# Dreamforce 2026 keynote: everything announced, and what actually matters

AIforce, Koa, the Enterprise AI Harness, Headless 360, seven job-ready agents, Agent Fabric, and partnerships with both Google Cloud and AWS. The complete verified roundup, sorted by what changes your architecture and what does not.

**Published:** 2026-09-16
**Canonical:** https://synconai.com/dreamforce-2026-keynote-announcements
**Author:** SynconAI Architecture Team

## In short

Dreamforce 2026 produced roughly a dozen announcements, not four. On keynote day Salesforce announced AIforce, the Koa reasoning model, and expanded partnerships with both Google Cloud and AWS. In the weeks before it announced the Enterprise AI Harness, Headless 360, seven job-ready agents, Claudeforce and Slackforce. Together they describe one architecture: Salesforce keeping the business context and opening the model and interface layers to everyone else.

## What the vendor announced

- **Salesforce Unveils AIforce, Bringing the Full Power of Its Platform to Any Interface** (2026-09-15)
  https://www.salesforce.com/news/stories/aiforce-announcement/
  > AIforce unlocks tremendous value by enabling agents anywhere to reason and take action across all the data, workflows, and logic inside Salesforce Instead of fixed UI, AIforce empowers anyone to build composable, intelligent, live interfaces, wherever work happens
- **Announcing Koa: Salesforce’s First CRM Reasoning Model, Built on NVIDIA Nemotron** (2026-09-15)
  https://www.salesforce.com/news/press-releases/2026/09/15/koa-reasoning-model/
  > Koa is trained with 27 years of Salesforce CRM intelligence to enable agents to reason through the complex, multistep tasks required for enterprise
- **Salesforce and Google Cloud Unify Infrastructure and Agents for One Connected AI Stack** (2026-09-15)
  https://www.salesforce.com/news/stories/salesforce-google-cloud-unify-infrastructure-and-agents/
  > Expanded strategic partnership enables cross-platform agent reasoning and action on a shared infrastructure and data foundation, brings Salesforce workloads to Google Cloud through Hyperforce, and accelerates AI adoption
- **AWS and Salesforce Put CRM Data, AI Agents, and Model Choice Into the Tools Teams Use Every Day** (2026-09-15)
  https://www.salesforce.com/news/stories/aws-salesforce-enterprise-ai-expansion/
  > New integrations bring Salesforce data, context, and actions into Amazon Quick, AWS agents into Slack, and Agent2Agent (A2A) support for real-time, bidirectional voice between Agentforce Voice and Amazon Connect Customer
- **Salesforce Introduces the Trusted Enterprise AI Harness** (2026-09-10)
  https://www.salesforce.com/news/stories/enterprise-ai-harness/
  > A new architecture that gives AI a shared understanding of the customer and the business and enables it to act with trust, spanning context, agency, action, governance, security, and models, delivered through a common, composable architecture
- **Salesforce Expands Agentforce With a New Portfolio of AI Agents Built for High-Value Work** (2026-09-11)
  https://www.salesforce.com/news/stories/agentforce-job-ready-ai-agents/
  > New job-ready agents help companies get to business outcomes faster across sales, service, commerce, and the workforce
- **Salesforce Turns Enterprise Applications into Enterprise Capabilities** (2026-08-19)
  https://www.salesforce.com/news/stories/expanding-headless-360-enterprise-capabilities/
  > Headless 360 is expanding across the Salesforce platform, transforming every Salesforce cloud into reusable enterprise capabilities that any authorized AI agent can securely discover and use through open standards
- **Salesforce Advances Agent Fabric: New Guided Determinism and Governance Controls to Scale Multi-Vendor AI Faster** (2026-04-15)
  https://www.salesforce.com/news/stories/agent-fabric-control-plane-announcement/
  > Expanded agent and MCP discovery, advanced capabilities for deterministic orchestration, and LLM governance give customers a trusted control plane for enterprise-grade agent management
- **Adecco Group announces Salesforce’s Agentforce Coworker rollout across 40 countries** (2026-09-15)
  https://www.adeccogroup.com/our-group/media/press-releases/adecco-group-salesforce-agentforce-40-countries
  > The Adecco Group (SIX: ADEN) today announced the global rollout of Agentforce Coworker across 40 plus countries following a successful pilot in the UK and France

