Agentforce left the builder
Dreamforce put Agentforce Coworker on the Lightning desk and piped Salesforce context into Claude and Slack. The agent workforce is no longer a side project — it is a surface.
Listen to this operator analysis
en-US-ChristopherNeural · 15:45
AI-generated narration from the final published article text. No interview or field audio is included.
For a year, Agentforce lived in the builder story: invent an agent, wire actions, prove a pilot, put a slide on the roadmap. Dreamforce week just moved the product onto the floor.
On September 15, 2026, Salesforce unveiled AIforce — a live interface layer that, in the company’s words, brings Salesforce data, workflows, business logic, semantics, permissions, security, and governance to “any AI interface.” The launch set included Claudeforce, Slackforce, and Agentforce Coworker. (Salesforce AIforce announcement; CRN; SiliconANGLE.)
Read that carefully. The headline brand is AIforce. The Agentforce product did not vanish. Coworker is the Agentforce teammate sitting inside Lightning — reasoning across accounts, activity, and history, calling specialized Agentforce agents the customer already built, activated with a button and no new permissions model, per Salesforce. The company also claims 100,000 users activated Coworker within its first 35 days. That figure is vendor-reported; treat it as a company claim, not an independent census. (Salesforce.)
The call: Agentforce left the builder. When agents sit on CRM and chat surfaces, inventory, revoke, and blast-radius stop being architecture theater and become Tuesday work.
What actually shipped this week (Agentforce key)
Agentforce Coworker is the spine of this piece. Salesforce positions it as an AI teammate in the Lightning interface, operating inside existing permissions and business rules, with nothing retained outside the trust boundary (company claim), calling the specialized agents already deployed. (Salesforce.)
AIforce is the distribution foil, not the title. It is how Salesforce argues platform context travels into Claude (Claudeforce / “Salesforce in Claude” MCP + prebuilt sales skills, beta) and Slack (Slackforce Surfaces, Slackbot grounded in Salesforce context, Slack CRM prompts). Benioff’s quote frames an “interface revolution” combining model intelligence with Salesforce context under “securely governed” and “Zero Data Retention” language — again, vendor framing. (Salesforce.)
Four days earlier, on September 11, Salesforce expanded Agentforce with a portfolio of job-ready agents and a long-horizon runtime so agents can pursue goals across days and weeks. Details and status mix sit in the next section — do not flatten the portfolio into “all GA.” (Salesforce job-ready agents.)
Surfaces beat consoles
Builder-centric agent platforms keep risk in a lab shape: limited users, named pilots, change tickets. Coworker + Slackforce + Claudeforce change the shape. Agents become a button on the desk and a prompt in the chat people already refuse to leave.
That is the operator tension:
- Surface sprawl — Lightning, Slack, Claude, and whatever AIforce adds next. Each surface is another place an agent can act with “existing permissions.”
- Permissions travel (claimed) — Salesforce says every request runs on existing permissions and business rules, and every action routes back through Salesforce. Useful if true in your org’s configuration. Not a substitute for proving revoke.
- Long-horizon goals — An agent that works a pipeline for weeks is not a chatbot turn. Memory, durable execution, and dynamic steering (Salesforce’s terms for the new runtime) extend the window in which a bad tool grant keeps paying rent. (Salesforce.)
- Inventory — “Push-button activate” and “100,000 users in 35 days” (company claim) is a provisioning story. It is not an offboarding story.
GSJ’s standing operator question applies: if you cannot name which agents hold which credentials and which surfaces can call them, you do not have a workforce. You have ambient privilege.
Claudeforce and Slackforce: the distribution doors
Coworker is the Agentforce body on Lightning. Claudeforce and Slackforce are how Salesforce argues the same governed context can leave the Salesforce UI without leaving Salesforce’s permission story.
Claudeforce, on Salesforce’s AIforce page, extends the Anthropic partnership: Salesforce in Claude as a prebuilt MCP server — marketed as skipping the usual friction of manual setup, complex authentication, and custom skill-mapping. Day-one packaging includes 37 prebuilt sales skills covering prospecting through pipeline hygiene. Salesforce says analytics with Tableau and skills for service, marketing, commerce, and industries come “in the near future.” For builders, a Salesforce Development plug-in for Claude Code brings more than 40 skills, access to a broader skills library on GitHub, and specialized sub-plug-ins that load dynamically. Pilot names on the company page: Deloitte, GitLab, and Legora. Availability: beta for all customers. (Salesforce.)
Beta is not a free pass for operators. A prebuilt MCP with write-capable sales skills is a connected-system event. Who installs it? Under which Salesforce user or integration identity? Which skills are read versus write? How long do tokens live? Salesforce’s developer guidance on securing hosted MCP servers — scopes, authentication, and token lifetime — is the supporting hygiene lane, not a substitute for your org’s change ticket. (Salesforce Developers — hosted MCP security). Treat “prebuilt” as faster to over-scope, not already least-privilege.
Slackforce is the multiplayer door. Salesforce describes Slackforce Surfaces as live interfaces pulled from Salesforce, Slack, and other tools — filterable, commentable, actionable in conversation. Slackbot is framed as an out-of-the-box assistant that can reason across Slack conversational context and Salesforce semantic intelligence and governed action. Slack CRM connects Slack conversation and updates back to Salesforce so users can create accounts, log notes, and update records by prompt without opening a separate CRM tool. (Salesforce; SiliconANGLE.)
