Salesforce Agentic Identity Gives AI Agents Their Own Login

📍 Part of our Dreamforce 2026 coverage — see also AIforce and the permission cleanup it just made urgent Until now an AI agent working in Salesforce borrowed the login of the person it was helping. 🔐 Salesforce Agentic Identity changes that and gives every agent its own badge, its own permissions and its own paper trail. For admins this is the security upgrade they quietly wanted. For finance teams it also brings a new line in the budget, so it pays to understand both sides before your first external agent goes live. BEFORE Maria Sales Rep login Full user permissions Agent acts as Maria AFTER Agent ID Own OAuth app Own scoped permission set Own activity log Its own badge, not a borrowed one. An agent that used to borrow a login now gets its own badge, its own permissions and its own activity log. What is Salesforce Agentic Identity Salesforce Agentic Identity is a registration system that gives each AI agent connecting to Salesforce its own OAuth credentials and its own scoped permission set, instead of acting under the login of the employee it serves. An agent gets issued its own badge rather than borrowing an employee’s badge, and every action it takes is tied back to that badge alone. This matters now because the quiet workaround is already everywhere. Claude, ChatGPT and custom built agents already read and write CRM data through MCP and direct API calls, almost always under a human user’s credentials, which means an audit log cannot actually tell you whether a given record change came from the person or from the tool acting on their behalf. What changes for admins Every external agent gets registered and scoped the way a new employee would be, under the principle of least privilege rather than inheriting a person’s full access Every agent action becomes fully traceable, and access can be revoked for one agent in a single click without touching the human user it used to borrow credentials from MCP clients will eventually move to the OAuth credentials of the registered agent identity instead of a shared user login Traditional integration Registered AI agent Identity Borrows a human user’s login Own OAuth credentials Permissions Inherits full user access Scoped, least privilege Audit trail Blends into user’s history Fully traceable to the agent Pricing model Standard API pricing Flex Credits per interaction Metered in sandbox Not applicable No, sandboxes are free Five rows, traditional integration against a registered AI agent. How Flex Credits metering will work Every successful call a registered agent makes to Salesforce, whether it arrives through MCP or a direct API call, will count as a Headless Platform Interaction and draw down Flex Credits, tracked through Digital Wallet. Traditional integrations keep today’s pricing, and sandboxes, scratch orgs and Developer Edition orgs are not metered under this model, so building and testing an agent costs nothing extra before it goes live. STEP 1 Agent calls MCP or direct API STEP 2 Identity checked Salesforce verifies the badge STEP 3 Action runs Scoped to agent permissions STEP 4 Logged Recorded in Digital Wallet What happens, in order, every time a registered agent reaches into Salesforce. ⏳ Salesforce has not yet published the Flex Credit multiplier for a Headless Platform Interaction, so the per call cost cannot be calculated yet. Salesforce has committed to 30 days of notice before metering actually begins, which gives every org a real window to measure expected agent volume before a single credit is charged. A five point readiness checklist Agentic Identity Readiness List every AI tool that already touches Salesforce Name one accountable owner per agent Draft a scoped permission set per agent Estimate monthly call volume per agent so the Flex Credit cost is not a surprise Build and test each agent in a sandbox first truesolv.com, before your first external agent goes live Before your first external agent goes live. Agents with their own identity are easier to trust, easier to audit and much easier to explain to a security team asking hard questions about what is touching customer data. Agentic Identity builds directly on the access review we covered in AIforce and the permission cleanup it just made urgent. For a structured way to do that review, see our Salesforce permission set audit guide. Dreamforce 2026Agentic IdentityAgentforceSalesforce AdminTrueSolv Share: LinkedIn Twitter / X Copy link In this article 01What is Agentic Identity 02What changes for admins 03How Flex Credits metering works 04Readiness checklist Key facts Billed unitHeadless Platform Interaction Paid inFlex Credits Tracked inDigital Wallet MultiplierNot yet published Notice before metering30 days SandboxesNot metered Dreamforce 2026 coverage ← Full recap hub AIforce & permissions Seven job ready agents Koa & multi-model AI → You are here: Agentic Identity Agents already touching your CRM? We inventory every AI tool with Salesforce access and scope a permission set per agent. Book an agent access review → About the Author ST Sergey TrusovCEO & Salesforce Architect at TrueSolv
Salesforce Koa and the New Multi Model AI Lineup

