Tython

SalesforceSecurity

Dreamforce 2026 Recap: Your Permission Model Is Now the Product

Scott Covert · 

Dreamforce 2026 wrapped Thursday: 43,000 attendees, three days of keynotes, and one product that reframes everything else–AIforce, a “live interface layer” that puts your Salesforce data, workflows, and permissions behind any AI surface your company uses. Last week we published a security playbook for working the conference; three weeks ago we argued that Claudeforce makes your permissions your AI guardrails. Dreamforce confirmed that thesis and then raised the stakes: permissions aren’t just your guardrails anymore. They’re the product Salesforce is selling. Here’s what was announced, what it means for your org’s security posture, and what deserves a spot on your calendar before the Salesforce+ recordings blur together.

The Announcements That Matter to Security Teams

  • AIforce is the headline. One admin connection exposes Salesforce to three launch interfaces–Claudeforce (Anthropic’s Claude, now in open beta), Slackforce, and Agentforce Coworker–with every request scoped to the requesting user’s existing permissions and business rules, under a zero-data-retention arrangement with the model providers. The pitch is “no new permissions model, no migration, no custom integration.” Read that again as a security engineer: the permission model you already have is the only control standing between your CRM and every AI interface in the building.
  • Salesforce Guardian and the Enterprise AI Harness. Salesforce consolidated six products–Informatica, Data 360, Tableau, Guardian, MuleSoft Agent Fabric, and Agentforce Studio–into a unified AI control plane. Guardian is the security layer: data protection, governance, and agent identity controls. Agent Fabric is the registry and monitoring surface for your digital workforce. This is the governance tooling we’ve been saying the agentic enterprise would need; now it exists, and it’s on you to actually turn it on.
  • Seven prebuilt agents, “configurable without IT involvement.” Casey, Fin, Paige, Carter, Hunter, Marshall, and Piper ship embedded across the CRM, aimed squarely at business teams. Hunter (sales pipeline automation) goes GA in November. “Without IT involvement” is the phrase to sit with–it’s also without security involvement unless you build the review process first.
  • The security keynote delivered a coherent frame. “Trust Across Agents, Data, and Platforms” organized the week’s 30+ security sessions around governing agents as identities: who an agent runs as, what it can touch, and how you monitor it. The breakouts are on Salesforce+ and worth your commute time–particularly the admin security fundamentals and security roadmap sessions.
  • Partnerships widen the perimeter. AWS and Salesforce demoed secure agent-to-agent voice handoffs between Amazon Connect and Agentforce Voice (launching this fall), and the Google Cloud expansion puts Salesforce data inside Gemini Enterprise. Every one of these is a new trust boundary between systems that each have their own identity and logging story.

One more note from conference week itself: Salesforce suffered a multi-instance outage on September 16 traced to an external dependency of its legacy login server–a timely reminder, mid-agentic-enterprise-keynote, that availability and dependency risk are still part of the trust conversation.

Deeper Dive

AIforce: The Feature and the Finding Are the Same Sentence

Every AIforce marketing sentence doubles as a security assessment finding, depending on the state of your org:

  • “Runs entirely within your existing permissions” is a guarantee only as good as those permissions. If your permission audit is clean, AIforce inherits that hygiene. If your org carries fifteen years of accumulated profile sprawl, over-broad permission sets, and “temporary” View All Data grants, every AI interface now inherits that instead–and surfaces it conversationally, to anyone who asks nicely.
  • “Agents can read across hundreds of records simultaneously” means the blast radius of one over-permissioned user is no longer bounded by what they’d realistically click through. Scale is the difference between a sharing-model imperfection and a bulk-exfiltration path.
  • “A single connection, no new integration work” means enablement will be easy and fast. Easy and fast is exactly how security review gets skipped. The window to finish the permission audit we prescribed in the Claudeforce post is closing–open beta means your executives can start the clock without you.

Anthropic’s framing at the conference–users authenticate with their own credentials, and Claude only sees what the person is allowed to see–is the right architecture. It’s also a precise description of where the responsibility now sits: with what the person is allowed to see. That’s yours.

Guardian and Agent Fabric: The Audit Program for Your Digital Workforce

The Enterprise AI Harness answers a question we’ve been raising all year: when agents proliferate, who keeps the inventory? Concretely, plan an evaluation this quarter:

  1. Stand up the agent registry. MuleSoft Agent Fabric is positioned as the system of record for every agent operating against your data. If an agent isn’t in the registry, it shouldn’t have credentials–make that a policy statement now, while the agent count is small.
  2. Map Guardian’s controls to your existing framework. Agent identity constraints, data protection policies, and governance rules need owners, review cadences, and alert routing–the same treatment you give Security Center policies today.
  3. Demand per-action audit trails. The expo-floor questions from last week’s playbook apply to Salesforce’s own agents too: which identity did the agent act as, what did it touch, and can you export the evidence?

The Seven Named Agents: Shadow AI, Now with First-Party Branding

Prebuilt agents configurable by business teams are the same governance challenge as unsanctioned SaaS, minus the procurement speed bump that used to give security a chance to intervene. Before Hunter’s November GA:

  1. Inventory which of the seven agents your business units are likely to activate, and find out who owns the decision.
  2. Define the minimum review for activation: which user or agent identity it runs as, which objects it can touch, where its actions land in Event Monitoring.
  3. Decide the escalation path now for an agent that misbehaves–deactivation authority during an incident should not be a novel question.

While You Were at Moscone: The September 30 Cliff

A deadline that didn’t get keynote time: all Marketing Cloud API client secrets–regardless of age–expire September 30, 2026, under the new 180-day rotation policy. Integrations that miss the rotation fail silently: API authentication errors, stopped triggered sends, skipped nightly syncs, web forms that stop adding subscribers. If your team spent this week in San Francisco, the twelve days left are fewer than they sound. Rotate now, and put the 180-day cadence on the calendar while you’re in there.

The Bottom Line

Dreamforce 2026 made the agentic enterprise concrete: one connection, many interfaces, your permission model enforcing all of it. That’s a better architecture than the alternative–but it promotes permission hygiene from best practice to the load-bearing wall of your AI security posture. Finish the audit, stand up the agent registry, gate the prebuilt agents, and rotate those Marketing Cloud secrets before the 30th. The vendors went home; the defaults they announced are yours to set.

Book a 15-Minute Security Strategy Call

Reference(s):

https://www.salesforce.com/blog/trust-security-at-dreamforce-2026/

https://www.salesforce.com/news/dreamforce-26-media-resources/

https://www.unite.ai/salesforce-unveils-aiforce-live-interface-layer-at-dreamforce/

https://cxfoundation.com/news/dreamforce-announcements-2026

https://www.mavlers.com/blog/what-are-the-security-changes-in-salesforce-marketing-cloud/