According to the architect guide published by Salesforce for the Winter ’27 release, the upcoming release retires legacy capabilities and introduces new platform features aimed at strengthening organizations' security posture and providing new ways to solve business needs. The guide directs architects to make coordinated decisions across four core areas: mandatory security enforcements, capacity and automation updates, agentic architecture, and governance and observability. The recommendation presented is to begin by mitigating operational risk, and subsequently evaluate how new platform capabilities may help scale existing configurations and influence the architecture roadmap.
Mandatory Security Enforcements and Legacy Authentication Retirements
According to the guide, several changes in Winter ’27 raise the platform's baseline security floor. Legacy authentication methods are being retired to close weak entry points, while refresh tokens will expire after inactivity to prevent forgotten credentials from lingering. In addition, External Client Apps expose less by default and replace Connected Apps, which require action to restrict user access. These changes can reduce security risks, but integrations relying on retiring methods may stop functioning without action:
- Refresh Token Inactivity Expiration: Starting November 4, 2026, the idle time-to-live (TTL) for refresh tokens in production environments will expire after 30 days of inactivity. This change may affect low-frequency integrations that assume the token remains valid indefinitely. Architects must identify these integrations, confirm how they renew credentials, and design for token rotation or re-authentication.
- Retirement of Legacy Authentication Patterns: It is necessary to map the authentication pattern of each integration and move it to the most secure option supported by the system. The OAuth 2.0 Device Flow will be restricted beginning November 30, 2026, while Username-Password, User-Agent, and Hybrid User-Agent flows will be retired on February 20, 2027.
- Retirement of Salesforce Connect Cross-Org Adapter and Salesforce to Salesforce: Both changes take effect in the Spring ’27 release. The Salesforce to Salesforce capability will be fully retired and will no longer function, and legacy Cross-Org adapter authentication will require migrating to Named Credentials.
- External Client Apps: Support for Connected Apps will end by Summer ’27. External Client Apps operate with a default-closed posture and separate application settings from administrative policies.
Capacity Updates, Platform Limits, and Automation Enhancements
The guide details that platform limit shifts allow revisiting solutions previously designed around system constraints, in order to support higher workloads:
- Apex Heap Limits: The synchronous Apex heap limit increases from 6 MB to 10 MB, and the asynchronous heap limit increases from 12 MB to 25 MB. The guide suggests revisiting code that chunks or streams data primarily to stay under the old ceiling, and simplifying it where the added headroom makes those workarounds unnecessary.
- Expansion of Elastic Async Apex Jobs (Beta): The capability now covers batch jobs in addition to future methods and Queueable jobs. This additional capacity is capped at either the licensed asynchronous Apex job limit or 2 million jobs, whichever is lower.
- Overriding Async Job Limits in Non-Production Environments: A feature enabling the override of the standard asynchronous Apex limit in non-production environments to test how workloads are processed within the elastic limit.
- Flow Improvements and Record Locking: A record-lock retry mechanism and loop-free filtering allow revisiting automations implemented in Apex code due to CPU constraints or locking in Flow.
- Retaining Manual Shares on Record Transfers: Sharing Settings now allow the organization to retain manual shares when record ownership changes, providing an opportunity to revisit replacing Apex or Flow processes that recreated shares after transfers.
Designing Agentforce Agentic Architecture
The guide highlights that most capabilities for building agentic systems arrive in Winter ’27, with Multi-Agent Orchestration having become generally available (GA) in August 2026:
- Multi-Agent Orchestration: Composing specialist agents as a supported pattern instead of relying on custom glue code, including streaming responses and handoffs or escalations across channels such as Embedded Chat v2, WhatsApp, and mobile.
- API Catalog: Enables registering and activating Model Context Protocol (MCP) servers and APIs that agents are authorized to invoke, including interfaces for MuleSoft, Heroku, and Apex.
- Resolving Parent-Child Relationships in Data 360: Enables grounding agents on complete record hierarchies, spanning zero-copy data model objects (DMOs) from BigQuery, Databricks, and Snowflake.
- SLDS AI Skills and ApexGuru: Capabilities for standardizing AI-generated code in agentic development environments, using static analysis and portable AI skills.
Evaluating New Governance and Observability Features
The Winter ’27 release introduces dedicated control points for continuous security posture, oversight of agent connections, and org-wide performance, with availability varying by edition, license, and support plan:
- Security Health Review: Replaces the point-in-time Health Check PDF report with continuous in-Setup findings, remediation, and an audit trail. This feature is limited to Signature Success Plan customers, and the Health Assessments Agent requires the Salesforce Foundations add-on. Organizations without access can continue using Health Check in Setup on a scheduled manual basis.
- Monitoring Org Health with Scale Center: Surfaces org-health alerts and Agentforce-assisted root-cause analysis in Slack, alongside direct links to Apex investigations and usage insights. The feature is not supported in Government Cloud Plus. Organizations not using it can continue utilizing debug logs, ApexGuru, and Setup usage insights.
- MCP Server Monitoring in Security Center (Beta): Centralizes visibility into configured MCP servers across connected Salesforce instances, including risk scores, suspicious URLs, and configuration changes.
- Security Mesh: Unifies security data from Salesforce and external sources into a common format within Security Center.
The guide recommends that architects create an Architectural Decision Record for every feature or change in the Winter ’27 release notes that requires an architectural decision, whether a mandatory enforcement or a new capability on the roadmap, to capture the question being answered, the assumptions behind it, the option chosen, and the business outcome it is meant to support.