Salesforce’s biggest bet in years is that your team will stop opening Salesforce. Not the data — the data is the whole point. The screens. On August 26, 2026, Salesforce and Anthropic announced Claudeforce, and the interesting part is not the name. It is that the largest CRM vendor has decided the interface people use to reach its data no longer has to be its own.
This article is the long version of my LinkedIn post from September 10: what actually shipped, what it means for a company that runs sales and marketing on Salesforce, how the architecture underneath works, how I would roll it out, and — the part most announcements skip — how you train twelve hundred people who never wanted to be technical.
Claudeforce does not add a new AI to your stack; it moves the place where your sales team works – into Claude and Slack – while every action still runs through Salesforce under the permissions you already have. Three things to decide before the pilot: who audits those permissions before the plugin reads everything it can reach; which skills may write, and where a human approves first; and how a rep working in Claude hands off to a campaign team still working in Marketing Cloud, because marketing skills are not in the first wave. The rest of this article is how those three get done.
What shipped, exactly
Claudeforce is a partnership brand. Underneath it are three separate things, and they are at three different stages of maturity.
- Salesforce in Claude. A plugin for Claude with 37 prebuilt sales skills: daily briefing, pipeline review, forecast narrative, stakeholder mapping, close plans, objection handling, account planning, lead triage, call prep, conversation summary, win-loss review, activity logging, hygiene checks. Available to select pilot customers now; open beta expected in September 2026; additional skills starting late 2026. Salesforce says it runs the plugin itself as “Customer Zero” against its own live pipeline.
- Claude in Salesforce. Claude is available as the reasoning model for the Atlas Reasoning Engine in Agentforce (Salesforce’s framework for AI agents that act inside the CRM), is the default model in Agentforce Vibes and Agentforce Coworker, and is selectable in Agent Builder. It is served through Amazon Bedrock inside the Salesforce Trust Boundary — Salesforce calls Anthropic the first LLM provider integrated at that level.
- Claude in Slack. Claude is the default model for Slack AI and Slackbot, powers Claude Tag, and Anthropic is a founding partner for Slack Code. Salesforce reports 8.1 million annualized hours of productivity gains from its own Claude-powered Slackbot, doubling quarter over quarter — a self-reported internal figure, so treat it as a direction, not a benchmark.
On the roadmap, marked “coming soon” on the product page: Service, Marketing, Commerce, Revenue, Field Service, Tableau, MuleSoft, Informatica, Data 360, Headless 360 and Industries. Enterprise Frontier Safeguards — Anthropic’s misuse-detection layer running on customer-controlled infrastructure — are announced for fall 2026. Benioff and Amodei present the partnership live at Dreamforce, September 15–17.
The scenario: a medtech company with two interfaces
Picture a European medical device manufacturer. 1,200 reps in 14 markets. Sales Cloud holds accounts, hospital tenders and opportunities; Marketing Cloud — now Agentforce Marketing — runs the HCP campaigns. Here is a Tuesday morning after the pilot goes live.
- A rep asks Claude for her morning briefing. The plugin pulls overnight pipeline changes, deals flagged at risk, and last night’s Slack threads about the tender she is chasing.
- She asks for a close plan on that tender. Claude drafts it from the opportunity record, the contact roles, and the email history it is allowed to see.
- She says “log it”. The activity and the stage change go through Salesforce — validation rules, Flows and Apex triggers fire exactly as they would from the Lightning UI.
- Every one of those calls runs as her user. Object permissions, field-level security and sharing rules apply. The audit trail carries her name, not “integration user”.
- Compliance wants a human approval before any external email leaves the building. That control already exists: approval can be required before an agent action executes, and the product page names external emails and record updates explicitly.
Here is what one of those requests looks like on the inside – six stations, one identity:
Meanwhile the campaign manager for the same hospital account is still in Journey Builder. Marketing skills are on the roadmap, not in the plugin. The customer is one; the interfaces are now two; and the permission model has to hold both. That is the omnichannel point of this announcement, and it is the reason the rollout is an architecture project, not a licensing decision.
The architecture behind it
This is not a chatbot bolted onto a CRM. Three layers matter.
