Skip to Content
0%

Data 360 Headless: Extend the Power of Data 360 to Any Agent, App, or Dev Tool

A couple of months ago, I stood on a stage in Chicago and let Claude talk to a live Salesforce org in front of a room full of practitioners. Real queries, real data.

The reaction wasn’t “wow, AI.” It was quieter. Someone in the third row asked how the connection knew what it should be seeing.

That’s exactly the right question. 

Why do agents fail? It’s rarely because the model is bad. It’s because they’re reasoning over incomplete, stale, or misunderstood business context.

Data 360 solves that problem at the layer that matters: the data foundation, not the app.

AI created a new consumer of enterprise data

For twenty years Salesforce was designed around a human sitting in front of a screen. Page layouts, validation rules, guided flows all shape what one person sees at one moment.

Agents don’t work that way. An agent doesn’t scroll. It doesn’t understand from a field label that a stage value means the deal is basically done. It doesn’t know your team stopped trusting a field eighteen months ago. It takes the context you hand it and reasons from there.

So the agent is a new user persona with an unusual requirement: unified, resolved, trusted business context delivered as data, not as UI.

That’s a context problem before it’s an agent problem. If the identity resolution ruleset is wrong, the agent is confidently wrong about who the customer is. If a calculated insight computes at the wrong grain, the agent quotes a number nobody recognizes. Bad context doesn’t produce a hesitant agent. It makes it confidently wrong.

Introducing Data 360 Headless

Data 360 Headless extends trusted business context beyond the Salesforce UI to agents, applications, and workflows wherever work happens.

Two pieces make it real. One delivers context and the other delivers expertise.

Data 360 MCP Server

The MCP Server connects your Data 360 environment to whatever AI client your team already uses, whether that’s Claude Code, Cursor, Agentforce, or whatever comes next. Instead of clicking through Setup, you describe what you want and the agent does the work: unify these profiles, build that segment, tell me what’s driving this account’s value.

Under the hood it reaches the full Data 360 toolkit, from data streams and field mappings to identity resolution, calculated insights, and segments. The whole foundation, available through conversation instead of clicks. For example, you can build calculated insights, data transforms, and segments using natural language e.g. create a calculated insight for the lifetime value of all customers for electronics purchases, excluding software.

And you won’t overwhelm the context window. Data 360 has around 200 operations, and handing an agent all 200 at once buries it. So the server offers three simple facade tools to consolidate and work smarter: one to find the right capability (search), one to show how to use it (payload_examples), and one to run it (execute). The agent searches, learns, then acts. Small surface, full reach. And, there’s a fourth tool I’ll cover below in its own section, which is where this really gets interesting.

The best part is that getting started is low-stakes. Spin up a free Data 360-enabled Trailhead playground, point the MCP server at it, and start asking questions. No production data, no code, just you and a grounded agent seeing what it can do. Begin with something you already know the answer to, like “what data do we have on this customer,” and check its work against what you know. That’s the fastest way to build trust in it and to spot where it needs guardrails.

Data 360 Prebuilt Skills

Accessing an MCP Server isn’t the same as knowing how to use it. Anyone who’s stood up identity resolution knows the difference.

The tooling will happily let you publish a ruleset matching on normalized email alone. It runs. It succeeds. No errors. The job is green. But your unified profile count just dropped forty percent, and your downstream insights (revenue metrics, segmentation, and agent responses) are now operating on a hallucinated view of your customers.

Same story elsewhere. A calculated insight whose SQL validates but computes at the wrong grain. A transform scheduled out of sync with when its upstream stream actually lands. A segment published against the wrong dataspace. None of these throw errors. All of them quietly influence what the agent says next.

That knowledge, the verification step, the “run this before you publish,” isn’t data. It’s practitioner grounding and judgment, and it lives in people’s heads.

That’s what Prebuilt Skills closes. Scenario-driven capabilities: structured instructions for complex workflows, so the experience is better and more predictable. Skills are to agents what onboarding is to a new hire. 

But what decides whether skills work at scale isn’t the content, it’s who keeps them current. Picture a fifty-person marketing team managing a skills folder by hand. It doesn’t happen. The skills drift, half the team runs a version behind, and the agent’s answer depends on whose laptop it’s on.

Headless 360 embeds the skills in the MCP server itself, delivered as a single, powerful tool alongside the three that run operations. They flow through the same connection as your data. Nobody installs anything, and when Salesforce improves a skill it just works on the next call. 

The first set of skills covers the core of foundation work: data modeling, data mapping, transforms, and code extensions. And this embedded approach is already proven in the Salesforce Headless 360 MCP.

Why they matter together

MCP provides context. Skills provide expertise.

Context without expertise gives you an agent that executes flawlessly in the wrong direction. Expertise without context gives you a well-behaved agent reasoning about a business it can’t see.

Together you get something closer to a competent data practitioner.

What this unlocks

Most of my work is with companies in regulated industries. Their data foundation is what’s blocking their AI program, and they usually don’t know that yet. Three things I’d build first:

Foundation work that compresses. Mapping, field analysis, transform design, and weeks of manual configuration happen conversationally, with the architect describing intent while the system executes and validates. That’s the difference between a program and a sprint.

Continuous readiness diagnostics. Unmapped DLO fields, match rates drifting month over month, insights nobody has queried since launch, streams silently failing. Today, that’s a person with a spreadsheet at kickoff. It should be an agent workflow that runs monthly.

The semantic layer as the real deliverable. Define dimensions, measures, and metrics once in Data 360 and every agent inherits the same definition of a qualified renewal. That’s how you stop three agents from producing three different revenue numbers.

When context goes ungoverned

Missing context fails loudly. The agent quotes a clearly wrong number and someone catches it. Ungoverned context fails silently, and that’s what matters even more.

Point a connection at your org without controls and the risk isn’t a wrong answer. It’s an agent surfacing a record to someone who was never entitled to see it or writing a change nobody can trace back to a source. In financial services or healthcare, that isn’t a bug report. It’s a disclosure event.

That’s the part I watched most closely when I ran the live connection in Chicago. It left its own footprint in the org: external client app secret retrievals in the Setup Audit Trail, logins stacked from a single IP range. All of it is observable with the same native tools I use to audit everything else. Permissions are enforced as the connected user, so the agent could only ever reach what that user could reach. Every action is attributable to a source.

That isn’t a limitation of headless architecture. It’s the proof that it belongs in a regulated org. Add Zero Copy, where the data stays in Snowflake, Databricks, BigQuery, or AWS and works from there, and you have something a CISO can approve without a six-month exception process.

Where this goes

Agent-powered operations won’t be won by whoever has the best model. Models are converging. Your business context won’t converge with anyone’s. Your unified profiles, your match rules, your metric definitions are yours alone.

That’s the moat. Data 360 Headless is how you make it available to whatever comes next without rebuilding it each time. 

The teams that win the next few years won’t be the ones with the flashiest agents. They’ll be the ones whose agents actually know the business because someone did the unglamorous work of making the context trusted, governed, and reachable. That work is the job now. Everything downstream depends on it.

So find the one workflow you know cold, and watch where an agent gets it wrong. That gap between what it assumes and what you know is the whole opportunity. Close it once, and you’ve built something every agent after it inherits.

That question from the third row in Chicago, how does the connection know what it should be seeing, turned out to be the whole story. It doesn’t. You tell it. Data 360 is where you do the telling, and everything an agent gets right after that traces back to the context, the rules, and the guardrails you put there first.

Start experimenting with Data 360 Headless

If you’re ready to start experimenting, here are a few resources to help you get hands-on:

Get the latest articles in your inbox.