What is Salesforce in Claude, and what opened on 15 September?

On 15 September 2026, as Dreamforce opened in San Francisco, Salesforce opened the beta of the connector that brings its CRM inside Claude, which the vendor presents as available to all its customers, subject to the edition requirement set out below. Anthropic added it to its release notes the same day, for every paid Claude plan, with a sign-up that Salesforce has to approve. The partnership behind it, branded Claudeforce, had been announced on 26 August.

Salesforce in Claude is a plugin that gives Claude direct access to the accounts, opportunities and pipeline of a Salesforce org, with 37 prebuilt sales skills. A seller can prepare a meeting, review a deal or update a record from the conversation, without opening the CRM interface and within the limits of their own permissions.

The skills cover a sales team’s working day: account research, call preparation, pipeline review and CRM updates. Under the hood, the connection runs through a Model Context Protocol (MCP) connector. Eligibility is limited to organisations with access to the latest Sales Cloud enterprise edition, and setting it up takes two admins. A Salesforce admin requests access and configures the CRM side, then an Owner of the Claude organisation distributes the plugin, to everyone or to selected groups, and enters the connector credentials. Each user then signs in with their own Salesforce account.

What else Salesforce showed at Dreamforce

The connector is part of a wider layer Salesforce calls AIforce, summed up on stage as “AI replaces the UI”: CRM data, business rules and access rights become reachable from any AI interface. Claudeforce is one building block, alongside Slackforce (the CRM inside Slack), Agentforce Coworker (an assistant built into the Lightning interface) and a headless toolkit that exposes the platform through MCP servers, APIs, plugins and developer tools. In the other direction, the August announcement made Claude the default model for Agentforce Coworker.

Salesforce in Claude or Agentforce: what is the difference?

Both products run on Claude, but in different places. Agentforce Coworker lives inside the Lightning interface: users stay in Salesforce and the assistant helps with the record in front of them. Salesforce in Claude works the other way round. Users work in Claude, where they write, analyse and prepare, and pull in the CRM when they need it. The first suits teams whose day already runs in Salesforce. The second targets people who use Claude as their main workspace and check the CRM only now and then. One company can open both, and that is exactly what makes governance harder: two access paths to the same data, one administered on the Salesforce side, the other on the Claude side.

Adecco, a large-scale rollout announced the same day

Also on 15 September, the Adecco Group announced it was moving 27,000 employees in more than 40 countries onto Agentforce Coworker, which its press release describes as “powered by Anthropic’s Claude”. The pilot ran in the UK and France. Recruiters use it to shortlist candidates and launch pre-screening or onboarding agents, while sales staff prepare their briefs. The group reports strong adoption within days. Separately, the tool draws on more than 2.5 million agent-candidate interactions accumulated since April 2025. Anthropic, for its part, names GitLab, Siemens and Legora among the organisations already using Salesforce in Claude.

What does the beta change for a European enterprise?

The place where work happens is moving. Until now, vendors added AI to their own screens. Here the direction flips: the seller stays in Claude and the CRM becomes a source the assistant queries and updates. Salesforce remains the system of record, yet it may no longer be where users spend their day. For a CIO, the consequences land on governance far more than on architecture.

The decision to switch it on can be taken outside IT

The rollout rests on two admins, and neither necessarily reports to IT. Salesforce administration may sit with a sales operations team under the commercial function, and the Owner role in the Claude organisation sometimes belongs to whichever team led the first Claude rollout. Who is allowed to approve the rollout has to be settled before anyone requests access. Otherwise a generative AI tool reaches production through the CRM, bypassing the committee that normally signs off on that kind of use.

Your permission model becomes the security boundary

Salesforce is clear on this point: Claude sees only what a given user is authorised to see and can do only what that user is authorised to do. That is reassuring. It also puts the whole risk on the quality of the permission model already in place. Long-lived Salesforce orgs accumulate over-broad profiles, permission sets granted for a project and never revoked, and sharing rules opened for convenience. While users clicked from screen to screen, that excess stayed mostly out of sight. An assistant that can query, in plain language, everything an account is able to read makes excess access usable in a single question. A review of profiles and sharing rules is the prerequisite for this beta.