📍 Part of our Dreamforce 2026 coverage — start with the full announcement recap For two years every Salesforce roadmap meeting had the same awkward question. Which AI should we bet on? At Dreamforce 2026 Salesforce gave the most generous answer possible. Pick any of them, and now there is a brand new one built specifically for CRM. 🧠 MULTI MODEL AI / WHERE YOU MEET EACH ONE YOUR DATA Koa Reasoning inside Salesforce Claude Salesforce in Claude, beta Gemini Prompt Builder, Gemini Enterprise Amazon Bedrock Available to Agentforce now OpenAI Inside Agentforce and ChatGPT Five models on the menu, one thing that decides how smart they look. Meet Koa Koa is the first Salesforce CRM reasoning model, built together with NVIDIA and trained on a synthetic dataset modeled on almost three decades of CRM deployments. Salesforce controls the weights and runs Koa inside its own infrastructure, so customer data stays within the trust boundary during inference, and no customer data was used for training. Koa is in pilot with select customers now, and general availability is expected in winter 2026 for US regions. Everyone else is invited too Model Where you will meet it in Salesforce Koa CRM reasoning inside Salesforce infrastructure Claude Salesforce in Claude, in beta on paid Claude plans, and powering Agentforce Vibes by default Gemini Prompt Builder and the Agentforce reasoning engine, plus Salesforce inside Gemini Enterprise Amazon Bedrock models Available to Agentforce customers now OpenAI models Inside Agentforce, with Agentforce also reachable from ChatGPT So who actually wins Your data does. When the model becomes a choice, picking the wrong one gets much cheaper, and the real value moves to what every model depends on. Clean records, sensible permissions and well documented business rules now decide how smart any of these models look inside your org. Three questions for your next leadership meeting 1Who in our company decides which model runs which workload? 2Where is our data allowed to go, and which regions matter for our customers in the US and Europe? 3How will we log and review what each model does inside Salesforce? Answer them now and next year’s model announcements turn into an easy upgrade instead of a long debate. Salesforce just turned AI from a single bet into a full menu, and the companies with the cleanest data will order best. Catch up on the rest of the series with the full announcement recap, or see AIforce and the permission cleanup it just made urgent. Dreamforce 2026Salesforce AIKoaAgentforceTrueSolv Share: LinkedIn Twitter / X Copy link In this article 01Meet Koa 02Everyone else is invited too 03So who actually wins 043 questions for leadership Dreamforce 2026 coverage ← Full recap hub AIforce & permission cleanup Seven job ready agents → You are here: Koa & model choice Not sure which model policy fits your org? Book a call to translate the new model lineup into a written AI policy. Book a strategy call → About the Author ST Sergey TrusovCEO & Salesforce Architect at TrueSolv
Meet the Seven New Agentforce Job Ready Agents

📍 Part of our Dreamforce 2026 coverage — start with the full announcement recap Their names are Piper, Hunter, Carter, Casey, Fin, Marshall and Paige. They never ask for a raise, they happily work weekends, and at Dreamforce 2026 Salesforce introduced all of them as job ready agents. 🤖 The real question for leadership is who inside your company will actually onboard them. A brilliant new hire with no access, no manager and no job description usually ends up sitting quietly in the corner. AGENTFORCE / SEVEN JOB READY AGENTS Piper Works inbound leads so no form fill goes cold GA Hunter Builds outbound pipeline PILOT, NOV Carter Helps shoppers in commerce GA Casey Handles customer service requests GA Fin Runs customer experience conversations GA Marshall Orchestrates back office and supply chain GA Paige Answers employee HR and IT requests GA Multi Agent Orchestration lets all seven pass work to each other. The new roster — six already on the job, one landing in November. Meet the new team Agent What it does Piper Works inbound leads so no form fill goes cold Hunter Builds outbound pipeline Carter Helps shoppers in commerce Casey Handles customer service requests Fin Runs customer experience conversations Marshall Orchestrates back office and supply chain processes Paige Answers employee HR and IT requests Most of the lineup is already generally available, and Hunter is in pilot with general availability planned for November 2026. Multi Agent Orchestration is generally available too, so these agents can pass work to each other instead of behaving like seven separate bots. The 90-minute moment everyone remembers One of the standout moments on the main stage showed Marshall learning a supplier onboarding process, business rules included, in about 90 minutes inside a sandbox. A new employee usually needs weeks for the same thing. That is genuinely impressive. Keep in mind that it measures learning time rather than go-live time. The weeks you save on training are best invested in the part no demo shows, which is preparing your org so the agent learns the right process from clean data. Job ready is not the same as org ready Think about how you onboard a strong senior hire. Nobody hands them admin rights, a company card and the CEO inbox on their first morning. Agents deserve the same careful start, and this onboarding plan works for all seven. 📝Write a job description. Pick one workflow, one owner and one measurable outcome. Replying to inbound demo requests within five minutes beats a vague goal like improving sales. 🔑Grant access deliberately. Agents act under your permissions, so decide which objects and fields they truly need. 🚦Set autonomy limits. Decide what the agent can send or change on its own and what always needs a human. 📊Schedule performance reviews. Define what a correct answer looks like and test the agent against your own data before and after launch. 