Dreamforce 2026

Dreamforce 2026 keynote: everything announced, and what actually matters

AIforce, Koa, the Enterprise AI Harness, Headless 360, seven job-ready agents, Agent Fabric, and partnerships with both Google Cloud and AWS. The complete verified roundup, sorted by what changes your architecture and what does not.

Dreamforce 2026 keynote roundup: AIforce, Koa, the Enterprise AI Harness and the cloud partnershipsDreamforce 2026

Dreamforce 2026 produced about a dozen announcements, not the three or four most recaps are carrying. This page lists all of them, separates what landed on keynote day from what landed in the run-up, and sorts them by what should actually change your plans.

Everything quoted below comes from a published source you can open. Where something was said from the stage but has no citable release, this page says so rather than paraphrasing it.

Keynote day: 15 September 2026

AnnouncementWhat it isWhy it matters
AIforce"A live interface layer that brings the full power of Salesforce to wherever people and agents work", launching with Claudeforce, Slackforce and Agentforce CoworkerThe biggest of the lot. It makes your permission model the security boundary for every new surface
KoaSalesforce's first CRM reasoning model, post-trained on NVIDIA Nemotron 3 SuperReasoning becomes a component. Notably, no customer data was used to train it
Google CloudAgentforce and Gemini Enterprise connected over MCP, Hyperforce on Google CloudMCP stops being a developer standard and becomes infrastructure
AWSSalesforce context into Amazon Quick, AWS agents into Slack, Agentforce model choice through Bedrock, Agentforce Voice with Amazon ConnectThe same story as Google, on the same day. That repetition is the actual signal
Agentforce Coworker at AdeccoRollout "across 40 plus countries following a successful pilot in the UK and France"Proof it ships, and a template for how to sequence a rollout

The run-up: August and early September

Dreamforce announcements no longer wait for Dreamforce. Four of the most consequential items landed in the weeks before the keynote, and any recap that starts on 15 September misses them.

AnnouncementDateWhat it is
Headless 36019 AugustEvery Salesforce cloud exposed as "reusable enterprise capabilities that any authorized AI agent can securely discover and use through open standards"
Claudeforce26 AugustSalesforce and Anthropic, the partnership AIforce later launched on
Enterprise AI Harness10 SeptemberThe architecture the whole week sits inside
Seven job-ready agents11 SeptemberCasey, Paige, Carter, Hunter, Marshall, Piper and Fin
Agent FabricThrough 2026MuleSoft's control plane for multi-vendor agents, with governance and discovery expanded in April

They are one announcement, and Salesforce named it

Read separately these are a model, two cloud deals, an interface, a customer win and a pile of agents. Read together they are one architecture, and you do not have to take our word for that because Salesforce published the architecture itself five days before the keynote.

The Enterprise AI Harness is described as bringing together "what agents need to understand the business, reason and plan, take action, and operate within enterprise controls, without companies having to build and manage those capabilities separately for every agent or AI experience". It spans six capabilities: "context, agency, action, governance, security, and models, delivered through a common, composable architecture".

The sentence worth reading twice is this one: "AI reasoning can be open-ended, but enterprise execution often cannot be. The Enterprise AI Harness connects that reasoning to the business rules, policies, and controls required for predictable execution."

That is the thesis of the entire week. Everything else announced is one of those six capabilities getting a product name. Koa is models. AIforce and Headless 360 are action and the surfaces it reaches. Agent Fabric is governance. The Google Cloud and AWS deals are context reaching further out. The seven agents are agency packaged as job roles.

Salesforce has decided the defensible thing is the governed business context, not the screens and not the model. We think that is correct, and the consequence for a customer is the mirror image of it. If reasoning and interface are both swappable, they are cheap to get wrong. The context layer is not swappable, so it is the expensive one, and it is the one most organisations have underinvested in for a decade.

The cloud story is not a Google story

Most coverage this week framed the Google Cloud partnership as a major alignment. It is worth noticing that AWS received an announcement of equivalent weight on the same day, covering Salesforce business context in Amazon Quick, "Agentforce model choice through Amazon Bedrock", Data 360 zero copy expansion, and Agentforce Voice with Amazon Connect. Koa, meanwhile, is built on NVIDIA.

