Salesforce Headless 360 is an architecture and marketing umbrella, not a product or SKU. It makes Salesforce data, business logic, orchestration, and experiences available beyond the standard Salesforce browser interface.
For admins and technology leaders, the immediate task is not to “buy Headless 360.” It is to identify a governed use case, confirm that the required component is generally available, map licenses and consumption, and test the permissions that will follow each user or service account.
Salesforce Headless 360 describes four decoupled layers: Data 360, business logic, orchestration, and the Headless Experience Layer (HXL). It matters to Salesforce owners, security teams, developers, integration leaders, and business teams that want agents or apps to use Salesforce outside the Salesforce UI. This guide helps teams separate GA features from broader roadmap messaging and build a safe pilot plan. Vantage Point can connect that plan to Salesforce architecture, integration, data, and governance decisions.
On July 16, 2026, Salesforce published its Help article, Understand the Salesforce Headless 360 Architecture. It clarifies that Headless 360 is a marketing umbrella for a group of capabilities—not a single product—and that “headless” does not mean Salesforce is removing its user interface.
The practical change is an architectural direction: Salesforce capabilities can be accessed and presented through agents, developer tools, collaboration apps, mobile experiences, and custom applications. Salesforce describes the API as the UI, but this does not make every workflow automatically portable or every integration simple.
Salesforce’s Help article says Headless 360 can compress some work that previously required months of custom middleware into days. Treat that as Salesforce’s directional claim, not a universal implementation estimate. Delivery time still depends on data readiness, process complexity, identity design, security review, testing, integration dependencies, and whether the selected components are GA.
This article differs from our broader TDX 2026 strategic outlook by focusing specifically on architecture, availability, controls, licensing, and an admin readiness plan.
Headless 360 affects more than developers.
Organizations that only use the standard Salesforce interface do not need to redesign immediately. Existing UI, API, Flow, and Apex investments remain relevant.
Salesforce’s architecture separates four layers so that data, logic, coordination, and presentation can evolve independently.
| Layer | Role | Examples | Admin question |
|---|---|---|---|
| Data 360 | Supplies governed business context and unified data | Salesforce records, Data 360 data and queries | Is the source data accurate, permitted, and fit for this use case? |
| Business logic | Exposes reusable operations and rules | Apex, Flow, APIs, validation and business processes | Which operations can the caller invoke, and what side effects can occur? |
| Orchestration | Coordinates agents, tools, steps, and controls | Agentforce, MuleSoft Agent Fabric, testing and tracing | Where are routing, approvals, retries, monitoring, and exception handling owned? |
| Headless Experience Layer (HXL) | Delivers interactive experiences to supported external surfaces | Slack, ChatGPT, web, mobile, or other supported channels | Is this exact surface and component GA, licensed, secured, and supported? |
Decoupling does not remove dependencies. A polished external experience can still fail if the data is incomplete, the Flow is unsafe to call, or the service account has excessive access. Teams should review the full chain rather than treating the experience layer as a standalone front end.
Model Context Protocol (MCP) is primarily inbound to Salesforce. HXL is primarily outbound from Salesforce.
| Decision | Hosted MCP | HXL |
|---|---|---|
| Primary direction | External AI client or tool calls Salesforce capabilities | Salesforce or Agentforce delivers an experience to another surface |
| Main purpose | Discover and invoke approved data or tools | Render interactive, channel-appropriate UI components |
| Control focus | Authentication, user context, OAuth scopes, tool allowlists, object/field permissions | Agent configuration, surface support, component behavior, identity, and channel governance |
| Example | A coding assistant reads permitted metadata or invokes an approved operation | An Agentforce interaction presents a rich component in a supported collaboration surface |
Salesforce’s Hosted MCP server overview explains the inbound model and advises teams to confirm whether MCP is the right fit. The HXL and orchestration overview describes how experiences can be delivered beyond the standard Salesforce interface.
MCP and HXL can complement each other, but neither replaces architecture work. MCP is not a universal integration protocol for every deterministic system-to-system workload. HXL does not eliminate accessibility, channel, testing, or support requirements.
Availability must be evaluated component by component as of July 17, 2026.
| Capability | Current evidence | Planning guidance |
|---|---|---|
| Salesforce Platform Hosted MCP Servers | Salesforce announced GA on April 29, 2026, for Enterprise Edition orgs and above | Confirm supported servers, tools, client requirements, region, identity, and org setup in current documentation |
| Headless 360 umbrella | Public architecture and marketing direction | Do not treat the umbrella itself as an orderable SKU or a promise that every component is GA |
| HXL Playground | Listed as GA in the July 16 Salesforce Help article | A playground does not establish production support for every surface or component |
| HXL for Slack and ChatGPT | The July 16 Help article identifies these as GA | Verify the exact agent, channel, feature, edition, and contractual entitlement before committing |
| Other HXL surfaces and components | Salesforce marketing describes broad deployment possibilities, but the Help article does not provide a complete GA matrix | Treat as planned or unclear until current product documentation and your Salesforce account team confirm availability |
| Individual MCP products, tools, and metadata features | Status varies; some documentation labels features Beta | Never infer GA for one tool from GA of the Hosted MCP platform |
| Agentforce, MuleSoft, Data 360, Tableau, and Informatica capabilities | Product-specific availability and terms apply | Check each product’s release notes, licenses, limits, and usage model separately |
Salesforce’s Hosted MCP GA announcement is the strongest public evidence for the core MCP availability statement. The Headless 360 Trailhead module is useful for concepts and terminology, but it should not replace release notes, contracts, or product documentation for purchasing and production decisions.
