During the live demo at this year's Salesforce conference, a sales representative did not open the CRM but directly asked Claude: "What are the risks in this deal?" Claude retrieved information from Salesforce and authorized emails, calendars, and Slack, quickly discovering that 50 of the 200 VIP seats required by the customer had not yet been secured.
After the sales representative confirmed the proposal, Claude immediately updated the business plan, drafted the customer email, and generated a new workspace interface. Throughout the entire process, Salesforce barely appeared on the screen, yet it participated in the complete task. This points to a significant shift: users may increasingly bypass enterprise software interfaces while more frequently invoking the data, rules, and execution capabilities behind them. So, when Agents begin to take over the user entry point, what must SaaS hold onto next?
Aifanalysis judges that the value of SaaS interfaces, general functions, and shallow domain knowledge will continue to decline. The core barriers will shift towards enterprise know-how, as well as the capabilities to define, execute, govern, and continuously accumulate such know-how.
01. Agents Are Separating the Entry Point from Business Systems
In the past, AI features were typically embedded within software interfaces; users still had to open the original system, and the product entry point of the software remained unchanged. The AIforce released by Salesforce this time is a set of platform capabilities that enable enterprise data, object relationships, business rules, permissions, and executable actions to be invoked by external Agents.
External AI entry points represented by Claude connect to Salesforce via MCP, APIs, and Skills: the model is responsible for understanding requirements, reasoning, and interacting, while Salesforce provides enterprise context, permissions, processes, and executable actions. Users see the Claude interface, but Claude does not know who the enterprise's customers are, what stage the opportunities are at, or who has the authority to modify contracts. Only by accessing the business context and execution capabilities accumulated by the enterprise over a long period can the model transition from answering questions to completing tasks. In addition to Claude, Salesforce is opening up this set of capabilities to more external Agents and work entry points.
For Salesforce, although the entry point has shifted, the product value remains behind every task, serving as the business system that Agents rely on to read enterprise facts and execute critical actions. By proactively opening capabilities to external Agents this time, Salesforce is no longer competing for which interface users stay on, but rather who bears the core logic of enterprise business. Salesforce in Claude is currently still in the Beta stage, but the strategic direction is clear: the entry point can be handed over to external Agents, but critical business capabilities must continue to be borne by Salesforce.
02. What SaaS Must Hold Onto Is the Software-Encoded Enterprise Know-How
If Agents can generate interfaces, invoke APIs, and also possess extensive industry knowledge, what remains of the moat for enterprise software? Common answers are data or the semantic layer, but neither answer is complete. Data records what has happened in the enterprise; semantics tell humans and Agents what customers, contracts, and orders mean respectively, what the relationships between them are, and what revenue recognition criteria are adopted. Without these definitions, even if the model is connected to the database, it is difficult to correctly understand the enterprise.
Figure 2: The Three-Layer Composition of Enterprise Know-How
However, understanding data and semantics does not equal completing the work.
Agents also require three types of know-how: first, enterprise-recognized business objects, metric definitions, and context; second, process states, rules, permissions, business exceptions, and exception handling; third, historical decisions, execution results, and manual correction records.
The first two types determine whether a task can be executed correctly, while the third determines whether the system can become more attuned to the enterprise the more it is used. For example, an Agent may know the definition of a refund amount, but that does not mean it knows under what circumstances a refund can be issued, who needs to approve it if it exceeds a certain amount, and how to restore the order status if the refund fails. Semantics serve as a crucial interface for know-how directed at Agents, but they do not constitute the entirety of know-how.
Different types of know-how are impacted by AI to varying degrees. General knowledge and standard processes are more easily absorbed by foundation models and, in the long run, more prone to commoditization; enterprise-specific object relationships, metric definitions, process exceptions, and permission systems require long-term governance and are harder to replicate; if real-time data and execution results can continuously influence subsequent judgments, a further accumulation effect will be formed.
However, know-how does not automatically become a barrier just by being packaged into enterprise software. If rules remain in employees' minds, processes rely on verbal coordination, and exception handling is scattered across project documents, all the software possesses are mere records.
In the past, breakpoints could be bridged by employees and software implementation consultants; however, when Agents execute tasks independently, these must be explicitly expressed, invoked, and governed. Therefore, what is truly impacted in the Agent era is the value formed by relying on interfaces, general functions, and shallow knowledge. Whether enterprise software can continue to serve as the business foundation depends on whether it has truly encoded the enterprise's operating methods, rather than whether it possesses a product named the semantic layer.
