Dome Systems

Salesforce MCP server and Dome

Let agents read the CRM. Decide which records they change.

Connect Salesforce's hosted sobject-all server to Dome once. Every call runs with the Salesforce login of the person the agent acts for, and rules decide each write on the object it names.

RepsAgentsDomeSalesforceCallersRepsAgentscase-triagerAgentspipeline-analystAgentsrenewal-taskerGatewaysrevenue-gatewayCases and TasksWritableOpportunitiesRead onlyModel poolAny providerRulesGuardsAuditsaudit-trail
pipeline-analyst→salesforce/soqlQuery· as a.lindqvistAllowed

How Dome helps

Dome provides a tool gateway and authorization for Salesforce

Decided on the object

One tool, allowed on a Case and refused on an Opportunity. Rules read the sobject-name of every call.

Their login, their sharing rules

Each rep signs in to Salesforce once, on their first call. Field-level security and sharing still apply on top of Dome's rules.

Deletes refused

Rules name the tool. Record deletes and edits that climb to a parent record never reach Salesforce.

Get started

Salesforce behind the Gateway in three steps

Create an External Client App in Salesforce, add the server to Dome with its consumer key and secret, then apply the rules.

  1. 01

    Add the Salesforce MCP server

    The External Client App needs the mcp_api and refresh_token scopes. Credentials are per user, through OAuth.

    $ dome tools add --name salesforce \
    --url https://api.salesforce.com/platform/mcp/v1/platform/sobject-all \
    --auth-method oauth --credential-type per-user \
    --oauth-client-origin manual \
    --oauth-client-id "$SF_CONSUMER_KEY" \
    --oauth-client-secret "$SF_CONSUMER_SECRET" \
    --oauth-authorize-url https://login.salesforce.com/services/oauth2/authorize \
    --oauth-token-url https://login.salesforce.com/services/oauth2/token \
    --oauth-default-scope mcp_api --oauth-default-scope refresh_token \
    --gateway revenue-gateway
  2. 02

    Sync the catalog

    Sync spends your own Salesforce credential, so sign in first. Until then it fails and agents get “tool not available in this gateway”.

    $ dome tools catalog sync salesforce
  3. 03

    Apply the rules

    Scope them to one agent while you try them. Simulate before you deploy.

    $ dome rules apply salesforce-args.cedar \
    --agent case-triager --name salesforce-per-object

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Salesforce itself, see Salesforce's documentation.

Rules

Cases and Tasks only

The permit opens Salesforce to the agent. The first forbid refuses creates and updates on any object but Case and Task, and the second refuses deletes and parent-record edits.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when { resource.connection_name == "salesforce" };
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "salesforce" &&
["createSobjectRecord", "updateSobjectRecord"].contains(resource.tool_name) &&
resource has arguments && resource.arguments has "sobject-name" &&
!["Case", "Task"].contains(resource.arguments["sobject-name"])
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "salesforce" &&
["deleteSobjectRecord", "deleteRelatedRecord", "updateRelatedRecord"].contains(resource.tool_name)
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Object

agent case-triager · acting as t.mbeki
salesforce/updateSobjectRecord(sobject-name: "Case", id: "500Hs00001XyZaQ", body: { Priority: "High" })
  1. Agentcase-triager is registered and active
  2. Callert.mbeki verified through Microsoft Entra ID
  3. RuleUpdates to Cases are allowed
DecisionAllowed

Example agents

Three agents on Salesforce

From our template library. Each one reads broadly and writes narrowly.

case-triager

Triage support cases

Reads each new Case and the Account behind it, then sets priority and owner. Changes stop at the Case.

  • salesforce/getObjectSchema
  • salesforce/soqlQuery
  • salesforce/updateSobjectRecord

pipeline-analyst

Answer pipeline questions

Answers questions about the pipeline from Opportunities and the contacts on them. It writes nothing.

  • salesforce/soqlQuery
  • salesforce/find
  • salesforce/getRelatedRecords

renewal-tasker

Queue renewal follow-ups

Finds Accounts with a renewal in the next 90 days and creates a follow-up Task for each owner.

  • salesforce/soqlQuery
  • salesforce/getRelatedRecords
  • salesforce/createSobjectRecord

Agent workflow

Bringing it together

Connecting Salesforce to registered agents, models, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Tools

MCP server

Salesforce

This page

FAQ

Common questions

Does Dome work with Salesforce Hosted MCP Servers?

Yes. Add it by URL with an External Client App's consumer key and secret, and each person signs in on their first call.

Can I let an agent update Cases but not Opportunities?

Yes. Rules read the sobject-name argument of every call, so the same update tool is allowed on one object and refused on another.

Why not use the sobject-reads server instead?

You can, for agents that never write. Rules let one connection serve an agent that writes Cases and one that writes nothing.

Do Salesforce permissions still apply?

Yes. Each call runs as the person the agent acts for, so their field-level security and sharing rules apply after Dome's rules allow it.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.