Layer 1: the substrate, Headless 360
Since July 2026, Salesforce offers a hosted MCP server called platform/headless-360 in beta. MCP — the Model Context Protocol — is the open standard that lets an AI assistant call another system’s tools. Instead of exposing thousands of endpoints, the server presents exactly four:
- Discover runs a semantic search over the operations your org can perform.
- Describe returns the technical contract for one of them: APIs, parameters, dependencies, steps.
- Dispatch executes it.
- Dispatch (Read-Only) executes GET operations only and, in Salesforce’s words, “never changes data or configuration”.
The 37 sales skills are task recipes on top of this: a skill knows which operations to discover and in which order, so the rep does not have to.
Layer 2: the identity model
Every Hosted MCP transaction runs as the authenticated user, scoped through an External Client App with the mcp_api OAuth scope, on API version 67.0 or later. There is no new permission concept. Object CRUD, field-level security, sharing rules, profiles and permission sets apply unchanged, and the audit trail attributes every action to the human who asked. This is the single most important sentence in the whole announcement, and it cuts both ways. It means your existing governance carries over for free. It also means every over-provisioned profile that survived the last three cleanups is now reachable through a conversational interface that will, on its first run, sweep everything the connection can access to build the rep’s tailored dashboard.
Layer 3: where the model runs
Claude is served through Amazon Bedrock inside the Salesforce Trust Boundary, with zero data retention on the Sonnet, Opus and Haiku models in this configuration. For a regulated company, this is the difference between a tool the security team can review and a tool it has to block. It does not answer the question of what your own contracts, DPIAs and internal policies require — that stays with your compliance team.
A rep asks the plugin for a list of accounts they have never been able to open in Lightning. What comes back?
Every transaction runs as the authenticated user, scoped through an External Client App with the mcp_api OAuth scope on API version 67.0 or later. Object CRUD, field-level security, sharing rules, profiles and permission sets apply unchanged.
Read it the other way round and it becomes a to-do: every over-provisioned profile that survived the last three cleanups is now reachable in conversation, and the plugin’s first context sweep reads everything the connection can see. The permission audit is not paperwork before the pilot – it is the pilot’s first phase.
The commercial picture
No list price has been published. Salesforce’s Patrick Stokes describes two lines: consumption pricing on the Salesforce side, with API access scaling by license edition, plus Anthropic’s inference costs billed separately. He also says token consumption is “certainly not zero, but nowhere close to development use case” levels. Both statements are reported in interviews, not documented in a price list. Plan for instrumentation before you plan for a budget number.
- Someone has exported the pilot users’ profiles, permission sets and sharing exposure – and removed what they do not need today.
- The External Client App carries the
mcp_apiscope, on API version 67.0 or later. - The security review has the zero-data-retention Bedrock configuration in writing, and your own DPIA position is settled separately.
- Consumption is instrumented per user and per skill before anyone quotes a budget number.
What it brings — by role
For the rep
The promise is the one Stokes puts as “10,000 clicks inside Salesforce, now 30 seconds”. The realistic version: the morning briefing, the call prep and the activity logging stop being chores that happen at 19:00 and start being questions asked at 08:15. Data hygiene improves because logging is one sentence away, not seven clicks.
For the head of sales operations
The plugin turns the pipeline review from a dashboard ritual into a dialogue with consistent numbers — the same records, the same sharing rules, whether the question is asked in Lightning, in Slack or in Claude. The catch: forecast narratives generated by an AI are only as good as the stage discipline underneath them.
For the CIO and the CISO
This is the first AI rollout where the governance layer already exists. The work is not writing an AI policy; it is auditing the permission model, deciding where human approval sits, and instrumenting consumption per user and per skill so the second invoice does not surprise anyone.
For the CMO
The honest answer is: not yet. Marketing skills are on the roadmap. What the CMO gets today is a sales team that increasingly works outside the CRM screens, and a campaign team that still works inside them. The handoff between the two — who knows what the rep promised the hospital, and when — is a process question that no plugin answers.
How to roll it out
I would run this in five phases, and I would not skip the first one.