💰Give it a budget. Consumption pricing turns agent volume into a real line item, so forecast usage the same way you forecast headcount. Which agent should you hire first If your biggest pain is Start with Inbound leads waiting hours for a reply Piper A support queue full of repeat questions Casey Employees flooding HR and IT with the same tickets Paige Slow supplier onboarding and manual back office work Marshall A thin outbound pipeline Hunter, once it reaches general availability Starting with one agent in one workflow is almost always faster than launching a whole portfolio. The first win builds trust, and trust is what gets the next six approved by the board. How TrueSolv helps Our Agentforce Implementation service covers the full onboarding cycle. We audit your data and permissions, choose the workflow with the fastest payback, configure and test the first agent, and set up the evaluation routine your team will keep using after launch. Seven new coworkers just joined the Salesforce ecosystem, and the companies that onboard them well will feel the difference long before next Dreamforce. 🚀 Continue the series with AIforce and the permission cleanup it just made urgent, or see Salesforce Koa and the new multi model AI lineup. AgentforceDreamforce 2026AI AgentsSalesforce AITrueSolv Share: LinkedIn Twitter / X Copy link In this article 01Meet the new team 02The 90-minute moment 03Job ready ≠ org ready 04Which agent first 05How TrueSolv helps Dreamforce 2026 coverage ← Full recap hub AIforce & permission cleanup → You are here: Seven agents Koa & multi-model AI The roster PiperGA HunterPilot → Nov CarterGA CaseyGA FinGA MarshallGA PaigeGA Ready to hire your first agent? Book an Agentforce readiness call to scope the fastest-payback workflow. Book a readiness call → About the Author DS Daria SavelievaSalesforce Consultant & Content Lead at TrueSolv
AIforce and the Permission Cleanup It Just Made Urgent

📍 Part of our Dreamforce 2026 coverage — start with the full announcement recap Your sales team may never open a Lightning page again. 😳 At Dreamforce 2026 Salesforce introduced AIforce, and the login screen quietly stopped being the only front door to your CRM. That is mostly great news. It also means every forgotten permission set in your org is about to get a much louder voice. AIFORCE / PERMISSION EXPOSURE “Show me every renewal above $50K closing this quarter that also has open support cases.” ! Permission set from a 2019 pilot still grants View All on Cases Row 2 includes a case this rep was never supposed to see One plain question, one old permission set, one exposed answer — nobody broke in. What AIforce actually does AIforce is a live interface layer that sits on top of Agentforce, Data 360 and Customer 360. Instead of clicking through tabs and list views, people and agents reach Salesforce data and actions from the tools they already work in, starting with Slack and Claude. Interfaces can be composed by simply describing what you need, so a sales manager no longer waits two sprints for an admin to build a new dashboard. Salesforce designed it with trust at the center. Every request runs on your existing permissions and business rules, each agent sees only what the person asking can see, and every action routes back through Salesforce. There is no new permission model to learn. Why that last sentence matters so much Because AIforce reuses your permission model, it also reuses every shortcut hiding inside it. For years complexity worked as an accidental security layer. A rep who technically had access to a sensitive object rarely stumbled onto it, because finding it required the right report, the right list view and a bit of luck. Plain language removes that friction. One question in Slack and the data simply shows up. Picture a rep asking for every renewal above 50K closing this quarter that also has open support cases. If a permission set from a 2019 pilot still grants View All on Cases, the answer will include records that rep was never supposed to see. Nobody broke in. Your org did exactly what it was told. Before AIforce With AIforce Overexposed data was hard to find Overexposed data is one question away Admins built every view Users compose their own views Mistakes surfaced during audits Mistakes surface during conversations Cleanup could wait until next year Cleanup becomes urgent Five things to check before AIforce reaches your team 🔑Profiles and permission sets with View All or Modify All that nobody can justify today. 📋Sharing rules created for a single project years ago and never removed. 👥Public groups and role hierarchies that grew one exception at a time. 🔌Integration users with broad access and no clear owner. 🏦Field level security on truly sensitive fields like margin, compensation or personal data. Each of these takes an afternoon to review and a lot longer to explain after the fact. The good news is timing Salesforce is still finalizing AIforce pricing and packaging, which gives most orgs a comfortable window to get their house in order. Teams that use this window will enjoy the new interface from day one, while everyone else will be tempted to pause the rollout at the worst possible moment. Salesforce just gave your data a bigger voice, so make sure it only says what it should. Continue the series with meet the seven new Agentforce job ready agents, or see Salesforce Koa and the new multi model AI lineup. Dreamforce 2026AIforceSalesforce SecuritySalesforce AdminTrueSolv Share: LinkedIn Twitter / X Copy link In this article 01What AIforce actually does 02Why that matters so much 035 things to check 04The good news is timing Dreamforce 2026 coverage ← Full recap hub → You are here: AIforce & permissions Seven job ready agents Koa & multi-model AI Not sure what AIforce would expose? Book a Health Check focused on security and permissions before rollout. Book a Health Check → About the Author AR Anastasia RashkinaSalesforce Developer at TrueSolv
Salesforce Duplicate Rules Setup, Block or Alert

