BusinessIndustry Guide14 min readPublished August 9, 2026

IL5 covers controlled unclassified information · agents handle routine work · humans retain authority

The Army Just Cleared Agents for Sensitive HR Data

Salesforce announced on August 5, 2026 that US Army Human Resources Command selected Missionforce National Security to run Agentforce inside a newly Impact Level 5 authorized environment. This is a deployment selection, not a finished rollout with published results — and the transferable part is not the technology. It is the boundary: agents take routine inquiries, summarization, policy surfacing and routing, while specialists keep decision-making authority over benefits and sensitive determinations.

DA
Digital Applied Team
Senior strategists · Published Aug 9, 2026
PublishedAug 9, 2026
Read time14 min
SourcesSalesforce, DefenseScoop, Microsoft Learn
IL5 data scope
CUI
controlled unclassified + unclassified NSS
not classified
HRC workload (command-wide)
1,500+
cases per day across the command
not agent-only
People HRC supports
9.2M
Soldiers, Veterans, civilians, families
HRC HR professionals
3,000+
analysts and HR staff in the command

The most common objection to deploying AI agents in a regulated business is that the data is too sensitive. That objection now has a specific counter-example: on August 5, 2026 Salesforce announced that US Army Human Resources Command selected Missionforce National Security to run Agentforce inside a newly Impact Level 5 authorized environment, supporting workloads that involve highly sensitive controlled unclassified information.

Read the announcement carefully and the interesting part is not the authorization. It is the line Salesforce drew inside the workflow. Agents respond to routine inquiries, summarize case histories and surface relevant policy and career information from approved Army sources. Complex matters involving benefits or other sensitive decisions still route to HRC specialists, who — in the release’s own words — retain decision-making authority. That split is a template, and it is the part any regulated buyer can copy without buying anything.

This piece covers what was actually announced and what was not, what Impact Level 5 does and does not cover, how to read the vendor figures attached to the release, and how to turn the same boundary into a written policy inside a private-sector firm. Every number below is attributed, and every forward-looking figure is labelled as a projection because that is how the source labels it.

Key takeaways
  1. 01
    This is a selection, not a published outcome.Salesforce announced on August 5, 2026 that Army HRC selected Missionforce National Security to deploy Agentforce under a newly IL5-authorized environment. No measured accuracy, error rate, cost-per-case or satisfaction result has been published for the deployment.
  2. 02
    IL5 is an unclassified authorization level.Impact Level 5 covers controlled unclassified information and unclassified national security systems that need more protection than IL4 provides. It is not an authorization to process classified material — that sits outside IL5 entirely.
  3. 03
    The boundary is the transferable asset.Routine inquiries, case summarization, policy and career-information surfacing, and routing go to agents. Benefits and other sensitive determinations route to human specialists who retain decision-making authority. Copy the split, not the stack.
  4. 04
    Scale figures describe the command, not the agents.More than 1,500 cases a day, 9.2 million people supported and more than 3,000 analysts and HR professionals are HRC’s own workload and headcount. Nothing in the release says agents handle that volume.
  5. 05
    The money figures are projections, and pre-production.The $6 million annual savings figure is described as projected and is stated to apply before a single Agentforce agent is deployed to production. The 55 million conversations a month figure is projected at full scale. Neither is a result.

01The AnnouncementA selection, announced August 5.

Salesforce’s newsroom post states that US Army Human Resources Command selected Missionforce National Security to deploy Agentforce, operating within Salesforce’s newly IL5-authorized environment, and describes HRC as the first organization within the Department of War to deploy the newly IL5-authorized Agentforce for workloads involving highly sensitive controlled unclassified information. Source: Salesforce Newsroom, August 5, 2026.

A companion release published the same day announced that Agentforce 360 is now IL5-authorized and embedded across Missionforce National Security for the Department of War, with HRC presented as the first live use case of the broader authorization rather than a standalone product. That release also notes the platform runs on Amazon Web Services GovCloud, which Salesforce describes as a physically and logically isolated region operated exclusively by US personnel, and carries a footnote that GovSlack remains authorized at IL4 rather than IL5. Source: Salesforce Newsroom, August 5, 2026.

The event was corroborated independently by defense trade press. DefenseScoop reported the same day that Salesforce briefed reporters ahead of the announcement, quoted Missionforce leadership directly, and confirmed the GovCloud hosting arrangement. DefenseScoop also describes Missionforce as the national-security business unit Salesforce leadership launched in 2025 — Kendall Collins called it a startup inside a 27-year-old company.