Phase 0 — Permission audit, before anyone installs anything
List the pilot users. Export their profiles, permission sets and sharing exposure. Remove what they do not need for their job today. The plugin’s first context sweep reads everything the connection can reach; do the cleanup before that moment, not after.
Phase 1 — Read-only pilot: ten users, four weeks
Enable the plugin with the read-only dispatch tool only. Skills allowed: daily briefing, pipeline review, call prep, conversation summary. Measure two things: time-to-first-useful-answer per user, and consumption per user per day.
Phase 2 — Write access, skill by skill
Add activity logging first — it is low-risk and high-value. Then stage updates and follow-up tasks. Each skill that writes gets a named owner and a rollback path (Salesforce Backup, sandbox rehearsal).
Phase 3 — Approvals where regulation bites
Require human approval before external emails, and before record updates on objects your compliance team flags. Test that the approval actually interrupts the flow, in a sandbox, with a real user.
Phase 4 — Scale and instrument
Expand by market, not by role. Keep the Agent Builder model choice as a maintained escape hatch: if you have Agentforce agents pinned to a specific model, somebody re-tests them when the default changes. Sequence the rollout around your release upgrade window so the team is not troubleshooting a beta plugin and a platform upgrade in the same week.
- The permission cleanup happened before the first install, not after the first sweep.
- Every skill that writes has a named owner and a rehearsed rollback path.
- An approval step has been tested in a sandbox by a real user, and it actually interrupted the flow.
- Expansion is planned by market, not by role, and it avoids your release upgrade window.
- Agentforce agents pinned to a specific model have an owner who re-tests them when the default changes.
How to train teams that never wanted to be technical
This is the part most enablement plans get wrong. They schedule a “prompt engineering” workshop. Reps do not need prompt engineering. They need three habits and a catalogue.
The catalogue
The 37 skills are the training material. Print them — literally, one page — grouped as Salesforce groups them: daily workflows, deal strategy, account management, call prep, governance. A rep who can see that “close plan” is a skill will ask for a close plan. A rep who is told “Claude can help with anything” will ask for nothing.
Three habits to teach
- Habit one: ask in your own words, then check one fact. The onboarding exercise is not “write a good prompt”. It is: ask for your morning briefing, then open one of the deals it mentions and confirm the stage is right. Do that for a week. Trust is built by verification, not by demos.
- Habit two: say what you want done, not how. Reps who worked in Lightning for years describe the clicks: “go to the opportunity, change the stage, add a task”. The skill layer does not need that. “Log the call and move it to proposal” is enough. This takes two weeks to unlearn and is the single biggest source of early frustration.
- Habit three: know where the line is. Every rep must be able to answer, without looking it up: which actions run without approval, which ones wait for a human, and what happens when the answer looks wrong (open a ticket, do not try again with a different wording). That is a ten-minute conversation per team, and it is the one that prevents the incident.
Format and cadence
Not a training day. Fifteen minutes in the weekly sales meeting for six weeks, each week one skill, each week one rep showing what they asked and what they got. One champion per market who collects the questions that did not work. Slack is the natural place for that channel — which is exactly why Claude in Slack matters more for adoption than the plugin itself.
What to measure
Not “number of prompts”. Activity-logging completeness (the hygiene skill will tell you), time from meeting to logged outcome, and the share of reps who used the plugin three days in a row. The third number is the only one that predicts whether the rollout survives month two.
Integrating it into daily work
Three rituals change, and it is worth deciding on purpose how they change.
- The morning briefing becomes personal instead of team-wide. Decide whether the manager still runs a stand-up on the same numbers, or whether the stand-up becomes exceptions-only.
- The pipeline review stops being a dashboard walk-through. The manager asks the questions in Claude during the meeting; the reps correct the data live. This is a good thing only if stage discipline is real. If it is not, the AI narrative will be fluent and wrong.
- The handoff to marketing needs a rule, because the rep now works where the campaign team cannot see. The practical answer in my projects: the activity log is the contract. If the rep logs it through the skill, the campaign team can build on it — through Data 360 today, through a marketing skill when it ships.
