Another year of Dreamforce in the books! In comparison to years past, Dreamforce 2026 did not have the feeling that Salesforce was repackaging and rebranding existing tech just to try to make a new splash. At Dreamforce 2026, Salesforce announced material updates that will impact how users work with their CRM on a day-to-day basis.
Chiefly, Salesforce announced AIforce at Dreamforce ’26 and framed it bluntly: AI replaces the UI. For teams administering a Salesforce org, that sentence is either a threat or a shrug depending on what is underneath it. Here is what shipped, what is real today, and what it means for the permissions model your team maintains.
AIforce: a dynamic interface, customizable by the user
AIforce is an interface layer. Instead of navigating to a screen, a user describes what they want and gets a composed view assembled on the spot. That can happen inside Claude, Slack, Lightning, Amazon Quick, or Google Gemini Enterprise.
The part that matters for admins is what does not change. Every request runs on existing permissions and business rules. An agent sees exactly what the person asking can see, not more. Salesforce also states a zero data retention policy: data used to answer a question is not retained by the model. With an emphasis on data security, Marc Benioff, Salesforce’s longtime CEO, assured the crowd that protecting customer data is the customer’s right.

Five adjacent pieces
Claudeforce, now in open beta, puts Salesforce inside Claude with 37 prebuilt sales skills aimed at prospecting through pipeline management. A separate Salesforce Development plug-in for Claude Code adds 40+ skills. Deloitte, GitLab, and Legora are named beta customers. Tableau analytics and service, marketing, and commerce skills are on the roadmap, not in the box.
Slackforce lets someone log a note or update a record without opening Salesforce. Slackforce Surfaces assembles live dashboards and reports on prompt, and Slackbot can reason over Slack conversations alongside CRM data. Common actions include flagging inactive accounts, reassigning ownership, and drafting follow-ups.
Agentforce Coworker is the AI teammate in Lightning, available to customers now. Salesforce reports 100,000 users activated in the first 35 days. Fulton Bank went from zero to more than 20 production use cases supporting roughly 3,000 users.
The Headless Toolkit is the developer surface: 60+ MCP tools, 30+ coding skills, 4,000+ APIs, and 220+ CLI commands, feeding an AgentExchange with Anthropic, AWS, Google, Vercel, Docusign, Ramp, Rippling, and others building on top.
Koa is Salesforce’s first CRM reasoning model, built on NVIDIA Nemotron 3 Super and trained on a synthetic dataset representing 27 years of CRM knowledge across 14+ industries. Salesforce claims it matches or beats leading models on CRM actions with three times fewer errors. It is in pilot now, with GA targeted for winter 2026 in U.S. regions.

What this actually asks of your org
When the interface was fixed, the screen was a control surface. A field your team did not expose was a field nobody saw. Composed views remove that backstop, making the permissions model the primary control between a question and an answer.
Three things get more load-bearing:
- Field-level security and sharing rules. Previously theoretical gaps become reachable by anyone who can phrase a question.
- Data quality. A composed view is only as good as what it composes. Stale ownership, duplicate accounts, and missing activity history stop being reporting annoyances and start being wrong answers delivered confidently.
- Capture completeness. If reps work in Slack and Claude, the record of what happened has to land in the CRM regardless of where the work occurred. Gaps in activity capture get more expensive, not less.
None of that is new work. It is existing work that just got a deadline.
What is real today vs. what is announced
Available now: Agentforce Coworker, Claudeforce (open beta), and the Headless Toolkit. Coming: Slackforce Surfaces, Koa GA (winter 2026, U.S.), and the service, marketing, and commerce skill sets.
The sensible sequence is to treat the GA pieces as pilotable and the beta pieces as evaluable — and to spend the interval auditing sharing rules and activity capture, because that work pays off whichever pieces your org eventually turns on.
Where to start
Pull your field-level security audit and ask a simple question of it: if any user could ask for anything they have access to, in plain language, would every answer be one the business is comfortable returning? Most orgs have carried a few gaps that the UI quietly covered. This is the quarter to close them.