None of this is a greenfield contract. The deployment sits under a pre-existing Army indefinite-delivery, indefinite-quantity vehicle announced on January 26, 2026 — a $5.6 billion, ten-year agreement structured as a five-year base plus one five-year option, awarded through Salesforce’s national-security subsidiary. Salesforce states plainly that the figure is a ceiling and not a guaranteed purchase amount, which is the only honest way to read any IDIQ number.

What the release does and does not say
It says HRC selected Missionforce National Security to deploy Agentforce inside an IL5-authorized environment, and describes the intended agent scope. It does not report a live production rollout, a measured deflection rate, an accuracy figure, a cost per case, or a satisfaction score. Any article you read that attaches performance results to this deployment is adding something the primary source does not contain.
“We’re the first ones, as a commercial software company, bringing an agentic platform that’s been productive in the commercial side into the national security environment… And it’s not just that we’re delivering the technology, but we’ve also got one of our first customers, Human Resources Command for the Army.”— Kendall Collins, CEO of Missionforce and Government Cloud at Salesforce, at a media roundtable reported by DefenseScoop, August 5, 2026

02Impact Level 5What IL5 actually covers.

Impact Level is the Department of Defense cloud-authorization ladder defined in the DoD Cloud Computing Security Requirements Guide. The most important thing to know about IL5 for the purposes of this story: it is an unclassified authorization. Per Microsoft’s vendor-neutral compliance documentation citing the SRG, IL5 covers controlled unclassified information that requires a higher level of protection than IL4 affords, plus unclassified national security systems, accommodating national security systems and CUI up to moderate confidentiality and moderate integrity under CNSSI 1253. Source: Microsoft Learn — DoD Impact Level 5.

Classified handling sits outside IL5 entirely. Anyone summarizing this announcement as the Army putting AI agents on classified data has misread the authorization. It is also worth noting that the numbered ladder is shorter than most write-ups imply: an independent compliance reference describes the framework as running IL2, IL4, IL5 and IL6 only, with no IL1, IL3 or IL7, and Salesforce’s own IL5 comparison table likewise stops at IL6. Source: CompassITC — DoD impact levels explained. Where you see a higher tier referenced, treat it as shorthand for classified handling arrangements rather than as a numbered cloud impact level.

IL2
Public and non-critical
Unclassified · lowest tier

Public or non-critical mission information. The baseline tier for DoD cloud workloads with no sensitivity constraint.

Lowest protection
IL4
Controlled unclassified
CUI · non-national-security systems

Controlled unclassified information on non-national-security systems. GovSlack sits here per the footnote in Salesforce's own companion release.

CUI baseline
IL5
Higher-sensitivity CUI
CUI needing more than IL4 · unclassified NSS

The level in this announcement. Adds DoD-specific hardening beyond FedRAMP High, physical separation from non-federal tenants, and US-person-only administrative access.

This deployment
IL6
Classified up to SECRET
Classified information

Classified handling, which sits outside IL5's unclassified CUI and NSS scope. Nothing in the HRC announcement touches this tier.

Out of scope here

The practical difference between FedRAMP High and IL5 is where the transferable lesson lives for commercial buyers. Microsoft’s documentation describes IL5 as requiring physical separation from non-DoD and non-federal tenants, with personnel access restricted to US citizens, nationals or persons. Salesforce’s own IL5 explainer goes further and states that DoD layers 47 additional security controls entirely beyond the FedRAMP High baseline — vendor-stated, and useful mainly as an order-of-magnitude signal for how much sits on top of a commercial certification. Source: Salesforce — What is IL5?

Salesforce also states that its Data 360 layer connects directly to sensitive records where they live, so data is never copied, moved or duplicated outside its secure boundary. That is a vendor claim about an architecture pattern, not an independently verified property, but the pattern itself is the one most regulated buyers should be asking for. We have written about the general version of that question in our guide to AI data-residency architecture patterns.

03The BoundaryAgents take the routine. Humans keep the authority.

The scope language in the release is unusually precise for a vendor announcement, and it is the reason this story is worth an operator’s attention. Agents respond to routine inquiries, summarize case histories, and surface relevant policy and career information from approved Army sources. Complex matters involving benefits or other sensitive decisions can still be routed to HRC specialists, who retain decision-making authority.

Two things are doing the work in that sentence. The first is the phrase approved Army sources — the agent is not reasoning from general world knowledge about entitlements, it is retrieving from a governed corpus. The second is that human authority is scoped to a class of decision, not to individual actions. Nobody is approving every agent response. Benefits and sensitive determinations are carved out as a category, which is what makes the arrangement operable at 1,500 cases a day rather than a review bottleneck.