One rule that is not optional
When the agent writes something wrong, it is an incident, not a chat message. Severity, owner, correction in Salesforce, note in the channel. Bulk updates through an agent trigger the same validation rules, Flows and triggers as a data-loader job; the failure modes are the same, and so is the cleanup.
The fine print
- Salesforce in Claude is in pilot; open beta is expected in September 2026 — not a GA date. Do not put revenue-critical processes on it this quarter.
- Headless 360 Hosted MCP Server is Beta under Salesforce’s Beta Services Terms; API v67.0 or later is required.
- The 37 skills are sales skills. Marketing, Service, Commerce, Revenue, Field Service, Tableau, MuleSoft, Informatica, Data 360, Headless 360 and Industries are “coming soon” with no dates.
- Pricing is consumption-based on two sides (Salesforce API access by license edition; Anthropic inference). No list price is published; the “two invoices” description is from an interview, not documentation.
- Zero data retention applies to Sonnet, Opus and Haiku in the Claudeforce setup. Whether that satisfies your DPIA or contractual requirements is your compliance team’s call, not the vendor’s.
- Slack agents (Claude Tag) are set up separately from the per-user plugin; check which credentials each agent carries before it touches regulated objects.
- Enterprise Frontier Safeguards are announced for fall 2026 — do not build a control on them yet.
- Model optionality exists in Agent Builder but is only real if somebody maintains and re-tests the alternative.
Questions to settle before you sign
- Which profiles and permission sets will the first pilot users carry — and who audits them before the plugin’s first context sweep?
- Read-only first: which skills are allowed to write, and from which sprint on?
- Where does human approval sit — external email only, or every record update on regulated objects?
- Who owns the Anthropic consumption line, and how is it instrumented per user and per skill?
- Which Agentforce agents are pinned to a specific model, and who re-tests them when the default changes?
- What is the handoff between a rep working in Claude and a campaign team working in Marketing Cloud — and where is it logged?
- Who owns the incident when an agent writes wrong data, and what is the correction path?
The line that matters
The screens are optional now. Your permission model isn’t. Salesforce has spent 27 years teaching people where to click. Claudeforce is the announcement that the clicks were never the product — the data, the rules and the permissions were. Companies that treat this as an AI project will buy licenses. Companies that treat it as a governance project will get the 30 seconds.
Also on Salesforce in regulated stacks: Marketing Cloud Next: the feature that stops you from writing is the real news · What ‘sovereign cloud’ means at Adobe, Salesforce and Veeva.
Frequently asked questions
What is Claudeforce?
A partnership brand announced on 26 August 2026, covering three things at three different stages. Salesforce in Claude is a plugin with 37 prebuilt sales skills, in pilot now with open beta expected in September 2026. Claude in Salesforce makes Claude the reasoning model for the Atlas Reasoning Engine in Agentforce, the default in Agentforce Vibes and Coworker, and selectable in Agent Builder. Claude in Slack makes it the default model for Slack AI and Slackbot. The interesting part is not the name: it is that the largest CRM vendor has decided the interface people use to reach its data no longer has to be its own.
Does Claudeforce introduce a new permission model?
No, and that is the single most important sentence in the announcement. Every Hosted MCP transaction runs as the authenticated user, scoped through an External Client App with the mcp_api OAuth scope on API version 67.0 or later. Object CRUD, field-level security, sharing rules, profiles and permission sets apply unchanged, and the audit trail attributes every action to the human who asked. It cuts both ways: existing governance carries over for free, and every over-provisioned profile that survived the last three cleanups is now reachable through a conversational interface.
What has to happen before the plugin is installed?
A permission audit – the cheapest step in the whole rollout and the one most pilots skip. List the pilot users, export their profiles, permission sets and sharing exposure, and remove what they do not need for their job today. The reason is timing: the plugin’s first context sweep reads everything the connection can reach, so the cleanup belongs before that moment rather than after it.
How should a Claudeforce rollout be sequenced?