03. Salesforce Opens the Use of Know-How but Retains Control
AIforce does not hand over the database and business logic entirely to Claude; instead, it provides an invocation path constrained by identity, permissions, Skills, and task scope. External Agents can obtain the minimum business context required to complete tasks and invoke authorized tools and actions; Salesforce, on the other hand, is responsible for permission verification, process execution, recording critical actions, and writing back results. In terms of its role, Salesforce provides external Agents with three layers of capabilities.
The first layer is defining business context: Data 360, Customer 360, and the metadata system organize customers, contracts, orders, business relationships, and metric definitions, enabling Agents to understand what the enterprise is dealing with.
The second layer is executing business actions: MCP and APIs provide connection and invocation entry points, while Flow, Apex, and Actions are responsible for reading information, updating records, initiating approvals, and advancing transactions, allowing Agents not only to answer questions but also to complete authorized business operations.
The third layer is controlling and accumulating results: identity, permissions, logs, auditing, exception handling, and manual corrections determine what Agents can do and record what has been done, continuously precipitating execution results and corrections back into the platform. These capabilities collectively serve a single purpose: to allow the enterprise know-how accumulated by Salesforce to be used by external Agents, while Salesforce continues to be responsible for defining enterprise facts, executing critical actions, process control, and result accumulation.
Figure 3: The Know-How Barrier Formed by Open Invocation and Result Feedback
Aifanalysis believes that the core of AIforce is a platform strategy of "open use, retained control." Salesforce yielding partial interface control is aimed at enabling its capabilities to enter more entry points while avoiding the degradation of the platform into an ordinary database. However, openness does not mean the barrier has already been formed. As interfaces such as MCP and Skills gradually become standardized, the mere ability to be invoked by Agents will soon become a standard feature. Supporting multiple models also does not mean that the experience, cost, and effects under different models are completely identical.
More critically, public demos and customer cases currently mainly prove that Agents can enter business processes, but have not yet fully answered questions regarding task success rates, manual correction rates, incident costs, and long-term ROI. If Agents still rely on a massive amount of manual wrap-up after execution, or if the generated results are not precipitated back into the business system, the open interfaces themselves cannot bring sustainable advantages.
For know-how to form a moat after open invocation, there is a clear prerequisite: each invocation must not only complete the task but also leave governable business records, and continuously improve data, rules, and subsequent decisions. Only by forming such a closed loop can this type of know-how become deeper with use.
04. Chinese SaaS Must Transform Project Know-How into Agent Assets
For Chinese enterprise software vendors, the inspiration from Salesforce is not to simply copy and build another AIforce, but to re-examine the know-how they have already accumulated. Domestic software vendors in ERP, CRM, and collaborative office have long served complex industries and large enterprises; they do not lack processes, rules, and implementation experience. However, this know-how is often scattered across product configurations, project plans, consultant experience, customer systems, and employee collaboration.
In the past, implementation consultants could bridge breakpoints between different systems and processes. However, for Agents to complete work independently, these tacit experiences must first be transformed into assets that machines can discover, understand, and execute. Some domestic vendors have begun to provide enterprise ontologies, Skills, process Agents, permission control, and auditing capabilities, and third-party AI entry points can also invoke these services through connectors. But this does not yet indicate that know-how has formed transferable Agent assets. What truly needs to be verified is whether this know-how can step out of proprietary interfaces, be stably invoked by third-party Agents, and be continuously controlled and accumulated by core business systems. Along this main thread, domestic software vendors need to complete three transformations.
First, transform project experience into structured assets. Extract business objects, metric definitions, processes, rules, and exception handling from consultants' minds and project documents, distinguishing between industry know-how that can be reused across customers and enterprise know-how that must be exclusively governed by the customer.
Second, transform software functions into governable invocation capabilities. APIs only specify what the system can do; Skills and Actions must also specify when to invoke, what permissions are required, under what circumstances manual confirmation is mandatory, and how to recover after failure. Only in this way can know-how be correctly used by Agents, rather than being simply exposed.
Third, enable continuous accumulation of execution results and form new business models. Every Agent execution should leave behind results, manual corrections, and exception records, feeding back into subsequent judgments. The key metrics for vendors to measure must also shift from how many Agents are launched to how many business processes are completed safely, how many manual corrections are reduced, and how much verifiable value is generated, and then explore invocation-, task-, or result-based billing accordingly.
Aifanalysis judges that the focus of competition in the next stage for Chinese SaaS is not to add another AI dialog box entry point, but to transform the enterprise know-how accumulated in products and projects in the past into production-grade assets that can be invoked by third-party Agents, controlled by enterprises, accumulated after use, and priced by vendors. From the platform evolution of Salesforce, what it has yielded is only partial interactive entry points; what it truly wants to hold onto is the definition, execution, governance, and accumulation of enterprise know-how. For all SaaS vendors, this is more important than holding onto a single interface.