Claudeforce: What Salesforce and Anthropic Actually Shipped

Claudeforce: What Salesforce and Anthropic Actually Shipped

September 25, 2026
Claudeforce was not announced at Dreamforce, and the 37 sales skills do not run in Salesforce. Here is what Salesforce and Anthropic actually shipped, why the beta is narrower than the keynote implied, and the two security facts a regulated client will ask about first.

Claudeforce is an umbrella brand for a Salesforce and Anthropic partnership, not a product you buy. It covers three separate things: a Salesforce-built plugin that runs inside Claude, Claude models available as reasoning models inside Agentforce, and Claude as the default model in Slack. Only the first is genuinely new, access is a beta gated by Salesforce approval, and neither company has published a price.

Two corrections before anything else, because most coverage has both of them wrong.

Claudeforce was not announced at Dreamforce. It was announced on 26 August 2026 alongside Salesforce's Q2 FY27 earnings. Dreamforce '26, 15 to 17 September, is where the beta opened.

And the 37 prebuilt sales skills are not in Salesforce. They live in the Claude-side plugin and run inside Claude. They are not in Lightning, not in Agentforce Builder, and not in your org.

What Claudeforce is, and why the answer is three things

No SKU, package or licence is named Claudeforce anywhere in Salesforce or Anthropic documentation. The brand covers three workstreams that have different maturity, different prerequisites and different risk profiles. Treating them as one product is how buying conversations go wrong.

Salesforce in Claude. A plugin inside Claude. Anthropic's documentation describes it as "a plugin that brings your Salesforce accounts, opportunities, and pipeline into Claude", and states it "currently works in chat and Claude Cowork on web and desktop". This is the new thing.

Claude in Salesforce. Claude models as the reasoning engine inside Agentforce, served through Amazon Bedrock inside the Salesforce trust boundary. This is largely the October 2025 partnership rebranded, with Claude's status upgraded from "preferred" to "default".

Claude in Slack. Claude as the default model for Slack AI and Slackbot.

Be careful with that word "default". Salesforce's live supported models documentation still says the Agentforce default is "a managed mix of trusted models (currently including GPT-4o) optimized by Salesforce", and the page does not contain the word Claudeforce at all. Either the documentation lags the announcement or "default" is marketing framing. We checked that page on 22 September 2026. Do not tell a client Claude is now their default model without confirming it in their org.

The Claude models currently listed as supported in Agentforce are Haiku 4.5, Opus 4.5 through 4.8, and Sonnet 4.5, 4.6 and 5, all served via Bedrock inside the Salesforce trust boundary.

Where the 37 sales skills actually live, and what is published about them

No full list of the 37 has been published. We checked the Salesforce press release across regional variants, Anthropic's blog, both Anthropic help centre articles, the AgentExchange listing and the Trailhead module. None enumerates them.

Five are named by slug in Salesforce's own Trailhead unit, which is the most concrete published detail anywhere:

Skill slugPublished purpose
account-tieringReviews accounts and opportunities against an ideal customer profile
pipeline-reviewStage-by-stage pipeline view, coverage, at-risk deals
call-prepMeeting briefs including stakeholder sentiment and discovery questions
call-follow-upTurns call transcripts into emails and Slack summaries
account-planClose plans grounded in live CRM records plus web research

Roughly eleven further workflows are described in prose across Salesforce and Anthropic sources: meeting prep, deal health review, renewal prep, QBR deck generation, pipeline coverage, lead triage, outreach drafting, stakeholder identification, call logging, forecasting and post-call follow-up. That is sixteen accounted for out of thirty-seven. The rest is an assertion, not a roster.

One distribution detail worth getting right, because it sounds pedantic and is not. The listing lives on the appexchange.salesforce.com domain but is branded AgentExchange. Coverage saying "available from the AppExchange" is right about the URL and wrong about the marketplace. If you send an admin looking in the wrong place they will not find it.

What a "skill" means here, and why the number can move

The kebab-case slugs are Anthropic's Agent Skills convention, not Salesforce's Agentforce vocabulary. A skill in this context is not an Agentforce topic, action or subagent. That distinction matters if you are trying to map Claudeforce onto agents you have already built, because there is no mapping.

Where "skill" does become Salesforce terminology is in Headless 360, and this is the part worth understanding properly. The Headless 360 MCP Server does not expose every Salesforce operation as its own MCP tool. It exposes exactly four, backed by a searchable skill library:

  • Discover, a semantic search across available Salesforce operations, with a configurable result limit of 1 to 50 and a default of 10
  • Describe, which returns the technical contract for an operation including parameters and ordered execution steps
  • Dispatch, which invokes operations over HTTP and, per Salesforce's beta announcement, "enforces the user access guards before anything runs"
  • Dispatch Read Only, which is GET only and "never modifies data or configuration"

Salesforce's own design principle for this is "an agent with four tools, not thousands". Headless 360 launched in July 2026 with roughly 100 skills and is intended to expand.

So the 37 sales skills are a curated subset of a library sitting behind a four-tool facade. That is why the number can change without anything being re-architected, and it is why "37 skills" tells you far less about capability than it appears to.