Turn on strict duplicate rules and reps start finding ways around them, turn them off and the database turns into a mess again. The short answer on block versus alert is to block on exact, high confidence matches, an identical email address, for example, and alert on everything looser, like a similar company name with a different domain. Blocking too broadly trains reps to fake a field just to get past the rule, which ends up creating worse data than the duplicate ever would have. DUPLICATE RULES / BLOCK VS ALERT New record entered EXACT MATCH BLOCK Exact email match Exact phone + last name PROBABLE MATCH ALERT Similar company name Phone formatted differently Block only what you’re basically certain about. Everything else deserves a human look. Same new record, two different matches, two different responses — block the certain ones, alert on the rest. Why default duplicate rules are either too strict or too loose Salesforce’s standard duplicate rules ship with generic matching logic that rarely reflects how a specific team actually enters data. Reps might type a company name three different ways over a year. A lead source field picks up an extra suffix depending on which form it came through. Default rules either catch too much, blocking two legitimately different contacts who happen to share a similar name at the same company, or too little, missing an obvious duplicate because a phone number was formatted with a different number of digits. How to build matching rules around how the team actually enters data Pull a sample of real duplicate pairs already sitting in the org and look at exactly what differs between them, a missing area code, Inc versus Incorporated, an extra space nobody notices. Build matching criteria around those actual patterns instead of theoretical ones, fuzzy matching on company name, exact matching on email domain, normalized comparison on phone number. Separate matching rules by object and by how that object typically gets created, since a lead from a web form behaves differently than a contact a rep types in by hand after a call. Setting rules to alert instead of block where it makes sense Block only for near certain duplicates, an exact email match, or an exact phone number paired with an exact last name. Alert for everything probable but not certain, and let the person entering the data see the potential match and decide, since they often have context the system doesn’t, this might genuinely be two different people who happen to work at the same company. Blocking a genuine near miss teaches people to route around the rule entirely, which defeats the point of having one. Cleaning up existing duplicates before turning rules on 📊Run Salesforce’s built-in duplicate management report first, to see the actual scale of what’s already sitting in the org before designing anything ✅Merge the obvious exact duplicates first, the low risk, high confidence matches, before touching anything ambiguous 👀For ambiguous matches, don’t mass merge blind, assign a quick manual review to whoever owns those accounts, since a wrong merge loses history that doesn’t come back 🔛Only turn on the new matching and duplicate rules once the existing backlog is under control, otherwise the new rule just alerts everyone constantly about a mess it didn’t create Blocking a genuine near miss teaches people to route around the rule entirely. A duplicate rule that reps have learned to defeat is worse than no rule at all — it just looks like protection. Book a data quality consultation through our contact form, and follow TrueSolv on LinkedIn for more Salesforce admin notes. Salesforce AdminData QualitySalesforce SetupCRM Best PracticesTrueSolv Share: LinkedIn Twitter / X Copy link In this article 01Why defaults are too strict or loose 02Build rules around real data 03When to alert instead of block 04Cleaning up before turning rules on Block vs Alert Exact email match→ BLOCK Exact phone + last name→ BLOCK Similar company name→ ALERT Phone formatted differently→ ALERT Duplicates piling up, or reps routing around your rules? Book a data quality consultation to get the balance right. Book a consultation → About the Author ST Sergey TrusovCEO & Salesforce Architect at TrueSolv
Dreamforce 2026 Announcements, Full Recap

More than 50,000 people came to Moscone Center, and over 122,000 more watched online. 🎤 Now the same question lands on every leadership team: what from all of that actually changes our Salesforce this year? We sorted the biggest Dreamforce 2026 announcements by the one thing that matters for planning — when they reach your org. The big picture in one paragraph Salesforce built the whole event around becoming an Agentic Enterprise and drew a clear four-layer stack. Data 360 holds data, metadata and memory. Customer 360 carries application logic. Agentforce runs the agents. On top sits the brand new AIforce, an interface layer that brings Salesforce data and actions into the tools people already use, starting with Slack and Claude, while keeping every existing permission and business rule in place. DREAMFORCE 2026 / THE STACK Slack Claude AIforce Interface layer, reaches Slack and Claude Agentforce, runs the agents Customer 360, application logic Data 360, data, metadata, memory Available now Beta or pilot Coming this fall Same permissions and business rules, all the way up the stack. Four layers, one architecture, reaching into the tools you already use. Available right now ✅ 🔀Multi Agent Orchestration is generally available, so several agents can pass work to each other instead of acting alone. 🤖Most of the new job ready agents are generally available, including Piper for inbound leads, Casey and Fin for service and customer experience, Carter for commerce, Marshall for back office and supply chain, and Paige for employee HR and IT requests. 🧠More model choice in Agentforce arrived with Amazon Bedrock models, plus Anthropic and NVIDIA models, available to Agentforce customers. 🗄Data 360 zero copy now reaches more AWS sources, including Apache Iceberg tables, Amazon Aurora, Amazon RDS and SageMaker Lakehouse. 