Agent-owned
Routine inquiry response

Answers common questions from approved sources. Reversible, low-consequence, high-volume. The agent serves the answer directly and the transcript is the record.

No human gate
Agent-owned
Case history summarization

Condenses long case histories so a specialist does not read the whole file to get oriented. The human still reads the summary before acting, so the agent shapes attention rather than outcomes.

Human reads before acting
Agent-owned
Policy and career-information surfacing

Retrieves the governing policy or career information from approved sources. Retrieval is separated from interpretation — the agent finds the text, the human applies it.

Retrieval only
Human-owned
Benefits and sensitive determinations

Routed to HRC specialists who retain decision-making authority. The agent may assemble context, but the determination and its record belong to a named person.

Named human decides
The line, in the source's own words
“Complex matters involving benefits or other sensitive decisions can still be routed to HRC specialists, who retain decision-making authority.” If you write one sentence into your own agent policy this quarter, write that one, with your own definition of sensitive substituted for theirs. Our escalation-design guide covers how to make that carve-out survive contact with production volume.

04Scale vs ScopeThe big numbers describe the command, not the agents.

The release attaches three headline figures to HRC: it processes more than 1,500 cases per day, supports 9.2 million Soldiers, Veterans, civilian employees and family members, and employs more than 3,000 analysts and HR professionals. These describe the organization. They are not a statement that agents handle 1,500 cases a day, serve 9.2 million people, or replace 3,000 staff — and reading them that way is the single easiest mistake to make with this story.

Command workload
Cases per day
1,500+

HRC's own daily case volume as stated in the release. The release separately says automated case summarization is expected to support over 1,500 cases per day — the same figure in a second framing, not a second, additive number.

Command-wide figure
Population served
People supported
9.2M

Soldiers, Veterans, civilian employees and family members supported by HRC as an organization. Not an agent-conversation count and not a user base for the deployment.

Organizational scope
Staff
Analysts and HR staff
3,000+

The number of analysts and HR professionals in the command. The release frames agents as giving those staff time back on routine work, not as a headcount reduction.

No displacement claim

One internal cross-check is worth doing because it tells you the figures are consistent rather than recycled. The release separately states that the underlying Digital Front Door platform — delivered before this agent announcement — helps HRC resolve 600,000 cases per year more efficiently. Divide 600,000 by 365 and you get roughly 1,640 cases a day, which sits just above the stated “more than 1,500 per day.” Run it the other way and 1,500 cases a day comes to about 547,500 a year. The two figures describe the same workload from different angles, and neither is an Agentforce outcome: the Digital Front Door predates the agent layer.

This matters beyond pedantry. When a board asks what the agent programme delivered, the difference between “the command handles 1,500 cases a day” and “agents resolved 1,500 cases a day” is the difference between a context figure and a fabricated result. Build the habit of tagging every number in your own agent business case with whose workload it describes, before anyone reads it back to you as a benefit.

05The NumbersEvery money figure here is a projection.

The release carries two forward-looking figures, and both are explicitly labelled as projections by Salesforce. The $6 million annual savings figure is described as projected, attributed to reductions in manual processing time, improved case routing and the elimination of redundant legacy systems — and, in the release’s own words, applying before a single Agentforce agent is deployed to production. That last clause is decisive: the savings are not even claimed for the agents. The second figure, over 55 million agent conversations per month, is projected at full scale, which is a capacity statement rather than a current volume.

The table below is our own reconciliation of each published figure against what it does and does not establish. It exists because secondary coverage of announcements like this routinely promotes projections into results within a news cycle.

Each published figure in the Army HRC Agentforce announcement, with Salesforce’s own wording, its status as a projection or stated fact, and what it does not establish.
FigureHow the source words itStatusWhat it does not establish
$6 million a year“$6 million in projected annual savings simply from reductions in manual processing time, improved case routing, and the elimination of redundant legacy systems… before a single Agentforce agent is deployed to production”Projection, pre-productionThat agents have saved anything. The release ties the figure to platform work that precedes agent deployment.
55 million conversations a month“Over 55 million agent conversations per month projected at full scale”Projection, at full scaleAny current or measured conversation volume. It is a capacity figure for a state the deployment has not reached.
1,500+ cases a dayHRC “processes more than 1,500 cases per day”; automated case summarization is “expected to be supported” at that volumeStated workload, command-wideThat agents resolve 1,500 cases a day. It is the command’s volume, restated as what summarization is expected to touch.
600,000 cases a yearThe Digital Front Door platform “helps HRC resolve 600,000 cases per year more efficiently”Base platform, pre-AgentforceAn Agentforce result. This is the case-management layer the agents are being added to.
$5.6 billion contractTen-year Army IDIQ announced January 26, 2026: five-year base plus one five-year option, described as “not a guaranteed purchase amount”Ceiling, not committed spendWhat the Army will actually spend, or what this deployment costs. IDIQ ceilings are capacity, not budget.
Analyst read
Independent industry analysis from Futurum Group frames the IL5 authorization as functioning like a reference architecture that competitors will struggle to replicate quickly, and expects the advantage to extend into other regulated verticals such as financial services and healthcare. Treat that as a competitive read on the authorization, not as evidence about the deployment’s results. Source: Futurum Group.

