What. A. Week.
Whether you walked through the San Francisco campus last week or watched from your desk on Salesforce+, the Dreamforce energy was everywhere. The event was packed with learning, meaningful connections, and an unprecedented wave of innovation.
For IT leaders, developers, and admins, the headline was unmistakable: the future of work is all about humans and AI building side-by-side on a single, trusted foundation. From security and governance, headless development, to agentic AI — we’ve got a lot to cover.
To help you jumpstart your strategy into action, here are the top five IT announcements coming out of the biggest event of year.
1. AIforce
AIforce is Salesforce’s live, composable interface layer that brings the rest of the platform to any surface.
Powered by the Headless Toolkit, every capability is accessible via API, MCP, or CLI. That means both human employees and AI agents can work side-by-side using the same trusted data, logic, and governance your business already relies on. Whether its Agentforce, Claude, or another agent of your choice — they can take action directly within your Salesforce permissions from wherever your team chooses to work, including Slack, Teams, Claude, or elsewhere.
Your Guide to Going Headless
Explore how headless capabilities under the hood and see how customers are taking Salesforce anywhere.
By unlocking value across every layer of the platform, AIforce ensures your core enterprise logic is reachable from any interface without requiring you to rebuild workflows for each surface.
2. Builder Central (Beta)
Admins are feeling the pressure — feeling the surging demand for custom apps and AI agents. Many teams may turn to standalone AI building tools, but trading enterprise security for speed is a trap. Generic tools lack your business context, and require brittle integrations and manual security setups that create severe shadow IT risks.
Builder Central bridges the gap between rapid execution and enterprise-grade security, accelerating the journey from initial concept to live production. Builder Central helps teams set up, build, and deploy solutions on Salesforce from one central hub. Now, you can use natural language prompts to turn your ideas into functional apps or AI agents. And the cherry on top? Built-in safety checks, automated testing, and strict deployment controls means built-in security throughout the entire process.
3. Headless Experience Layer and Multi-Framework (GA)
We’ve launched several updates to help your team build flexible, modern digital experiences faster. First, the Headless Experience Layer is now generally available. It lets you set up your core business rules just once, then automatically translates them into secure, native user interfaces across any surface — whether that’s a Salesforce Lightning component or a Slack message.
Another innovation making it easier for teams to build with flexibility is Salesforce Multi-Framework. Engineers can build with industry-standard frameworks like React and, newly, Angular. And now generally available: micro-frontends, letting React and Angular components embed natively within Lightning, Experience Cloud, Salesforce Mobile, and Mobile Publisher apps. On the horizon, new beta features include: Angular support for building, previewing, and deploying production apps natively on Multi-Framework, plus Quick Pages and Builder Central for natural-language app building.
4. Security Mesh
Enterprises have access to more data than ever, for many security teams, this means fragmented visibility across isolated system — making it difficult to spot connected threats, like an identity compromise spanning both Salesforce and an external identity provider.
To solve this, we introduced Security Mesh, a native solution built specifically for Salesforce admins and security personnel. Delivered directly through Security Center, our centralized add-on for overall security posture management. Security Mesh unifies and normalizes disparate security telemetry across multiple platforms. This gives your security operators a single, normalized pane of glass to identify anomalous API activity, detect compromised accounts, and shut down security blind spots before they escalate.
Dreamforce
Security Keynote
Learn how to secure and govern your Agentic Enterprise. Outpace evolving threats and accelerate AI initiatives with ironclad trust, visibility, and guardrails.
5. MCP Security & Risk Scores
Agents are gaining broader access than ever before to external data and tools. Extending an agent’s capabilities means connecting it to outside systems, but with every external integration, a potential vulnerability is introduced. Without proactive safeguards, organizations risk exposing their environments to hidden risks, data exposure, and unauthorized actions.
Now, MCP Risk Scores automatically scans these servers during Agentforce registration to uncover hidden threats that traditional natural language controls miss, such as prompt injections, tool poisoning, and rug pull attacks. Upon registration, the system evaluates each server to deliver a clear risk rating — Low, Medium, or High — alongside actionable remediation steps before any connection is authorized.
Once integrated, continuous scanning detects and flags malicious post-registration changes over time. As your agent ecosystem grows, you can ensure your platform remains secure and resilient.
Build the Future with Trust
Dreamforce spent the week redefining enterprise innovation, showing that true speed is only possible when trust is built in from day one.
The Salesforce Platform provides the underlying security and governance infrastructure required to power your Agentic Enterprise. By embedding these guardrails directly into every tool and workflow, organizations can safely accelerate their path from idea to impact.