In five phases, and the order matters. Phase 0 is the permission audit before anything is installed. Phase 1 is a read-only pilot: ten users, four weeks, read-only dispatch only, limited to briefing, pipeline review, call prep and conversation summary, measuring time-to-first-useful-answer and consumption per user per day. Phase 2 adds write access skill by skill, starting with activity logging, each writing skill with a named owner and a rollback path. Phase 3 puts human approval where regulation bites and tests that the approval actually interrupts the flow, in a sandbox, with a real user. Phase 4 scales by market and instruments consumption. Nothing writes before Phase 2, nothing scales before Phase 3.
How do you train a sales team that never wanted to be technical?
Not with a prompt-engineering workshop. Representatives need a catalogue and three habits. The catalogue is the 37 skills on one printed page, grouped the way Salesforce groups them – someone who can see that close plan is a skill will ask for a close plan, someone told that Claude can help with anything will ask for nothing. Habit one: ask in your own words, then verify one fact. Habit two: say what you want done, not how – this takes about two weeks to unlearn after years in Lightning. Habit three: know which actions wait for a human and what to do when an answer looks wrong. The format is fifteen minutes in the weekly sales meeting for six weeks, one skill per week, one representative showing what they asked and what they got.
Which number predicts whether a Claudeforce rollout survives month two?
The share of representatives who used the plugin three days in a row. Not the number of prompts. Two other numbers are worth tracking alongside it – activity-logging completeness, which the hygiene skill reports, and the time from meeting to logged outcome – but the three-days-in-a-row figure is the one that predicts survival.
How does a representative working in Claude hand off to a team working in Marketing Cloud?
Through the activity log, which becomes the contract between them. Marketing skills are not in the first wave – Service, Marketing, Commerce, Revenue, Field Service, Tableau, MuleSoft, Informatica, Data 360, Headless 360 and Industries are marked coming soon with no dates – so the representative now works where the campaign team cannot see. If the representative logs the interaction through the skill, the campaign team can build on it: through Data 360 today, through a marketing skill when it ships.
What happens when an agent writes wrong data?
It is an incident, not a chat message. That means a severity, an owner, a correction in Salesforce and a note in the channel. Bulk updates through an agent trigger the same validation rules, Flows and Apex triggers as a data-loader job, so the failure modes are the same and so is the cleanup.
What is Headless 360 and how does it work?
A hosted MCP server called platform/headless-360, in beta since July 2026. MCP, the Model Context Protocol, is the open standard that lets an AI assistant call another system’s tools. Rather than exposing thousands of endpoints, the server presents exactly four: Discover runs a semantic search over the operations your org can perform, Describe returns the technical contract for one of them, Dispatch executes it, and Dispatch Read-Only executes GET operations and, in Salesforce’s words, never changes data or configuration. The 37 sales skills are task recipes on top of these four.
Where does Claude run, and what happens to the data?
Claude is served through Amazon Bedrock inside the Salesforce Trust Boundary, with zero data retention on the Sonnet, Opus and Haiku models in this configuration. Salesforce calls Anthropic the first LLM provider integrated at that level. For a regulated company that is the difference between a tool the security team can review and one it has to block – but whether it satisfies your own data protection impact assessment and contractual requirements is your compliance team’s call, not the vendor’s.
What does Claudeforce cost?
No list price has been published. Salesforce’s Patrick Stokes describes two lines: consumption pricing on the Salesforce side, with API access scaling by license edition, plus Anthropic’s inference costs billed separately. He also says token consumption is certainly not zero, but nowhere close to development use case levels. Both statements come from interviews rather than a documented price list, so plan for instrumentation before you plan for a budget number.
If your team is weighing this up, the useful question is not what the agent can do but which of your objects it is allowed to write to. I work through that with Salesforce teams in regulated industries.
Get in touch →Sources: Salesforce press release, August 26, 2026 · salesforce.com/claudeforce · Salesforce Developers — Headless 360 (Beta), Hosted MCP Servers · Salesforce Developers Blog, July 14, 2026 · Dreamforce 2026 · interviews with Patrick Stokes in VentureBeat and CIO.com. Salesforce, Agentforce, Slack and Data 360 are trademarks of Salesforce, Inc.; Claude is a trademark of Anthropic, PBC. This is an independent analysis; no partnership with or endorsement by Salesforce or Anthropic. First published as part of my LinkedIn series, September 2026.

