惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Security @ Cisco Blogs
H
Hacker News: Front Page
P
Privacy International News Feed
N
News and Events Feed by Topic
T
Threatpost
Simon Willison's Weblog
Simon Willison's Weblog
S
Schneier on Security
K
Kaspersky official blog
S
Secure Thoughts
V2EX - 技术
V2EX - 技术
Security Latest
Security Latest
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
www.infosecurity-magazine.com
www.infosecurity-magazine.com
C
CERT Recently Published Vulnerability Notes
L
Lohrmann on Cybersecurity
Jina AI
Jina AI
P
Proofpoint News Feed
AI
AI
雷峰网
雷峰网
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Recent Commits to openclaw:main
Recent Commits to openclaw:main
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
博客园 - 叶小钗
Webroot Blog
Webroot Blog
Apple Machine Learning Research
Apple Machine Learning Research
SecWiki News
SecWiki News
罗磊的独立博客
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
Google DeepMind News
Google DeepMind News
Cyberwarzone
Cyberwarzone
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
Schneier on Security
Schneier on Security
The GitHub Blog
The GitHub Blog
S
Security Affairs
Blog — PlanetScale
Blog — PlanetScale
Last Week in AI
Last Week in AI
P
Proofpoint News Feed
月光博客
月光博客
D
Docker
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
Securelist
W
WeLiveSecurity
T
Troy Hunt's Blog
A
Arctic Wolf
博客园 - 司徒正美

Salesforce

Scale Your MRR: Subscription Management For Small Business Streamlining Commerce Media Ad Inventory Management 12 AI Sales Strategies for Startups That Actually Work Sell Smarter: Ecommerce Metrics To Track For Your Small Business Shop Apply the Orchestration Density Framework to Your Next Automation Decision Wait, Black Friday Planning In Spring? It’s Time to Start Holiday Promotions AI-First Operations, One Process at a Time How BCU Is Transforming Banking Service with Agentforce Salesforce Headless 360: What the Agent Consumer Means for Your Integration Architecture Meet Customers Where They Are: Agentforce Contact Center Now Offers WhatsApp Voice 11 Free Lead Generation Tips for Small and Growing Businesses SFR-VibeTrain: The Agent That Trains Agents Why Technical Accuracy is the Wrong Metric for Agent Success Strengthening Salesforce Security Against AI-Driven Threats Join Us in the Community Hub at Connections 2026 The Best Way To Build AI Agents That Customers Trust 5 Ways AI is Changing the Communication Game For Startups Trust in the Era of Agents: Highlights from the 2nd Annual Trusted AI Impact Report You Can Be an Agentic Enterprise No Matter What Size Business How to Make Your Email Marketing Accessible for Everyone What is Headless? Don’t Lose Your Head, SMBs: It’s a Good Thing Architect the Future UI: Slack as Your Agentic Surface Point of Sale Innovations to Modernize the Shopper Experience Governing the Agentic Enterprise at Scale with MuleSoft Omni Gateway How to Cut Service Time with Case Routing Automation 5 Tips for Marketers to Get Started with Salesforce Flow No One is Vibe Coding Trade Promotion Management 7th Edition State of Sales Report: 3 Growth Trends for Startups and SMBs How the Architect Vista Brought Architectural Thinking to Life at TDX 2026 5 Steps to Develop an Architect Mindset With AI Why AI Isn’t Replacing Developers, It’s Empowering Them 10 Ways to Make Your AI Agent a Better Communicator AI in Design 2025: What Real Use Taught Us. How Salesforce Personalization Learns Which Offers Drive Revenue The 4-Step Guide to Salesforce Agent and Application Development Get Ready for Connections 2026: Top Sessions and New Reveals 8 Ways AI Agents Are Evolving in 2026 4 Principles to Make the Right Salesforce UI Decisions Apprentice Journey Shines a Light on Talent Pathways at Salesforce Agent Script: The Control Plane for Agentic Decisions Scaling the Agentforce Life Sciences Ecosystem to Drive the Future of Pharma and MedTech Unlocking Unstructured Data: Building AI-Powered Support Triage with Data 360 Asking For a Friend: What Are Rich Communication Services (RCS)? 5 Slack Shortcuts For Small Teams 195% ROI In Field Service? Here’s How They Did It Submit Your Architect Session: The Dreamforce 2026 Call for Participation Is Open What Is an AI Assistant for Small Business? B2C Commerce April release: Transforming the B2C developer experience with agents Meet Your 24/7 Prospecting Partner — And 5 More Stand-Out Features In Our April Release 11+ Small Business YouTube Channels You Need to Follow Today Stop Treating Disputes Management Like IT Tickets Limitless Service: A New Operating Model for Growth in the Agentic Era What is Transactional Reconciliation in Email and SMS Marketing? How to Prepare for National Small Business Week (2026) How to Design a High-Scale Multi-Cloud Incident Journey 10 Ways An AI CRM Can Amplify Your Startup Vibe Code Better Agents with Agentforce Free vs. Paid CRM: Which is Right for Your Business? Salesforce Customer Success Awards 2026: Lead Era of the Agentic Enterprise 12 Free Webinars for Small Business Owners (2026) The Agentforce Life Sciences Consultant Certification Maximize Growth: The Power of Partnerships for SMBs Salesforce AI Research at ICLR 2026 Data Protection For Small Business: How To Safeguard Yourself Beyond 100K Tokens: Evaluating AI Agents in Long-Context Software Engineering Top 32 Small Business Tools To Try Today 6 New Innovations Redefining Salesforce Development How to Win the Battle for Attention in the Agentic Email Inbox Mastering the Eisenhower Matrix: Prioritize Like a Pro 10 Signs It’s Time To Upgrade Your CRM and How To Get Started (2026) Celebrating 10 Years of Financial Services Innovation How SMBs Can Gain An Edge With Agentic AI: Key Trends From Our Marketing Report How MAN Truck & Bus is Shaping the Future of Sales with Salesfive Introducing the Future of Salesforce Data Protection: Backup & Recover Next Stop Making AI Slop – Build a Foundation for Authentic AI Content 5 Tips to Help Marketers Navigate AI Email Summaries Data Sharing: Is it Safe? Is it Secure? Everything You Need to Know Small Business Week Readiness: 4 Things to Do Before May (2026) How Salesforce Employees Make an Impact During Earth Month AI Agents Are Advancing Rapidly… Is Your Testing Strategy Keeping Up? What Is Microproductivity and Why Is It Helping So Many Teams? TDX 2026 Roundup: Agentforce Edition 3 Ways Salesforce Connections Has Boosted My Career AI Agents Don’t Just Answer‌ — ‌They Act. Do You Have a Governance Strategy? The Future of MedTech Field Execution is Agentic 5 Steps to Prepare Your Data For an AI CRM From Break/Fix to Profit Engine: Aftermarket Service for Robot OEMs Building Trusted Human-Agent Collaboration: A Practical Framework ISV Strategy for the Salesforce Summer ’26 Release 5 Email Marketing Tips for Small Business Commerce Shops Should You Give Your AI Agent a Human Name? Creating Pathways into AI for People with Disabilities The Organized Chaos of Upfronts: 3 Hurdles Impacting Your Yield Trying to Scale Beyond ‘One-Off’ AI Tasks? You’re Probably Using the Wrong Interface What is Cost Per Lead (CPL)? The Case for Unified CCaaS and CRM — And Why the Data Makes It Clear In the New Era of AI, You Need to Win Over Both Humans and Agents What Is SPIN Selling? A Way to Build Trust With Your Customers G2 Crowns Salesforce as Best Financial Services Software Hidden Insights: The Guide to Tableau For Small Business Owners
Headless Doesn’t Mean Ungoverned: How Trust Works When Agents Call Salesforce
Miriam McCab · 2026-05-20 · via Salesforce

