On September 15, 2026, Anthropic released Salesforce in Claude in beta on all paid Claude plans, and Salesforce opened the beta to all customers the same day. It brings accounts, opportunities, and pipeline into Claude with 37 prebuilt sales skills. The security model is the part that makes it adoptable: Claude signs in as each individual user, sees only what that user's Salesforce permissions already allow, and asks for approval before writing any change. The prerequisites: your org must opt in, a Salesforce admin must request the plugin through AgentExchange, and the beta requires a current Sales Cloud Enterprise Edition. This article is the rollout sequence we recommend to clients — the same one we would run ourselves.
Why the permission model is the right starting point
Most 'AI reads your CRM' integrations fail security review for one reason: they introduce a new service account with broad read access, which means the AI can surface records the asking user could never open themselves. Salesforce in Claude avoids that class of problem by inheriting the requesting user's own permission set — sharing rules, field-level security, and record visibility all apply exactly as they do in Lightning. The audit question changes from 'what can the AI see?' to 'what can this user see?' — a question your org already answers.
Writes are gated separately: by default, Claude proposes a change and the user approves it before anything is committed. Keep that default. The productivity cost of one approval click is trivial; the governance value of a human-confirmed write trail in a beta integration is not.
A rollout sequence that holds up
- 01Confirm eligibility: current Sales Cloud Enterprise Edition, and an admin willing to own the AgentExchange plugin request. Without both, stop here.
- 02Pilot in a sandbox org first — the skills behave identically, and your sharing-rule edge cases surface where they cost nothing.
- 03Pick a pilot cohort with clean permission hygiene: sellers whose profiles and permission sets you have actually reviewed. The integration faithfully reproduces whatever over-provisioning already exists.
- 04Run a read-mostly phase: let the cohort use the research and pipeline-summary skills for two or three weeks before enabling any write flows beyond the default approval gate.
- 05Review the audit trail with your admin: which skills were used, what was written, what was approved. Expand the cohort only after that review reads clean.
Where it fits next to Coworker and autonomous agents
Salesforce now has three distinct AI surfaces, and conflating them produces bad rollout decisions. Agentforce Coworker is the assistant inside Lightning — for people who live in Salesforce. Salesforce in Claude is for people who live in Claude and visit Salesforce — sellers and leaders who want pipeline answers inside the tool where they already write, research, and plan. Autonomous Agentforce 360 agents are not an interface at all: they execute work without a human driving. The adoption questions are different for each — Coworker is an enablement rollout, Salesforce in Claude is a permissions-and-governance rollout, and autonomous agents are an engineering project with testing and observability requirements.
The beta is free to try on plans you already have. The risk is not the feature — it is skipping the permission review that the feature will faithfully amplify.
We build and govern agentic systems in production — in client orgs and inside our own company, where an MCP orchestration server runs daily operations. If you want a second set of eyes on your permission model before switching the beta on, that review is a small, bounded piece of work with your own admin in the room.