Salesforce turns enterprise apps into agent capabilities
Covered by Signal Brief for B2B SaaS product managers — one of 5 tools in Issue #11 · salesforce.com
What it does
Salesforce on Tuesday significantly expanded Headless 360, its effort to transform every Salesforce cloud from an application into reusable enterprise capabilities that any authorized AI agent can discover and use through open standards. The premise, in the company’s own framing: AI agents are rapidly becoming the new interface for enterprise software — yet most organizations still cannot let agents act safely across the business without custom integrations, duplicated business logic, and fragmented governance. The centerpiece is the Headless 360 MCP Server, now in open beta, which lets agents running in Agentforce, Claude, ChatGPT, Cursor, and other platforms dynamically discover, understand, and invoke Salesforce capabilities in real time. Because it is metadata-aware, agents don’t just find endpoints — they understand the relationships, permissions, workflows, validation rules, and governance behind them, and every action inherits the identity and permission model the customer has already built. Also shipping: the Data 360 MCP Server, now generally available, exposing nearly 200 APIs so agents can build semantic models, transform data, generate calculated insights, create audience segments, and activate campaigns in natural language; a generally available Slackbot MCP Client connecting Slackbot to Salesforce and more than 20 partner apps including Atlassian, Box, Canva, Docusign, Notion, and Zoom; a repository of more than 100 reusable Agent Skills; a generally available multi-framework for building React apps with native Salesforce authentication; a headless experience layer in open beta; and MuleSoft and Informatica capabilities exposed as governed MCP services. Distribution reaches the Anthropic, OpenAI, Google, and AWS surfaces through AgentExchange.
Why it matters for PMs
This is the clearest statement yet from an enterprise incumbent that the application UI is no longer the primary interface to its own product — the governed capability layer is. Two implications for B2B SaaS PMs. If you build on Salesforce, the objects, flows, and validation rules you maintain are now product surface that third-party agents read and invoke; metadata hygiene becomes a product-quality issue, not an admin chore. If you sell beside or against it, note the strategic bet: the platform that owns the trusted capability layer — identity, permissions, and business logic intact, reusable by any authorized agent — owns the agentic era, and Salesforce is pushing those capabilities into every major AI surface at once. The pattern worth copying wherever you build: expose capabilities with metadata-aware discovery, so agents inherit your permission model instead of forcing a new one. The bar is now explicit: capabilities that an authorized agent cannot discover and invoke increasingly don’t exist in the workflows where your customers’ work gets done.
The link Signal Brief published for this tool in Issue #11.
The other 4 tools in Issue #11
5 tools like these, every weekday before standup.
Join Signal Brief for $10/month or $96/year — every tool with why it matters for PMs and a direct link. No sponsors, no noise.
Start your 7-day free trialNo card required to start. Cancel anytime.