AI Articles CRM Salesforce

What is Claudeforce? Salesforce architecture explained

2 September 2026

Salesforce presents Claudeforce as an expanded partnership between Salesforce and Anthropic encompassing multiple products and integrations rather than as a single standalone product. Announced in August 2026, the partnership brings Claude’s reasoning together with Salesforce data, workflows, business logic, actions, and governance.

Its launch product is Salesforce in Claude. Salesforce says the experience is enabled by AIforce, its trusted enterprise harness for making business data and workflows available to agents through MCP servers, APIs, and CLI tools. Headless 360 is part of this broader agent-accessible Salesforce approach, alongside capabilities including Data 360, Tableau, and Slack.

For Salesforce professionals, the important question is therefore not only “what is Claudeforce?” It is how Salesforce in Claude, AIforce, Headless 360, Model Context Protocol (MCP), Agentforce, Data 360, MuleSoft, Slack, and Salesforce security fit together. This article explains how those components connect and what that means in practice.

Table of contents

What is Claudeforce?

Claudeforce is the name Salesforce and Anthropic are using for their expanded strategic partnership. Salesforce describes it as bringing Claude’s intelligence and reasoning together with Salesforce data, workflows, business logic, actions, and governance. The first announced product is Salesforce in Claude, a Claude plugin with 37 prebuilt sales skills.

Those skills are designed for work such as meeting preparation, deal health reviews, pipeline reviews, and governed updates to Salesforce. Salesforce says actions are routed through Salesforce so that existing business rules and permissions continue to apply.

Salesforce in Claude is currently available to selected pilot customers. Salesforce plans to open the beta more broadly in September 2026, but has not yet announced a specific launch date. Additional prebuilt capabilities are planned later in 2026. The sections below therefore distinguish between capabilities Salesforce already documents and the broader direction announced for Claudeforce.

Claudeforce architecture at a glance

Salesforce says Salesforce in Claude is made possible by AIforce, its trusted enterprise harness for connecting business data and workflows with agents through MCP servers, APIs, and CLI tools. Headless 360 is part of this broader approach, making Salesforce capabilities accessible to authorised AI agents without requiring every interaction to begin in a traditional Salesforce application interface.

The exact request path depends on the Salesforce products, Hosted MCP Servers, tools, data sources, integrations, and permissions configured by an organisation. Claude may interact with Salesforce data and automation through Hosted MCP Servers, invoke configured Agentforce capabilities, use Data 360 context, access Tableau analytics, or interact with external systems through integration tools such as MuleSoft.

Salesforce in Claude: reasoning and interaction

Salesforce in Claude provides a Claude-based user experience for working with Salesforce context and capabilities. A user can ask a question or request an action in natural language, while Claude reasons over the request and selects from the tools and capabilities that have been made available to it.

That does not mean Claude replaces Salesforce logic. Salesforce in Claude is designed to use live enterprise context and route governed actions through Salesforce. Salesforce remains responsible for CRM records, workflows, permissions, validation rules, and other business logic behind authorised actions.

MCP: connecting Claude to Salesforce

Model Context Protocol, or MCP, is an open protocol for connecting compatible AI clients with tools and capabilities. Salesforce Hosted MCP Servers allow clients such as Claude to connect to a Salesforce org through OAuth-based authentication and interact with Salesforce data and automation on behalf of an authorised user.

Salesforce documents Hosted MCP capabilities for reading, creating, updating, and deleting records, running supported data operations, invoking configured custom tools based on technologies such as Apex and Flow, querying Data 360, accessing Tableau analytics, using Prompt Builder templates, and exposing eligible Agentforce agents as tools.

For standard Hosted MCP operations, the authenticated user’s Salesforce permissions continue to apply. These include object permissions, field-level security, and record-sharing rules. Connecting an AI client does not automatically give that client broader access to Salesforce data.

Salesforce and Agentforce: business logic and specialised agents

Salesforce remains the system of record and business platform. CRM objects, Flow, Apex, prompt templates, and other Salesforce capabilities provide data, deterministic logic, and authorised actions that external AI clients can use when those capabilities are exposed.

Agentforce adds specialised Salesforce-native agents. Where configured, Salesforce allows eligible Agentforce agents to be exposed as MCP tools. Salesforce currently specifies that only agents created with the new Agent Script Builder can be exposed this way. Legacy agents must be upgraded before they can be used with custom MCP servers.

Agentforce agents and Prompt Builder templates are not automatically available to an external assistant. An administrator must configure and publish them as tools through an appropriate MCP server.