06The TemplateThe split, written out as a policy.

This table is ours. The agent-owned rows are drawn directly from the scope language in the Salesforce release; the human-owned rows and every column beyond the first are our reconstruction of what that boundary implies once you have to operate it. Nothing here is published Army policy — it is the shape of the split, generalized so a private-sector team can adopt it in a working session.

A transferable agent-versus-human boundary template: work class, what the agent does, the human gate, data handling, and the evidence trail to keep, split into agent-owned and human-owned groups.
Work classWhat the agent doesHuman gateData handlingEvidence you keep
Agent-owned — routine, reversible, high volume
Routine inquiryAnswers from an approved, governed corpus onlyNone; answer served directlyRead-only against sensitive recordsFull transcript plus the source document cited
Case summarizationCondenses a long history into a brief for the specialistSpecialist reads before actingRead-only; no write-backSummary plus a link to the underlying record
Policy surfacingRetrieves the governing policy or entitlement textNone for retrieval; human interpretsRead-only; retrieval loggedDocument identifiers and version retrieved
RoutingClassifies and routes to the correct specialist queueSpecialist may reclassify on pickupMetadata only where possibleRouting decision, features used, reclassification rate
Human-owned — consequential, contested, irreversible
Benefits determinationAssembles context; proposes no outcomeNamed specialist decides and signsDecision authority never delegated to the modelDecision record attributed to the deciding person
Adverse or sensitive outcomeGathers the file; flags missing informationNamed specialist decidesFull record access under the human’s permissionsDecision plus written rationale and the evidence relied on
Low-confidence or novel caseStops and escalates with the unresolved question statedMandatory human pickupVaries by caseEscalation reason, timestamp, and time to human pickup

The column most teams skip is the last one. An agent boundary that exists only in a slide is unenforceable; an agent boundary with a named evidence artefact per row is auditable, and the audit is what a regulator, a customer or your own board will actually ask for. The general pattern set behind this — oversight, escalation, logging and documentation across regulated sectors — is covered in our guide to agentic AI oversight patterns in regulated industries, which is the companion piece to this one rather than a repeat of it.

07Trust SignalAuthorization as a procurement argument.

The commercial reason this announcement matters to a private-sector buyer has little to do with the Army. Government authorizations function as portable trust signals: clearing a control regime that demands physical tenant separation, US-person-only administration and dozens of controls beyond a commercial baseline is generally treated across the compliance industry as evidence a vendor can survive a hard security review, which tends to shorten the review outside government too. That is a general property of these authorizations rather than a Salesforce-specific claim, and it cuts both ways — an authorization tells you about the environment, not about whether the agent is any good at the work.

It is also not the first deployment of its kind from this business unit. On July 8, 2026 Salesforce announced a Missionforce National Security deployment with the US Air Force 441st Vehicle Support Chain Operations Squadron, an 85-person unit managing a $13.5 billion vehicle fleet — the release’s body text puts the fleet at roughly 84,000 vehicles across about 389 locations supporting over 7,300 personnel, while its own headline uses a larger round number, so treat the fleet size as approximate. Source: Salesforce Newsroom, July 8, 2026.

On the “first” claim, precision is worth the extra word. Salesforce describes HRC as the first organization within the Department of War to deploy the newly IL5-authorized Agentforce, and no comparable third-party regulated agent deployment at an equivalent authorization level surfaced in our research. That supports first publicly disclosed, which is a defensible claim. It does not support “first ever” — an absence of public precedent is not proof one does not exist, and defense and financial-services deployments are frequently not announced at all.

“Guardrails, to me, built-in means I can accelerate. It’s not a speed bump. It’s actually something that allows me to go fast.”— Retired Maj. Gen. Allan Day, VP and Industry Strategy Executive at Salesforce, reported by DefenseScoop, August 5, 2026

That framing is the one worth stealing, whatever you think of the source. In most private-sector agent programmes the guardrail conversation happens after a pilot stalls in a security review, which is the most expensive possible order. The Army sequence runs the other way: the environment is authorized, the decision boundary is written down, and only then does the agent scope get defined. It is slower to start and materially faster to scale, because the questions that normally kill an agent rollout in month four were answered in month zero.

