Salesforce's Winter '27 release reaches production orgs over several weekends, with the main wave on October 9 and 10, 2026. For admins, two enforced release updates need a check: profile filtering, and a requirement that users and integrations signing in through SOAP API login() hold the Use Any API Auth permission. A new View Setup Audit Trail permission also arrives, with enforcement planned for Spring '27. Several optional features are worth switching on, including field history tracking on the User object and more flexible list view editing. For business owners, the headline changes are in Agentforce, Slack and Tableau, and most of them are opt-in, though enforced release updates take effect automatically.
When does Winter '27 reach your org?
Salesforce upgrades orgs in waves. Preview instances moved to Winter '27 at the end of August 2026; most production instances upgrade on October 9 and 10, 2026, with other waves on surrounding weekends. Check Salesforce's Trust status site for your instance to see your exact date, and remember that sandboxes on preview instances have already been running the release, which is where you should have tested.
Which release updates are enforced?
| Update | What changes | What to do |
|---|---|---|
| Profile filtering | Users see only their own profile unless they have the View All Profiles permission | Grant View All Profiles to anyone, such as delegated admins, who genuinely needs to see other profiles |
| Use Any API Auth for SOAP login() | Users and integration users without the Use Any API Auth permission can no longer authenticate with SOAP API login() | Find integrations, data loaders and middleware that use SOAP login() and assign the permission, or move them to OAuth |
The SOAP login() change can break older integrations and data loading tools, so check them before your upgrade date. Separately, a new View Setup Audit Trail permission lets auditors see the audit trail without broader setup rights; Salesforce plans to enforce it in Spring '27, and existing access carries over.
Which admin features are worth switching on?
- Field history tracking on the User object (generally available): track up to 20 user fields and see who changed what. Useful for audits of role, profile and manager changes. Enable it in User Management Settings.
- Keep manual shares when transferring records (generally available, off by default): stops record transfers from silently removing access that was granted by hand. Turn it on in Sharing Settings if your teams rely on manual sharing.
- More flexible inline editing in list views (generally available, off by default): users can edit fields they have access to even when the field is not on the page layout, and edit list views that mix record types.
- Follow button on the dynamic highlights panel: lets users subscribe to updates on a record.
- Report record preview, LWR site report and dashboard components, and common rows only in joined reports (beta): useful, but test in a sandbox before relying on beta features.
- Setup with Agentforce updates: natural-language help for some setup tasks, such as related list enrichments and mobile dynamic actions.
What changes for Agentforce, Slack and Tableau?
Salesforce's Winter '27 announcement leads with AI. Agentforce gains adaptive experiences that update resolution plans as a service conversation unfolds, broader Agentforce Contact Center availability, voice-based scheduling, more than 100 prebuilt agent skills and third-party agent orchestration across AWS, Azure and Google. Slack adds Slack Code for collaborative AI coding and Slack Frontline for shift-based workers. Tableau adds Tableau Knowledge, which builds knowledge graphs agents can use. These are largely new capabilities to evaluate and license, not changes that switch on in your org automatically.
A one-week Winter '27 checklist
- Confirm your instance's upgrade date on Salesforce Trust.
- Review the enforced release updates, especially any integration that signs in through SOAP login(), and assign permissions where needed.
- Run your key processes in a preview sandbox: quoting, case routing, integrations and any custom code.
- Decide which optional features to enable, and in what order, with a named owner for each.
- Check integrations and managed packages for release notes from their vendors.
- Send users a short note on anything they will see differently.
- Note the AI features worth a business conversation and add them to your roadmap rather than switching them on mid-quarter.
If release preparation keeps landing on one overloaded admin, it is usually a sign the org needs a predictable release process. In our managed services engagements, we review each release with clients and test the processes they depend on in a sandbox.

