static or applied only at the UI layer, an agent calling the same data through an API can end up seeing more than a human user could.
Dynamic, policy-driven masking that is enforced consistently across UI, API, and agent access is what closes that gap. This is also where Informatica’s classification work upstream earns its keep. A field can only be masked correctly if it has first been correctly identified and tagged as sensitive, which is a data governance problem before it is a security control.
Ensuring explainability across the ecosystem
Examiners do not ask “what did Agentforce do?” They ask – “what did the customer’s data look like, everywhere, at the moment the agent acted, and how did it get that way?” That question crosses Salesforce, Informatica, the data warehouse, and whatever core system of record sits underneath all of it.
Explainability that stops at the Salesforce boundary answers half the question and leaves the harder half. The provenance of the data itself, unaddressed.
A complete explainability answer requires three things stitched together:
- Model and agent-level reasoning logs, showing what the agent was asked, what it retrieved, and what it decided
- Field-level lineage, showing where each value the agent relied on originated and every transformation it passed through
- A unified audit trail a compliance team can pull without chasing down three different platform teams
Mapping to critical governance frameworks
None of this exists in the abstract. It maps directly onto obligations regulated enterprises carry:
Any life sciences or healthcare organization requires administrative, technical, and physical safeguards around protected health information. And an agent that can read or act on PHI is squarely inside that scope.
It’s enforced by the FTC and requires financial institutions to maintain a written information security program covering how customer information is accessed, used, and protected. This extends directly to whatever an AI agent is permitted to query.
State privacy laws
An increasingly fragmented patchwork across US states adds consent, access, and deletion obligations that a governed data foundation with real lineage can operationalize, where an ungoverned one cannot.
These come under the Equal Credit Opportunity Act and place the burden on the institution to explain and defend a credit decision. This means any agent involved in underwriting, pricing, or servicing needs a documented, reviewable decision path.
The common thread across all four is that compliance is not a policy document sitting next to the architecture. It has to be built into the architecture, or it is not defensible when someone actually asks.
How LumenData builds governed agent foundations for regulated enterprises
As a proud Platinum Enterprise Partner with Informatica and Salesforce partner, LumenData connects Informatica’s mastering, governance, and lineage with Salesforce Data 360 and Agentforce’s trust controls into one architecture. For financial services, healthcare, and life sciences enterprises specifically, that means governed, AI-ready data foundations built with the audit trail, classification, and lineage regulated organizations are asked to produce on exam day.
Ready to find out whether your AI agents can explain themselves? Talk to LumenData about building a governed data and agent architecture your compliance team can stand behind.
About LumenData
LumenData is a leading provider of Enterprise Data Management, Cloud and Analytics solutions and helps businesses handle data silos, discover their potential, and prepare for end-to-end digital transformation. Founded in 2008, the company is headquartered in Santa Clara, California, with locations in India.
With 150+ Technical and Functional Consultants, LumenData forms strong client partnerships to drive high-quality outcomes. Their work across multiple industries and with prestigious clients like Versant Health, Boston Consulting Group, FDA, Department of Labor, Kroger, Nissan, Autodesk, Bayer, Bausch & Lomb, Citibank, Credit Suisse, Cummins, Gilead, HP, Nintendo, PC Connection, Starbucks, University of Colorado, Weight Watchers, KAO, HealthEdge, Amylyx, Brinks, Clara Analytics, and Royal Caribbean Group, speaks to their capabilities.
For media inquiries, please contact: marketing@lumendata.com.
Ready to find out whether your AI agents can explain themselves?
Authors
References
- Summary of the HIPAA Privacy Rule - U.S. Department of Health and Human Services
- FTC Safeguards Rule - Federal Trade Commission
- Fair Lending - Consumer Financial Protection Bureau
- Data 360 Security Architecture - Salesforce Developers
- Data Masking | Agentforce Developer Guide - Salesforce Developers
- Data Foundation for AI Services - LumenData
- Enterprise Data Governance: What It Is & Why You Need It - LumenData