Salesforce Safe Harbor applies to forward-looking features. Build commitments around current GA documentation, not demos, announcements, or inferred timelines.
Salesforce says basic Hosted MCP access is included with Enterprise Edition and above and does not require an additional Agentforce SKU. That statement does not make every action free or every related product included. Users or service accounts still need valid Salesforce access; prebuilt Agentforce agents and other products retain their own licensing requirements; external AI clients may have separate subscriptions.
Calls through Hosted MCP are authenticated and authorized. Salesforce object-level and field-level security continue to shape what data can be returned. Admins should also verify record access, Apex class access, Flow permissions, connected-app policies, OAuth scopes, session controls, and the permissions of any service account.
Do not use a broadly privileged integration user merely to simplify a pilot. Prefer named user context where accountability matters, or a narrowly scoped service identity with documented ownership and rotation.
The July 16 Help article identifies new Customer 360 Platform usage types for Salesforce Record Operation and Salesforce Process Invocation. It says numerical multipliers were TBA, the types were not yet metered, and Salesforce would provide 30 days’ notice before metering begins. This is time-sensitive vendor guidance; verify current terms in your contract and Digital Wallet before launch.
Agentforce actions and Data 360 queries can consume Flex Credits. Salesforce’s Agentforce pricing and Digital Wallet guidance describe consumption options and near-real-time usage monitoring. Pricing pages are not a substitute for your order form.
Use this readiness checklist before approving a Headless 360 pilot.
| Step | Action | Evidence to retain |
|---|---|---|
| 1. Choose one workflow | Define the user, trigger, data read, action, outcome, and human approval point | One-page use-case and process map |
| 2. Confirm availability | Check the exact server, tool, HXL surface, region, edition, and feature status | Dated links to product docs and release notes |
| 3. Map entitlements | Document Salesforce licenses, add-ons, third-party subscriptions, and Flex Credits | Order forms, entitlement notes, and budget owner |
| 4. Threat-model the path | Review identity, OAuth, data classification, prompt injection, write actions, and downstream effects | Security assessment and approved controls |
| 5. Apply least privilege | Limit objects, fields, records, Apex, Flow, tools, and connected-app scopes | Permission matrix and access owner |
| 6. Build a sandbox test set | Include happy paths, denials, malformed prompts, stale data, duplicate actions, and rollback cases | Test scripts, results, and acceptance criteria |
| 7. Add governance | Define human approvals, traces, logs, alerts, incident response, and change control | Runbook, dashboard, and escalation owner |
| 8. Measure consumption | Tag the pilot where available and set budget thresholds and alerts | Digital Wallet baseline and alert settings |
| 9. Release gradually | Start with read-only or low-risk actions and a small user group | Pilot roster, enablement plan, and rollback decision |
| 10. Revalidate quarterly | Recheck availability, pricing, permissions, tools, and vendor terms | Dated architecture and entitlement review |
For complex environments, align the pilot with a broader Salesforce implementation and advisory plan, system integration and data migration controls, and compliance and security requirements.
Vantage Point helps teams turn Headless 360 messaging into a controlled architecture decision. Our senior consultants can assess the use case, separate native Salesforce capabilities from integration needs, map identity and permissions, design a sandbox pilot, and create a production governance and consumption plan.
If your organization is evaluating Hosted MCP, Agentforce, HXL, MuleSoft, or an external AI client, contact Vantage Point to build a practical readiness roadmap. We can also connect the work to AI-driven personalization and analytics without treating AI as a substitute for sound data and process design.
No. Salesforce defines Headless 360 as an architecture and marketing umbrella for multiple platform capabilities. Each underlying product, feature, license, and consumption model must be evaluated separately.
No. Salesforce says its existing UI remains available. Headless 360 allows selected Salesforce data, logic, and experiences to operate on additional surfaces rather than forcing every user into one interface.
Yes, the Salesforce Platform Hosted MCP service was announced GA for Enterprise Edition orgs and above on April 29, 2026. Individual servers, tools, clients, and metadata capabilities can have different statuses, requirements, and limits, so check their current documentation.
MCP is the inbound path that lets an external agent or tool call approved Salesforce capabilities. HXL is the outbound presentation path that lets Salesforce or Agentforce deliver an interactive experience on a supported external surface.
No. Hosted MCP requests are authenticated and authorized, and Salesforce object- and field-level access still applies. Admins must also evaluate record access, Flow and Apex permissions, connected-app policies, OAuth scopes, and the external provider’s data handling.
Salesforce says basic MCP access in Enterprise Edition and above does not require an additional Agentforce SKU. Agentforce actions, Data 360 queries, prebuilt agents, other Salesforce products, and third-party clients can still create separate license or consumption obligations.
Do not assume it is free. The July 16 Help article says two new usage types were not yet metered and their multipliers were TBA, but existing Agentforce, Data 360, platform, and third-party charges can still apply. Verify your contract, Digital Wallet, and current Salesforce guidance.
Start with one bounded, low-risk workflow in a sandbox. Confirm GA status and entitlements, apply least privilege, test denial and failure cases, add human approvals and observability, monitor consumption, and expand only after the controls work as designed.