Tython

SalesforceSecurity

Claudeforce Is Here: Your Org's Permissions Are Now Its AI Guardrails

Scott Covert · 

On Wednesday’s Q2 ’27 earnings call, Marc Benioff and Dario Amodei took the stage together to announce Claudeforce–an expanded Salesforce-Anthropic partnership that puts Claude inside Salesforce and, more consequentially for security teams, puts Salesforce inside Claude. Last month we covered what one vendor’s stale credential cost roughly 195 Salesforce customers, and back in March we called permission set overprivileging the silent risk in every Salesforce org. Claudeforce is where those two threads meet: it is the biggest integration most orgs will approve this year, and its entire authorization model is the permissions you already have.

What Was Actually Announced

Claudeforce runs in two directions:

  • Claude moves into Salesforce. Claude is now available as a reasoning model for the Atlas Reasoning Engine and is the default model powering Agentforce Vibes and Agentforce Coworker. Inference runs through Amazon Bedrock inside the Salesforce Trust Boundary, so data and AI workloads stay within Salesforce’s security perimeter rather than routing to an external API–the detail that matters most for regulated industries.
  • Salesforce moves into Claude. The “Salesforce in Claude” plugin ships with 37 prebuilt sales skills–meeting prep, deal health review, pipeline management–that let sellers read live CRM data and take governed actions without opening the Salesforce app. It’s with select pilot customers now, with open beta expected in September 2026 and more skills promised for late 2026.

Under the hood, both directions ride on what Salesforce calls its enterprise harness: MCP servers, APIs, and CLI tools that expose platform operations to agents in a structured, permission-scoped way. The hosted MCP server has been in beta since July and requires API v67.0 or later.

The Headline Feature Is a Security Decision

The pitch admins will hear is genuinely appealing: an administrator connects Salesforce in Claude once, authentication and permissions are managed centrally, and every seller on the team gets access from day one–no per-user setup, no new permissions model to build, no re-auditing account by account.

Read that again as a security architect. “No new permissions model” means authorization is delegated entirely to the one you already have. When a seller queries their pipeline inside Claude, the MCP layer retrieves only what that user’s profile, permission sets, field-level security, and sharing rules allow, and enforces validation rules and automation before any write lands. There is no separate AI permission layer to configure–your existing access model is the AI permission layer.

That cuts both ways:

  • It’s the right architecture. Since TDX, teams have been hand-rolling agent access to Salesforce through DIY MCP connections, each with its own tokens, its own auth, and no central governance–exactly the token sprawl that turned the Klue breach into 195 breached orgs. One sanctioned, centrally governed path beats a dozen shadow ones.
  • It makes your permission debt executable. Overprovisioning that was tolerable for a human clicking through record pages is a different proposition behind an agent that can chain queries, follow relationships, and touch hundreds of records a minute without getting bored. The access nobody noticed a user had is now access an AI will actually exercise.

Anthropic says it put a “huge amount of effort” into the permissions work, and the two companies are building what they call Enterprise Frontier Safeguards around data privacy and model behavior. Take the help–but the enforcement boundary in your org is still the one you configured.

Deeper Dive

Audit Before You Connect, Not After

The vendors’ message is that you don’t need to re-audit accounts to turn this on. Our advice: that’s precisely the moment to re-audit accounts. Before your org joins the September open beta:

  1. Sweep the dangerous permissions. Query who holds View All Data, Modify All Data, Export Reports, and API Enabled–via permission sets and permission set groups. Every one of those grants is about to be inherited by an agent acting on that user’s behalf.
  2. Check field-level security on sensitive objects. An agent summarizing “everything about this account” will surface every readable field, including the ones users never scrolled to. Compensation fields, SSNs in custom fields, and internal notes are all in scope if FLS says they are.
  3. Revisit sharing defaults. Public Read/Write org-wide defaults that survived because “nobody would ever look” no longer have that excuse. The agent looks at everything the user is allowed to see, systematically.

Start Read-Only, Widen Deliberately

The MCP tooling exposes a read-only dispatch mode alongside full read/write. Use that asymmetry:

  1. Pilot with read-only access scoped to the specific objects and fields the sales skills actually need.
  2. Let the analysis skills–meeting prep, deal health–prove themselves before any skill can write.
  3. Grant write access per skill, deliberately, after you’ve watched the agent’s behavior in logs. “It can update records” should be a decision you make per use case, not a default you accept at connection time.

Know Which Identity Is Doing the Talking

There are two distinct connection patterns in this stack, and they have very different audit stories:

  • Per-user OAuth (the hosted MCP route, via an External Client App with the mcp_api scope): every call runs as the person making it. Attribution is clean, and your sharing model applies per user. Review the app’s scopes, token lifetimes, and refresh token policies the way you would for any high-value connected app.
  • Integration-user routes (the client-credentials pattern used for agent connections like Slack’s): one dedicated identity acts for many people. That user’s permission sets deserve the least-privilege treatment you’d give an admin account, and you’ll need conventions to trace which human asked for which action.

Know which pattern each Claudeforce surface in your org uses before you enable it, because your incident-response playbook depends on it.

Make Agent Activity Visible

Agent-initiated actions flow through the same APIs as everything else, which means your existing telemetry works–if you point it in the right direction:

  • Filter Event Monitoring by the connected app or external client app identity so agent-driven API calls are distinguishable from human sessions, and baseline the query volume during your pilot.
  • Your Transaction Security export policy–mandatory since July 13–applies to agent-initiated bulk reads too. Confirm the thresholds make sense when a legitimate agent workflow might touch far more records per minute than a human ever did.
  • Writes still fire validation rules, Flows, and Apex triggers exactly as traditional DML would. That’s good–your business rules hold–but it also means agent actions can cascade through automation. Know which of your Flows send email or call out to external systems before an agent starts triggering them.

Keep One Sanctioned Path

The centralized connection only reduces risk if it’s the only connection. Use API Access Control to allowlist the sanctioned client apps and block teams from standing up parallel MCP integrations–otherwise you’ve recreated shadow IT with agents attached. And two timing cautions: both the plugin and the MCP server are beta, so keep critical Q4 processes off them; and with Winter ’27 sandbox previews starting this weekend and production upgrades landing September 4 through October 9, stagger your AI pilot so you’re not debugging a new platform release and a new agent surface in the same sandbox at the same time.

The Bottom Line

Claudeforce’s one-connection setup is honest about something the industry usually obscures: there is no separate “AI security” for your CRM. The agent is exactly as safe as the permission model it inherits. Orgs that have spent this year tightening permission sets, migrating off profiles, and turning on Event Monitoring are ready to pilot this in September. Orgs carrying a decade of permission debt are about to hand a very capable agent the keys to all of it. “Scoped to their own permissions” is only as reassuring as the permissions–audit yours before Claude reads them.

Book a 15-Minute Security Strategy Call

Reference(s):

https://www.salesforce.com/news/press-releases/2026/08/26/salesforce-and-anthropic-announce-claudeforce/

https://www.cnbc.com/2026/08/26/salesforce-anthropic-partnership-claudeforce.html

https://www.apexhours.com/claudeforce-explained-what-salesforce-anthropic-actually-ship/

https://www.salesforceben.com/salesforce-and-anthropic-announce-claudeforce-in-q2-27-earnings/

https://salesforcetime.com/2026/08/27/claudeforce-salesforce-meets-claude/