Is Claudeforce in open beta? The documentation says something narrower

This is worth pinning down, because "open beta" implies you can go and get it.

Salesforce's press release said, on 26 August: "Salesforce in Claude is available to select pilot customers now and expects to launch in open beta in September 2026." That is a forecast, and the present-tense word in it is pilot.

Anthropic's help centre currently says: "Available in beta on all paid plans for organizations Salesforce approves through its beta sign-up." The AgentExchange listing gives the stage as Beta and notes that "approved requests receive activation instructions".

Every primary source describes a gated beta where Salesforce approves your org. The phrase "moved into open beta" comes from conference reporting, not from documentation. Functionally this is an allowlist beta with open enrolment, which is a different thing from open beta when you are telling a client what they can expect this quarter.

No GA date or target has been published. No regional exclusions have been published either, which is not the same as there being none.

What does Claudeforce cost?

Nothing has been published. Not by Salesforce, not by Anthropic.

We checked the press release, the Anthropic blog, both help articles, the AgentExchange listing and the Trailhead module on 22 September 2026. There is no pricing, no metering statement, and no answer to whether it draws Flex Credits, Einstein Requests or Agentforce Conversations. There is no statement about whether it is free during beta or what happens at GA.

The one cost you can be certain of is on the Anthropic side. The plugin requires a paid Claude plan, and Team or Enterprise for the org-level approval workflows. That is a real per-seat cost independent of anything Salesforce charges.

Analysts have filled the gap with inference rather than fact. NPI's assessment is that the likely structure involves "separate Salesforce and Anthropic charges, potentially layering Salesforce API or headless consumption and Claude inference on top of existing Agentforce credits". Others describe a dual-meter risk where Salesforce bills API calls against org entitlement while Anthropic bills tokens separately. Both are reasoned guesses by people who say so. Neither is published, and we are not going to dress either up as a forecast.

If a partner gives you a confident cost per user for Claudeforce today, ask them which page they read it on.

Zero data retention is not a Claudeforce claim

This is the section we would most want a client to read, because the phrase is everywhere in the coverage and it does not appear in the source material.

"Zero data retention" appears nowhere in the Salesforce Claudeforce press release, the Anthropic announcement, or either Anthropic help article. It appears to be shorthand imported from the Einstein Trust Layer's general posture.

What the Trust Layer actually says, on Salesforce's own Trailhead: "Salesforce has a zero data retention policy with third-party LLM providers like Open AI and Azure Open AI." The Agentforce developer Trust Layer guide likewise cites agreements "with LLM providers, such as OpenAI" carrying "commitments for zero data retention".

Both name OpenAI. Neither names Anthropic. An Anthropic-specific zero-retention commitment is not documented in Salesforce's public material. What is documented is a containment claim rather than a retention claim: Claude runs on Bedrock inside the Salesforce trust boundary, and the October 2025 language was that "all of Claude's traffic" is "contained within the Salesforce virtual private cloud". Those are different assurances and they answer different audit questions.

There is a second wrinkle, and it needs stating carefully because overclaiming here would be worse than saying nothing. Anthropic now publishes a Covered Models policy under which "prompts submitted to, and outputs generated by, covered models are retained for 30 days to support our safety work, on every platform where these models are offered", and states that zero data retention "is not available" for those models, including on Amazon Bedrock. The models currently listed as Covered are Fable 5, Mythos 5, Fable 5.1 and Mythos 5.1.

None of those is currently among the Claude models supported in Agentforce. So the 30-day floor does not apply today on the published evidence. The point is forward-looking: if a Covered Model is ever routed into Agentforce or into the plugin, a blanket zero-retention assurance stops being accurate by Anthropic's own policy. We could not verify which model version backs the Salesforce in Claude plugin, which is exactly the question a regulated client's security team will ask first.

Data masking is disabled for agents, and this is an agentic path

Salesforce states it plainly: "Pattern-based and field-based data masking for large language models (LLMs) is disabled for agents." The stated rationale is that masking degrades accuracy, because masking a reference account's details removes the context the model needs.

The important detail is the scope. Salesforce's documentation confirms that masking remains disabled for agents even when using LLMs hosted inside its own trust boundary, and names Anthropic Claude when it says so. Being inside the trust boundary does not switch masking back on.

Masking is available for embedded generative features such as Einstein Service Replies and Einstein Work Summaries. It is not available on the path Claudeforce uses. That is enforced platform behaviour rather than a configuration choice, and it is the single most relevant fact for anyone pointing Claude at a CRM containing personal or financial data.

We could not establish whether Trust Layer toxicity scoring and the Data 360 audit trail apply to the Claude-side plugin at all. Architecturally it is doubtful, because the plugin path runs from Claude through the Headless 360 MCP server to Salesforce and does not obviously traverse the Einstein Trust Layer. Nothing published answers it either way, so we are flagging it rather than assuming.

The permission model, by contrast, is well documented and genuinely reassuring. More on that below.

