Claudeforce Adds A Second Vendor To Your Stack
Everyone is asking whether Claudeforce is safe. That is the wrong question.
Salesforce and Anthropic announced Claudeforce on 26 August, on the Q2 FY27 earnings call. The commentary since has been dominated by one question. Is your data safe if you turn this on.
It is a fair question and it has an answer. The answer is mostly yes, and it has been mostly yes since October 2025, which we will come back to.
The question almost nobody is asking is the one that will actually show up in a budget. Claudeforce does not bill the way Salesforce has billed for twenty-seven years. It meters. And the Claude half of it does not appear on your Salesforce invoice at all, because Anthropic sends you a separate one.
Lilstak rebuilds bloated go-to-market stacks into lean ones you own. From that angle this is not an AI story. It is a second vendor entering your stack with a variable rate and no clear contract owner.
What actually got announced
Salesforce in Claude is a Cowork plugin carrying 37 prebuilt sales skills, built jointly by the two companies. Meeting preparation, deal health review, pipeline management. A seller works in Claude, reads live CRM context, and acts without opening Salesforce.
Claude in Salesforce is the other direction. Claude is now the reasoning model behind the Atlas Reasoning Engine, powers Agentforce Vibes and Agentforce Coworker by default, and is available in Agent Builder.
Slack gets Claude as its default model, powering Slackbot.
Underneath all three sits AIforce, which Salesforce describes as its "trusted enterprise harness that brings all your business data and workflows to any agent through MCP servers, APIs, and CLI tools, without complicated and costly integrations."
That sentence is the architectural claim that Salesforce can be the backend for someone else's interface and still be Salesforce. Interesting, and not the part that will cost you money.
The billing model is the story
Salesforce charges this new usage through its headless consumption pricing. In Salesforce's own framing, "depending on your edition of your user license within Salesforce, you effectively get more incremental access to more and more API calls."
Read that slowly. Your entitlement is denominated in API calls, and an agent working a pipeline makes considerably more of them than a person clicking through it.
Then there is the second invoice. Customers contract Anthropic separately for the Claude inference itself. A Salesforce executive put it plainly: "You can't buy this on one piece of paper at the moment."
We give them credit for saying that out loud rather than burying it. But sit with what it means on the procurement side. The thing your sales org wants to pilot has two suppliers, two contracts, two renewal cycles, and quite possibly two different budget owners. The person who signs your Salesforce renewal is rarely the person who signs an AI inference agreement.
A contract nobody owns is a contract nobody reviews until it renews. That is the shape stack bloat usually arrives in.
A word on the numbers, because the commentary is already conflating two things. Salesforce has published Flex Credits pricing for Agentforce: a minimum of 100,000 credits for 500 US dollars, with an agent action consuming 20 credits, so roughly 10 cents per action. Flex Credits are consumed only when an agent action actually executes inside Salesforce; simple MCP tool reads and writes typically do not consume them. That distinction matters more than the rate does.
But those are Agentforce numbers, not Claudeforce numbers. No price was disclosed for Claudeforce, and Salesforce's own release says pricing and packaging are subject to change. Anyone quoting you a cost per seller today is extrapolating.
Salesforce said the quiet part on the earnings call
The consumption shift is not something we are reading into the announcement. Salesforce said it out loud, in the same session, as good news.
Miguel Milano, President and COO: "Fifty percent of the bookings came from customers refilling the tank: they consume Flex Credits, they want more."
Marc Benioff, Co-Chief Executive and Founder: "Customers want that kind of diversity in pricing, we have created a high level of flexibility, and that has really expanded our ability to sign very large transactions."
Refilling the tank. That is a metaphor about a thing that empties. The market liked it. Q2 revenue came in at 11.3 billion US dollars, up 11 percent year on year, and the stock rose 12 percent.
