# Agentforce और PII: AI Deployment से पहले Sensitive Data की सुरक्षा

> Agentforce Salesforce text fields में छुपी PII पढ़ता है। compliance risk घटाने के लिए deployment से पहले sensitive data खोजना और remediate करना सीखें।

Source: https://dataqualitysense.com/hi/resources/ai-readiness/agentforce-pii-compliance/
Last updated: 2026-06-12

---

जब Agentforce एक record retrieve करता है, तो यह जिन fields को पढ़ता है उनमें मौजूद सब कुछ AI context में enter करता है। इसमें free-text fields में छुपी कोई भी personally identifiable information (PII) शामिल है, भले ही उन fields का कभी sensitive data रखने का इरादा नहीं था। एक case comment में paste किया गया Social Security Number उसका हिस्सा बन जाता है जिसे agent पढ़ता है, जिस पर reason करता है, और जिसे एक generated response में surface कर सकता है।

यह guide समझाती है कि PII Agentforce context तक कैसे पहुँचती है, यह Salesforce में कहाँ accumulate होती है, और इसे go-live से पहले कैसे खोजें और remediate करें। यह दो संबंधित guides पर बनती है: पूरी deployment readiness के लिए [Agentforce Preparation](/hi/resources/ai-readiness/agentforce-preparation/) hub, और DQS pattern matching कैसे काम करता है इसके लिए [PII Detection](/hi/resources/ai-readiness/pii-detection/)।

## PII Agentforce Context में कैसे enter करती है?

Agentforce agents एक consistent flow का पालन करते हैं: वे Salesforce records retrieve करते हैं, जिन field values को पढ़ते हैं उनमें अपनी reasoning ground करते हैं, और उस context से एक response generate करते हैं। PII retrieval step पर enter करती है। Agent sensitive data के लिए बने field और एक free-text field जहाँ sensitive data गलती से उतर गया, के बीच फर्क नहीं करता। यह दोनों को पढ़ता है।

तीन स्रोत समय के साथ text fields को PII से भरते हैं:

- **Email-to-case.** Incoming messages Case Description और Comments में verbatim capture हो जाते हैं। जब customers किसी समस्या का वर्णन करते हैं तो वे SSNs, account numbers, और card details शामिल करते हैं। यह सब एक text field में उतरता है।
- **Support और sales notes.** Agents एक call के दौरान identity-verification details, payment information, और contact data को notes में paste करते हैं। interaction के बहुत बाद तक note बना रहता है।
- **Imported और integrated data.** Migrations और integrations contact details, dates of birth, और identifiers को description और comment fields में लिखते हैं जहाँ कोई validation नहीं चलती।

एक बार वह डेटा एक retrievable field में बैठ जाता है, तो object पढ़ने के लिए scoped कोई भी agent इसे context में खींच सकता है। Exposure तब मौजूद होता है जब आप एक भी agent deploy करते हैं उससे पहले। Deployment एक dormant data समस्या को एक active समस्या में बदल देता है।

## PII Salesforce में कहाँ छुपती है?

PII unstructured text fields में केंद्रित होती है। Structured fields (Email, Phone) में PII design से होती है और तदनुसार governed होती है। Risk उन free-text fields में रहता है जिन्हें users scratch space की तरह treat करते हैं।

| Object | High-Risk Fields | यह क्यों Accumulate होती है |
|--------|-----------------|--------------------|
| Case | Description, Comments | Email-to-case customer messages verbatim लिखता है |
| Lead | Description | Imported lists और form submissions यहाँ उतरते हैं |
| Contact | Description | verification और account details के बारे में notes |
| Account | Description | Relationship notes और billing context |
| Task / Event | Description, Comments | verification data capture करने वाले call notes |
| Opportunity | Description | payment terms का संदर्भ देने वाले deal notes |
| Note (Content) | Body | किसी भी record से free-form attachments |

Case पर Description और Comments fields सबसे अधिक risk उठाते हैं क्योंकि email-to-case इन्हें automatically और volume में feed करता है। किसी भी scan में उन दो fields को अपनी पहली priority मानें। where-it-hides scenarios के पूरे set के लिए, [PII Detection Scenarios](/hi/resources/use-cases/pii-detection-scenarios/) देखें।