## What to take away

- It is one architecture, not a dozen announcements. Salesforce named it itself: the Enterprise AI Harness, spanning context, agency, action, governance, security and models.
- Google Cloud was not a Google alignment. AWS got an equivalent announcement the same day, and Koa runs on NVIDIA. The posture is deliberate cloud and model neutrality.
- The seven new agents are the most concrete thing announced. Casey, Paige, Carter, Marshall, Piper and Fin are GA now; Hunter is in pilot with GA in November 2026.
- AIforce is still the one that changes your architecture, because it makes your existing permission model the security boundary for every new surface.
- Headless 360 is the quiet one. Its MCP server lets agents in Claude, ChatGPT and Cursor invoke Salesforce capabilities directly, which is a much larger surface than AIforce alone.

## Our read

Dreamforce 2026 produced about a dozen announcements, not the three or four most recaps are carrying. This page lists all of them, separates what landed on keynote day from what landed in the run-up, and sorts them by what should actually change your plans.

Everything quoted below comes from a published source you can open. Where something was said from the stage but has no citable release, this page says so rather than paraphrasing it.

## Keynote day: 15 September 2026

| Announcement | What it is | Why it matters |
| --- | --- | --- |
| **AIforce** | "A live interface layer that brings the full power of Salesforce to wherever people and agents work", launching with Claudeforce, Slackforce and Agentforce Coworker | The biggest of the lot. It makes your permission model the security boundary for every new surface |
| **Koa** | Salesforce's first CRM reasoning model, post-trained on NVIDIA Nemotron 3 Super | Reasoning becomes a component. Notably, no customer data was used to train it |
| **Google Cloud** | Agentforce and Gemini Enterprise connected over MCP, Hyperforce on Google Cloud | MCP stops being a developer standard and becomes infrastructure |
| **AWS** | Salesforce context into Amazon Quick, AWS agents into Slack, Agentforce model choice through Bedrock, Agentforce Voice with Amazon Connect | The same story as Google, on the same day. That repetition is the actual signal |
| **Agentforce Coworker at Adecco** | Rollout "across 40 plus countries following a successful pilot in the UK and France" | Proof it ships, and a template for how to sequence a rollout |

## The run-up: August and early September

Dreamforce announcements no longer wait for Dreamforce. Four of the most consequential items landed in the weeks before the keynote, and any recap that starts on 15 September misses them.

| Announcement | Date | What it is |
| --- | --- | --- |
| **Headless 360** | 19 August | Every Salesforce cloud exposed as "reusable enterprise capabilities that any authorized AI agent can securely discover and use through open standards" |
| **Claudeforce** | 26 August | Salesforce and Anthropic, the partnership AIforce later launched on |
| **Enterprise AI Harness** | 10 September | The architecture the whole week sits inside |
| **Seven job-ready agents** | 11 September | Casey, Paige, Carter, Hunter, Marshall, Piper and Fin |
| **Agent Fabric** | Through 2026 | MuleSoft's control plane for multi-vendor agents, with governance and discovery expanded in April |

## They are one announcement, and Salesforce named it

Read separately these are a model, two cloud deals, an interface, a customer win and a pile of agents. Read together they are one architecture, and you do not have to take our word for that because Salesforce published the architecture itself five days before the keynote.

The Enterprise AI Harness is described as bringing together "what agents need to understand the business, reason and plan, take action, and operate within enterprise controls, without companies having to build and manage those capabilities separately for every agent or AI experience". It spans six capabilities: "context, agency, action, governance, security, and models, delivered through a common, composable architecture".

The sentence worth reading twice is this one: "AI reasoning can be open-ended, but enterprise execution often cannot be. The Enterprise AI Harness connects that reasoning to the business rules, policies, and controls required for predictable execution."

