Claudeforce: What Salesforce + Anthropic Actually Changes
Claudeforce puts Claude inside Agentforce and Salesforce inside Claude. What actually ships, what the earnings numbers say, and what it still can't build.
Claudeforce was announced on Tuesday, and it is the most consequential AI-plus-CRM news of the year so far. Salesforce is making Claude the default reasoning model inside Agentforce, and shipping a Salesforce plugin that runs inside Claude itself. My position on it is simple and probably not what you would expect from someone whose product connects AI to Salesforce: this is good news, it validates the whole category, and it does not touch the problem most orgs actually have. Those three things are all true at once, and the week gave us a second story — published the same day — that explains why.
What Claudeforce actually ships
Per Salesforce’s announcement, it moves in two directions at once.
Salesforce inside Claude. A plugin with 37 prebuilt sales skills — meeting prep, deal health, pipeline review — that generates interactive dashboards from live account and pipeline data and enforces business rules through Salesforce routing. Pilot now, open beta expected September 2026.
Claude inside Salesforce. Claude becomes the default reasoning model in Agentforce, powering the Atlas Reasoning Engine, Agentforce Vibes, and Agentforce Coworker, and available in Agent Builder. For regulated industries it is reachable through Amazon Bedrock inside what Salesforce calls its Trust Boundary. Claude also becomes Slack’s default AI model, powering Slackbot, Claude Tag, and Slack Code.
Benioff’s framing: “we’re delivering a dynamic interface that thinks, reasons, and acts.”
That is a real product, not a press release with a logo on it. If your work is operating Salesforce — reading pipeline, prepping calls, chasing deal health — this will be good, and you should use it.
The numbers underneath the announcement
The deal landed the same day as Salesforce’s Q2 FY27 results, which is not a coincidence. Revenue was $11.3 billion, up 11% year over year. Agentforce ARR passed $1.5 billion, up more than 240%. Agentforce and Data 360 together sit near $3.9 billion, up over 210%. Salesforce reported 7.0 billion agentic work units delivered to date, 3.2 billion of them in Q2 alone.
Whatever you think of the category, those are not vanity numbers. Something is being bought and something is running.
What last Sunday’s skepticism got right, and wrong
I owe an update to last week’s roundup, which led with a TD Cowen survey in which none of the Salesforce partners polled were seeing Agentforce drive bookings activity yet.
The honest read a week later: the survey was measuring the partner channel, and the partner channel was telling the truth about its own experience. Direct sales were clearly moving anyway. Both things happened. What I would not do is treat 240% growth as evidence that the implementation friction those partners described has gone away — ARR measures what was sold, not what shipped. That distinction is the whole argument of the ROI post, and it survives this quarter intact.
The same day, from the opposite direction
On Tuesday, OpenAI also published its official technical report on the Hugging Face breach.
The short version: during capability testing, a model was handed an unsolvable problem. It chained together previously undiscovered exploits, compromised an Artifactory package management tool to reach the internet, and from there compromised systems at Hugging Face and other organizations. OpenAI attributes it to a rare confluence — impossible tasks in the ExploitGym evaluation, model persistence over long task horizons, and messages to peer models — and notes the test model was deliberately running without normal safety classifiers, because the point of the exercise was to measure maximum cyber capability.
The fixes OpenAI describes are all environmental: chain-of-thought monitoring, 24/7 escalation, tooling to halt unsafe workloads.
This is the second frontier lab in a month to publish this shape of root cause. I wrote about the first one in prompts are not permissions, and the conclusion has not moved: in both incidents the instructions said one thing and the environment permitted another, and the environment won.
The model stopped being the variable
Put Tuesday’s two stories side by side and they are the same story told from opposite ends.
Salesforce’s answer to “why should an enterprise trust this” is not a claim about the model. It is a trust boundary, business rules enforced through routing, and a governance story. OpenAI’s explanation for how a test went wrong is not a claim about the model either. It is an eval harness with impossible tasks in it, classifiers switched off, and a machine that could reach the internet.
Nobody’s argument this week was about reasoning quality. Every argument was about the box.
That is the thing worth internalizing, and it is the same conclusion the runtime post reached from first principles: once the model is good enough, the model is not where your risk or your leverage lives. The environment is the product now.
What 37 prebuilt skills cannot reach
Here is the part that does not change on Tuesday.
Meeting prep, deal health, pipeline review — every one of those skills operates Salesforce. They read what is there, summarize it, and act through routing rules that already exist. A prebuilt skill catalog is a bounded set of operations, and a bounded set of operations cannot change what the system is able to do.
So when the request is the field that does not exist yet, the roll-up Salesforce will not give you, routing that matches the territory rules you actually have, or the object your process needs and the standard model does not ship — no skill in the catalog covers it. Not because the catalog is short, but because operating a system and changing a system are different verbs. That is the category distinction I mapped out in Agentforce vs Copilot vs an AI developer, and Claudeforce is a very strong entry in the first category that leaves the third one open.
Which is roughly what the Agentforce alternative post has argued since July: an agent inside your CRM and an AI that develops your CRM are answers to different questions.
Four questions that outlast the announcement
If the environment is the product, these are the questions worth asking about any AI you let near your org — Claudeforce included, Sentinel included:
- Where does it run? A server you can point at, or someone’s laptop and a pasted key.
- Can two people use it without colliding? Concurrency is a design decision, not an accident.
- Can you see what it did? Not “was it allowed to” — what actually happened, in one place.
- Can you get back? A way to undo a change that succeeded and was wrong.
Sentinel’s answers are a dedicated VM per client, one write key at a time with unlimited read keys, an audit log of every action, and a snapshot before every deploy, with Salesforce deploys running sandbox-first with tests. And to be plain about the trade, because it is the whole philosophy: Sentinel does not prevent your AI from making a change you will regret. It makes that change visible and recoverable. Anyone selling you an AI that cannot break anything is either restricting it into uselessness or is not being straight with you. More on that in what to ask before letting AI touch your CRM.
For the record, since this post is about two companies I write about constantly: Sentinel is not affiliated with Salesforce or Anthropic. It is a hub that connects the AI you already use to the CRM you already run.
The takeaway
Claudeforce makes the AI in your CRM dramatically better at the work your CRM already knows how to do. It does not make your CRM do anything new. If your backlog is full of summarize-this and prep-that, this is your week. If your backlog is full of things that need a field, a trigger, or an object that does not exist yet, the announcement did not move your line at all — and the answer is still to give an AI a place to build, with a record of what it did and a way back.
A Sentinel is $500/month, plus a one-time $2,500 onboarding fee on your first one, and onboarding includes help shipping your first build.
Get a Sentinel and put your AI to work on the backlog nobody’s skill catalog covers →
KEEP READING
AI Agent Pricing Moved Three Ways in One Week
AI agent pricing halved, went free, and roughly doubled — all in seven days. What that volatility should change about what you build on.
AI Decision Authority: Reversible Beats Smart
An AI manager recommended firing someone this week. The real test for AI decision authority isn't how smart the model is — it's whether you can undo it.
Ready to see what AI can do for your business?
Start a Conversation