## कौन से Regulations लागू होते हैं?

Retrievable fields में PII उन privacy और security frameworks को implicate कर सकती है जिनके तहत आपका organization पहले से operate करता है। विशिष्टताएँ आपके डेटा, आपके jurisdiction, और आपके contractual obligations पर निर्भर करती हैं, इसलिए नीचे के बिंदुओं को अपनी compliance team के साथ समीक्षा करने के लिए एक शुरुआती list मानें, legal advice नहीं।

- **GDPR.** data minimization और purpose limitation जैसे principles आमतौर पर इसका मतलब हैं कि PII को अपने intended use से परे fields में नहीं बैठना चाहिए। एक description field से birth date पढ़ने वाला agent उस purpose से बाहर हो सकता है जिसके लिए वह डेटा collect किया गया था।
- **HIPAA.** जहाँ protected health information (PHI) support notes या case text में दिखाई देती है, वहाँ handling rules उन fields को process करने वाले किसी भी system पर लागू हो सकते हैं, एक AI agent सहित।
- **PCI DSS.** free-text fields में card data आमतौर पर storage और handling requirements के तहत आता है। Case Comments में card numbers एक आम और high-priority finding है।

क्योंकि DQS पूरी तरह Salesforce के अंदर चलता है, PII के लिए scanning एक नया data transfer नहीं बनाती या डेटा को किसी external service में move नहीं करती। कोई डेटा आपके org से बाहर नहीं जाता। यह discovery step को ही cross-border transfer और processor concerns के scope से बाहर रखता है। deployment से पहले अपनी स्थिति के लिए regulatory mapping की पुष्टि अपनी compliance team के साथ करें।

## आप DQS के साथ PII के लिए कैसे scan करते हैं?

DQS text fields को आठ predefined regex patterns के साथ scan करता है और exposure को एक single metric के रूप में report करता है। Detection deterministic और transparent है: आप लागू किया गया हर pattern देखते हैं, और वही input हमेशा वही result लौटाता है।

आठ patterns चार categories को cover करते हैं:

| Category | Patterns |
|----------|----------|
| Financial | Social Security Number, Credit Card Number, IBAN |
| Contact | Email Address, US Phone Number, International Phone |
| Technical | IP Address |
| Identity | Date of Birth |

तीन controls के साथ scans configure करें:

- **Presets.** **Critical** preset केवल SSN और Credit Card activate करता है। near-zero false positives के साथ एक fast financial-PII check के लिए इसका उपयोग करें। **Standard** preset Email और US Phone जोड़ता है। **Extended** preset सभी आठ चलाता है।
- **Per-field overrides.** अलग-अलग fields पर अलग-अलग pattern sets apply करें। एक Email field को केवल SSN और Credit Card के लिए scan करें, क्योंकि वहाँ email matches अपेक्षित हैं। Description और Comments को पूरे Extended set के साथ scan करें, क्योंकि कोई भी PII type दिख सकती है।
- **PII Exposure Rate.** यह headline metric है: कम से कम एक pattern match वाले scanned records का प्रतिशत। अपनी cleanup को scope करने के लिए इसे Records with PII count के साथ pair करें।

[Definition Builder](/hi/resources/using-dqs/running-scans/) में हर high-risk object के लिए एक definition बनाएँ, इसे Description और Comments fields की ओर point करें, और financial PII isolate करने के लिए पहले Critical preset चलाएँ। फिर एक complete inventory के लिए Extended चलाएँ।

## Remediation Playbook कैसा दिखता है?

एक PII scan matches की एक list पैदा करता है। Remediation उस list को resolved findings में बदलती है। इस क्रम में काम करें।

