In its latest announcement, Salesforce cites Agentforce, Claude, and ChatGPT as applications that allow customers to work with Salesforce. This reaffirms its headless strategy. A CRM vendor promoting competitors’ interfaces, that’s a clear strategy. Salesforce is giving away the interface layer to own something far more important: the layer beneath it. AI only works well with the right context, actions, and governance; whoever has that, and can deliver it effectively, is in the best position. That is exactly Salesforce’s focus.
In April, after introducing Headless 360, we wrote that the “SaaSpocalypse” is a myth. The comparison we made at the time was: Salesforce gives you the chassis, including the engine, steering, brakes, and safety systems, and you build the body yourself. Building a complete chassis from scratch is technically possible, but for a single organization, it’s expensive, complex, and rarely worth the effort.
Back in April, that promise was mostly just a promise: sixty MCP tools, a direction, and the assurance that eventually, everything you do through Salesforce.com will also be possible via an API or MCP. What we have now is considerably more concrete, and also significantly more ambitious, than Headless alone.
From sixty tools to a server that explains itself
The most important new component is the Headless 360 MCP Server, now available in open beta. The main difference from April is the architecture. Sixty MCP tools constitute a predefined list: someone determines which actions are available, and that’s the limit.
The new server turns that on its head. Agents running in Agentforce, Claude, ChatGPT, or Cursor (as well as Gemini and Microsoft Copilot) discover which capabilities are available as they work. The new MCP server is metadata-aware, meaning agents see not only endpoints but also the relationships, permissions, workflows, and validation rules associated with them. Salesforce itself summarizes the difference: most MCP servers make APIs available, while Salesforce makes business capabilities available.
That’s a major and important difference. You don’t want to give just any agent access to an MCP server, which would let it control a dozen business applications and take action without any context or governance. Without that, you can only hope that the agent makes the right choice and follows the business processes exactly as you’ve designed them.
Salesforce, therefore, provides an agent with your organization’s context, validation rules, permissions, and business processes. This is also the key advantage of a good platform. The alternative is that a developer would have to write all of this themselves in prompts and code.
Data 360 moves from reading to building
The second major step is the Data 360 MCP Server, now generally available and featuring nearly two hundred APIs. Until now, headless applications mainly did the obvious: retrieving customer data.
With this MCP server, agents can now also build semantic models, transform data, map fields, inspect identity graphs, create audience segments, activate campaigns, and set up entirely new data streams, all via natural language. It includes ready-to-use skills for modeling, mapping, transformations, and activation; these will become generally available this month.
Think about what that means. An agent who simply reads a record falls into one risk category. An agent that independently modifies a data model and activates a campaign falls into a completely different one. That’s not an argument against it, it’s an argument for the governance layer that Salesforce is explicitly building around it.
Slack becomes the agent interface for twenty other vendors
The Slackbot MCP client is now generally available. This makes Slack not just a place where agents show up, but a client that securely connects to more than twenty partner applications, including Atlassian, Box, Canva, Docusign, Notion, and Zoom.
Employees can update an opportunity, retrieve a contract, or start a workflow right from a conversation, while retaining the same permissions and identity as elsewhere. Zoom notes that users can access their meeting intelligence via Slackbot without switching applications.
Whereas Salesforce completely abandons the UI, Slack is the SaaS provider that renders the UIs of twenty other applications redundant. While we understand that Salesforce, with its comprehensive applications, workflows, business processes, and governance, can easily survive as an intelligence layer, we doubt whether the same applies to all those Slack partner applications. If people no longer need to check Atlassian, Box, Canva, Docusign, Notion, or Zoom, won’t they lose their connection with the user? Most of those applications have a less complex layer than Salesforce.
More than 100 agent skills and plugins
To ensure Salesforce functions effectively as an intelligence and governance layer, all internal agents and MCP servers utilize skills. These skills encapsulate business logic and processes into reusable actions with the appropriate governance.
As a result, Salesforce will soon be able to tell you exactly which agent had access to which MCP server at what time, what data was accessed, and which skills and actions were executed. Every step an agent takes on the Salesforce platform is tracked, monitored, and verified.
Microsoft security veteran leads Salesforce platform
Rohan Kumar has been the new President & Chief Platform and Engineering Officer at Salesforce for several months now. Before that, he spent 28 years at Microsoft in various roles, and his background in Microsoft Security is clearly reflected in the story behind these announcements.
For example, Kumar was also responsible for Purview, which specializes in data security, compliance, governance, and privacy. Now he is applying that terminology and technology to agents.
We spoke briefly with him, and he focused primarily on the Enterprise AI Harness. Models provide the intelligence, but an organization possesses trusted context, actions, and governance, and an agent needs these to perform its job effectively. That’s what Salesforce has now effectively organized, along with a control plane that can show which models an agent uses, what data it accesses, which tools it calls upon, what it costs, and what it delivers. Unfortunately, nothing is known yet about the availability of this control plane, but that will undoubtedly be announced next month during Dreamforce.
With Salesforce, you can bring your own agent, your own model, and your own interface, as long as you use Salesforce’s context and Harness. In other words, the layer underneath.
SaaSpocalypse: Not the end of SaaS, but the end of the seat
In a LinkedIn post, Kumar stated that the rise of AI isn’t the end of SaaS. We agree, we wrote about that back in April as well. However, we do believe that SaaS will undergo significant changes, with the number of seats (licenses) dropping dramatically and the number of agents rising sharply.
Salesforce is increasingly becoming the underlying layer needed to ensure business processes run smoothly and are automated through agents. This does mean, however, that Salesforce’s revenue model will shift from a fixed subscription model to revenue based on how often organizations use AI. This transition has been underway for some time, and its effects will naturally become clearer in the coming years. Fewer seats and more AI will help organizations grow efficiently and boost Salesforce’s revenue.