Salesforce is changing how external AI agents identify themselves to the platform and how their activity can be billed. For enterprise organizations experimenting with Claude, ChatGPT, custom agents, or orchestrators that reach Salesforce through Model Context Protocol (MCP) or direct APIs, this is no longer just a technical connector decision.

Core Architectural Shift: External AI agents will no longer borrow the credentials of the employees they assist. Under Salesforce announced Agentic Identity model, registered agents receive discrete platform identities with scoped permissions, turning each successful MCP or direct API call into a trackable Headless Platform Interaction (HPI).

Salesforce September 17 guidance confirms it is targeting November for Agentic Identity, new security controls, and a new billing model within the Headless Toolkit. Instead of operating under the identity of the person the agent assists, a registered agent would receive a discrete platform identity with its own scoped permissions. Each successful call from that registered agent to Salesforce, whether through MCP or a direct API, would be tracked as a Headless Platform Interaction and could consume Flex Credits.

Several commercial and operational details are not yet final. Salesforce has not published the numerical HPI multiplier. Agentic HPI usage is not currently metered. Salesforce has stated it will provide at least 30 days notice before adding a multiplier and activating consumption billing. That pricing uncertainty is not a reason to delay. It is an urgent reason to prepare the technical and architectural facts before pricing and availability become live production realities.

What Salesforce Has Confirmed

Salesforce describes Agentic Identity as a dedicated platform identity for an external agent. Administrators will register each agent on the platform, assign a tailored, least-privilege permission set, obtain discrete OAuth credentials, reconfigure the host MCP client or API connection, and reconnect the agent.

The same registration framework creates the foundation for both security governance and consumption billing. Salesforce states that every successful call from a registered agent will be recorded as a Headless Platform Interaction (HPI) and tracked in Digital Wallet. Crucially, the announced model applies exclusively to agentic traffic, leaving traditional system-to-system integrations unchanged.

The migration timing depends directly on the customer contract status and connection pattern:

  • New Customers (purchasing on or after September 17, 2026): Expected to register any agents utilizing Salesforce APIs within three months of Salesforce issuing notification that Agentic Identity is available.
  • Existing Customers (with active API agent connections prior to September 17): Expected to register those agents and transition their connections to the new identity and billing model at contract renewal.
  • All MCP Users (regardless of contract date): Salesforce specifies that use of any Salesforce Hosted MCP server will require agent registration within three months of notice that Agentic Identity is available.

Salesforce has also confirmed that HPI Flex Credit consumption will apply only in active production orgs once registration and a numerical multiplier are established. Sandboxes, scratch orgs, and Developer Edition orgs are excluded from HPI metering under the announced architecture, providing safe environments for testing and validation.

The First Problem Is Classification, Not Configuration

Before configuring OAuth apps or updating firewalls, enterprise teams face a fundamental operational challenge: most organizations cannot yet reliably classify which inbound connections are AI agents versus conventional integrations.

A typical enterprise Salesforce estate may host a hosted Claude Desktop MCP connection, an internal customer support assistant calling REST endpoints, an enterprise workflow orchestrator invoking Flow or Apex, an Agentforce agent exposed as an external MCP tool, a developer coding assistant, and conventional ETL pipelines that happen to ingest AI-generated summaries upstream. Treating all of these connections under a single generic integration category will produce an inaccurate migration plan and unexpected billing surprises.

Enterprise architecture teams must establish an Agent Connection Register immediately. For every inbound connection, document the following ten core attributes:

  • Business Sponsor & Technical Steward: Accountable business leader and engineering owner responsible for operations and budget.
  • User Population & Business Outcome: Target audience, operational objectives, and expected transaction volumes.
  • Target Environments: Specific production orgs, developer sandboxes, and scratch orgs accessed by the connection.
  • Client & Endpoint Topology: External model provider, client runtime (e.g., Claude, Cursor, LangChain), middleware, and Salesforce API gateway.
  • Invocation Mechanisms: Specific MCP tools, REST/SOAP endpoints, invocable Apex classes, Flow definitions, or Data 360 queries utilized.
  • Identity & Auth Configuration: Existing Connected App or External Client App, OAuth scopes, token lifecycle policy, and assigned user/service account.
  • Data Access Scope: Standard and custom objects, fields, records, and write operations (Create, Read, Update, Delete) accessible to the client.
  • Call Volume & Concurrency: Median and peak successful calls, failure rates, automated retry loops, and multi-step reasoning chains per task.
  • Contractual Alignment: Contract owner, renewal anniversary date, current Salesforce edition, and existing Flex Credit entitlements.
  • Operational Governance: Audit logging mechanisms, security monitoring, incident response protocols, and emergency kill-switch procedures.