08Your VersionCopying this without an IL5 environment.

You almost certainly do not need a defense authorization. What you need is the same sequence in miniature, and it is achievable in a quarter for most mid-market firms holding sensitive customer data.

Start with the decision classes, not the use cases. Write down every class of decision your function makes, then mark each one reversible or irreversible, and contested or uncontested. A decision that is irreversible or likely to be disputed belongs to a named human, permanently — not until the model improves. This is a twenty-minute exercise that most teams postpone until after they have already shipped an agent into a workflow it should never have touched.

Then constrain the corpus. The Army version reads “from approved Army sources.” Yours should name the systems, document sets and record types the agent may retrieve from, and explicitly exclude everything else.

Then decide where the data physically sits, because that determines which vendors are even eligible. Salesforce’s answer here is an isolated government region with US-person-only administration and a connect-in-place data layer; yours might be a regional tenancy, a private deployment or a zero-retention API agreement. Whatever it is, decide it before you scope the agent, not after procurement has fallen in love with a demo.

Finally, budget for the metered part. Agent programmes fail on unit economics more often than on capability, and the pricing models are still moving — the broader vendor shift away from credit-metered AI pricing is visible in HubSpot’s Q2 2026 pricing concession, and the arithmetic of what an agent conversation actually costs is worked through in our agent token-budget framework. A boundary you cannot afford to run is not a boundary.

If you would rather not assemble this from first principles, that sequence — decision classes, retrieval scope, data residency, unit economics, evidence trail — is exactly how our AI transformation engagements open, and it is the same groundwork behind our CRM automation work where service agents touch customer records.

What to watch next
The honest position at the time of writing is that this deployment has no published outcomes. The signals worth tracking are whether Salesforce or the Army publishes measured results, whether the decision boundary holds or quietly widens as volume grows, and whether any comparable IL5-authorized agent deployment appears from another vendor. Until then, treat this as proof of permission, not proof of performance.

09ConclusionThe excuse that just got weaker.

Regulated agent deployment, August 2026

Sensitivity was never the real blocker. An undefined decision boundary was.

“Our data is too sensitive for agents” has been the most durable objection in regulated industries, and it has always been slightly dishonest. The Army did not solve sensitivity with better models. It solved it with an authorized environment and a written line between the work an agent may own and the decisions a named person must keep. That combination is available to any firm willing to do the unglamorous half.

Hold the caveats, though, because they are the difference between learning from this and repeating vendor copy. This is a selection announced on August 5, 2026, not a rollout with results. The savings and conversation-volume figures are projections, and the savings figure is explicitly stated to apply before any agent reaches production. The scale figures belong to the command, not the agents. IL5 is an unclassified authorization. Every one of those distinctions will be flattened somewhere in the secondary coverage over the next fortnight.

The forward read is straightforward. If an IL5-authorized environment becomes the reference architecture for regulated agent deployment, the next twelve months are likely to bring the same pattern into financial services and healthcare, where the authorization vocabulary differs but the buyer’s question is identical: who is accountable when the agent is wrong. The firms that answer that in writing first will move fastest, and they will not be the ones with the best models. They will be the ones who decided, early and specifically, what their agents are not allowed to decide.

Deploy agents on sensitive data, safely

Sensitive data is not the blocker. An undefined boundary is.

We help regulated businesses define the agent-versus-human decision boundary, constrain retrieval scope, settle data residency, and stand up the evidence trail an audit will ask for — before anything ships into a customer-facing workflow.

Free consultationExpert guidanceTailored solutions
What we work on

Regulated agent deployments

  • Decision-class mapping — what agents may never decide
  • Retrieval-scope design against approved source systems
  • Data residency and tenancy decisions before vendor selection
  • Escalation and human-gate design that survives volume
  • Evidence trails and audit artefacts per workflow
FAQ · Army HRC Agentforce at IL5

The questions operators ask first.

Salesforce announced that US Army Human Resources Command selected Missionforce National Security to deploy Agentforce inside Salesforce's newly Impact Level 5 authorized environment, supporting workloads that involve highly sensitive controlled unclassified information. The release describes HRC as the first organization within the Department of War to deploy the newly IL5-authorized Agentforce. A companion release the same day announced that Agentforce 360 is now IL5-authorized and embedded across Missionforce National Security for the Department of War. It is important to read this as a deployment selection rather than a finished rollout: the release describes intended agent scope and projected impact, and does not report measured production results.