Salesforce in Claude Permissions and Governance Guide
On this page
Quick answer
Salesforce says an admin connects Salesforce in Claude once, centrally manages authentication and permissions, and routes answers and actions through existing Salesforce permissions and business rules. That is a design claim to verify—not permission to skip a new integration review.
The trust path now includes the user, Claude workspace, plugin, Salesforce connection, any Slack or email connectors, generated reasoning, and actions returned to Salesforce. Prove least privilege, denial, approval, audit, failure, incident, and offboarding behavior across the entire path.
Control claims and required proof
| Vendor statement | Evidence to require |
|---|---|
| Existing permissions apply | Object, field, record, sharing, restriction, and permission-set tests for representative users |
| Business rules are enforced | Validation, flow, approval, duplicate, required-field, and blocked-action test results |
| One admin connection serves the team | Connection owner, credential model, user mapping, assignment, revocation, rotation, and break-glass plan |
| No per-user reconfiguration | Verified onboarding and offboarding with no residual access |
| Field-specific updates | Before/after evidence, exact record and field, concurrency behavior, and audit event |
| External send can require approval | Recipient and content preview, approver identity, delivery evidence, retry and duplicate controls |
Do not accept a successful administrator demo as proof for sellers with different roles, territories, account teams, sharing rules, managed packages, or connector access.
Identity and least privilege
Document how the Claude user maps to the Salesforce user for every read and write. Test disabled users, suspended Claude access, role changes, permission-set removal, delegated administration, session expiry, token rotation, sandbox versus production, and cross-org confusion.
Build a role matrix for representative sellers, managers, operations staff, administrators, contractors, and support users. Each test should include records they may see, records they must not see, fields hidden by field-level security, restricted objects, private activities, and actions denied by business rules.
Connector and data boundary
The product materials mention Salesforce, Slack, email, and Claude connectors. Inventory each enabled source:
- data types, accounts, channels, mailboxes, objects, fields, and time windows;
- user and administrator consent;
- where content is processed, stored, logged, cached, retained, and deleted;
- training and product-improvement settings, subprocessors, residency, legal holds, and incident terms;
- how source citations, freshness, and authorization survive when content is combined.
Treat instructions inside CRM text, email, attachments, or Slack as untrusted data. Test prompt injection that asks Claude to reveal another record, change its goal, suppress evidence, or invoke a higher-risk skill.
Read, reason, and write separately
For a sensitive workflow, preserve three checkpoints:
- Read evidence: show the exact source records and timestamps available to the user.
- Reasoned proposal: label assumptions, missing data, conflicts, and recommendations without changing the system of record.
- Authorized action: preview the record, fields, workflow, message, or recipient; obtain required approval; then reconcile the final Salesforce state.
Use idempotency or equivalent duplicate protection for retries. If a multi-step action partially fails, stop, expose completed steps, and route recovery to an accountable owner instead of repeating the entire sequence blindly.
Audit and operating response
An auditor should be able to reconstruct user identity, skill and version, source records, connector context, prompt or objective, proposed action, approval, Salesforce request, business-rule response, record change, error, retry, and final state.
Define alerting for denied-record probes, unexpected write volume, new external recipients, repeated validation failures, connector-scope drift, disabled logging, admin changes, and anomalous cross-user access. Practice token revocation, plugin disablement, rollback or correction, user notification, evidence preservation, vendor escalation, and revalidation.
Use the pilot guide for lifecycle boundaries, the 37 skills guide for the action register, the Claudeforce versus Agentforce guide for direction, and the readiness check for a local gate.
Frequently asked questions
Does Salesforce in Claude use existing Salesforce permissions?
Salesforce says it does. Verify object, field, record, sharing, workflow, connector, and action behavior in the exact pilot tenant.
Does using existing permissions remove the need for a security review?
No. The integration adds Claude, a plugin, connectors, generated reasoning, and new action paths.
Can it send external email without approval?
Salesforce says customers can configure whether Claude checks before sending externally. Begin with explicit approval and test the complete send path.
Are all enterprise controls complete?
The product page says additional controls for data storage, access, and automated review are still being developed.
Official sources
Source check: August 29, 2026. Recheck contracts, data handling, regional availability, identity, permission behavior, connectors, audit, and future controls in the live tenant.