
Dreamforce 2026 opens Tuesday: September 15-17 at Moscone Center, with 1,600+ sessions, 50+ keynotes, and one organizing idea–becoming an “Agentic Enterprise.” Three weeks ago we previewed Winter ’27’s quiet security changes, and two weeks ago we covered Claudeforce and the permission model that now doubles as your AI guardrail. Dreamforce is where both stories accelerate: every announcement on that stage will be an agent announcement, and every agent announcement is, underneath the demo, an access-model decision your org will have to make. Here’s how to work the conference like a security professional–and how to make sure your org survives the week you spend doing it.
Why Security Should Set Your Agenda This Year
The agentic-enterprise pitch is a pitch to give software more autonomy over your CRM data. That makes this the highest-leverage Dreamforce in years for security teams–the governance patterns being announced now will be the defaults everyone inherits later. Three threads worth following across the week:
- Agent governance is maturing fast. Security Center’s Agentforce-powered anomaly investigation is in beta with Winter ’27, User Access Management improvements keep appearing in Sneak Peeks, and the enterprise harness underneath Claudeforce (hosted MCP, External Client Apps, permission-scoped dispatch) is the architecture every vendor will be copying.
- The Claudeforce open beta is landing now. Expect stage time, expect your executives to come home wanting it, and expect the “connect once, scoped to each user’s permissions” pitch. Your pre-beta permission audit is the homework to finish before the keynote convinces someone to skip it.
- The security track is worth planning around. The full Trust & Security catalog drops with the session builder, but last year’s programming is a reliable preview: a Trust & Security Zone with hands-on demos, Circles of Success on Agentforce guardrails, executive roundtables on AI risk, and the Secure the ’Force capture-the-flag–which added Agentforce challenges last year and is the single best hour of security education on the schedule.
Can’t travel? Keynotes and selected sessions stream free on Salesforce+, and the governance announcements will all be there.
Deeper Dive
Build a Security Agenda, Not a Souvenir Agenda
- Prioritize roundtables and hands-on training over recorded content. Breakout recordings hit Salesforce+ later; the 240+ roundtables and 150+ hands-on trainings don’t. Spend your in-person hours where the format requires it.
- Go to True to the Core. It remains the one session where product leadership answers unfiltered questions–and permission model gaps, audit tooling, and agent governance questions belong there.
- Hit Sneak Peeks for User Access Management. Unreleased UAM and agent-governance features preview here first, and they’re the roadmap for next year’s audits.
- Play the CTF. Secure the ’Force runs in a real trial org and teaches attacker-perspective thinking you can’t get from slides. Bring your admins.
Five Questions for Every AI Vendor on the Expo Floor
The expo floor will be wall-to-wall agents. Before any of them touches your org, make the booth staff answer these:
- Which identity does your integration run as–per-user OAuth or a shared integration user–and what does attribution look like in my logs?
- What OAuth scopes do you request, and what are your token lifetimes and refresh policies?
- What data do you copy out of (or into) my org, and how long do you retain it? Synced transcripts and cached records are breach inventory sitting outside your controls.
- Can I see a per-action audit trail of everything your agent did, and can I export it?
- What’s the shutdown story? If I need you gone in five minutes, what do I deactivate, and what happens to my data afterward?
A vendor who can’t answer these crisply at Dreamforce won’t answer them better during your incident.
Protect the Org You Left Behind
Conference weeks are social-engineering season. Attackers know exactly where your admins are September 15-17, and the vishing playbook we’ve covered all year thrives on it:
- Pre-brief the help desk. “I’m at Dreamforce, locked out, and about to meet a customer–just reset my MFA” is the pretext of the week. Identity verification procedures get zero exceptions, especially for admins and executives, especially this week.
- Freeze high-risk changes. No new connected apps, no auth-config changes, no permission grants approved from a conference hallway. If it can wait until the 18th, it waits.
- Watch for conference-themed phishing. Fake session-scheduler logins, party invites, badge QR codes, and “your Dreamforce receipt” emails all spike this month. Remind the whole company, not just attendees.
- Travel like a target. Hardware keys and passkeys work great on the road; hotel and expo Wi-Fi deserve a VPN; and the person reviewing your anomaly alerts should be someone who stayed home.
Mind the Winter ’27 Collision
Winter ’27 production upgrades run September 4 through October 9–which means some orgs upgrade the very weekend of Dreamforce. Before you fly:
- Look up your instance’s exact upgrade date on Salesforce Trust. “October for most orgs” is not a plan.
- If your date falls in conference week, finish your preview-sandbox testing of the auth-layer changes–instanced URL retirement and profile-visibility lockdown fail silently–before you pack.
- Open Setup > Release Updates and confirm nothing enforces while the people who’d notice are in a keynote.
The Bottom Line
Dreamforce 2026 will be three days of demos arguing that agents deserve more access to your data. Go, learn, and enjoy it–but walk the floor asking who each agent runs as, what it retains, and how it shuts off, and leave your org locked while you do. The agentic enterprise is coming either way; the orgs that thrive will be the ones that showed up with a security agenda instead of inheriting someone else’s defaults.
Book a 15-Minute Security Strategy Call
Reference(s):
https://www.salesforce.com/dreamforce/
https://www.salesforce.com/blog/dreamforce-agenda-schedule/
https://www.salesforce.com/blog/trust-security-at-dreamforce-2025/
https://admin.salesforce.com/blog/2026/salesforce-admins-guide-to-dreamforce-2026