📊Salesforce and Tableau inside Gemini Enterprise are live for Google Cloud customers. 📖The Well Architected Framework now has five pillars with an agentic lens, and it is probably the most practical free read of the week for architects. In beta or pilot 🧪 💬Salesforce in Claude is in beta on all paid Claude plans. 🧬Koa, the first Salesforce CRM reasoning model built together with NVIDIA, is piloting with select customers. General availability is expected in winter 2026 for US regions. 🔌Headless 360 MCP Server is in open beta, while the Data 360 MCP Server is already generally available. 🆕AIforce is officially announced, and Salesforce is still finalizing pricing and packaging. Coming this fall 📅 ⚙️Agent Optimizer is planned for October. 📣Campaign Agent is expected in Marketing Cloud Next Advanced by October 2026. 🎯Hunter, the outbound pipeline agent, is planned for general availability in November 2026. ☁️Hyperforce on Google Cloud is planned for general availability in North America in November 2026. 📞Agentforce Voice with Amazon Connect is due later this fall, and OpenAI models through Bedrock are on the way as well. Also worth knowing Salesforce kept growing its platform through acquisitions this year, with Contentful joining on September 1 and Fin, formerly known as Intercom, joining on September 10. That is also why one of the new customer agents carries the Fin name. What actually matters for a mid-sized org Big keynotes are built for every audience at once. A company with 50 to 500 Salesforce users usually needs only a slice of it, and this table shows where to look first. If your company is Focus on first Sales led with strong inbound demand Piper and a clean lead routing process Service heavy with a busy support queue Casey or Fin together with Multi Agent Orchestration Running on AWS or Google Cloud Zero copy data access and wider model choice Planning 2027 budgets right now AIforce readiness and a written AI model policy Three moves for this quarter 🔍Audit permissions and sharing. AIforce and every new agent run on the access you already have, so old shortcuts become visible much faster. 🎯Pick one workflow for one agent. Choose a process with a clear owner and a measurable outcome before anyone proposes a whole portfolio. 🧠Decide who chooses the model. With Koa, Claude, Gemini, OpenAI and Bedrock all on the table, write down which model runs which workload and where your data is allowed to go. This week we are breaking the biggest topics down in separate articles, starting with AIforce and permissions, then the seven new agents, then Koa and model choice. Start with AIforce and the permission cleanup it just made urgent, then see who’s on the roster in meet the seven new Agentforce job ready agents, and close it out with Salesforce Koa and the new multi model AI lineup. Dreamforce 2026 handed every Salesforce customer a bigger toolbox, and the teams that plan the first steps now will be the ones using it by spring. Dreamforce 2026SalesforceAgentforceSalesforce NewsTrueSolv Share: LinkedIn Twitter / X Copy link In this article —The big picture ✅Available right now 🧪In beta or pilot 📅Coming this fall —What matters for mid-sized orgs —Three moves this quarter Dreamforce 2026 coverage → You are here: Full recap hub AIforce & permission cleanup Seven job ready agents Koa & multi-model AI Timeline legend Available right now Beta or pilot Coming this fall About the Author ST Sergey TrusovCEO & Salesforce Architect at TrueSolv
Dreamforce 2026, What to Expect September 15 to 17

Dreamforce returns to Moscone Center September 15 through 17, and this year the whole event is built around one idea, the agentic enterprise. Dreamforce 2026 runs September 15 through 17 at Moscone Center in San Francisco, with the full program also streaming free on Salesforce+ from September 15 through 18. The theme this year, Becoming an Agentic Enterprise, isn’t just a keynote tagline. It’s the lens the whole schedule of more than 1,600 sessions gets built around. DREAMFORCE 2026 / EVENT PREVIEW Becoming an Agentic Enterprise Moscone Center, SF Free on Salesforce+ 1,600+ sessions SEPTEMBER 2026 12-14 Bootcamp SEP 15 – 17 Dreamforce, on site SEP 18 Virtual extends Salesforce+ streams free, Sept 15 to 18 Opening keynote Tuesday Sept 15. TrueSolv covers the announcements the week after. One week, three days on site, one extra day to stream it free on Salesforce+. Quick facts In person, September 15 to 17 at Moscone Center, San Francisco, with a Trailblazer Bootcamp running September 12 to 14 beforehand. Free virtual access on Salesforce+, September 15 to 18, one day longer than the in-person event, with 400-plus sessions available live and on demand. Opening keynote Tuesday, September 15, historically where the year’s biggest product announcements land. What the theme means in practice Expect sessions organized around Agentforce 360, Salesforce’s unified platform bundling the Agentforce builder, Data 360, Customer 360 apps, and Slack into one connected stack. Less of the conference is going to be a single flashy agent demo this year, and more of it is going to be agents doing real multi-step work across sales, service, and operations at enterprise scale. Governance, observability, and adoption are set to get as much airtime as new features. What to actually watch if you’re not flying to San Francisco The opening keynote livestream on Tuesday is the highest value hour for anyone watching remotely. After that, the product-specific breakout recaps that surface over the following day or two tend to carry the detail the keynote skips, and the customer story sessions are where the actual deployment specifics, the parts that don’t make a highlight reel, tend to show up. Less of a single flashy agent