When a user logs into Salesforce and clicks a button, trust is familiar. You know who they are, you decide what they’re allowed to do, and there’s an audit trail with their name on it. When an external agent connects to your org, it feels different. Yet, the same principles apply, even if the session is established and scoped differently.

For a human user, we manage scope and security through login and user permissions with profiles and permission sets. For an external agent, what it can access and do is governed through OAuth and the external client app configuration.

Architects designing agentic systems often focus on the capabilities of the agent. The new question for the Salesforce Architect designing for Salesforce Headless 360 is: what should agents be allowed to do, and how does Salesforce know whether to trust them in the first place?

This blog answers that question across five dimensions: 

  • how authentication works without an interactive login, 
  • how authorization scopes what the agent can access, 
  • how you trace what it actually did
  • how you manage the token lifecycle, and 
  • how the Well-Architected Framework fits into the decisions you make along the way.

Understand why Headless 360 changes the trust equation

In a traditional Salesforce integration, an external client app authenticates on behalf of a named user or as a service account and interacts with a defined API. That API contract sets the scope: the integration can only do what the API exposes, and you know precisely what that is.

With an external agent connecting via Headless 360, there is no traditional API contract. The agent gets whatever CRUD access the authenticated user holds and determines how to use it. You don’t control who built the agent, what model it is running, or what its internal guardrails allow. You can’t rely on those guardrails to keep the agent within your boundaries.

That means your permission design has to do the work the API contract used to do. Object permissions, field-level security (FLS), and sharing rules are your primary controls. Design them specifically for the agent, not as a byproduct of a human user’s access needs. If a field has no business being visible to the agent, restrict it. If an object is outside the agent’s scope, remove access entirely.

When an external agent connects to Headless 360 via Model Context Protocol (MCP), every call runs under the authenticated user’s identity. The platform security model applies automatically: object permissions, FLS, and sharing rules all work exactly as they would in the browser.

Per-user authentication scopes every agent call to that individual’s exact permissions, preserving the per-user permission boundary throughout. For governance at the MCP tool call level, Agent Fabric adds least-privilege enforcement on top.

Introducing Salesforce Headless 360. No Browser Required.

Everything on Salesforce is now an API, MCP tool, or CLI command, and agents can use all of it.

