Salesforce Hosted MCP
Expose approved record operations, standard platform services, Flows, Apex actions, REST endpoints, prompts, and agents as discoverable capabilities.
OAuth-authenticated and scoped to the Salesforce user context.

DataInbox policy boundary
State · rules · permissions · approval · evidence
Companion architecture
DataInbox does not need to recreate Salesforce. It needs a stable contract for discovering, permitting, invoking, and recording the capabilities Salesforce already owns.
Business signal
Renewal approaching
Case escalated
Quote requested
Order changed
DataInbox Capability Registry
Resolve identity, current state, purpose, policy, eligible tool, required approval, and accepted result contract.
Salesforce Companion
Hosted MCP tool
Flow or Apex action
SObject operation
Agentforce capability
The Salesforce result returns through the same boundary. It is validated, stored as evidence, and becomes the next explicit business message rather than disappearing into an agent conversation.
Capability sources
The Companion can select the most appropriate supported surface without changing who owns the business decision.
Expose approved record operations, standard platform services, Flows, Apex actions, REST endpoints, prompts, and agents as discoverable capabilities.
OAuth-authenticated and scoped to the Salesforce user context.
Discover registered APIs and MCP servers, inspect operations, and manage which external MCP assets are allowed inside the Salesforce organisation.
A programmatic capability inventory instead of a hand-maintained connector list.
Use Salesforce's open agent skills for repeatable workflows, the Salesforce CLI for deterministic development operations, and direct APIs where the contract requires them.
Instructions and transport remain separate from business authority.
The Companion contract
A connector can move payloads. A Companion makes a provider's capabilities legible to the runtime: what exists, who can use it, which schema it expects, what it may change, and which evidence returns.
It never receives permission merely because a tool is technically available.
Explore the full architectureOAuth, External Client App, scopes, user identity, and revocation.
Available MCP tools, APIs, skills, schemas, and versioned operations.
Accounts, contacts, opportunities, cases, quotes, orders, and custom objects.
Flows, Apex logic, REST endpoints, prompts, and specialist Agentforce agents.
Permitted reads and writes plus results returned as governed business messages.
Tool identity, input contract, approval, result, error, and resulting business state.
Example operation
Intelligence can help prepare the proposal. Deterministic state, policy, permission, execution, and evidence remain explicit.
A renewal signal enters the relevant Inbox as a verified business message.
DataInbox resolves current account state, policy, purpose, permissions, and required approval.
The Companion identifies the eligible Salesforce capability and its input contract.
An approved model may prepare the renewal proposal from the bounded context.
Salesforce executes the approved Flow, Apex action, or record operation in the user's context.
The result returns to DataInbox with evidence and becomes the next governed business message.
Clear authority boundary
DataInbox owns
Salesforce owns
Skills are not the runtime
Salesforce in Claude includes a product-specific set of sales skills. Separately, Salesforce maintains an open development skills library that supports multiple compatible coding agents, including Codex.
DataInbox should reproduce the durable business capability, such as preparing a renewal, not copy a provider-specific prompt experience. That keeps the same operation available when the model or interface changes.
Read the complete analysisDirect answers
No. A conventional connector mainly transports data. The Salesforce Companion also describes authenticated capabilities, schemas, operations, and result contracts so DataInbox can decide when and under which conditions they may be used.
No. Salesforce keeps its object permissions, field-level security, sharing rules, and authenticated user context. DataInbox adds company-level purpose, cross-system state, routing, approval, and evidence around the call.
Not when Salesforce can expose the existing operation through Hosted MCP or an approved API. DataInbox can invoke that capability after its own rules and permissions have been resolved.
No. A model may interpret or generate where intelligence is required, but the Salesforce capability contract and DataInbox governance remain independent of that model.
Start with one high-value operation, define its state and authority boundary, then expose only the Salesforce capabilities that operation actually needs.