Skip to main content

Salesforce AIforce Can Act on Commerce. What Should It Be Allowed to Change?

Salesforce AIforce Can Act on Commerce. What Should It Be Allowed to Change?

The interesting part of AIforce is not that an AI assistant can read Salesforce data.

It is what happens when the assistant can change something.

A merchandiser says, “Boost high-margin products that are overstocked.”

An order manager asks, “Move orders away from this fulfillment location before we miss the delivery promise.”

A developer tells an AI assistant to investigate an incident and fix the configuration causing it.

All three requests are easy to express.

The difficult part begins when the system decides to act.

Which records can it touch? Which rules must still apply? Does a person need to approve the change? What gets recorded? And if an agent makes the wrong decision, can the business understand exactly what happened?

That is the more consequential story behind Salesforce’s latest push into AIforce.

Salesforce describes AIforce as a live interface layer that makes Salesforce data, workflows, business logic, semantics, permissions and governance available wherever humans and AI agents work. The Headless Toolkit underneath it exposes those capabilities through MCP, APIs, plug-ins, skills and developer tooling.

For commerce teams, that changes the conversation.

The question is no longer just:

Can AI understand the business?

It is increasingly:

What should AI be allowed to do to the business?

AIforce Makes the Action Boundary More Important

For years, commerce permissions were largely designed around humans navigating applications.

A merchandiser opened Business Manager.

An operations user worked in an OMS.

A developer used an IDE, CLI or administration console.

The interface provided a natural boundary between intention and execution.

AI weakens that boundary.

Salesforce Merchant Agent can already turn natural-language merchandising requests into activities such as product categorization, sequencing, and boost-and-bury rules. Salesforce currently marks several of these capabilities as generally available.

Salesforce’s Order Management direction goes further. Its Commerce innovation page describes an MCP Server for OMS that allows agents to query, update and resolve order issues through a headless architecture, alongside Slack actions for modifying routing rules and estimated processing times.

That is a useful shift.

But it changes the risk model.

A poorly chosen search term is annoying.

A poorly executed refund, price update, routing change or inventory action can have an immediate operational or financial consequence.

The closer AI gets to execution, the clearer the execution boundary needs to become.

A Useful Way to Think About AI Autonomy in Commerce

Our view is that commerce teams should not treat “agent access” as a binary question.

There are really four progressively more consequential levels:

  1. Read — The agent can retrieve order, product, customer, inventory or operational information but cannot change it.
  2. Recommend — The agent can reason over the information and propose an action, but a human or deterministic system decides whether to proceed.
  3. Approve and execute — The agent can prepare the action, but defined categories of change require explicit approval before execution.
  4. Autonomous execution — The agent can perform bounded, well-understood operations without human approval because permissions, validation, observability and recovery have already been established.

Not every commerce operation belongs at level four.

And that is fine.

The objective should not be maximum autonomy.

It should be appropriate autonomy.

Salesforce’s MCP Design Shows Why the Distinction Matters

Salesforce’s broader Headless 360 MCP Server, now under the AIforce naming transition, provides a useful architectural example.

The server separates discovery from execution.

An agent can first discover available Salesforce operations, retrieve the technical contract for an operation, and then dispatch it. Salesforce also provides a separate read-only dispatch path.

That separation is more important than it may initially appear.

The model does not have to invent how Salesforce should be changed.

It can discover an existing capability.

It can inspect the contract.

Then the platform decides whether execution is permitted.

Salesforce states that Hosted MCP transactions run as the authenticated user and continue to respect CRUD permissions, field-level security, sharing rules, profiles and permission sets. Its documentation also says audit trails attribute actions to that user.

Salesforce goes a step further in its own guidance: MCP clients should be configured carefully and, particularly for operations that modify or delete data, teams should consider requiring approval before tools execute.

That is a sensible pattern for commerce as well.

MCP Should Expose Commerce Capabilities, Not Become Your Commerce Logic

As MCP adoption grows, there is a risk that teams treat the protocol itself as the architecture.

It isn’t.

MCP can help an agent discover that a capability exists and provide a structured way to invoke it.

But the commercial rules should still belong to the systems responsible for them.

Consider:

“Give these products another 10% discount.”

The AI can interpret the instruction.

The underlying pricing capability should still determine whether the products are eligible, which price books apply, when the change becomes effective, whether promotions conflict, and which markets or channels inherit the adjustment.

Or:

“Reroute orders away from warehouse A.”

The model may correctly identify the requested outcome.

The OMS still needs to decide which locations are eligible, whether inventory exists, whether delivery promises can be maintained and which routing rules have priority.

AI can reason about the request.

Commerce systems should remain responsible for the transaction.

That gives us a principle we think will become increasingly important:

Reason probabilistically. Execute deterministically. Observe everything.

This Is Already Becoming a Commerce-Specific Salesforce Story

It would be easy to treat AIforce purely as another platform announcement.

Commerce is already giving us concrete examples.

Salesforce’s Agentic B2C Developer Toolkit includes a B2C CLI, IDE integration, MCP support and agent skills that let AI-assisted development tools work with B2C Commerce documentation, logs, cartridges and SCAPI administration.

Merchant Agent brings natural-language operations into merchandising.