What you need before you can turn it on

  1. The latest Sales Cloud Enterprise edition. Anthropic's help centre states the integration "requires access to the latest Sales Cloud enterprise edition to be eligible for beta".
  2. A beta access request through AgentExchange, approved by Salesforce. Approved requests receive activation instructions by email.
  3. An External Client App configured with the mcp_api scope, because the underlying Headless 360 MCP Server requires one. It also requires API version 67.0 or later.
  4. OAuth credentials handed to your Claude administrator. The Salesforce admin supplies the consumer key and secret.
  5. A paid Claude plan, with Team or Enterprise needed for org-level distribution and approval workflows, plus Primary Owner or Owner access to configure the Claude organisation.
  6. Per-user activation. Each user activates the plugin and signs in with their own Salesforce credentials.

Note what is absent from that list. There is no Data 360 provisioning step, no named seasonal release, no Agentforce licence and no Anthropic API key. The plugin path is MCP to CRM, not Data 360 mediated, which makes it materially cheaper to stand up than most Agentforce work.

On security, the documented model is strong and worth quoting to a nervous stakeholder. Every transaction executes as the authenticated user. Object permissions, field-level security, sharing rules, profiles and permission sets all apply. Salesforce's own wording on the MCP server is the line to use: "If you can't perform an action in Salesforce, your agent can't perform it through the MCP server." Claude proposes writes and, by default, "asks the seller to approve each proposed change before it is written", with approval available as one-time or standing.

What we would use it for, and what we would not use it yet

We would put this in front of a sales team doing pipeline review, call prep and follow-up, on a Claude plan they already pay for, in an org where the data is commercially sensitive rather than personally sensitive. The prerequisites are light, the permission model is enforced by the existing platform rather than by new configuration, and the write-approval default means a bad suggestion costs a click rather than a record.

We would not yet put it on a path touching health data, payment data or anything under a data processing agreement that names retention terms. Not because we think it is unsafe, but because masking is off for agents by design, an Anthropic-specific retention commitment is not documented in Salesforce's own material, and we cannot tell you which model version backs the plugin. Those three facts together make it an uncomfortable conversation with an auditor, and the answer "it runs inside the trust boundary" does not close it.

The alternative we considered for one client and rejected was building equivalent functionality as an Agentforce agent inside Salesforce instead. It would have put the work inside the Trust Layer and inside their existing Flex Credit entitlement, which is a real advantage. It lost on effort and on adoption: five or six of the published skills would have needed building, testing and maintaining as topics and actions, and the sales team was already living in Claude all day. The deciding factor was not capability, it was that the plugin met users where they already were. That is a legitimate reason to choose it and a bad reason to skip the security review.

Frequently Asked Questions

What is Claudeforce?

Claudeforce is the brand for an extended Salesforce and Anthropic partnership announced on 26 August 2026. It covers a Salesforce-built plugin that runs inside Claude, Claude models as reasoning models inside Agentforce via Amazon Bedrock, and Claude as the default model in Slack. It is not a product SKU, and no licence of that name exists.

Do the 37 sales skills run inside Salesforce?

No. They run inside Claude, through the Salesforce in Claude plugin, which works in Claude chat and Claude Cowork on web and desktop. They are not available in Lightning or the Agentforce Builder. Salesforce has published five skill slugs and described roughly eleven further workflows, but no full list of all 37 exists in any source.

How much does Claudeforce cost?

No pricing has been published by Salesforce or Anthropic as of 22 September 2026, including whether it consumes Flex Credits, Einstein Requests or Agentforce Conversations. The one certain cost is a paid Claude plan, with Team or Enterprise required for org-level distribution. Any per-user figure you are quoted today is an estimate, so ask what it is based on.

Does Claudeforce have zero data retention?

The phrase does not appear in any Salesforce or Anthropic primary source about Claudeforce. Salesforce's published zero-retention language names OpenAI and Azure OpenAI, not Anthropic. What is documented is that Claude runs inside the Salesforce trust boundary on Bedrock, which is a containment assurance rather than a retention one.

Is field-level security enforced when Claude reads CRM data?

Yes, and it is well documented. Every transaction executes as the authenticated user, with object permissions, field-level security, sharing rules, profiles and permission sets all applying. Salesforce states that if you cannot perform an action in Salesforce, your agent cannot perform it through the MCP server either. Audit trails attribute actions to the originating user.

How do we get access to the beta?

Your Salesforce administrator submits a beta access request through AgentExchange, and Salesforce approves the org before activation instructions are issued. Despite the "open beta" language used at Dreamforce, every primary source describes an approval-gated beta. You will also need the latest Sales Cloud Enterprise edition and a paid Claude plan.

The question to settle before you request the beta

The specific problem this post describes is that Claudeforce is unusually cheap to switch on and unusually hard to get a straight security answer about. The prerequisites are light, the permission model is enforced, and masking is off for agents with no published Anthropic-specific retention commitment in Salesforce's own documentation.

Decide which of your objects the plugin should be able to reach before you request access, not after. If you want help drawing that line and writing it into the External Client App scope, talk to us. It is a half-day exercise that is much harder to do once sellers are already using it.

Have Questions or Need Assistance?

Our team of Salesforce experts is ready to help you implement the solutions discussed in this article.

Contact Us Today