Salesforce data in Claude is no longer a future scenario. An employee can use an MCP connection to ask questions about accounts and opportunities without opening Salesforce. That is convenient, but it raises a question you would rather answer up front than afterwards: who sees which records through that connection?

Two routes, different status

There are currently two separate things, and they are often mixed up.

Hosted MCP servers. In a post on its developer blog, Salesforce states that these have been generally available since April 2026, for Enterprise Edition and above. According to that post an MCP server does not switch on by itself: you enable it deliberately.

Salesforce in Claude. This is a plugin that Salesforce announced on 26 August 2026 as part of Claudeforce, the expanded partnership with Anthropic. According to Salesforce, the plugin started as a pilot, with an open beta to follow in September 2026. Salesforce gives no date for general availability. Anthropic reports a beta for organizations that Salesforce approves, with Sales Cloud Enterprise as a prerequisite. Expect further changes, and check the current status before you build on it.

The question is not the technology

According to Salesforce, both routes work within the permissions of the signed-in user. That means your existing setup decides what becomes visible. A generously configured profile used to be an unnoticed risk, because nobody exploited it. Once an AI tool can search through it quickly, it becomes visible.

So before you switch anything on, work through these points:

  • Profiles and permission sets. Who may read which objects and fields? Look especially at users who have more access than their job requires.
  • Sharing rules. Which records are visible to whom through roles, teams and rules? Are those the records you deliberately share?
  • Sensitive fields. Do you hold personal data, pricing agreements or bank details? Restrict access through field-level security, not through agreements.
  • Write access. Is the connection read-only, or can it also change data? For Salesforce in Claude, Anthropic says Claude asks for approval of each change by default. Check that this is how yours is set.
  • Logging. Which actions are logged, and can you later find out who queried or changed something through which connection? Verify this for your own licence and configuration.
  • Where the data goes. Where does the answer end up, and under what terms with your AI vendor? Put that in your policy.

Start small

Do not switch a connection on for everyone at once. Start with a small group, a limited set of objects and read access. See what is asked in practice and adjust the permissions. Only then do you expand.

This is the same kind of work as the checks in our article on Agentforce switching itself on with Winter ’27: the switch is not the risk, what becomes visible afterwards is.

Have your setup reviewed first

Our consultancy reviews your profiles, permission sets and sharing rules, points out where the connection would reveal more than you want, and helps you start the first group of users safely. Get in touch and we will schedule it.