AIforce moves CRM work beyond the screen; governance must follow every action
Salesforce wants data, permissions and workflows to travel into Claude, Slack and other interfaces. Buyers should test effective permissions, attribution and recovery across the whole action path—not assume that a familiar CRM policy survives every new surface.

What happened
Salesforce announced AIforce, a headless interface layer that exposes governed CRM data and actions in external AI interfaces, alongside a planned enterprise control plane.
Why it matters
When work leaves the application screen, leaders need evidence that identity, permissions, logging and rollback remain intact across users, agents, connectors and downstream actions.
Salesforce is trying to separate enterprise work from the traditional application screen. Its new AIforce announcement says employees and agents will be able to query records, update data and trigger workflows from interfaces such as Claude and Slack while requests still pass through Salesforce permissions and business rules. A prebuilt Salesforce-in-Claude integration enters beta with 37 sales skills; further capabilities are described as forthcoming.
The architecture could reduce friction. It also turns a permissions statement into a system-wide hypothesis that buyers need to test. A rule defined in CRM may be affected by user identity, delegated agent authority, an MCP server, a third-party model, a generated interface and the downstream system that executes an action. “Uses existing permissions” is therefore a starting condition, not proof of effective control.
Follow the complete action path
The first test is identity continuity. A log should show which human or service initiated a request, which agent interpreted it, which skill or connector ran and which record changed. Delegation must narrow authority: an agent acting for a sales manager should not silently inherit unrelated administrative privileges.
The second test is context minimisation. Salesforce says requests use existing permissions and Zero Data Retention with model providers. Buyers still need to know what data crosses each boundary, what enters logs or memory, how derived data is classified and what happens when a third-party interface changes. Zero retention by one provider does not describe the lifecycle of every copy, cache or audit record.
The third test is recovery. Generated interfaces can make actions feel conversational, but a mistaken update remains a state change. Teams need idempotency, approval thresholds, transaction limits and rollback evidence for actions such as changing an opportunity owner, creating a task or sending a communication.
Salesforce’s separate Enterprise AI Harness announcement describes a future AI Control Plane for discovering agents, managing identity and policy, evaluating performance, observing behaviour and controlling cost across Salesforce and third-party AI. The unified experience is planned to begin rolling out in early fiscal FY28, with pricing and packaging to come later. That timing is material: organisations should base commitments on controls available now, not on a future control plane.
Portability can increase both value and risk
The strongest case for AIforce is that governed business context becomes available where employees already work. The counterargument is concentration: one interface layer can make many systems easier to reach, so a permission error or compromised connector can travel farther. Vendor examples and beta adoption figures show interest, not independent evidence of accuracy, productivity or risk reduction.
Procurement teams should therefore run role-pair tests before scale. Give two users different entitlements, ask the same question through each interface and compare data returned, actions offered and logs produced. Repeat with a revoked permission, stale session, ambiguous instruction and attempted action outside the allowed record scope. Confirm that the system fails closed and that operators can reconstruct the sequence without proprietary guesswork.
Do the same for role change. Move a user from one team to another, remove access and test every supported surface before and after cache expiry. Record any window in which the conversational interface still exposes data or proposes an action that the source application would deny. That test turns an abstract permission claim into a measurable revocation objective and surfaces ownership between CRM administration, identity engineering and the external-interface provider.
The Skills Atlas can help identify the admin, integration, security and workflow skills needed around these interfaces. The decision is not whether conversational access is convenient. It is whether the organisation can prove that policy follows the work wherever the interface moves.
A minimum evidence package
Preserve product and connector versions, the identity chain, effective permissions, data fields disclosed, requested and completed actions, approval points, failure logs and rollback results. Separate vendor availability from roadmap claims and user convenience from business outcomes. Repeat tests after changes to models, skills, connectors or permissions, and keep a human route for challenge when an action affects work, opportunity or rights.