Understand how Headless 360 authenticates external agents

For external agents connecting via Headless 360, there is one prescribed authentication flow: OAuth 2.0 Authorization Code with PKCE (Proof Key for Code Exchange). PKCE replaces the client secret used in traditional OAuth flows. This is the OAuth flow for Headless 360 for a reason, as Headless 360 is designed for public clients (for example, desktop apps, CLI tools, and AI clients like Claude Desktop), where storing a client secret securely is not practical. The agent presents a Consumer Key and a PKCE code verifier. No secret is shared or stored.

Other OAuth flows are ruled out for specific reasons. The client credentials flow would create a service account pattern where all calls run as one identity, losing per-user permissions and the audit trail. Implicit flow is deprecated and does not support refresh tokens. And, the username-password flow is not appropriate for agentic contexts.

In the prescribed Authorization Code with PKCE flow, every connection running under the authenticated user’s identity preserves per-user permissions and the audit trail. The agent can only access what that user can access, and every action is attributable to that user, not to a generic bot or service account.

Two scopes matter for configuration: mcp_api, which grants access to MCP servers, and refresh_token, which allows the agent to operate without re-prompting the user on every call. Without refresh_token, the agent cannot sustain a session across multiple interactions.

Scope what the agent can access

Authentication answers “who are you.” Authorization answers “what are you allowed to do.” For external agents connecting via Headless 360, the answer to that second question lives in the permission set and FLS configuration of the authenticated user. Design it deliberately.

Consider an organization that has standardized on Claude as their enterprise AI platform. Claude connects to Salesforce via Headless 360 to access customer data as part of a broader workflow. The agent needs to read account and contact records to identify the customer, and read case history to understand context. That is the full extent of what it needs to do in Salesforce.

If you assign that agent a permission set built for a customer service rep, it inherits everything that rep can see, including opportunities in the pipeline, billing data, financial records, internal notes, and fields that have no bearing on the agent’s task. The agent may never use that access intentionally. But if the permission is granted, you cannot rely on the agent’s internal guardrails to ensure it never uses it.

Build the permission set from scratch against the agent’s documented action list. Start with what the agent needs to do, derive the minimum object and field access required to do it, and build to that. Grant read access on Account and Contact. Grant read access on Case and the specific fields relevant to case history. Nothing else. Again, if a field is not on the action list, restrict it. And if an object is outside the agent’s scope, remove access entirely.

The same principle applies to FLS. Go field-by-field on the objects the agent touches. A customer’s billing address, payment method, or internal account tier may sit on the same object as the fields the agent legitimately needs. FLS lets you expose the fields the agent requires without exposing the ones it doesn’t. This granularity is what makes the permission set auditable: you can read it and know exactly what the agent can see.

Design the audit trail before you need it

With a human user, you can investigate an incident by talking to the person. With an agent, the audit trail is your only witness. That shifts it from a compliance checkbox to a core architectural concern, and the Well-Architected Framework Trusted pillar treats it as one.

Event Monitoring captures the external client app name, the authenticated user, the object, the operation, and timestamps for every API call the agent makes. That data tells you what happened. To know what changed, enable field history tracking on every object the agent can modify. Together, these two layers give you the audit depth to reconstruct an incident, support a rollback, and satisfy the traceability requirements the Well-Architected Framework recommends for any production agentic deployment.

For retention, stream Event Monitoring data to Salesforce Shield or an external log management tool.

Manage the token lifecycle deliberately

The refresh_token scope is not optional. Without it, the OAuth session cannot re-authenticate on its own and the agent will fail to operate across multiple interactions. Include it alongside mcp_api when you configure the external client app.

The refresh token is tied to the individual authenticated user’s OAuth session. There is no pooling and no shared service account. This is by design: it preserves the per-user permission boundary and the audit trail. It also means that revoking a user’s token immediately removes the agent’s ability to act on their behalf. That matters when access changes due to role changes, departures, or security incidents.

One operational consideration worth building into your deployment plan: in some client environments, tokens stored locally can go stale without triggering automatic re-authentication on session restart. This is not specific to Headless 360, but a function of how the OAuth lifecycle is managed on the client side. Design your agent deployment to handle token refresh explicitly rather than assuming the client will manage it. Test re-authentication behavior in a non-production environment before go-live.

Govern the integration, not just the agent

The question this post started with was how Salesforce knows whether to trust an external agent. The answer is that it doesn’t decide at runtime. You decide at design time, through the external client app configuration, the authenticated user’s permission set and FLS, and the audit trail you put in place before anything goes to production.

The mechanisms are the same ones you already use. OAuth 2.0 Authorization Code with PKCE establishes the session. The authenticated user’s profile and permission sets scope what the agent can access. Event Monitoring and field history tracking tell you what it did. None of this requires new tooling. It requires deliberate design.

The shift from traditional integrations to agentic ones is not a shift in platform capability. It is a shift in design responsibility. A traditional integration is bounded by its API contract. An external agent is bound by the permissions you give it and nothing else. That makes the permission design, the FLS configuration, and the audit trail more consequential than they would be for a known, deterministic integration.

Headless doesn’t mean ungoverned. It means that the governance is yours to build, using the tools already provided by the Agentforce 360 Platform.