Write actions need a written rule

By default, Claude asks the user to approve each proposed change before writing it, and each user can relax that setting afterwards. Left to individual judgement, that relaxation will produce very different practices from one seller to the next. It is better to decide up front which objects and fields the assistant may change on its own, which require confirmation, and which stay out of reach: opportunity amount and stage, the forecast submitted to leadership, contact data covered by the GDPR.

Where does CRM data go when a seller queries it from Claude?

Salesforce states that AIforce products run with zero data retention at the model provider. The Claudeforce page adds that this option is available on the Sonnet, Opus and Haiku models. Anthropic is rolling out its Enterprise Frontier Safeguards, with customer-controlled encryption and audit logging, in phases, and targets broad availability by the end of autumn 2026. These are vendor statements, and they need to appear in your contracts before you rely on them.

The two directions of the integration do not follow the same path. When Claude works inside Agentforce, it runs within the Salesforce trust boundary through Amazon Bedrock. When the CRM is queried from Claude, records flow into a Claude conversation, and your Claude subscription terms govern how they are handled: retention, logging and data location. A legal team that has cleared one path has not yet cleared the other, which matters for any DPO working under the GDPR.

Which questions should be settled before opening the beta?

Before signing up, you need to know who approves the rollout, which permissions the assistant will inherit, which records it may write on its own, which contract covers the data and how usage will be tracked. The answers fit on one page and spare you discovering the real scope after the fact.

  1. Who approves the rollout? Name the decision owner, IT or the AI committee, and brief both control points: the Salesforce admin who requests access and the Claude organisation Owner who distributes the plugin.
  2. Are profiles clean? Review profiles, permission sets and sharing rules for the target users, starting with the broadest accounts.
  3. Which writes are allowed? Sort objects and fields into free edit, confirmed edit and read only.
  4. Which contract covers the data? Check the Claude plan in use, the retention that applies and the logging available.
  5. How will usage be measured? Pick a handful of tracking indicators and have them running from day one.

This checklist maps onto the trust zones of our LOOP™ AI governance methodology: reading an account sits in the Green zone, updating a forecast in the Orange zone with human validation, and some actions stay in the Black zone. The same grid applies when an agent drives a screen rather than an API, as we set out in our analysis of computer use versus API integration for AI agents.

Does agent-assisted recruitment fall under the EU AI Act?

The Adecco case shows one agent platform serving both sales and recruitment. Annex III of the EU AI Act lists as high-risk the systems intended for recruiting or selecting candidates, in particular to filter applications and evaluate people. A pre-screening agent can therefore fall under the high-risk regime, where a sales assistant generally does not. The related obligations were pushed back to 2 December 2027 by the digital omnibus, which we cover in our piece on the EU AI Act timeline after the delay.

The delay buys time to build an inventory calmly. It does not remove the need to know which uses are already running: a connector opened to sales in September can serve HR by spring, on the same infrastructure and with the same admins. Our page on EU AI Act compliance for enterprises covers use-case classification and the documentation expected.

Measure real usage before widening the scope

On 10 September Anthropic opened usage reports in beta on Enterprise plans. They describe the work done, costs, friction points in sessions and repeated patterns worth packaging as shared skills. These reports let you judge a beta on evidence rather than impressions. According to Deloitte (State of AI in the Enterprise, 2026 edition), only 21% of organisations have a mature governance model for their AI agents, and Gartner expects over 40% of agentic AI projects to be cancelled by the end of 2027 because of escalating costs, unclear business value or inadequate risk controls.

What the beta does not tell you yet

No pricing has been disclosed for the connector, skills beyond sales are announced for later in the year, and a beta can change scope before general availability. Any governance rule written today should carry a date and be reviewed when the beta ends.

Our view: the interface moves, the system of record stays

At Koneetiv, a pure player and official Anthropic partner, we read this beta as good news for companies that have invested in a clean CRM, and as a stress test for everyone else. On a poorly maintained database, the assistant speeds up access to duplicates and over-broad rights as much as to good data. The connector’s value depends almost entirely on the data quality and permission model it finds when it arrives.

We advise opening the beta to a limited group, with written write rules and usage tracking in place from the start, then widening based on what you observe. It is the approach we apply to every Claude agent in the enterprise and, more broadly, to AI agents in production. For groups that want an outside view on this groundwork, our Claude integration partner page describes how we work.

Before opening the beta, benchmark where your organisation stands: the AI maturity assessment, built on the Koneetiv framework (2026 edition), measures your governance, data and tooling in a few minutes, agentic readiness included.