When those tools are available, Claude can select and invoke a configured Agentforce MCP tool when its name and description match the user’s request. Salesforce notes that external models use this tool metadata when deciding which tool to call, which makes clear and precise tool names and descriptions important.

Data 360: enterprise context

The quality of agent responses depends heavily on the quality and relevance of the context available to them. Data 360 is Salesforce’s data platform for unifying and activating enterprise data across CRM, external platforms, and unstructured sources.

Data 360 can provide governed enterprise data, profile and context services, and structured or unstructured retrieval capabilities that organisations can use to ground agentic applications. The exact context available to an agent depends on the organisation’s data architecture and configured tools.

Data 360 also supports interoperability with platforms such as Snowflake, Databricks, BigQuery, and Redshift. Federation and zero-copy patterns can make external data available without requiring every dataset to be duplicated inside Salesforce.

MuleSoft: connecting external systems

MuleSoft and MCP address different integration needs. MCP standardises how compatible AI clients discover and invoke available tools and capabilities. MuleSoft provides broader enterprise integration across APIs, applications, workflows, databases, and external systems.

For example, MuleSoft can connect Salesforce and Agentforce with ERP, finance, HR, legacy applications, and third-party APIs. The two technologies can work together, but MuleSoft is not the only possible route to an external system and not every Claudeforce request requires MuleSoft.

MCP MuleSoft
Primary role Connect AI clients to tools and capabilities Integrate systems, APIs, and workflows
Typical connection Claude → Salesforce capability Salesforce/Agentforce → external enterprise system

Slack: human and agent collaboration

Salesforce positions Slack as an engagement layer where people, agents, connected tools, and Salesforce capabilities can work together through conversation.

Salesforce has also documented how Slackbot can use Salesforce Hosted MCP Servers to work with Salesforce business context. In its August 2026 Claudeforce announcement, Salesforce describes Claude as the AI model powering Slackbot for Salesforce customers and employees. Salesforce also says Claude is the default model for Slack AI, Slackbot, Salesforce in Claude, Headless 360, and Agentforce Coworker, while remaining available as a reasoning model in Agentforce and Agent Builder.

That makes Slack relevant to the broader Claudeforce partnership, but it does not mean every Slack interaction follows the same technical path. Product availability, model choices, packaging, and implementation can vary.

Trust, security and governance

Security and governance depend on the Salesforce capability and tool being used. Salesforce Hosted MCP Servers use per-user authentication, and standard Hosted MCP calls operate within the authenticated user’s Salesforce permissions.

  • OAuth-based authentication
  • Object-level permissions
  • Field-level security
  • Record-sharing rules
  • Permission sets and least-privilege access
  • Tool-level configuration and controls
  • Hosted-server observability and request-level telemetry where supported

Additional safeguards depend on the tool type. Salesforce documents that configured Agentforce agents and Prompt Builder templates execute in the authenticated user’s context and can also apply relevant Einstein Trust Layer policies. This should not be interpreted to mean that every MCP tool call automatically receives the same generative-AI safeguards.

The practical rule is that standard Hosted MCP operations remain constrained by the authenticated user’s Salesforce permissions. If a user does not have access to a Salesforce record or field, connecting an AI client through a standard Hosted MCP operation does not give that client broader access.

How a Claudeforce request works

Consider a sales leader asking Claude: “Which opportunities are most at risk this quarter, and create follow-up tasks for their owners?”

  1. Ask: The user gives Claude the request in natural language.
  2. Reason: Claude interprets the goal and determines which available Salesforce context, capabilities, and tools may be relevant.
  3. Connect: Claude can use configured Salesforce Hosted MCP Servers and other supported interfaces to access Salesforce capabilities that the authenticated user is permitted to use.
  4. Retrieve context: Salesforce and, where relevant, Data 360 can provide opportunity, account, activity, and other configured enterprise context.
  5. Select a tool: Claude can use an available Salesforce tool directly or select a configured Agentforce MCP tool based on the tool metadata exposed to the model.
  6. Act: Salesforce Flow, Apex, Agentforce actions, or integrated systems can execute the permitted business action.
  7. Respond: Claude returns the result to the user. Applicable Salesforce identity, permissions, sharing rules, business logic, security controls, and hosted-server observability remain in effect. The exact logging, telemetry, and approval behaviour depends on the configured tools, Salesforce products, and client experience.