That is the thesis of the entire week. Everything else announced is one of those six capabilities getting a product name. Koa is **models**. AIforce and Headless 360 are **action** and the surfaces it reaches. Agent Fabric is **governance**. The Google Cloud and AWS deals are **context** reaching further out. The seven agents are **agency** packaged as job roles.

Salesforce has decided the defensible thing is the governed business context, not the screens and not the model. We think that is correct, and the consequence for a customer is the mirror image of it. If reasoning and interface are both swappable, they are cheap to get wrong. The context layer is not swappable, so it is the expensive one, and it is the one most organisations have underinvested in for a decade.

## The cloud story is not a Google story

Most coverage this week framed the Google Cloud partnership as a major alignment. It is worth noticing that AWS received an announcement of equivalent weight on the same day, covering Salesforce business context in Amazon Quick, "Agentforce model choice through Amazon Bedrock", Data 360 zero copy expansion, and Agentforce Voice with Amazon Connect. Koa, meanwhile, is built on NVIDIA.

One partnership is an alignment. Two on one day, plus a third-party model foundation, is a posture. Salesforce is deliberately making the cloud and the model into choices, and it can only afford to do that because it intends to own the layer underneath both.

For you that means the cloud and model questions are less strategic than they looked on Monday, and the data and permissions question is more so.

## What each one actually changes

**AIforce is the one to read twice.** Salesforce states that because every request runs on existing permissions, every agent sees only what the person asking can see. That is the right architecture. It also means your sharing model, exactly as it stands today, is about to be exercised by more requests from more surfaces than it was designed for. Detail in [Salesforce AIforce explained](/salesforce-aiforce-explained).

**Headless 360 is the sleeper.** Its MCP server lets "agents running in Agentforce, Claude, ChatGPT, Cursor, and other AI platforms to dynamically discover, understand, and invoke Salesforce capabilities in real time". Read that surface area honestly. It is considerably wider than AIforce alone, it includes tools your developers are already running today, and the same permission question applies to all of it.

**Koa answers the question most model announcements avoid.** Salesforce says the training corpus "was built entirely from synthetic scenarios", that "no customer data was used to train the Koa reasoning model", and that it controls the weights and runs the model in its own infrastructure so "no customer data crosses the trust boundary during inference". Training provenance and inference boundary are separate questions, and a vendor answering only the first is a familiar way of sounding reassuring without being reassuring. Both are covered here. More in [Salesforce Koa explained](/salesforce-koa-crm-reasoning-model).

**The cloud partnerships are plumbing, and plumbing is underrated.** Platforms of this size choosing published open protocols over bespoke integrations is what turns MCP from a developer convenience into something you can design against. The detail worth stealing is the Tableau one: governance and row-level security "are enforced with every agent query", at the protocol rather than inside the agent. More in [the Salesforce and Google Cloud partnership](/salesforce-google-cloud-gemini-agentforce-mcp).

**Agent Fabric is the governance answer, and it already shipped.** MuleSoft's control plane discovers agents across Agentforce, Amazon Bedrock, Google Vertex AI and Microsoft Copilot Studio, and its Trusted Agent Identity "enables agents to execute actions using specific user permissions". If you run agents from more than one vendor, and by next year most enterprises will, this is the layer that stops that becoming an inventory problem nobody owns.

**The seven agents are the most concrete thing announced.** Named roles with stated availability beat a platform capability you have to assemble. Casey, Paige, Carter, Marshall, Piper and Fin are GA now. Hunter is in pilot with GA stated for November 2026.

**Adecco is the proof, and the method.** A pilot in the UK and France, then more than 40 countries. That sequence is the opposite of the failure pattern we get called in to fix, which is a proof of concept on curated data declared a success and scaled sideways into teams whose permissions were never examined.

## What was announced but is not covered here

Two things we have heard attributed to this keynote have no published release, after searching twice: **Salesforce Guardian** and **AIforce Max Edition**.