One partnership is an alignment. Two on one day, plus a third-party model foundation, is a posture. Salesforce is deliberately making the cloud and the model into choices, and it can only afford to do that because it intends to own the layer underneath both.

For you that means the cloud and model questions are less strategic than they looked on Monday, and the data and permissions question is more so.

What each one actually changes

AIforce is the one to read twice. Salesforce states that because every request runs on existing permissions, every agent sees only what the person asking can see. That is the right architecture. It also means your sharing model, exactly as it stands today, is about to be exercised by more requests from more surfaces than it was designed for. Detail in Salesforce AIforce explained.

Headless 360 is the sleeper. Its MCP server lets "agents running in Agentforce, Claude, ChatGPT, Cursor, and other AI platforms to dynamically discover, understand, and invoke Salesforce capabilities in real time". Read that surface area honestly. It is considerably wider than AIforce alone, it includes tools your developers are already running today, and the same permission question applies to all of it.

Koa answers the question most model announcements avoid. Salesforce says the training corpus "was built entirely from synthetic scenarios", that "no customer data was used to train the Koa reasoning model", and that it controls the weights and runs the model in its own infrastructure so "no customer data crosses the trust boundary during inference". Training provenance and inference boundary are separate questions, and a vendor answering only the first is a familiar way of sounding reassuring without being reassuring. Both are covered here. More in Salesforce Koa explained.

The cloud partnerships are plumbing, and plumbing is underrated. Platforms of this size choosing published open protocols over bespoke integrations is what turns MCP from a developer convenience into something you can design against. The detail worth stealing is the Tableau one: governance and row-level security "are enforced with every agent query", at the protocol rather than inside the agent. More in the Salesforce and Google Cloud partnership.

Agent Fabric is the governance answer, and it already shipped. MuleSoft's control plane discovers agents across Agentforce, Amazon Bedrock, Google Vertex AI and Microsoft Copilot Studio, and its Trusted Agent Identity "enables agents to execute actions using specific user permissions". If you run agents from more than one vendor, and by next year most enterprises will, this is the layer that stops that becoming an inventory problem nobody owns.

The seven agents are the most concrete thing announced. Named roles with stated availability beat a platform capability you have to assemble. Casey, Paige, Carter, Marshall, Piper and Fin are GA now. Hunter is in pilot with GA stated for November 2026.

Adecco is the proof, and the method. A pilot in the UK and France, then more than 40 countries. That sequence is the opposite of the failure pattern we get called in to fix, which is a proof of concept on curated data declared a success and scaled sideways into teams whose permissions were never examined.

What was announced but is not covered here

Two things we have heard attributed to this keynote have no published release, after searching twice: Salesforce Guardian and AIforce Max Edition.

Guardian is worth a note, because it shows how these recaps go wrong. Cyera ships a product called Agent Guardian. Salesforce ships Agentforce in Security Center and Privacy Center. Merge those in a transcript and you invent a Salesforce product that does not exist. The same risk applies to product names generally this year: Agentforce is now written Agentforce 360 in Salesforce's own releases, and the transcript we reviewed rendered Claudeforce as "CloudForce".

We will add both if Salesforce publishes them. We will not infer them.

The three questions a keynote never answers

Platform announcements describe capability. Delivery is about constraints, and there are three that no keynote has ever addressed because they are specific to your org rather than to the product. We ask all three in the first week of every engagement, and the answers predict the outcome better than anything on the roadmap.

Who can see what, really? Not what the sharing model was designed to do. What it does now, after however many years of profile clones, permission set groups added for a project that ended, sharing rules written to unblock a go-live, and "temporary" Modify All Data that outlived the person who granted it. An interface layer that runs on the requesting user's permissions is only as safe as those permissions are accurate, and most orgs have never audited them against the org chart they have today.

Which system is right when they disagree? Every organisation past a certain size has the same customer in three places with three spellings, the same contract value in CRM and in finance with two numbers, and an account owner in Salesforce who left last quarter. A human reading that notices the contradiction and asks someone. A reasoning chain resolves it silently, picks one, and produces a fluent answer built on the wrong half.

