Demo Request
Take a personalized product tour with a member of our team to see how we can help make your existing security teams and tools more effective within minutes.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Home
Blog

Claudeforce Makes One Thing Clear: Apps Aren't Dying. They're the Agent's Runtime.

Tal Shapira
Updated
September 2, 2026
September 2, 2026
3 min read
Ready to Close the SaaS Security Gap?
Chat with us

Two things landed last week that, on the surface, have nothing to do with each other. Read together, they tell you exactly where enterprise AI is headed.

Claudeforce Is More Than a Salesforce Integration

Salesforce and Anthropic announced Claudeforce, an expanded partnership that plugs Claude directly into the data, workflows, and governance of the Salesforce platform. The headline product is Salesforce in Claude — a plugin with 37 prebuilt sales skills (e.g., meeting prep, deal health, pipeline review) that lets a seller reason over live revenue data and take governed action without leaving Claude. Under the hood, it runs on AIforce, Salesforce's new harness that exposes business data and workflows to any agent through MCP servers, APIs, and CLI tools. Claude, in turn, shows up inside Agentforce, Slack, and the Salesforce Trust Boundary via Bedrock.

Strip away the branding and here's what actually happened: an AI model got a standing, governed connection into a third-party SaaS platform's data and actions, mediated by MCP.

This isn’t a new move for Anthropic. It's the third time this year:

  • Claude Tag: an agent that lives inside Slack channels, tagged in like a teammate
  • Claude for Microsoft 365: Claude embedded across Excel, Word, PowerPoint, and Outlook, carrying context between apps
  • Claudeforce: Claude embedded inside Salesforce, running through Salesforce's own MCP layer

Three different apps, three different integration mechanics, one consistent thesis: the way you deliver a genuinely useful agent isn't a better chatbot. Rather, it's deep, native wiring into the app that already holds the data, the workflow, and the permission model.

The "SaaS is Dead" Crowd Should Look at Workday's Numbers

For the past two years, a certain corner of tech commentary has insisted that agents kill SaaS — that a good enough model plus a browser makes the app layer irrelevant. Workday's Q2 earnings, released the same week as Claudeforce, say the opposite. Aneel Bhusri reported that AI is now driving over a quarter of Workday's new annual contract value, and more than 5,500 customers are actively running at least one of Workday's own agents. Instead of agents replacing the platform, we’re increasingly seeing agents inside the platform, sold as the platform, driving the platform's growth.

Put Claudeforce and Workday side by side and the pattern is unmistakable: the agent is not competing with the SaaS app. The agent's tools are the SaaS app. Its knowledge is the SaaS app's data. This is how the overwhelming majority of enterprise AI — I'd put it north of 95% — is actually being consumed today: not as a standalone model answering questions from memory, but as a model reasoning over live, permissioned, governed access to the systems of record the business already runs on.

This Means the Security Perimeter Just Moved…Again

Every one of these integrations creates a new access path: an agent identity with live credentials, scoped permissions, and the ability to read and act on production business data. 

This is the exact problem Reco was built for. If protecting AI and agents matters, you can't stop at knowing which SaaS apps exist. You have to be able to connect the dots across every app-to-agent and app-to-app connection — who's talking to what, through which protocol, with which permissions.

The Takeaway

Claudeforce, Claude Tag, and Claude for Microsoft 365 aren't three separate product launches. They're the same bet, placed three times: the winning agent architecture is the one wired natively into the apps where work already happens. Workday's earnings call is the proof that this bet is paying off in revenue, not just press releases.

For those of us in security, that's the whole point. The apps aren't dying — they're becoming the runtime for AI. Which means the only way to actually protect AI and agents is to see, in real time, every connection between them.

No items found.

Tal Shapira

ABOUT THE AUTHOR

Tal is the Cofounder & CTO of Reco. Tal has a Ph.D. from the school of Electrical Engineering at Tel Aviv University, where his research focused on deep learning, computer networks, and cybersecurity. Tal is a graduate of the Talpiot Excellence Program, and a former head of a cybersecurity R&D group within the Israeli Prime Minister's Office. In addition to serving as the CTO, Tal is a member of the AI Controls Security Working Group with the Cloud Security Alliance.

Technical Review by:
Gal Nakash
Technical Review by:
Tal Shapira

Tal is the Cofounder & CTO of Reco. Tal has a Ph.D. from the school of Electrical Engineering at Tel Aviv University, where his research focused on deep learning, computer networks, and cybersecurity. Tal is a graduate of the Talpiot Excellence Program, and a former head of a cybersecurity R&D group within the Israeli Prime Minister's Office. In addition to serving as the CTO, Tal is a member of the AI Controls Security Working Group with the Cloud Security Alliance.

Table of Contents
Let’s Talk About Your Non-Human Users
Chat with us
Get the Latest SaaS Security Insights
Subscribe to receive updates on the latest cyber security attacks and trends in SaaS Security.

Your agents are already running. Do you know what they're doing?

Request a demo