Dreamforce 2026: What Actually Matters If You’re Not a Fortune 500

Dreamforce 2026 is over, and the single most useful thing we heard all week was a complaint about a word.

Flat illustration in deep plum and pale rose of a solid building with four new white-framed doorways cut into its walls at different heights, light spilling out of each one onto the ground, while a figure standing outside holds up a ring of gold keys and a low garden wall to the left runs a short way and simply stops.

We spent three days on the floor and published six dispatches while we were there, one from the advisory side and one from the build side each day. This is the synthesis: what a twenty person business or a nonprofit with four people in the office should actually take from Dreamforce 2026, and what you can safely skip. In August we wrote about what not to decide on the show floor. This is the other half of that promise.

“Headless” is the wrong word, and the presenters kept saying so

Almost every speaker we saw used the term and then apologized for it. Their objection is that “headless” sounds like something is being removed from Salesforce. Nothing is being removed. What is being added is a pile of new ways to reach the data and context already sitting in the platform.

That distinction tells you what to do about it. Nothing you have built stops working. These are new doors into a building you already own, and the question in front of you is who gets a key.

What actually shipped, and what is still a slide

The layer doing the work is AIforce, which sits above Salesforce’s AI agents and connects to whatever front end you put in front of it. Claude. Slack. Something you build. The Claude connector is generally available now.

Two other pieces are worth knowing by name, because they are the ones your users will eventually ask for.

The Headless Experience Layer, shortened to HXL, builds a piece of interface once and renders it natively wherever your people already are: Slack, Teams, ChatGPT, or Salesforce itself. The dynamic version assembles that interface in real time from what was asked for. Beta now, general availability in November.

Quick Pages is the other half. Describe the page you need in plain language, get a working application back in minutes, inside Salesforce, obeying your existing permissions and sharing rules. Salesforce is pitching it straight at shadow IT, which is the right pitch. Beta by the end of October, general availability in 2027.

Now the part to hold onto. In the keynote demo, every single action was triggered by a human being. Someone pressed go, then pressed go again. Take that as a warning about your budget rather than a knock on the demo. Fund the interface change, which is real and available today. Leave the autonomy out of the number until it arrives.

We have been running this for a while, which is how we know where it bites

We are not neutral on this. Iron Triangle already runs a fleet of AI agents across our own business, one per function, and they have had command line access into our own Salesforce org for some time. Watching Salesforce stand up and formally support a pattern we were already running was a strange and welcome morning.

What we did not have is the structure around it, and that is what was announced. Governed MCP servers settled our own early nervousness about opening an org up this way. MCP, the Model Context Protocol, is the standard an outside tool uses to reach into a system on your behalf. Named Queries do the same job from another angle: a tightly scoped, read only endpoint that lets another system reach specific data without a developer writing a pile of code to expose it.

Put those together and you can see where this goes. Salesforce becomes the beating heart of your operations rather than the one platform everything has to happen inside.

The honest risk assessment

Part of what made Salesforce safe was that it was hard to get into.

Not a compliment anyone at the conference would enjoy, but true, and it mattered most to exactly the organizations we work with. If you have twelve staff and no developer, the practical reason your Salesforce data never leaked through an integration is that building one was too hard to do casually. The difficulty was the control.

Those gates are coming off. Every organization that adopts this needs someone who can answer, precisely, what each connected system is allowed to read, change and delete. Not roughly. Precisely.

So the advice is restraint, which is not advice we give often. The pull to switch this on the week it ships will be strong, and the right move is to spend that week writing down the plan instead.

What will bite first: your page layouts

Here is the specific failure we expect to see most, and we wrote about it from the floor on the last day.

A great many organizations use required fields on the page layout as their data validation. The field is marked required on the screen, so nobody can save the record without filling it in, and that is the entire rule. No validation rule behind it. Not required in the metadata. It has worked for years because every record has always arrived through a screen.

Now picture the thing HXL makes easy: a user spins up a small surface in Slack showing just the three fields they care about, and updates a record from there. The layout never loads. The requirement never fires. It only ever existed on the layout.

Relying on layout requirements for data that matters has always been the wrong pattern, and plenty of people have said so for years. The difference is that it used to be a tidiness argument, and now it is a correctness one. Headless access will force the issue whether or not anyone gets around to it first.

The change management nobody is costing

Security gets the attention. Adoption is the harder bill.

Ask what happens to the person who has done the same job the same way for six years, through the same screen, and is now told the screen is optional. The page layout problem is one instance of a much larger pattern: this changes where work happens, who sees what, and what “done” looks like, for people who did not ask for any of it.

For calibration, take the two nonprofits who described their migration off NPSP onto Nonprofit Cloud, the most useful session of the week because they brought real numbers. Thirteen months against a nine month plan. Revenue up by more than half afterward. The payoff was large, and it still took four months longer than anyone told them. Budget the same way here.

What to do in the next thirty days

Three things, and none of them requires a purchase.

Find out where your org is held together by a page layout. Pull the list of fields marked required on layouts and check which have a real validation rule or a required flag in the metadata. Every gap is a record an agent can write badly.

Decide who is allowed to connect something, and who reviews it. The control point for all of this sits with your administrator, which was the clearest message of the week. Settle that before anything is installed, not after the first bad write.

If you have developers, start from Salesforce’s own published skills rather than writing your own. A skill is a packaged task an AI tool already knows how to run in your org, and Salesforce maintains a validated set. Do not write your own until you hit something theirs cannot do.

What you can skip

The managed package gap, unless you sell software. Packaged products cannot yet ship with their connection configuration ready to switch on, so each customer’s admin wires it up. Enormous for a software vendor, irrelevant otherwise.

Quick Pages, for now. General availability in 2027 makes it a reason to keep reading rather than a plan.

The credit arithmetic. Work out what the interface change is worth to you before you model what it costs.

Where this leaves you

The gap between what a large enterprise can do with this and what you can do with it just narrowed, which is not something we get to write often. The interface problem is being solved in public by people with more engineers than any of us have. Your data and your processes are still yours, and nothing announced this week fixes them for you.

We did this ourselves before Salesforce shipped the tooling to make it easy, and we have taken a few clients through it since. That is the whole reason we can tell you where it hurts.

Ready to find out what an agent would actually find in your Salesforce data? Let’s talk about what it would take to open your org up safely. Schedule a consultation today!

Responses

Leave a comment

Your email address is not published, and we will not add you to anything. Required fields are marked with an asterisk.

Subscribe to our Updates

Sign up to hear from us!