Sandeep Kumar Panda
BuiltDesigned

Karya

An agentic employee experience platform on Agentforce and Data Cloud, covering the employee lifecycle from hiring to appraisal, plus IT and HR service desk.

Every employee moment, one agent away.

Recruiting slice built. Remaining domains designed.

27
step engagement dossier
Designed
133
catalogued requirements
Designed
7
agents, with 21 subagents and about 80 actions
Designed
12
architecture decision records
Designed
66
Apex classes
Built
76
custom metadata records
Built
10
permission sets, in 2 permission set groups
Built
9 of 9
regression fixtures passed by the first prompt template
Built

How it fits together

  1. Candidates and employees

    Six HR and IT domains

  2. Agents, split by security context

    Seven designed; the public one is isolated

  3. Code around every prompt

    Preparation before, citation checks after

  4. Core objects and provenance records

    Anything a person edits or approves

  5. Data Cloud

    Anything that exists to be searched or unified

Orange marks what is built today.

The problem

Employees and candidates spend a lot of time waiting on someone who is busy, away, or working from memory: a recruiter reading resumes, a manager writing an appraisal, an IT desk granting access.

Six domains

Recruiting
Resume extraction with citations, job-match scoring, dynamic application forms, interviewer tools.
Performance
Sprint-based feedback, a consolidated year record, appraisal drafting.
Skills
Repeat-gap detection, one-to-one briefs, development plans.
Workforce Ops
Skill inventory, demand, staffing match, bench management.
Time and Leave
Timesheet automation, end-of-day notes, leave.
IT and HR Service Desk
Policy answers, access provisioning, incident triage, assets.

Design principles

AI drafts, humans decide
Nothing that affects a person happens without a human approving it. No candidate is ever rejected automatically.
Rules stay rules
Hours, balances, thresholds and routing are Flow or Apex, never a prompt.
Everything generated is cited
Each extracted value stores the exact source text it came from, and code verifies the citation before saving.
Access control is the platform's job
Permission sets and sharing rules decide who sees what. A prompt never does.
Every artefact traces to a requirement
Nothing is built without an ID that leads back to why.

Architecture highlights

  • Seven agents, split by security context first and by domain second. The only public-facing agent is fully isolated from employee data.
  • Agents never call each other. Cross-domain effects travel through Platform Events, so they stay testable.
  • A clear rule for what lives in core objects and what lives in Data Cloud: if a person edits it or an approval depends on it, it is a core object; if it exists to be searched or unified, it is Data Cloud.
  • Every prompt that touches a record is wrapped in code: deterministic preparation before, verification after.
  • AI provenance is a record of its own, written in the same transaction as the value it describes.

Built so far

  • Skill taxonomy and resolver.
  • AI provenance service.
  • Prompt regression harness, with the first template passing 9 of 9 fixtures.
  • Requisition intake Flow and job-description quality check.
  • Trust Layer masking verified.

Designed, not yet built

  • The agents themselves: no agent metadata is deployed yet.
  • Data Cloud: streams, data model objects, identity resolution and retrievers.
  • The five domains beyond Recruiting.

Technology

In the built slice

  • Apex
  • Flow
  • Prompt Builder
  • Custom Metadata
  • Permission sets
  • Platform Events
  • Einstein Trust Layer
  • Salesforce CLI

Designed for

Designed and documented. Not yet deployed.

  • Agentforce agents
  • Data Cloud

Planning and delivery

  • Notion
  • Linear
  • Claude Chat
  • Claude Cowork
  • Claude Code

Links

  • Demo video: coming soon
  • GitHub repository: in progress, linked when public