Guardian is worth a note, because it shows how these recaps go wrong. Cyera ships a product called Agent Guardian. Salesforce ships Agentforce in Security Center and Privacy Center. Merge those in a transcript and you invent a Salesforce product that does not exist. The same risk applies to product names generally this year: Agentforce is now written **Agentforce 360** in Salesforce's own releases, and the transcript we reviewed rendered Claudeforce as "CloudForce".

We will add both if Salesforce publishes them. We will not infer them.

## The three questions a keynote never answers

Platform announcements describe capability. Delivery is about constraints, and there are three that no keynote has ever addressed because they are specific to your org rather than to the product. We ask all three in the first week of every engagement, and the answers predict the outcome better than anything on the roadmap.

**Who can see what, really?** Not what the sharing model was designed to do. What it does now, after however many years of profile clones, permission set groups added for a project that ended, sharing rules written to unblock a go-live, and "temporary" Modify All Data that outlived the person who granted it. An interface layer that runs on the requesting user's permissions is only as safe as those permissions are accurate, and most orgs have never audited them against the org chart they have today.

**Which system is right when they disagree?** Every organisation past a certain size has the same customer in three places with three spellings, the same contract value in CRM and in finance with two numbers, and an account owner in Salesforce who left last quarter. A human reading that notices the contradiction and asks someone. A reasoning chain resolves it silently, picks one, and produces a fluent answer built on the wrong half.

**What is the agent not allowed to do?** The refusal set is the part teams skip, and it is the part that determines whether the deployment survives its first bad month. Not "be helpful and safe" in a prompt, but an enumerated list: does not quote a price outside the approved band, does not commit to a delivery date, does not tell a customer their claim is approved, does not write to these five fields. Then tests that prove each refusal actually fires.

None of these three are AI problems. They are the ordinary, unglamorous work of running a platform, and every announcement this week raised the cost of having skipped them.

## Where all of it sits on your roadmap

| Announcement | Act now, or wait | What it should trigger |
| --- | --- | --- |
| **AIforce** | Act now | A sharing model audit. The work is the same whether you adopt AIforce this year or not, and it is the long pole |
| **Headless 360** | Act now | Find out which of your developers already have MCP clients pointed at the org. That is a live surface, not a future one |
| **The seven agents** | Act now if one matches a real queue | Pick the one that maps to work you already measure, so the pilot has a baseline |
| **Koa** | Wait, then evaluate | Nothing structural. Build the evaluation set that lets you compare it against whatever you run today |
| **Agent Fabric** | Act if you run multi-vendor agents | An inventory of every agent already running against your data, from any vendor |
| **Google Cloud and AWS** | Act if you already run Gemini or Bedrock | Review where integrations are point-to-point and would be better on a protocol |
| **Guardian, AIforce Max** | Wait | Nothing. No published release means no procurement conversation |

The column that matters is the second one. Announcements arrive at vendor pace. Adoption happens at the pace your data and permissions allow, and those two speeds have never matched.

## What we would actually do next quarter

Not a platform decision. An audit.

**Trace one workflow end to end.** Every object it touches, every field, the sharing model on each, and what a reasoning chain running as a normal user could reach. This routinely surfaces one object that has been Public Read/Write since an implementation nobody currently at the company ran.

**Inventory the agents already running.** Not the ones you plan to build. The MCP clients, the copilots and the assistants that already have credentials against your org. Most teams are surprised by this list, which is the entire argument for a control plane.

**Fix the facts that disagree.** Where the same value lives in four systems with four answers, resolve which one wins before any agent reads it. A better model does not resolve a disagreement, it states one side of it more convincingly.

**Build an evaluation set from closed work.** Twenty cases already resolved, with the human decision as the known-good answer. It outlives every model choice, and when you swap a reasoning model, which the architecture announced this week says you will, this set is what turns that swap from a leap of faith into a measurement.

**Write the refusal set down before the prompt.** Enumerate what the agent must not do, then write a test for each line. A refusal that has not been tested is a hope.

