Salesforce

SalesforceSales Cloud/ Platform

Salesforce Sales Cloud / Platform is included for generally available hosted MCP servers that can expose org records, SOQL/search, prompt templates, and administrator-curated Flow, Apex, REST, and API Catalog tools to external AI clients.

CRM, revenue & customerSystem of recordBYO-UI-ready platform
An illustration of access surfaces surrounding a governed system.
System roleSystem of record
Access maturityBYO-UI-ready platform
MCP supportOfficial MCP server
Reference updatedNot stated by publisher
BYO-UI reviewedJul 22, 2026

Concrete capability record

Data, retrieval, actions, identity, and operating limits

A field-by-field summary of what the reviewed first-party references actually support. Publisher update dates and BYO-UI review dates are shown separately below.

01 · Records and state owned

Standard and custom SObjects, schema, SOQL and search results; prompt templates; and curated tools backed by autolaunched Flows, Apex invocable or Aura-enabled methods, Apex REST, Named Queries, and cataloged REST endpoints, plus separately licensed product servers.

02 · Data you can retrieve

Use read-only SObject servers for schema, query, search, and relationship traversal, or expose selected read tools from prompts, Flows, Apex, REST, Named Queries, API Catalog, Data 360, and Tableau through a custom server.

03 · Actions and write paths

Choose immutable standard servers for full CRUD, create/update without delete, or delete-only access; custom servers can invoke state-changing Flow, Apex, REST, or API Catalog tools selected by an administrator. Each operation remains constrained by the authenticated user.

04 · Authentication and permissions

Each client is registered as an External Client App and uses per-user OAuth 2.0 Authorization Code with PKCE. GA scopes are mcp_api and refresh_token; every call enforces the user's object permissions, field-level security, sharing rules, and underlying automation access.

05 · Monitoring, approval, and recovery

Servers are disabled by default and require administrator enablement. Use scoped standard servers or persona-specific custom servers, preserve request telemetry and user audit attribution, and annotate custom tools accurately; annotations guide clients but do not enforce confirmation.

06 · Limits and caveats

GA is documented for Enterprise Edition and above. Standard server toolsets are fixed, custom server behavior depends on selected org logic, not every REST endpoint is available through API Catalog, clients may ignore tool annotations, and broad SObject servers can expose every object permitted to the user.

Agent access

MCP support

Official MCP serverSalesforce-hosted configurable org MCP servers plus separate DX/developer MCPGeneral availability

Support: Official MCP server

Read scope: Read-only SObject schema/query/search/relationships plus administrator-selected prompt, Flow, Apex, REST, Named Query, API Catalog, Data 360, or Tableau reads exposed by the chosen standard or custom server.

Write scope: SObject All supports create/read/update/delete; SObject Mutations omits delete; SObject Deletes is delete-only. Custom Flow, Apex, REST, and catalog tools may have their own effects, so the active server and tool determine write risk.

Authentication: Per-user OAuth 2.0 Authorization Code with PKCE through an administrator-created External Client App; GA connections request mcp_api and refresh_token.

Approval boundary: Salesforce marks platform tools with read-only and destructive hints, but annotations are advisory and some clients ignore them. BYO-UI must require confirmation for delete servers and consequential custom tools, and should inspect custom annotations rather than treating them as enforcement.

Protocol does not erase product boundaries.

Confirm the current tool catalog, plan, region, scopes, rate limits, terms, and write behavior before implementation.

Editorial assessment

Access-maturity dimensions

A comparative architecture lens—not a quality score, market ranking, or buying recommendation. Scale: 1–5.

Data access4
Action access4
Event access4
Identity4
Governance4
Agent access4
UI extensibility3
Portability4
Observability3
Documentation5

Proposed customer-shaped experiences

What customers could create on top.

The output could be an export, report, graph, artifact, application, agent, workflow, or downstream feed. These proposals are derived from documented access—not claims that Salesforce ships them.

Single-platform patterns

  • Account, pipeline, service, and workflow cockpit
  • Account journey room
  • Pipeline-quality debugger
  • Customer expansion cockpit
Use in the brief builder →

Multi-platform compositions

  • Salesforce Sales Cloud / Platform + marketing or intent platform: account journey room
  • Salesforce Sales Cloud / Platform + conversation or support system + analytics or warehouse: cross-system decision workspace
Explore composition recipes →

Evidence and dates

First-party references, with publisher and review dates separated

“Publisher updated” is shown only when the page exposes an update date. “BYO-UI reviewed” records when this research checked the reference. A missing publisher date is reported as missing—not replaced with the review date.

10 recorded sources
APISource inventory
https://developer.salesforce.com/docs/apis ↗

First-party API reference or API overview recorded for this platform.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

Developer docsSource inventory
https://developer.salesforce.com/ ↗

First-party developer documentation or platform overview.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

HomepageSource inventory
https://www.salesforce.com/sales/ ↗

First-party product homepage used to confirm product identity and current positioning.

Publisher updated
May 28, 2026
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

Verified fact

Tied to cited first-party evidence reviewed for this profile.

Source inventory

Official links recorded for deeper research but not necessarily reopened endpoint by endpoint.

Editorial assessment

System role, maturity interpretation, and architectural boundary.

Proposed design

Interface patterns and compositions—not vendor product claims.