Claudeforce architecture cheat sheet

Component Role
Claude Reasoning and user interaction
Salesforce in Claude Claude experience with prebuilt Salesforce sales capabilities
AIforce Salesforce’s trusted enterprise harness for connecting business data and workflows with agents through MCP servers, APIs, and CLI tools
MCP Open protocol for AI-to-tool connections
Headless 360 Part of Salesforce’s headless approach for making governed Salesforce capabilities accessible to authorised agents
Salesforce CRM data, business logic, automation, and actions
Agentforce Specialised Salesforce-native agents that can be exposed as tools when eligible and configured
Data 360 Governed enterprise data and context for analytics and agentic applications
Tableau Analytics capabilities that can be surfaced through Salesforce’s MCP-enabled experiences
MuleSoft APIs and external system integration
Slack Conversational engagement layer for people, agents, and connected capabilities
Governance Identity, permissions, security, tool controls, and applicable observability

What Claudeforce means for Salesforce professionals

Claudeforce does not make existing Salesforce architecture skills less relevant. It makes the connections between data, permissions, automation, integration, agent design, and external AI access more visible.

  • MCP becomes a useful skill for understanding how external AI clients can access Salesforce capabilities through governed interfaces.
  • Claude and Agentforce play different roles. Claude can reason across a request, while configured Agentforce agents can provide specialised Salesforce-native capabilities.
  • Tool design matters because external models rely on tool names and descriptions when selecting which MCP capabilities to invoke.
  • Data architecture matters because agent quality depends on the context that can be retrieved, trusted, and interpreted.
  • MuleSoft remains relevant when work must cross Salesforce boundaries into external systems and APIs.
  • Permissions, exposed tools, observability, and human approval patterns affect what an AI client can access and safely do.

What this means for Salesforce admins

For Salesforce admins, the immediate relevance is less about learning the 37 sales skills themselves and more about understanding the configuration behind AI access.

In practice, organisations adopting Salesforce Hosted MCP Servers should expect Salesforce admins, developers, architects, and security teams to participate in areas such as:

  • Configuring access to Salesforce Hosted MCP Servers and approved external AI clients.
  • Managing External Client Apps, OAuth access, permission sets, and least-privilege policies.
  • Deciding which data, tools, Flow or Apex capabilities, Prompt Builder templates, and eligible Agentforce agents are exposed.
  • Writing clear tool names and descriptions so external AI models can select the correct MCP tools.
  • Maintaining CRM data quality and business rules so agents work with reliable context.
  • Testing AI access across different user roles, permissions, and edge cases.
  • Reviewing available observability and telemetry and deciding where human confirmation or approval is appropriate.

Salesforce frames the broader direction with the phrase “the UI is the AI.” The idea is that agents can access approved Salesforce data, workflows, and rules through governed interfaces rather than requiring every task to begin in a conventional application screen. This does not mean the traditional Salesforce UI disappears, but it does make the configuration and governance behind AI access more relevant for Salesforce professionals.

What Claudeforce does not mean

  • Claude does not automatically receive access to every Salesforce record or capability.
  • Agentforce is not replaced by Claude. Eligible and explicitly configured Agentforce agents can be exposed as MCP tools that external assistants such as Claude can invoke.
  • Agentforce agents and Prompt Builder templates are not automatically exposed to external AI clients.
  • MCP does not replace MuleSoft. They address different integration needs and can be used together.
  • Headless 360 should not be interpreted as the only technical layer behind every Salesforce in Claude interaction.
  • Not every MCP tool call automatically receives identical Einstein Trust Layer safeguards.
  • Not every announced Claudeforce capability is generally available today.
  • A successful implementation still depends on configuration, data quality, permissions, integrations, tool design, and governance.

Conclusion

So, what is Claudeforce? Salesforce presents it as the expanded strategic partnership between Salesforce and Anthropic, connecting Claude’s reasoning with Salesforce data, workflows, business logic, actions, and enterprise controls.

Salesforce in Claude is the partnership’s launch product. Salesforce says it is made possible by AIforce, with MCP servers, APIs, CLI tools, Headless 360, Data 360, Tableau, Slack, Agentforce, and Salesforce’s existing security model contributing different capabilities across the wider ecosystem.

For Salesforce professionals, the useful lesson is how these components can work together without assuming that every implementation follows one fixed technical architecture. For Salesforce admins in particular, external AI access introduces practical considerations around authentication, permissions, tool exposure, data quality, testing, and observability.

Sources

Popular Salesforce courses

Enhance your skills with our most popular training courses and certifications.

Your Cart (0)

Your cart is empty

Looks like you haven't added any items to your cart yet.