Claude works with Salesforce in three main ways: as a model that Agentforce itself can run on, as an assistant your people use that reaches Salesforce through MCP connections, and as a model your own integration calls through Anthropic's API. None of these replaces Agentforce. Agentforce is Salesforce's platform for agents that act inside the CRM under its permissions and Trust Layer, while Claude is a model and an assistant. The useful question is which work belongs on which path, and what data each path may touch.
The ways Claude and Salesforce connect
Claude models have been available in Salesforce since 2024, and in August 2026 Salesforce and Anthropic announced an expanded partnership under the name Claudeforce. That announcement bundled several things that are easy to blur together, so it helps to separate them by where the AI runs and who configures it.
| Path | How it works | Who configures it | Typical use |
|---|---|---|---|
| Claude inside Agentforce | Claude models are selectable in prompt templates and Agentforce Builder, and Salesforce says Claude serves as a reasoning model for the Atlas Reasoning Engine; traffic stays inside the Salesforce trust boundary | Salesforce admins and Agentforce builders | Agents and prompt templates that run in the org, for employees or customers |
| Claude connected through hosted MCP servers | Claude acts as an MCP client and calls Salesforce-hosted MCP servers, which run every request as the signed-in user | Salesforce admin plus whoever manages Claude for your company | Questions, analysis and approved updates from inside Claude |
| Salesforce in Claude | A plugin announced in August 2026 with prebuilt sales skills such as meeting prep, deal health review and pipeline review; it began as a pilot in August 2026 and opened in beta on all paid Claude plans on September 15, 2026, during Dreamforce, where Salesforce grouped it with Slackforce in Slack and Agentforce Coworker in Salesforce under its AIforce banner | One admin connection with central authentication and permissions | Seller preparation and pipeline work |
| Custom integration through the API | Your own middleware reads Salesforce data through its APIs, sends it to Claude, and writes structured results back | Your developers or a partner | Scheduled or high-volume jobs with fixed inputs and outputs |
Availability differs by path, and the Salesforce in Claude plugin is still in beta, so confirm what your org and your Claude plan can use today before you design around it.
Alongside Agentforce, not instead of it
Choosing Claude does not mean choosing against Salesforce's AI, because Claude is one of the models Agentforce runs on. The real split is between work that should happen inside the CRM and work that happens in an assistant a person already uses all day.
Agentforce is the better home for anything customer-facing, anything that must follow a defined set of subagents and actions, and anything that needs Salesforce's audit, masking and monitoring around it. A service agent answering customers on your website belongs there. So does an internal agent that updates opportunities through approved Flows.
Claude used directly is stronger when a person is thinking rather than processing: pulling together a view that spans Salesforce and other systems, working through an ambiguous question in several steps, or drafting something long that needs judgment. A sales leader asking which late-stage deals have gone quiet, and why, then turning the answer into a plan for Monday's pipeline meeting, is a good example. That work rarely fits a predefined subagent.
Four patterns that work well
- Summaries: condense an account history, a long case thread or a quarter of activity into what the reader needs before a meeting or handoff.
- Drafting: prepare follow-up emails, internal updates, recognition notes or account plans that a person edits and sends.
- Document understanding: read contracts, call transcripts, PDFs and emails, then extract structured fields or scores that can be stored on a record.
- Analysis: review pipeline aging, slipping close dates, coverage and forecast quality, and turn the findings into ranked recommendations.
A payments company we worked with used Claude for drafting and for decision support. A recurring workflow called Daily Wins reviews Salesforce activity, picks out contributions worth recognizing, checks attribution and whether someone was already recognized, and drafts messages for leadership; a person reviews and posts every one. A second workflow turned leadership's existing way of evaluating deals into something repeatable, organizing terms and comparing tradeoffs before vendor and partner discussions, while leaving legal and financial review with the people responsible for it.
For document understanding, Abstrakt Marketing Group, where our team first built out Salesforce and today a client, uses Claude to compare sales calls with each account's approved talk track, covering introductions, recaps, closing and objection handling, so managers can see where conversations drift from the agreed approach and coach to it. That reporting went live in July 2026 as part of a phased rollout that began in May.
In both cases Claude prepares the material and a person makes the call. Build that division of labor in from the first workflow, and treat any later step where Claude changes records as a separate, narrowly scoped and logged project.
Security and data handling
The data questions change depending on the path. Inside Agentforce, the Einstein Trust Layer applies its grounding, masking and toxicity checks, and Salesforce states that Claude traffic stays inside its trust boundary. When Claude connects from outside, the controls come from Salesforce permissions on one side and your agreement with Anthropic on the other.
| Question | Claude inside Agentforce | Claude through MCP or the API |
|---|---|---|
| Whose permissions apply? | The agent user or the running user, as configured in the org | The authenticated Salesforce user for hosted MCP; the integration user for custom API work |
| Where does data go? | Stays within the Salesforce trust boundary | Leaves Salesforce for Claude under your Anthropic commercial terms |
| How long is it kept? | Governed by Salesforce and your org settings | API inputs and outputs are deleted within 30 days by default; zero data retention needs a separate agreement |
| Who can see what the AI did? | Salesforce audit and feedback data | The admin tools in your Claude plan plus whatever your integration records |
- Create a dedicated permission set for MCP access and pre-authorize only the users who need it through the External Client App policy.
- Activate only the hosted MCP servers you plan to use; Salesforce ships them inactive.
- Decide which fields must never leave Salesforce, such as health, financial or government identifiers, and keep them out of scope for external paths.
- Keep reading and writing separate, and require a person to approve each write until the workflow has earned more trust.
- Have legal review Anthropic's commercial terms on retention and training for the Claude products you use.
- Name one owner for each workflow and record what it reads, what it may change, and how its output is checked.
Where to start
Pick one team and one recurring task that currently eats senior time, such as weekly pipeline review or pre-meeting account research. Run it read-only for a few weeks, compare Claude's output with what the team would have produced, and fix the data problems it exposes, because stale close dates and missing contacts will show up quickly in any summary. If the output holds up, add a drafting step with human review, and consider write access last.
If you already run Agentforce, look at which requests your agents decline or hand off. Some of those are better served by Claude working with an employee than by widening an agent's scope, and the reverse is true for repeatable tasks people are doing by hand in Claude. As a Salesforce Consulting Partner since 2017 with 150 Salesforce certifications, we help teams make that split and build both sides.

