The Three Security Questions Salesforce Needs to Answer at Dreamforce 2026

Dreamforce 2026, running September 15-17 in San Francisco, will feature a dedicated security keynote titled "Trust Across Agents, Data, and Platforms" along with more than 30 security-focused sessions. For enterprise security teams, the event is less about announcements and more about whether Salesforce can answer three fundamental questions about how autonomous agents get authenticated, audited, and constrained.
The threat landscape driving those questions is concrete. In 2026, security researchers documented active exploitation of an MCP Gateway authentication bypass (CVE-2026-59822) chained with a command injection (CVE-2026-42271). Trend Micro found 492 MCP servers running without any authentication. Hugging Face was breached by 700 rogue agents operating without human direction. Aurora ransomware affiliates used the Cursor coding agent for hands-on intrusion work.
Salesforce's answer, the Trusted Enterprise AI Harness with its AI Control Plane, is designed for agent identity, policy enforcement, and lifecycle management. The integration of Anthropic's Claude into the Salesforce Trust Boundary via Amazon Bedrock, branded "Claudeforce," wraps a third-party model in an enterprise-grade security layer.
Key Takeaways
- Agent identity is still unresolved. When an agent acts on behalf of a user, how are its permissions scoped, and how does the system prevent privilege escalation beyond the user's original intent? Standard OAuth flows may be insufficient for multi-step agent reasoning chains.
- Headless authentication is the hardest problem. When an agent is running in the background, disconnected from a human session, how does the enterprise verify its identity and confirm it has not been tampered with?
- Multi-agent audit trails are required, not optional. In a multi-agent environment, tracing a malicious action to a specific agent, model, or policy configuration is difficult without granular, immutable logs that security teams can use for incident response.
Sessions to watch at Dreamforce: "Headless is Not Brainless: Security at Agentic Scale" and "A Governance Playbook for Agentforce and MCP."
Read the full article on Forkast
Stay in Rhythm
Subscribe for insights that resonate • from strategic leadership to AI-fueled growth. The kind of content that makes your work thrum.
More from Thrum
Additional pieces exploring adjacent ideas