1. **Matches review करें।** कुछ patterns false-positive risk उठाते हैं। Date of Birth किसी भी US-formatted date से match करता है, और Credit Card लंबे order numbers से match कर सकता है। हर match को PII मानने से पहले पुष्टि करें। triage के लिए pattern category का उपयोग करें: Financial findings पहले आते हैं।
2. **प्रति field action तय करें।** हर confirmed finding के लिए, तीन responses में से एक चुनें:
   - **Mask.** Sensitive value को replace करें जबकि आसपास के text को agent के लिए usable रखें।
   - **Delete.** जहाँ यह कोई business purpose नहीं serve करती वहाँ value हटा दें।
   - **field को agent scope से exclude करें।** जहाँ एक field reliably ऐसी PII रखता है जिसकी agent को जरूरत नहीं, इसे agent के retrieval scope से हटा दें ताकि डेटा कभी context में enter न करे।
3. **validate करने के लिए rerun करें।** Remediation के बाद, वही scan फिर से चलाएँ। PII Exposure Rate की तुलना अपने pre-remediation baseline से करें। संख्या पुष्टि करती है कि cleanup काम कर गई। सभी dimensions में एक structured cleanup sequence के लिए, [Agentforce के लिए Salesforce Data Cleanup](/hi/resources/ai-readiness/salesforce-data-cleanup-for-agentforce/) guide का पालन करें।

जब एक field की कोई AI value नहीं होती तो उसे agent scope से exclude करना सबसे तेज control है। Masking और deletion उन fields को address करते हैं जिन्हें agent को अभी भी पढ़ने की जरूरत है।

## Pre-Deployment PII Safety Targets

deployment तब तक रोकें जब तक आपका डेटा हर उस text field पर इन targets पर खरा न उतरे जिसे Agentforce access करेगा:

- agent scope में text fields पर **PII Exposure Rate 1% से नीचे**।
- Case Description और Comments पर **शून्य SSN matches**।
- Case Description और Comments पर **शून्य credit card matches**।
- expected-content fields के लिए **Per-field overrides configured** ताकि Email और Phone fields rate को inflate न करें।

ये thresholds [Agentforce Data Readiness Checklist](/hi/resources/ai-readiness/agentforce-data-readiness-checklist/) से आते हैं। go-live से पहले इनके विरुद्ध compliance team sign-off प्राप्त करें, और remediated data पर agent responses test करें ताकि पुष्टि हो कि generated content में कोई PII नहीं दिखती।

## Go-Live के बाद PII को कैसे बाहर रखें?

PII exposure कोई one-time cleanup नहीं है। Email-to-case customer messages को Case fields में लिखता रहता है, और users verification details को notes में paste करते रहते हैं। एक clean dataset हफ्तों के भीतर नया exposure accumulate करता है।

regression को जल्दी पकड़ने के लिए recurring scans schedule करें:

| Scan | Frequency | Objects |
|------|-----------|---------|
| PII Detection (Critical preset) | साप्ताहिक | Cases, Leads (high-volume text fields) |
| PII Detection (Extended preset) | मासिक | agent scope में सभी objects |

समय के साथ PII Exposure Rate track करें ताकि एक rising trend इसके आपके agents तक पहुँचने से पहले review trigger करे। Case और Lead पर साप्ताहिक scans उन fields को cover करते हैं जहाँ नई PII सबसे तेजी से उतरती है। findings की समीक्षा के लिए ownership assign करें ताकि scan results action में बदलें।

Undetected PII सबसे आम कारणों में से एक है कि agents non-compliant output पैदा करते हैं। व्यापक failure patterns के लिए, [Agentforce Agents क्यों Fail होते हैं](/hi/resources/ai-readiness/why-agentforce-agents-fail/) देखें।

## अगले कदम

- [PII Detection](/hi/resources/ai-readiness/pii-detection/): आठ patterns, presets, और per-field configuration विस्तार से
- [Agentforce Preparation](/hi/resources/ai-readiness/agentforce-preparation/): सभी छह dimensions में पूरी deployment readiness
- [Agentforce Data Readiness Checklist](/hi/resources/ai-readiness/agentforce-data-readiness-checklist/): पूरी pre-deployment target list
- [Agentforce Data Quality FAQ](/hi/resources/ai-readiness/agentforce-data-quality-faq/): agents के लिए डेटा तैयार करने पर सामान्य सवाल
- [AI Readiness Assessment](/hi/ai-readiness/): अपनी current readiness score करें