Now the other side, because a post that only quotes the vendor is a press release with a byline. Gartner warned in October 2025 that consumption models like Flex Credits "can be credit-based, with rates that may change unilaterally by the vendor, exposing buyers to unexpected cost increases," and predicts that all-you-can-eat agentic license agreements will convert to "defined quantity contracts at the end of the agreement."
Both of those things can be true at once. Consumption pricing genuinely is more flexible when your usage is lumpy, and it genuinely does move forecasting risk from the vendor onto you. Under per-seat licensing you knew your cost the day you signed. Under consumption you find out in arrears. That is not a scandal. It is a new job, and somebody in your company now has to do it who did not have to before.
Nothing here is generally available
| Component | Status |
|---|---|
| Salesforce in Claude | Select pilot customers only |
| Salesforce in Claude, open beta | Expected September 2026 |
| Service, marketing and commerce skills | Q3 |
| Additional prebuilt skills | Beginning late 2026 |
| Claude in Agentforce and Slack | Shipping |
| Claudeforce pricing | Not disclosed, subject to change |
Read that table before you promise anyone a date. The headline capability is in pilot, the open beta has not opened, most of the skill catalogue does not exist yet, and the pricing is explicitly provisional. Anyone planning a Q3 rollout is planning around a beta whose commercial terms can still move.
The security line everyone is quoting is ten months old
The line doing the rounds is that Claude is now the first model provider fully integrated inside the Salesforce Trust Boundary.
That is true. It has also been true since 14 October 2025, when Salesforce and Anthropic announced exactly that, along with all of Claude's traffic being contained within the Salesforce virtual private cloud, delivery through Amazon Bedrock, a regulated-industries collaboration covering financial services, healthcare, cybersecurity and life sciences, and CrowdStrike and RBC Wealth Management as early adopters.
Salesforce's own Claudeforce release treats it accordingly, in the present tense, as settled background: "Through Amazon Bedrock, Claude is available within the Salesforce Trust Boundary." Not a new capability. A precondition for the new capability.
The word carrying the falsehood is "now." Strip it out and the sentence is accurate and ten months old.
What this does not fix
Permissions inherit through the MCP servers, so actions are governed by your existing permissions and sharing rules. Claude does not receive unrestricted access to your CRM. If your organisation already approved Salesforce's environment, the perimeter review is genuinely shorter.
Everything downstream of the perimeter is still open. David Girvin, founder and chief executive of Assury, argues that model-in-the-loop review is fundamentally unreliable in regulated environments, on the grounds that even the strongest models miss a meaningful share of violations. That is a claim about output quality under audit, and no network diagram answers it.
We are not going to speculate about any specific compliance regime, and nothing in the published material addresses business associate agreements or any named framework. The structural point is enough on its own: a perimeter guarantee is not a compliance programme. Knowing your data stayed inside a virtual private cloud tells you nothing about whether an agent gave a customer advice you are obliged to supervise.
Those are two different reviews, and in most companies they belong to two different people. Do not let the first one being easy convince anyone that the second one happened.
What to do this week
- Find out who would own the Anthropic contract. It is not your Salesforce renewal and it is probably not your Salesforce buyer. If the answer is a shrug, you have found the thing that will delay your pilot by a quarter, and you have found it early, which is the only good time to find it.
- Ask for a consumption forecast before you pilot, and ask what happens if rates change. Model your pipeline volume against API-call entitlements by licence edition. Then ask, in writing, what notice you get if credit rates move. Gartner's warning is about unilateral changes, and the answer to that question belongs in a contract, not a conversation.
- Put both contracts on one renewal calendar before either one exists. Two suppliers on two cycles is how stacks quietly bloat. The cheapest moment to decide who reviews them together, and when, is now.
- Separate the perimeter question from the supervision question. The perimeter answer is good and it is old. Audit, evidence and supervision are open, and they belong to a different reviewer. Book two meetings, not one.
Wondering what Claudeforce would actually cost you, as opposed to what it would do? Book a call — we will get the forecast and the contract questions straight before the pilot, not after the first invoice.