That is the distribution foil in one sentence: the CRM write path follows the chat habit. Inventory which workspaces and which Salesforce orgs are linked before the demo becomes the production habit.
Salesforce also says AIforce rides the Headless Toolkit — MCP, APIs, plug-ins, skills — with AgentExchange as a partner marketplace. Packaging accelerates adoption. Acceleration without an agent inventory is how ambient privilege scales. (Salesforce.)
Job-ready agents and the long-horizon problem
The September 11 Agentforce expansion is not a second lead. It is the portfolio that Coworker can call — and the runtime that changes how long a bad grant keeps working.
Salesforce’s job-ready list (customers may rename) includes: Casey (help — GA), Paige (IT & HR — GA), Carter (shopper — GA), Hunter (outbound sales — pilot now; GA November ’26), Marshall (supply chain — GA), Piper (inbound pipe gen — GA), and Fin (customer agent — GA). Multi-Agent Orchestration is listed as GA now; AI Skills in Coworker as pilot with GA October ’26; Agent Optimizer as GA October ’26. (Salesforce job-ready agents.)
Do not write Hunter as generally available today. A FAQ help agent and a weeks-long outbound sales agent are different blast-radius classes even when they share a brand family.
The long-horizon runtime is the fold that matters for governance. Salesforce’s example: a seller asks Hunter to rescue at-risk deals before quarter end; Hunter turns that into a measurable goal and works toward it across sessions — with memory, durable execution, and dynamic steering. Hunter is named as the first agent on that runtime. (Salesforce.)
Operator translation: a chatbot turn you watch is one monitoring problem. A goal that survives overnight is an access-review problem. Standing reviews and approval boundaries belong in the runbook before November ’26 GA pressure hits your tenants.
Salesforce also states 7 billion Agentic Work Units (AWUs) across Agentforce and Slack, including 3.2 billion in Q2 alone, plus customer outcome percentages. Those figures are Salesforce-defined units, vendor-reported. Cite as company claims. Do not baptize them as independent ROI. (Salesforce.)
Permissions travel — and what public docs leave open
Salesforce’s AIforce framing repeats: every request runs on existing permissions and business rules; every agent sees only what the person asking can see; every action routes back through Salesforce; Zero Data Retention with the model provider for the question at hand. (Salesforce.)
Take the useful half seriously. If there is “no new permissions model,” then your current sharing debt is the agent firewall. Profiles and permission sets designed for human click-speed can be catastrophic when a prompt can update records from Slack or Claude.
Leave the other half open where public materials are thin: human versus agent-under-user attribution in audit trails across Lightning Coworker, Claude MCP, and Slack CRM write-back. Do not invent a forensics guarantee. Flag the workshop question: can you prove which mutations were agent-mediated?
Trusted Enterprise AI Harness: named now, unified later
September 10’s Trusted Enterprise AI Harness post is the governance foil. Salesforce describes six trusted capabilities — Context, Agency, Action, Governance, Security, Models — plus an AI Control Plane to discover agents, establish identity and policy, manage lifecycle, evaluate performance, observe outcomes, and control cost across Salesforce and third-party AI.
Availability language on the Salesforce primary: many foundation technologies are available today; new capabilities and the unified experience are planned to begin rolling out in early fiscal FY28; packaging and pricing closer to GA. (Salesforce.)
That is supporting tension, not a second title. Dreamforce week puts agents on surfaces now. The unified control experience is on a later fiscal calendar. Naming the harness does not finish the plane. Waiting for FY28 packaging before listing which agents can write Opportunities is how you inventory after the incident.
Operator checklist (MSP / Salesforce admin)
- Org inventory — Coworker on/off, profiles, Manage AI Agents (or equivalent), job-ready vs custom agents in production vs pilot.
- Surface map — Lightning Coworker; Slackforce / Slack CRM workspaces; Claudeforce / Salesforce-in-Claude MCP installs.
- Skill and action review — Separate read from write; block write packs until a named owner signs least-privilege.
- Revoke drill — Sandbox first: deactivate agent / Coworker / connected app; confirm mutations stop; document kill order.
- Long-horizon gate — Hunter (or similar) pilots get standing access reviews and a human owner for autonomous steps before GA marketing.
- Logging questions — What can you attribute today: user, session, agent, surface? Where thin, dual-control high-impact writes.
- Vendor vs evidence — AWU totals and customer % slides stay “company-reported.” Permission-set exports and revoke screenshots go in the audit folder.
Written “within existing permissions” is atmosphere until you can show the permission set and the kill switch.
Close
Agentforce left the builder when Coworker sat down in Lightning and AIforce claimed the same context could ride into Claude and Slack. The workforce is a surface. Surfaces inherit the sharing model you already shipped — and they extend the window in which a long-horizon agent can keep working.
Cite Salesforce primaries for what shipped. Hold brochure math as vendor-reported. Keep the harness/control-plane FY28 unified experience as roadmap tension, not a reason to delay Tuesday’s inventory. Leave human-versus-agent audit attribution open where docs are thin. The tokens / NIST identity lane stays a separate story — out of this one.
The agents are on the floor. The only grown-up question left is whether your revoke path can keep up with your activation button.
Sources
- Salesforce — AIforce announcement — Salesforce
- Salesforce — Agentforce job-ready agents — Salesforce
- Salesforce — Trusted Enterprise AI Harness — Salesforce
- CRN — Dreamforce 2026 AIforce — CRN
- SiliconANGLE — AIforce composable agents — SiliconANGLE