Skip to content
Tekunda Team

Tekunda Team

Enterprise MCP Integration: Connecting AI Agents to Salesforce Safely

Enterprise MCP Integration: Connecting AI Agents to Salesforce Safely

Enterprise MCP integration means exposing your business systems to AI agents through the Model Context Protocol, an open standard, instead of building one custom connector per agent and per tool. Done well, every agent call runs under a real user's identity and permissions, so the security model you already trust carries over. Done badly, it is a new, unaudited back door into your CRM.

What is enterprise MCP integration?

MCP is an open protocol that lets an AI client (Claude, ChatGPT, Agentforce, an IDE) discover and call tools published by an MCP server. Anthropic introduced it in November 2024, and in December 2025 it was donated to the Agentic AI Foundation under the Linux Foundation, so no single vendor controls it.

The word "enterprise" adds three requirements that quick demos skip: per-user authentication, least-privilege authorization and an audit trail for every tool call.

Why are enterprises standardizing on MCP now?

Because the major platforms shipped it. OpenAI adopted MCP in March 2025 and Google DeepMind followed in April 2025. On the Salesforce side, hosted MCP servers reached general availability on April 29, 2026 for Enterprise Edition and above, with no separate connector fee. On August 19, 2026 Salesforce expanded Headless 360 with a Headless 360 MCP Server in open beta and a generally available Data 360 MCP Server.

The practical effect: integration work shifts from writing connectors to governing what agents may do. It is the same discipline as classic Salesforce integration architecture, applied to a new kind of caller.

What is the Salesforce Headless 360 MCP server?

The Headless 360 MCP Server gives an agent four tools instead of thousands of endpoints:

  • Discover - semantic search over a library of skills.
  • Describe - returns the API contract and ordered steps for one skill.
  • Dispatch - executes the chosen skill.
  • Dispatch Read Only - runs read-only operations.

The beta launched in July 2026 with roughly 100 skills, covering user management, Apex triggers, platform events, Change Data Capture and Named Credentials. Salesforce says agents inherit the identity, permissions and business logic already configured in the org. We cover rollout and sizing in our Headless 360 adoption guide.

How is MCP different from a direct API integration?

  • Caller: an API integration is a fixed program; an MCP caller is an agent choosing tools at runtime.
  • Contract: APIs are coded against ahead of time; MCP tools are discovered and described on the fly.
  • Identity: API integrations often run as one integration user; a well-built MCP setup runs per user with OAuth.
  • Risk: an API does exactly what it was coded to do; an agent can chain tools in ways nobody tested.

MCP does not replace your middleware. Order sync between Salesforce and an ERP still belongs in deterministic flows, as in our Salesforce and SAP integration patterns. MCP is the layer for agent-driven, human-supervised actions.

What belongs on an enterprise MCP security checklist?

  1. Per-user OAuth, never a shared token. Salesforce hosted servers use OAuth 2.0 with PKCE through an External Client App, so CRUD, field-level security and sharing rules apply to every call.
  2. Audience-bound tokens. The MCP authorization specification requires servers to accept only tokens issued for them and forbids passing other tokens through.
  3. Read first. Start with a read-only server or tool, then grant write access per use case.
  4. Human approval on writes. Require approval before any tool call that changes data.
  5. Vet every third-party server. Prefer vendor-published servers and review community ones like code you are about to deploy.
  6. Log every tool call with user, input and outcome.

For Salesforce teams the upshot is simple: your Salesforce security checklist (profiles, permission set groups, sharing) is now your agent security checklist too. Over-permissioned users become over-permissioned agents.

Does RingCentral have an MCP server?

Yes, in labs form. RingCentral staff point users to servers for RingEX Phone, Chat and Admin documented at mcp.labs.ringcentral.com, according to the RingCentral community. (If you searched for ringcentral.vom, the domain is ringcentral.com.) Community-built RingCentral servers also exist, and their security quality varies, which is exactly why item 5 on the checklist exists.

How do you calculate the ROI of Agentforce and MCP integration?

Salesforce's Agentforce calculator estimates Flex Credits and list price from your industry, company size, seats and action volumes, for the first year, and Salesforce labels the results illustrative only. To build a business case you can defend:

  1. Pick one workflow and count how often it runs per month.
  2. Measure today's handling time, including swivel-chair work across systems.
  3. Estimate the share of runs an agent can complete with human approval.
  4. Subtract consumption costs and the integration and governance build.

Cross-system workflows usually carry the most value, because that is where people copy data between tabs. See running CRM actions from one agentic hub for a worked example.

How do you choose a Salesforce implementation partner for MCP work?

  • They start with your permission model, not the demo.
  • They can explain which flows stay in middleware and which move to MCP.
  • They scope a read-only pilot with a measurable outcome before granting write access.
  • They hand over logging, runbooks and ownership, not just a working agent.

That is how we run Headless MCP projects at Tekunda: one governed workflow first, then scale. You can learn more about our team on tekunda.com.

FAQ

Does the Salesforce hosted MCP server cost extra?

There is no separate connector fee, but it requires Enterprise Edition or above. Agentforce usage is metered separately, which is what the Agentforce calculator estimates.

Is the Headless 360 MCP server generally available?

As of August 2026 it is in open beta. The Data 360 MCP Server is generally available.

Can an MCP agent bypass Salesforce permissions?

Not on Salesforce's hosted servers. Each user signs in with OAuth, and object permissions, field-level security and sharing rules apply to every call.

Should MCP replace our integration middleware?

No. Keep high-volume, deterministic syncs in middleware and use MCP for agent-driven actions that benefit from human oversight.

Related Articles