By LinkedInEditors
Publication Date: 2026-10-07 10:00:00
In one week in August 2026, Salesforce launched Slack Code, which lets anyone tag a coding agent into a conversation and ship a pull request, and then announced Claudeforce, which wires Claude directly into live Salesforce data and workflows. It was Anthropic’s third native embed of the year, after Slack and Microsoft 365. Each announcement promised the agents would “inherit” the host platform’s security model from day one. Not one of them passed through a procurement review, because nothing was procured.
Agents are the first attack surface that grows without an adoption decision.
AI security assumed a moment: a committee, a license, a review, a surface to instrument. The toolkit built for that moment (model scanning, prompt inspection, gateway enforcement) only works when someone in the company chose the thing being secured. Agents…