demo this year, more agents doing real multi-step work across sales, service, and operations at enterprise scale. Governance and adoption get as much airtime as new features. TrueSolv will cover the biggest announcements the following week, so nobody has to sit through 1,600 sessions to find out what actually changed. Follow TrueSolv on LinkedIn and Instagram for Dreamforce coverage, and book a post-Dreamforce strategy call through our contact form once the announcements land. Dreamforce 2026SalesforceAgentforce AISalesforce CommunityTrueSolv Share: LinkedIn Twitter / X Copy link In this article 01Quick facts 02What the theme means 03What to watch remotely Dreamforce 2026 Sep 15–17 Moscone Center, San FranciscoBootcamp: Sep 12–14Free on Salesforce+: Sep 15–18 Want the announcements decoded? Book a post-Dreamforce strategy call once the news lands. Book a strategy call → About the Author AS Anastasia SokolovaSalesforce Developer at TrueSolv
Salesforce Winter 27 Release, Dates and What Changes

Release notes went live on August 19, sandbox preview opened August 28, and the first production wave lands the weekend of September 4. Salesforce’s Winter ’27 release notes published August 19, 2026, sandbox preview opened August 28, and production upgrades roll out across three weekends — September 4, October 2, and October 9, assigned by instance. The most useful thing an admin can do this week is find their own org’s exact date, since two changes in this release can quietly break something before anyone notices. WINTER ’27 RELEASE TIMELINE AUG 19 Release notes AUG 28 Sandbox preview SEP 4 Production wave 1 OCT 2 Production wave 2 OCT 9 Production wave 3 Enable Profile Filtering ENFORCES THIS CYCLE Users without View All Profiles can now see only their own profile name. Apex or Flow logic querying another user’s Profile now returns empty for them. OAuth Username-Password POSTPONED TO FEB 20, 2027 Scheduled for Winter ’27, then pushed back. Delayed, not cancelled. Integrations still using username and password logins are worth auditing now. Find your org’s exact weekend on Salesforce Trust, under Maintenance. Five dates, one permission change, one deadline that moved to February 2027. The permission change worth flagging to your team Enable Profile Filtering enforces this cycle. Users without the View All Profiles permission can now see only their own profile name. If any Apex or Flow logic queries the Profile of a user other than the one running it, that query now returns empty for anyone without the permission. Worth checking before the upgrade weekend, not after a report or an automation quietly stops working and nobody can figure out why. The API login change that got a reprieve Here’s a correction worth knowing before it spreads further. The retirement of the OAuth 2.0 username-password flow — the one where an integration logs in with a username, password, and security token — was originally scheduled to enforce in Winter ’27. Salesforce postponed the enforcement date to February 20, 2027. Treat that as delayed, not cancelled. Any integration still authenticating that way will stop getting a token on the later date, and finding every affected integration takes real time, so the extra months are worth spending now rather than in January. Check Login History filtered for OAuth password logins, and review Connected Apps OAuth Usage in Setup, to see what’s actually exposed in your org. What’s actually new to use this cycle 🧩Flow Builder — grouped sections, edit history, beta Test ModeCollapsible grouped sections with their own labels, an edit history timeline that shows every save and lets you restore older versions, and a new beta Flow Test Mode that splits Build and Test inside the builder with code coverage and mock outputs. 🤖Agentforce — beta Custom Scorers, Hosted MCP ServersLets a team define its own pass or fail evaluation logic for an agent session instead of relying only on Salesforce’s built-in quality metrics, plus expanded interoperability through Hosted MCP Servers. 🌐Experience Cloud — LWR sites embed real Lightning reportsCloses a long-standing gap: LWR sites can now embed an actual Lightning report, with charts, tables, and record editing, without falling back to the older Aura framework to get it. Find your exact upgrade weekend Production dates are assigned per instance, not per org type or edition. Check Salesforce Trust, search by instance name or domain, and open the Maintenance tab to see the exact weekend for that specific org. Writer note Dates above reflect Salesforce’s published Winter ’27 schedule and Trust status as of late August 2026. Production weekends are assigned per instance, so confirm the exact date on Salesforce Trust before publishing or promising a client a timeline. Two changes in this release can quietly break something before anyone notices. Finding your org’s exact date is the highest-leverage five minutes an admin can spend this week. Book a pre-upgrade Health Check through our contact form to catch breaking integrations before your org’s wave hits, and follow TrueSolv on LinkedIn for release coverage like this. Salesforce Winter ’27Salesforce ReleaseSalesforce AdminSalesforce SecurityTrueSolv Share: LinkedIn Twitter / X Copy link In this article 01Enable Profile Filtering 02OAuth password flow — postponed 03What’s new this cycle 04Find your upgrade weekend Key dates Aug 19Release notes published Aug 28Sandbox preview opens Sep 4Production wave 1 Oct 2Production wave 2 Oct 9Production wave 3 Feb 20OAuth password flow retires (2027) Not sure what breaks in your org? Book a pre-upgrade Health Check before your production wave hits. Book a Health Check → About the Author ST Sergey TrusovCEO & Salesforce Architect at TrueSolv
TrueSolv 7th Anniversary. Here Is What We Are Doing With Them.