What is the agent not allowed to do? The refusal set is the part teams skip, and it is the part that determines whether the deployment survives its first bad month. Not "be helpful and safe" in a prompt, but an enumerated list: does not quote a price outside the approved band, does not commit to a delivery date, does not tell a customer their claim is approved, does not write to these five fields. Then tests that prove each refusal actually fires.

None of these three are AI problems. They are the ordinary, unglamorous work of running a platform, and every announcement this week raised the cost of having skipped them.

Where all of it sits on your roadmap

AnnouncementAct now, or waitWhat it should trigger
AIforceAct nowA sharing model audit. The work is the same whether you adopt AIforce this year or not, and it is the long pole
Headless 360Act nowFind out which of your developers already have MCP clients pointed at the org. That is a live surface, not a future one
The seven agentsAct now if one matches a real queuePick the one that maps to work you already measure, so the pilot has a baseline
KoaWait, then evaluateNothing structural. Build the evaluation set that lets you compare it against whatever you run today
Agent FabricAct if you run multi-vendor agentsAn inventory of every agent already running against your data, from any vendor
Google Cloud and AWSAct if you already run Gemini or BedrockReview where integrations are point-to-point and would be better on a protocol
Guardian, AIforce MaxWaitNothing. No published release means no procurement conversation

The column that matters is the second one. Announcements arrive at vendor pace. Adoption happens at the pace your data and permissions allow, and those two speeds have never matched.

What we would actually do next quarter

Not a platform decision. An audit.

Trace one workflow end to end. Every object it touches, every field, the sharing model on each, and what a reasoning chain running as a normal user could reach. This routinely surfaces one object that has been Public Read/Write since an implementation nobody currently at the company ran.

Inventory the agents already running. Not the ones you plan to build. The MCP clients, the copilots and the assistants that already have credentials against your org. Most teams are surprised by this list, which is the entire argument for a control plane.

Fix the facts that disagree. Where the same value lives in four systems with four answers, resolve which one wins before any agent reads it. A better model does not resolve a disagreement, it states one side of it more convincingly.

Build an evaluation set from closed work. Twenty cases already resolved, with the human decision as the known-good answer. It outlives every model choice, and when you swap a reasoning model, which the architecture announced this week says you will, this set is what turns that swap from a leap of faith into a measurement.

Write the refusal set down before the prompt. Enumerate what the agent must not do, then write a test for each line. A refusal that has not been tested is a hope.

Then deploy narrowly, the way Adecco did. One surface, one workflow, and a named person who can switch it off without asking anyone's approval.

How we work on this

We are a Salesforce consultancy and an OpenAI Select Partner, which means we spend our time on both halves of the problem announced this week: the platform underneath and the reasoning layer on top.

The engagements that come out of a week like this one usually start in the same place. A grounding and permissions audit, which is the trace described above, delivered as a list of what an agent could reach today and what should be closed before it does. An agent inventory across every vendor already connected. A data reconciliation pass on the two or three objects a target workflow actually depends on. An evaluation harness built from closed cases, so model and prompt changes can be measured rather than argued about. Then a narrow pilot with the refusal set tested, on one surface, sized so that it can be switched off without a committee.

That is deliberately less exciting than the keynote. It is also the part that is still true in eighteen months, whichever of these products you end up running.

The honest summary

This was a strong week and the architecture behind it is coherent, which is more than most platform keynotes manage. Salesforce published the architecture before it published the products, and the products fit it.

It is also, like every platform announcement, a statement about what becomes possible rather than what becomes easy. The organisations that get value from any of this in 2027 will not be the ones that adopted first. They will be the ones whose data, permissions and business logic were worth connecting to when the interface layer arrived.

Sources

  • SynconAI Consulting are Simply the Best in the Business When it comes to Salesforce implementation and AI-powered solutions, SynconAI are in a league of their own. Their expertise, dedication, and ability to deliver results that truly move the needle sets them apart from every other consulting partner we've worked with. What they achieved with our Sales Cloud, Service Cloud, and custom Agentforce agent has completely transformed how we operate streamlining our pipelines and our customer service, and automating tasks that used to consume hours of our team's time. They don't just implement technology they transform businesses. If you want the best, you work with their team.

