Salesforce Companion

    Salesforce supplies the capabilities. DataInbox governs the operation.

    Connect Salesforce data, automation, APIs, skills, and MCP tools to a company-owned control layer. Keep current state, rules, authority, approval, and evidence in DataInbox while Salesforce remains the system that performs its specialist operations.
    • OAuth-authenticated capabilities
    • Reuse Flows and Apex
    • Model-independent operation
    • Evidence returned to the Inbox
    Salesforce
    MCP
    APIs
    Skills
    governed by

    DataInbox policy boundary

    State · rules · permissions · approval · evidence

    Companion architecture

    One governed boundary around every Salesforce capability.

    DataInbox does not need to recreate Salesforce. It needs a stable contract for discovering, permitting, invoking, and recording the capabilities Salesforce already owns.

    Business signal

    Renewal approaching

    Case escalated

    Quote requested

    Order changed

    DataInbox Capability Registry

    Resolve identity, current state, purpose, policy, eligible tool, required approval, and accepted result contract.

    Salesforce Companion

    Hosted MCP tool

    Flow or Apex action

    SObject operation

    Agentforce capability

    The Salesforce result returns through the same boundary. It is validated, stored as evidence, and becomes the next explicit business message rather than disappearing into an agent conversation.

    Capability sources

    Use what Salesforce exposes. Keep the operating contract yours.

    The Companion can select the most appropriate supported surface without changing who owns the business decision.

    Salesforce Hosted MCP

    Expose approved record operations, standard platform services, Flows, Apex actions, REST endpoints, prompts, and agents as discoverable capabilities.

    OAuth-authenticated and scoped to the Salesforce user context.

    API Catalog

    Discover registered APIs and MCP servers, inspect operations, and manage which external MCP assets are allowed inside the Salesforce organisation.

    A programmatic capability inventory instead of a hand-maintained connector list.

    Skills, CLI, and APIs

    Use Salesforce's open agent skills for repeatable workflows, the Salesforce CLI for deterministic development operations, and direct APIs where the contract requires them.

    Instructions and transport remain separate from business authority.

    The Companion contract

    More than a connector. Less than a new authority.

    A connector can move payloads. A Companion makes a provider's capabilities legible to the runtime: what exists, who can use it, which schema it expects, what it may change, and which evidence returns.

    It never receives permission merely because a tool is technically available.

    Explore the full architecture

    Authentication

    OAuth, External Client App, scopes, user identity, and revocation.

    Discovery

    Available MCP tools, APIs, skills, schemas, and versioned operations.

    Business objects

    Accounts, contacts, opportunities, cases, quotes, orders, and custom objects.

    Existing automation

    Flows, Apex logic, REST endpoints, prompts, and specialist Agentforce agents.

    Actions and events

    Permitted reads and writes plus results returned as governed business messages.

    Evidence

    Tool identity, input contract, approval, result, error, and resulting business state.

    Example operation

    Prepare a renewal without handing the process to the model.

    Intelligence can help prepare the proposal. Deterministic state, policy, permission, execution, and evidence remain explicit.

    1. 01

      Receive

      A renewal signal enters the relevant Inbox as a verified business message.

    2. 02

      Resolve

      DataInbox resolves current account state, policy, purpose, permissions, and required approval.

    3. 03

      Discover

      The Companion identifies the eligible Salesforce capability and its input contract.

    4. 04

      Propose

      An approved model may prepare the renewal proposal from the bounded context.

    5. 05

      Perform

      Salesforce executes the approved Flow, Apex action, or record operation in the user's context.

    6. 06

      Record

      The result returns to DataInbox with evidence and becomes the next governed business message.

    Clear authority boundary

    Let each platform own what it is good at.

    DataInbox owns

    • Cross-system business state and objectives
    • Purpose, policy, routing, and capability eligibility
    • Human approval and accepted result contracts
    • Evidence, lineage, and the next business message

    Salesforce owns

    • Salesforce records, schemas, and relationships
    • Salesforce permissions, sharing, and user context
    • Flows, Apex, APIs, prompts, and Agentforce logic
    • Execution inside the Salesforce transaction boundary

    Skills are not the runtime

    Reuse the capability. Do not bind the business to one assistant.

    Salesforce in Claude includes a product-specific set of sales skills. Separately, Salesforce maintains an open development skills library that supports multiple compatible coding agents, including Codex.

    DataInbox should reproduce the durable business capability, such as preparing a renewal, not copy a provider-specific prompt experience. That keeps the same operation available when the model or interface changes.

    Read the complete analysis

    Direct answers

    Salesforce Companion FAQ

    Is the Salesforce Companion another CRM integration?

    No. A conventional connector mainly transports data. The Salesforce Companion also describes authenticated capabilities, schemas, operations, and result contracts so DataInbox can decide when and under which conditions they may be used.

    Does DataInbox replace Salesforce permissions?

    No. Salesforce keeps its object permissions, field-level security, sharing rules, and authenticated user context. DataInbox adds company-level purpose, cross-system state, routing, approval, and evidence around the call.

    Do existing Salesforce Flows or Apex actions need to be rebuilt?

    Not when Salesforce can expose the existing operation through Hosted MCP or an approved API. DataInbox can invoke that capability after its own rules and permissions have been resolved.

    Is the Companion tied to one AI model?

    No. A model may interpret or generate where intelligence is required, but the Salesforce capability contract and DataInbox governance remain independent of that model.

    Make Salesforce your first governed Companion.

    Start with one high-value operation, define its state and authority boundary, then expose only the Salesforce capabilities that operation actually needs.