Seven years ago TrueSolv started with a laptop, a Salesforce login, and considerably more confidence than clients. The anniversary was Sunday. This post is the Monday version. We are marking it the way that actually matters to you — not with a party you cannot attend, but with free hours on your Salesforce org. No strings, no upsell script, just work that needs doing. 7 Seven Years in the Making Founded in Tbilisi, Georgia · Also operating from Dubai, UAE 7years of Salesforce implementation, development, and consulting 2countries · 1 distributed team · 1 timezone gap that somehow works 7industries served across the client portfolio Industries: NonprofitFintechHealthcareSaaSRoboticsLegalReal estate What seven years of Salesforce consulting actually looks like TrueSolv was founded in Tbilisi, Georgia, and now operates across Tbilisi and Dubai. Seven years in a single industry gives you a particular kind of longitudinal view: you see the same problems appear in different clients, at different stages, in different industries, in the same repeating patterns. You also see how the platform changes underneath the work. When we started, the conversation was Classic versus Lightning and whether Lightning was actually ready. Now the conversation is how Agentforce agents should be scoped and what the data quality requirements are for a reliable AI deployment. The specific questions change; the underlying work — understanding what a business needs from Salesforce and building it correctly — stays constant. We have worked across nonprofits, fintech companies, healthcare teams, SaaS businesses, robotics companies, legal firms, and real estate operations. The industries are different. The version of “we built something that worked and then something changed and now it does not quite work anymore” is surprisingly consistent across all of them. To every client who brought us that problem over the past seven years: thank you. The challenging ones especially. You are the reason we got better at this. The campaign: free Salesforce work through August 10 From July 27 through August 10, TrueSolv is offering free Salesforce work under four hours. No minimum commitment, no catch. If the job takes longer than four hours, the first four hours are still free — you only pay for anything beyond that, and we will tell you before we go further. What four hours actually covers What four free hours can actually coverNo projects, no retainers — just work that needs doing, this week, for free ⚙️A stuck automationA Flow that fires at the wrong time, a process that was working six months ago and stopped, an integration that produces errors nobody has tracked down. 🔐A permission issueA user who should see something and cannot. A user who can see something they should not. A profile configuration question that has been bouncing between your team and Salesforce support. 📊A report that never works rightThe numbers do not match what your team expects, the filters are not doing what they look like they should be doing, a dashboard that someone decided to trust and probably should not. ✅A configuration change on the backlogSomething small that would make the CRM noticeably better for the people using it every day, but has been sitting on a list because nobody has gotten to it. These are not the kinds of problems that require a multi-week project. They require someone who knows Salesforce to look at them without billing pressure. That is what the free hours are for. 🎂 7th Anniversary Free Hours CampaignEnds Aug 10 4Free hours on your Salesforce org — no minimum commitment, no catch Aug 10Campaign closes — this week only If the job takes longer than 4 hours, the first 4 are still free. You only pay for anything beyond — and we tell you before we go further. Seven years is a good time to do something useful. Book your free hours at truesolv.com before August 10 — no strings, no catch. Follow us on LinkedIn and Instagram — we will be sharing more from the last seven years all month. TrueSolvSalesforce Consulting7 Year AnniversaryFree Consultation Share: LinkedIn Twitter / X Copy link In this article 01Seven years of consulting 02The free-hours campaign 03What 4 hours covers 🎂 Anniversary Offer 4 free hours on your Salesforce org No strings. No catch. Through August 10 only. Claim your free hours → About the Author AR Anastasia RashkunaMarketing Specialist & Author at TrueSolv
Salesforce Report Step-Up MFA

Starting July 1, your Salesforce users will be prompted to verify their identity every time they open a report. Not when they export it. Every time they open it. Every 120 minutes by default. If nobody on your team knew this was coming, Monday morning answered that question with a support queue. Here is what it is, why Salesforce introduced it, and what admins need to configure — including the setting most documentation skips. ⚡ SalesforceReports → Q2 Customer Pipeline Report content loading… 🔐 Verify your identity to view this report Salesforce requires identity re-verification to access reports. This prompt appears every 120 minutes by default. 