Karya
An agentic employee experience platform on Agentforce and Data Cloud, covering the employee lifecycle from hiring to appraisal, plus IT and HR service desk.
Every employee moment, one agent away.
Recruiting slice built. Remaining domains designed.
- 27
- step engagement dossier
- 133
- catalogued requirements
- 7
- agents, with 21 subagents and about 80 actions
- 12
- architecture decision records
- 66
- Apex classes
- 76
- custom metadata records
- 10
- permission sets, in 2 permission set groups
- 9 of 9
- regression fixtures passed by the first prompt template
How it fits together
Candidates and employees
Six HR and IT domains
Agents, split by security context
Seven designed; the public one is isolated
Code around every prompt
Preparation before, citation checks after
Core objects and provenance records
Anything a person edits or approves
Data Cloud
Anything that exists to be searched or unified
Orange marks what is built today.
The problem
Employees and candidates spend a lot of time waiting on someone who is busy, away, or working from memory: a recruiter reading resumes, a manager writing an appraisal, an IT desk granting access.
Six domains
- Recruiting
- Resume extraction with citations, job-match scoring, dynamic application forms, interviewer tools.
- Performance
- Sprint-based feedback, a consolidated year record, appraisal drafting.
- Skills
- Repeat-gap detection, one-to-one briefs, development plans.
- Workforce Ops
- Skill inventory, demand, staffing match, bench management.
- Time and Leave
- Timesheet automation, end-of-day notes, leave.
- IT and HR Service Desk
- Policy answers, access provisioning, incident triage, assets.
Design principles
- AI drafts, humans decide
- Nothing that affects a person happens without a human approving it. No candidate is ever rejected automatically.
- Rules stay rules
- Hours, balances, thresholds and routing are Flow or Apex, never a prompt.
- Everything generated is cited
- Each extracted value stores the exact source text it came from, and code verifies the citation before saving.
- Access control is the platform's job
- Permission sets and sharing rules decide who sees what. A prompt never does.
- Every artefact traces to a requirement
- Nothing is built without an ID that leads back to why.
Architecture highlights
- Seven agents, split by security context first and by domain second. The only public-facing agent is fully isolated from employee data.
- Agents never call each other. Cross-domain effects travel through Platform Events, so they stay testable.
- A clear rule for what lives in core objects and what lives in Data Cloud: if a person edits it or an approval depends on it, it is a core object; if it exists to be searched or unified, it is Data Cloud.
- Every prompt that touches a record is wrapped in code: deterministic preparation before, verification after.
- AI provenance is a record of its own, written in the same transaction as the value it describes.
Built so far
- Skill taxonomy and resolver.
- AI provenance service.
- Prompt regression harness, with the first template passing 9 of 9 fixtures.
- Requisition intake Flow and job-description quality check.
- Trust Layer masking verified.
Designed, not yet built
- The agents themselves: no agent metadata is deployed yet.
- Data Cloud: streams, data model objects, identity resolution and retrievers.
- The five domains beyond Recruiting.
Technology
In the built slice
- Apex
- Flow
- Prompt Builder
- Custom Metadata
- Permission sets
- Platform Events
- Einstein Trust Layer
- Salesforce CLI
Designed for
Designed and documented. Not yet deployed.
- Agentforce agents
- Data Cloud
Planning and delivery
- Notion
- Linear
- Claude Chat
- Claude Cowork
- Claude Code
Links
- Demo video: coming soon
- GitHub repository: in progress, linked when public