Order Management exposes order intelligence and actions beyond a traditional OMS screen, including through MCP and Slack.

There is an important availability nuance, though.

The B2C developer tooling and several Commerce features are listed as GA, while Salesforce’s broader Headless 360 MCP Server is still documented as a Beta service.

That distinction matters when an architect moves from a Dreamforce announcement to a production design.

Vision, beta capability and generally available functionality should not be treated as interchangeable.

And Yes, Headless 360 Is Now AIforce

The naming deserves a short clarification because even Salesforce’s documentation is still transitioning.

Salesforce’s release notes state that Headless 360 was rebranded to AIforce on September 4, 2026 and warn that Headless 360 references may continue to appear during the transition.

The underlying idea remains consistent: turn Salesforce functionality into reusable capabilities that humans, applications and AI agents can consume outside a fixed application interface.

What has become more interesting at Dreamforce is what happens once those capabilities stop being theoretical and begin changing real operational systems. As explored in our analysis of AI Agents as the New Storefront, the real hurdle is never the conversation—it is the enterprise commerce foundations underneath.

The Permission Model May Matter More Than the Model

Much of the AI market is still focused on model selection.

Claude or GPT? Which reasoning model? How large is the context window? How good is the benchmark score?

Those questions matter, but commerce introduces another set of questions that may ultimately be more important:

  • Who is the agent acting as?
  • What can that identity access?
  • Which operations are read-only?
  • Which require approval?
  • Which rules execute regardless of what the model requests?
  • What evidence remains after the action?
  • How do you reverse it?

One of the more useful themes in the practitioner discussion around Dreamforce was exactly this shift.

People were less interested in whether MCP could technically connect AI to Salesforce and more interested in what identity, permissions and auditability look like once AI starts writing back into enterprise systems.

That is the right question.

The Best AI Architecture May Contain More Deterministic Software, Not Less

There is a tendency to treat each improvement in AI capability as another reason to remove traditional software.

Commerce may prove the opposite.

The more naturally an AI agent can interpret ambiguous instructions, the more valuable clear downstream contracts become:

  • The agent can decide what the user probably means.
  • A workflow can validate it.
  • A pricing service can enforce commercial rules.
  • An OMS can protect fulfillment invariants.
  • A payment system can maintain transaction controls.
  • An audit layer can preserve what happened.

AI becomes the reasoning layer.

It does not need to become every layer.

Where Tailoredd Fits

Tailoredd supports MCP as part of making commerce capabilities accessible to AI-driven experiences and agents.

Our preference is the same architectural separation described above: expose clear capabilities rather than duplicating business logic inside prompts.

An agent should be able to understand what a commerce service can do, discover the inputs it needs and invoke it when authorized.

The service itself should remain responsible for its business rules, validation and execution.

That matters especially as commerce becomes increasingly distributed across storefronts, CRM, OMS, ERP, payments, subscriptions, reviews, marketplaces and fulfillment systems. For a detailed technical blueprint covering boundary enforcement, tool schema validation, and audit trail patterns for autonomous tools, review our engineering reference on Commerce MCP Agents & Operational Boundaries.

AI can make that complexity much easier to operate.

It should not make responsibility for the underlying operation harder to understand.

Learn more in the Tailoredd documentation and explore our native commerce platform cartridges across ratings and reviews (ReviewFlow), subscriptions (Orderly), COD risk (Flo), and multi-vendor marketplaces (Emporio).

The Real AIforce Question

The first era of enterprise AI was largely about answers.

The next one is about actions.

That is a far more meaningful transition.

Once an agent can alter a catalog, modify an order, adjust routing, update customer data or trigger downstream workflows, intelligence alone is not enough.

Commerce needs:

  • Identity
  • Permissions
  • Business rules
  • Approval boundaries
  • Auditability
  • Predictable execution

Salesforce is making it much easier for AI to reach the systems that run commerce.

The companies that benefit most may not be the ones that give agents access to everything first.

They may be the ones that define most clearly what an agent is allowed to change, under which conditions, and how every action is governed once it leaves the prompt.

Reason with AI. Execute with certainty.


Frequently Asked Questions

What is Salesforce AIforce?

AIforce is Salesforce’s current name for the architecture previously called Headless 360. Salesforce positions it as an interface layer that brings its data, workflows, business logic, permissions and governance into AI and other external interfaces.

Does Salesforce AIforce replace Flow or Apex?

No. AIforce and MCP make Salesforce capabilities easier for agents to discover and invoke. Existing workflows, Apex, APIs, validation, security and application logic can still provide the deterministic execution behind those actions.

Is Salesforce’s AIforce MCP Server generally available?

The broader Headless 360 MCP Server is currently documented by Salesforce as Beta. Commerce-specific capabilities have their own availability states; for example, Salesforce currently lists the B2C MCP developer tooling and several Merchant Agent capabilities as GA.

What is the Salesforce OMS MCP Server?

Salesforce describes its OMS MCP Server as a headless interface through which AI agents can query order information, update information and resolve order issues using natural language.

tailoredd Data and AI Practice
Written by

tailoredd Data and AI Practice

Data Cloud, AI, and Automation Systems

The tailoredd Data and AI Practice writes about production AI workflows, data architecture, and governance patterns for commerce teams.

View Profile →