Salesforce Packaged Its Hardest Integration Problem Into a Plugin — 4,000 Employees Are Using It

Salesforce Packaged Its Hardest Integration Problem Into a Plugin — 4,000 Employees Are Using It

BackerLeader 44 266 470
calendar_today agoschedule3 min read

Six months ago, wiring an AI agent into Salesforce meant handing the job to whoever on your team actually understood MCP servers. That person could get it working for themselves. Getting the same setup in front of 10,000 knowledge workers was a different problem entirely.

"Not every seller or marketer knows what an MCP server is and knows how to go do that wire up," said Patrick Stokes, Salesforce's president of applications and marketing, at the company's Dreamforce news preview. Salesforce had opened up that raw access back in the spring, exposing its MCP servers and APIs under what it calls Headless 360. Developers could connect the pieces. But access alone didn't tell an agent what to do with it. "The AI just tries to figure it out," Stokes said. "A lot of times that choice, that reasoning, is going to be wrong or not exactly what you expect."

That's the gap Salesforce and Anthropic set out to close with ClaudeForce, which moved into open beta this week through Claude's AppExchange. It's a plugin, not a new set of raw connectors. Install it into a Claude Enterprise org, and it wires up the MCP servers, packages the "skills" that tell the agent how Salesforce actually expects things done, and turns on zero data retention and permission-scoped access — all as one toggle, not a build project. Stokes calls the distinction between this and Headless 360 "the raw ingredients" versus "the chocolate chip cookie that comes out of the oven." Headless 360 gave you the parts. ClaudeForce gives you the packaged thing your whole org can install without a technical project behind it.

The access controls are worth a closer look if you're the one who'd get paged when something goes wrong. Scott White, Anthropic's head of enterprise product, described how the permission model works in practice: "Claude only sees what the person is allowed to see. They authenticate with their credentials, and Claude only has access to the data that they should have access to. Every action flows through Salesforce, so its access rules and records apply every time." Rohan Kumar, Salesforce's president and chief platform and engineering officer, framed the security work as its own product line, Salesforce Guardian, built around two problems specifically: agent identity — what an agent is actually authorized to do on a user's behalf — and data protection, since most agents today act with the privileges of whoever they're serving.

Stokes demoed what an org actually gets to build with this during the Dreamforce keynote, and it's a decent gauge of how far natural-language configuration has come. He built his own live sales dashboard inside Claude Cowork — pipeline data, service cases, and marketing signals pulled together — plus a Slack integration and a custom notification voice modeled after co-founder Parker Harris, complete with a 3D avatar and a sound effect that logs a real Salesforce activity record when a deal stalls. None of it was written by an engineer. "That is a UI that I personally created for myself by just asking," Stokes said, putting the initial build at six to eight minutes, with a few days of back-and-forth to add the finer details.

Early usage numbers back up that this isn't just a stage demo. Salesforce says roughly 40 customers are running pilots, including Deloitte, Siemens, and GitLab, with Salesforce and Anthropic themselves as the largest deployments — about 4,000 daily active users inside Salesforce within days of rollout. Most companies are starting small, Stokes said, rolling ClaudeForce out to a pilot group of maybe 100 users before expanding.

What's worth sitting with is where Kumar thinks this leaves the actual coding work. He argued that agent logic — the code an agent runs to reason through a task — is heading toward commodity status, something models increasingly generate on their own. The differentiation, in his view, moves down a layer: into what he calls the enterprise AI harness, the combination of data readiness, business context, semantic models, and governance that determines whether an agent behaves correctly inside a real company's rules. Salesforce is folding its own products — Informatica, Data 360, Tableau, Guardian, and MuleSoft's Agent Fabric — into a single control plane meant to manage that layer at scale, since the open question isn't whether enterprises will deploy agents, but how anyone governs thousands of them at once.

That's a reasonable read of where the work goes next for developers building on this kind of stack: less time hand-wiring individual connections, more time defining the skills, guardrails, and context an agent needs to be trusted with real access. Whether ClaudeForce and its packaged-plugin approach hold up outside a keynote demo is the thing to watch as the open beta reaches more of the 40 pilot customers over the next few months.

🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

The Sovereign Vault — A Comprehensive Guide to Protocol-Driven AI

Ken W. Algerverified - Jun 4

MCP Is the USB-C of AI. So Why Are You Plugging Everything In?

Ken W. Algerverified - Jun 10

Sovereign Intelligence: The Complete 25,000 Word Blueprint (Download)

Pocket Portfolio - Apr 1

Your AI Doesn't Just Write Tests. It Runs Them Too.

Kevin Martinez - May 12

AI Agents Don't Have Identities. That's Everyone's Problem.

Tom Smithverified - Mar 13
chevron_left
18.2k Points780 Badges
245Posts
141Comments
105Connections
LLM Training & Evaluation Specialist with hands-on experience building major AI models. As one of th... Show more

Related Jobs

View all jobs →

Commenters (This Week)

1 comment
1 comment
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!