📱Salesforce AuthenticatorTap the notification in the app 🔑Security KeyInsert and touch your key Verify with Salesforce Authenticator No enrolled method? You’ll receive a one-time code by email or SMS instead. This prompt is expected — not a security incident. All Salesforce users now see this every 120 min when accessing reports. Interval is configurable by your admin. What step-up MFA on reports actually means Step-up MFA is a secondary verification that fires when a user reaches a high-risk surface, even if they already authenticated with MFA at login. In this case, the trigger is any Salesforce report — opening it, not exporting it. The prompt appears before the report loads. The default re-verification window is 120 minutes. After a user verifies, they can open reports freely for 120 minutes before the prompt returns. This is configurable — which is the part most admin documentation understates. For users already enrolled in an MFA method, the step takes 15 to 30 seconds. For users with no enrolled method, the system falls back to email or SMS one-time passcode. If that also fails, the user cannot open the report at all. This applies to all internal orgs platform-wide, live since July 1. Why Salesforce introduced it Reports are the highest-risk data surface in most Salesforce orgs. A user with View All Data can navigate to the Reports tab, open a standard contact report, run it unfiltered, and export 50,000 records to a spreadsheet in under two minutes. The exported file leaves Salesforce with no record that it happened unless a Transaction Security Policy was in place. The step-up MFA requirement is specifically about the gap between “authenticated at login” and “accessing a surface that enables bulk data extraction.” Login MFA proves identity when a session starts. Step-up MFA proves continued identity at the moment of high-risk data access. What admins need to do now — four steps Report Step-Up MFA — Admin ActionsLive July 1 1Communicate to all report users before they discover it themselvesWithout context, users interpret the verification prompt as a security incident, phishing attempt, or system error. A one-paragraph internal message — what the prompt is, why it appears, what to do if it fails, who to contact — prevents a wave of support tickets and builds trust rather than confusion. 2Verify all active users have an enrolled MFA methodSetup → Identity → Identity Verification. Add MFA enrollment status column to your user list view. Users without any enrolled method fall back to email or SMS OTP. If that also fails — no mobile number registered, slow email delivery — they cannot open reports. Reach out to unenrolled users directly. 3Configure the re-verification interval for your team’s workflowThe 120-minute default is adjustable and most documentation skips this. Find it at: Setup → Identity → Session Settings → High-Assurance Session Timeout. The setting is org-wide. Consider shorter (60 min) for regulated environments; consider longer (240 min) for teams running reports continuously throughout the day. 4Create a user FAQ covering the four questions that will recurAnswer proactively: what is this prompt, how to enroll an MFA method, what to do if verification fails, and whether the prompt means the account has been hacked. A Chatter post or internal knowledge article takes an hour and replaces dozens of individual support conversations. Configuring the re-verification interval — where to find it Setup → Identity → Session Settings → High-Assurance Session Timeout 60 minRegulated environments — HIPAA, SOC 2, or internal policies requiring shorter session timeouts. More frequent prompts, stronger security posture. Appropriate if your audit requirements specify session limits. 120 minDefault — Salesforce’s chosen balance between security and usability. Suitable for most orgs. Users in standard report workflows will see the prompt once or twice per working day. 240 minHigh-frequency reporting teams — Analytics, operations, and management teams running reports throughout the day who find 120-minute prompts disruptive. One prompt at the start of the work session, one at the end. The setting is org-wide. No per-profile or per-permission-set configuration is available in the current release. One interval applies to all internal users. What this does not affect External users and Experience Cloud community users are not covered by the report step-up requirement in the current enforcement scope. The change applies to internal users accessing Salesforce through the standard internal login path. Reports embedded in Lightning record page dashboards operate differently from reports accessed directly through the Reports tab. The step-up prompt fires when a user navigates directly to a report — not currently when a dashboard component rendering report data is loaded on a record page. This distinction matters for orgs where report data is primarily surfaced through embedded dashboard components rather than the Reports tab itself. Step-up MFA on reports has been live since July 1. If your users have already encountered it, the communication gap already cost you some support tickets. The remaining configuration work — interval adjustment and the internal FAQ — takes less than a day and prevents the same tickets from recurring every time a new user hits the prompt for the first time. Salesforce AdminSalesforce SecurityMFASalesforce Reports Share: LinkedIn Twitter / X Copy link In this article 01What step-up MFA means 02Why Salesforce introduced it 034 admin actions required 04What this does not affect ⚡ Four admin actions Communicate to all report users first Check MFA enrollment for every user