    Jack BennettConsumer Goods & RetailUnited States

  • I had a very urgent deadline for our project reporting to be delivered and needed to build the module, dashboard and output reports in Salesforce. SynconAI were very responsive - they met with me online, responded to my emails quickly and took calls - whatever was needed to progress the work quickly. We are thrilled with the outcome and will continue to work with SynconAI in the future to continue to build our Salesforce capability and platform.

    Salesforce Managed ServicesAustralia

  • The team at SynconAI were fantastic, and promptly delivered on each project. They were able to guide us through every stage and made sure we were satisfied with the outcomes on multiple scopes of work.

    ManufacturingAustralia

  • They have been great and helping us transform out business by bringing what I conceptualize to life. Great at translating process/workflow needs into a solution. Been a pleasure work with and they're a critical part of our team and will be instrumental into bringing about my vision.

    Financial ServicesUnited States

  • Working with SynconAI was a seamless and highly professional experience from start to finish. They took the time to deeply understand our business processes before designing and implementing a Salesforce solution tailored specifically to our operational needs. The team demonstrated strong technical expertise across Salesforce configuration, automation, integrations, reporting, and user experience design.

    Salesforce Implementation

Common questions

Answered, directly.

What people are asking us about this announcement.

On keynote day, 15 September 2026: AIforce, a live interface layer launching with Claudeforce, Slackforce and Agentforce Coworker; Koa, Salesforce’s first CRM reasoning model built on NVIDIA Nemotron; an expanded Google Cloud partnership connecting Agentforce and Gemini Enterprise over MCP; and an expanded AWS collaboration covering Amazon Quick, Bedrock model choice and Agentforce Voice. In the run-up Salesforce also announced the Enterprise AI Harness, Headless 360, a portfolio of seven job-ready agents, Claudeforce and Slackforce, and the Adecco Group announced an Agentforce Coworker rollout across more than 40 countries.

Seven were announced: Casey for customer service across voice, SMS, WhatsApp and chat; Paige for IT and HR requests; Carter for e-commerce; Marshall for supply chain and back-office orchestration; Piper for inbound sales qualification; Fin for complex customer experience workflows; and Hunter for outbound sales. Six are generally available now. Hunter is in pilot with general availability stated for November 2026.

AIforce, with Headless 360 close behind. A reasoning model is a component you can swap and a cloud partnership is plumbing, but an interface layer changes what your Salesforce org is for. If the UI is no longer fixed, the durable value of your org becomes the quality of its data, logic and permissions, and nothing else survives the move.

There is no way to answer that from a press release, and anyone who tells you otherwise is guessing. Build an evaluation set of twenty already-resolved cases from your own closed work, with the human decision as the known-good answer, and run both against it. That set costs a week, outlives every model on the market, and is the only thing that turns a swap into a measurement.

No. Google Cloud and AWS both received expanded partnership announcements on the same day, and Koa is built on NVIDIA Nemotron. Reading any one of those as an alignment misses the pattern. Salesforce is making the cloud and the model into choices, which is only possible because it intends to keep the layer underneath them, your governed business context.

Because no citable release exists for either, and we searched twice. Guardian in particular looks like transcript confusion: Cyera ships a product called Agent Guardian and Salesforce ships Agentforce in Security Center, and a keynote recap that merges those into a new Salesforce product would be inventing one. Every other claim on this page is quoted from a source you can open and check. These will be added if and when Salesforce publishes them.

Free architect conversation

Talk to an architect, not a sales rep.

60 seconds to brief us, and a certified architect replies within one business day.

What are you looking to architect?

Pick the closest fit. You can add detail in a moment.

Which clouds or systems are in scope?

Optional. Choose any that apply, or skip ahead.

Where does your org stand today?

Optional. A few sentences is plenty: what is working, what is stuck, and what you want to be true. Or skip ahead and tell us on the call.

Who should the architect reach?

A certified architect will reply to these details.

Takes about 30–60 seconds · No obligation · Architect replies within one business day

Protected by reCAPTCHA. Google's Privacy Policy and Terms apply.