Salesforce MCP server and Dome
Let agents read the CRM. Decide which records they change.
Connect Salesforce's hosted sobject-all server to Dome once. Every call runs with the Salesforce login of the person the agent acts for, and rules decide each write on the object it names.
How Dome helps
Dome provides a tool gateway and authorization for Salesforce
Decided on the object
One tool, allowed on a Case and refused on an Opportunity. Rules read the sobject-name of every call.
Their login, their sharing rules
Each rep signs in to Salesforce once, on their first call. Field-level security and sharing still apply on top of Dome's rules.
Deletes refused
Rules name the tool. Record deletes and edits that climb to a parent record never reach Salesforce.
Get started
Salesforce behind the Gateway in three steps
Create an External Client App in Salesforce, add the server to Dome with its consumer key and secret, then apply the rules.
01
Add the Salesforce MCP server
The External Client App needs the mcp_api and refresh_token scopes. Credentials are per user, through OAuth.
$ dome tools add --name salesforce \--url https://api.salesforce.com/platform/mcp/v1/platform/sobject-all \--auth-method oauth --credential-type per-user \--oauth-client-origin manual \--oauth-client-id "$SF_CONSUMER_KEY" \--oauth-client-secret "$SF_CONSUMER_SECRET" \--oauth-authorize-url https://login.salesforce.com/services/oauth2/authorize \--oauth-token-url https://login.salesforce.com/services/oauth2/token \--oauth-default-scope mcp_api --oauth-default-scope refresh_token \--gateway revenue-gateway02
Sync the catalog
Sync spends your own Salesforce credential, so sign in first. Until then it fails and agents get “tool not available in this gateway”.
$ dome tools catalog sync salesforce03
Apply the rules
Scope them to one agent while you try them. Simulate before you deploy.
$ dome rules apply salesforce-args.cedar \--agent case-triager --name salesforce-per-object
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Salesforce itself, see Salesforce's documentation.
Rules
Cases and Tasks only
The permit opens Salesforce to the agent. The first forbid refuses creates and updates on any object but Case and Task, and the second refuses deletes and parent-record edits.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "salesforce" }; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "salesforce" && ["createSobjectRecord", "updateSobjectRecord"].contains(resource.tool_name) && resource has arguments && resource.arguments has "sobject-name" && !["Case", "Task"].contains(resource.arguments["sobject-name"])}; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "salesforce" && ["deleteSobjectRecord", "deleteRelatedRecord", "updateRelatedRecord"].contains(resource.tool_name)};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Object
- Agentcase-triager is registered and active
- Callert.mbeki verified through Microsoft Entra ID
- RuleUpdates to Cases are allowed
Example agents
Three agents on Salesforce
From our template library. Each one reads broadly and writes narrowly.
case-triager
Triage support cases
Reads each new Case and the Account behind it, then sets priority and owner. Changes stop at the Case.
- salesforce/getObjectSchema
- salesforce/soqlQuery
- salesforce/updateSobjectRecord
pipeline-analyst
Answer pipeline questions
Answers questions about the pipeline from Opportunities and the contacts on them. It writes nothing.
- salesforce/soqlQuery
- salesforce/find
- salesforce/getRelatedRecords
renewal-tasker
Queue renewal follow-ups
Finds Accounts with a renewal in the next 90 days and creates a follow-up Task for each owner.
- salesforce/soqlQuery
- salesforce/getRelatedRecords
- salesforce/createSobjectRecord
Agent workflow
Bringing it together
Connecting Salesforce to registered agents, models, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
MCP server
Salesforce
This page
Models
FAQ
Common questions
Does Dome work with Salesforce Hosted MCP Servers?
Yes. Add it by URL with an External Client App's consumer key and secret, and each person signs in on their first call.
Can I let an agent update Cases but not Opportunities?
Yes. Rules read the sobject-name argument of every call, so the same update tool is allowed on one object and refused on another.
Why not use the sobject-reads server instead?
You can, for agents that never write. Rules let one connection serve an agent that writes Cases and one that writes nothing.
Do Salesforce permissions still apply?
Yes. Each call runs as the person the agent acts for, so their field-level security and sharing rules apply after Dome's rules allow it.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreIdentity
Okta
Okta tokens verified on every agent call, so rules and audit name the person each agent acted for.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
MCP servers for AI agents: per-argument rules on every call
Put any remote MCP server behind the Tool Gateway. Agents reach it through one governed endpoint, and rules decide each call on its arguments.
See them all