This register serves as the vital bridge aligning enterprise architecture, information security, procurement, and measurable business ROI.

Eight Actions to Take Before Agentic Identity Arrives

1. Separate Agentic Traffic from Traditional Integrations

Salesforce has stated that the new HPI model is designed specifically for agentic traffic, leaving conventional system-to-system integrations untouched. Your technical team requires an objective, defensible classification rule.

Engage Salesforce to clarify how it will determine whether a direct API connection is agentic. Determine whether classification relies on agent registration, credential type, accessed endpoints, declared use cases, or heuristic traffic inspection. Do not attempt to rename an autonomous AI agent as a standard integration to avoid governance. The objective is architectural clarity and contracting accuracy, not semantic camouflage.

2. Baseline Production Call Behavior

Because a Headless Platform Interaction is defined as a successful call, measuring conversational turn volume alone will not expose your true consumption. A single user prompt to an external agent can trigger multiple record queries, an invocable Flow execution, an Apex action, a retry, and a final database write.

Instrument and measure the entire call chain by use case. Record the median and 95th-percentile API calls required per completed business outcome, the success-to-failure ratio, retry logic, and variation across communication channels. Maintaining this empirical baseline today ensures that when Salesforce publishes the numerical multiplier, your FinOps team can calculate real financial exposure in minutes rather than scrambling under renewal pressure.

3. Model Cost per Business Outcome

Avoid building AI budgets based purely on raw monthly call counts. An inexpensive, low-volume workflow that generates trivial business impact is far less valuable than a high-volume agentic workflow that autonomously resolves customer service bottlenecks or accelerates clinical intake.

Tie projected HPI consumption directly to tangible business units: resolved support tickets, verified insurance eligibility requests, prepared renewal summaries, or processed grant applications. Construct sensitivity tables across conservative, expected, and stress-tested call volumes. Factor in external LLM token fees, middleware costs, Data 360 credit usage, and human-in-the-loop review overhead as part of broader AI-driven enterprise architecture .

Financial Modeling Rule: Because the HPI Flex Credit multiplier is currently unpublished, build a sensitivity matrix rather than a static forecast. The essential executive decision is identifying at what exact multiplier or call volume threshold the AI workflow ceases to deliver positive net ROI.

4. Design the Future Identity Before Migrating Credentials

Salesforce June security guidance for Hosted MCP Servers outlines a per-user OAuth model utilizing dedicated External Client Apps, where all activity is attributed to the authenticating user. The announced Agentic Identity model transitions to a discrete identity for the agent itself. How these two authentication models will interact requires careful architectural planning.

Do not convert active connections into broad shared service accounts in anticipation of change. Define the exact operational permissions an agent requires: allowed standard objects, field-level security, record-level sharing rules, and read versus write rights. Identify which high-risk actions require human approval gates. Create specialized permission sets mapped to specific business functions rather than a blanket external-agent super-user profile.

5. Preserve Least Privilege Across Tools and Data

An identity boundary is only as secure as the tools and endpoints operating behind it. Audit every MCP tool, invocable Flow, Apex method, prompt template, and Data 360 query exposed to external agents. An agent deployed for read-only case research must never inherit permissions to create, update, delete, bulk-export, or modify platform schemas simply because a developer used default configurations.

Enforce the core security principles Salesforce established for Hosted MCP Servers: constrained OAuth scopes, pre-authorized user access, limited server activations, short token lifetimes, granular permission testing, and comprehensive Event Monitoring. Retest these boundaries as new Agentic Identity features enter preview.

6. Build the Reconnection Runbook

Transitioning to Agentic Identity entails registering each agent, provisioning new OAuth credentials, updating client configurations, and reconnecting endpoints. This represents a tangible operational change that carries service disruption risks if not rigorously managed.

Develop a comprehensive reconnection runbook covering secret management, endpoint configuration, token revocation, automated connection tests, rollback procedures, and named support owners. Test full transaction lifecycles in sandbox environments. A successful OAuth handshake proves only connectivity; it does not confirm that multi-step case updates, lead routing, or patient verification workflows still function correctly.

7. Align the Migration with Renewal and Procurement

Because existing API agent customers and MCP users follow different compliance deadlines, map your contractual milestones directly against technical migration schedules. Engage your Salesforce account team to confirm your specific registration grace period, baseline included Flex Credits, non-production entitlements, and formal notification channels.