**Then deploy narrowly, the way Adecco did.** One surface, one workflow, and a named person who can switch it off without asking anyone's approval.

## How we work on this

We are a Salesforce consultancy and an OpenAI Select Partner, which means we spend our time on both halves of the problem announced this week: the platform underneath and the reasoning layer on top.

The engagements that come out of a week like this one usually start in the same place. A **grounding and permissions audit**, which is the trace described above, delivered as a list of what an agent could reach today and what should be closed before it does. An **agent inventory** across every vendor already connected. A **data reconciliation pass** on the two or three objects a target workflow actually depends on. An **evaluation harness** built from closed cases, so model and prompt changes can be measured rather than argued about. Then a **narrow pilot** with the refusal set tested, on one surface, sized so that it can be switched off without a committee.

That is deliberately less exciting than the keynote. It is also the part that is still true in eighteen months, whichever of these products you end up running.

## The honest summary

This was a strong week and the architecture behind it is coherent, which is more than most platform keynotes manage. Salesforce published the architecture before it published the products, and the products fit it.

It is also, like every platform announcement, a statement about what becomes possible rather than what becomes easy. The organisations that get value from any of this in 2027 will not be the ones that adopted first. They will be the ones whose data, permissions and business logic were worth connecting to when the interface layer arrived.

## Questions

### What was announced at Dreamforce 2026?

On keynote day, 15 September 2026: AIforce, a live interface layer launching with Claudeforce, Slackforce and Agentforce Coworker; Koa, Salesforce’s first CRM reasoning model built on NVIDIA Nemotron; an expanded Google Cloud partnership connecting Agentforce and Gemini Enterprise over MCP; and an expanded AWS collaboration covering Amazon Quick, Bedrock model choice and Agentforce Voice. In the run-up Salesforce also announced the Enterprise AI Harness, Headless 360, a portfolio of seven job-ready agents, Claudeforce and Slackforce, and the Adecco Group announced an Agentforce Coworker rollout across more than 40 countries.

### What are the new Agentforce agents called?

Seven were announced: Casey for customer service across voice, SMS, WhatsApp and chat; Paige for IT and HR requests; Carter for e-commerce; Marshall for supply chain and back-office orchestration; Piper for inbound sales qualification; Fin for complex customer experience workflows; and Hunter for outbound sales. Six are generally available now. Hunter is in pilot with general availability stated for November 2026.

### What is the single most important announcement?

AIforce, with Headless 360 close behind. A reasoning model is a component you can swap and a cloud partnership is plumbing, but an interface layer changes what your Salesforce org is for. If the UI is no longer fixed, the durable value of your org becomes the quality of its data, logic and permissions, and nothing else survives the move.

### Is Koa worth switching to from whatever model we run today?

There is no way to answer that from a press release, and anyone who tells you otherwise is guessing. Build an evaluation set of twenty already-resolved cases from your own closed work, with the human decision as the known-good answer, and run both against it. That set costs a week, outlives every model on the market, and is the only thing that turns a swap into a measurement.

### Does this mean Salesforce is moving to Google Cloud?

No. Google Cloud and AWS both received expanded partnership announcements on the same day, and Koa is built on NVIDIA Nemotron. Reading any one of those as an alignment misses the pattern. Salesforce is making the cloud and the model into choices, which is only possible because it intends to keep the layer underneath them, your governed business context.

### Why does this page not cover Salesforce Guardian or AIforce Max Edition?

Because no citable release exists for either, and we searched twice. Guardian in particular looks like transcript confusion: Cyera ships a product called Agent Guardian and Salesforce ships Agentforce in Security Center, and a keynote recap that merges those into a new Salesforce product would be inventing one. Every other claim on this page is quoted from a source you can open and check. These will be added if and when Salesforce publishes them.

---

SynconAI is a Salesforce Select Partner and an OpenAI Select Partner, delivering architect-led Salesforce and AI programmes across the United States and Australia. Related service: Salesforce architecture and consulting (https://synconai.com/salesforce-consultancy).