Procurement and finance teams must also verify whether consumption fees from third-party LLM providers, Salesforce HPIs, Agentforce conversational actions, and Data 360 queries can compound on the same business workflow. Clarify this cost stack before pilot implementations become unmanaged production dependencies.

8. Define a Formal Production Gate

Do not permit an external agent into production simply because it demonstrated technical viability in a sandbox where HPI consumption is unbilled. Enforce an objective pre-production readiness checklist requiring:

  • Validated discrete agent identity with verified least-privilege permission sets;
  • End-to-end integration and business process testing across standard and exception paths;
  • Documented baseline HPI call ranges and consumption thresholds per completed outcome;
  • Approved cost sensitivity analysis and designated departmental funding ownership;
  • Immutable audit attribution, Event Monitoring telemetry, and real-time error logging;
  • Deterministic human escalation paths, approval gates, and immediate kill-switch mechanisms;
  • Procurement alignment on contract entitlements, renewal dates, and Flex Credit pools; and
  • Post-deployment verification and regression testing runbooks.

What This Means for Healthcare, Insurance, and Nonprofits

Healthcare & Life Sciences

In healthcare organizations, external agents frequently interact with patient service cases, physician directories, scheduling workflows, and clinical coordination records. Granting an agent a discrete identity enhances audit accountability, but it does not automatically guarantee HIPAA compliance or data minimization. Healthcare IT leaders must test field-level masking, record sharing rules, restricted write actions, and clinical escalation paths in close coordination with security and compliance officers.

Insurance & Financial Services

Insurance workflows often require an agent to traverse policy administration, claims processing, billing, underwriting, and broker management systems in a single interaction. The primary operational risk is not just API call volume; it is the legal and financial authority attached to each action. Insurers must draw strict architectural boundaries between informational read actions and binding transactional updates that require deterministic logic, multi-party approvals, or licensed underwriter review.

Nonprofit Foundations & Higher Education

Nonprofit institutions often operate with lean Salesforce administration teams and strictly restricted donor or grant budgets. Unmonitored agent traffic introduces both operational maintenance overhead and unpredictable consumption expenses. Foundations should prioritize a small portfolio of high-value workflows—such as automating grant applicant inquiries or routine donor updates—assign clear stewards, and measure outcomes against tangible administrative time savings.

Eight Questions to Ask Salesforce Before Contract Renewal

Before approving external agent architectures or committing to upcoming renewals, request formal written clarification on these key questions:

  1. When will Agentic Identity features become active in our specific production and sandbox orgs, and what event officially triggers our 3-month registration window?
  2. What exact criteria will Salesforce use to differentiate our direct API connections between standard integration traffic and agentic HPI traffic?
  3. How will the Agentic Identity model reconcile with our existing External Client Apps and per-user OAuth configurations for Hosted MCP Servers?
  4. What technical events constitute a single billable HPI across multi-object reads, composite requests, Flow triggers, Apex invocations, and retries?
  5. Can a single customer transaction trigger both HPI consumption and other Flex Credit charges (such as Data 360 queries or Agentforce actions)?
  6. What telemetry, filtering, and reporting granularity will Digital Wallet provide to attribute HPI consumption by agent ID, user, and business unit?
  7. What formal notification mechanisms will Salesforce use to announce the numerical HPI multiplier and the 30-day countdown to live metering?
  8. Which specific contract terms, bundled credit pools, and sandbox exclusions apply to our active enterprise order forms?

Prepare for the Architecture Shift Without Inventing the Price

The appropriate strategic response to an emerging billing model is neither paralysis nor ungrounded speculation. Enterprise leaders should inventory their inbound connections, classify agentic traffic, establish empirical call baselines, enforce least-privilege permissions, prepare reconnection procedures, and link AI utilization to measurable business outcomes. When Salesforce finalizes the numerical multiplier and technical tooling, your organization will be ready to execute with confidence.

YuniQ provides end-to-end Salesforce consulting and integration services , including architecture assessment, identity design, External Client App configuration, security hardening, and validation testing. Our team helps organizations evaluate external agent connections, map permission boundaries, stress-test reconnection runbooks, and build the governance required for safe, cost-controlled production deployments.

Assess Your Salesforce Agent Connections Before Agentic Identity Launches

Ensure your external AI agents, MCP servers, and API connections are secure, compliant, and cost-controlled before Salesforce Agentic Identity and Headless Platform Interaction billing go live. Partner with YuniQ for an enterprise agent architecture and identity readiness assessment.

Explore Salesforce Consulting Services