News

Salesforce Outlines Architect Highlights for Winter ’27

The architect guide details security enforcements, higher heap limits, Agentforce orchestration, and monitoring tools

4 min read
עב
Salesforce Outlines Architect Highlights for Winter ’27
Based on original reporting bySalesforce Blog ↗Translated and summarized by our AI-assisted news systemHow we work

Executive summary

5 things to know

  1. Starting November 4, 2026, production refresh tokens will expire after 30 days of inactivity.

  2. The OAuth 2.0 Device Flow will be restricted on November 30, 2026, with additional legacy flows retired in February 2027.

  3. Apex heap limits increase to 10 MB for synchronous execution and 25 MB for asynchronous execution.

  4. Multi-Agent Orchestration supports streaming responses and handoffs across channels such as WhatsApp.

  5. Monitoring tools for MCP servers and security governance have been added in Security Center and Scale Center.

According to the architect guide published by Salesforce for the Winter ’27 release, the upcoming release retires legacy capabilities and introduces new platform features aimed at strengthening organizations' security posture and providing new ways to solve business needs. The guide directs architects to make coordinated decisions across four core areas: mandatory security enforcements, capacity and automation updates, agentic architecture, and governance and observability. The recommendation presented is to begin by mitigating operational risk, and subsequently evaluate how new platform capabilities may help scale existing configurations and influence the architecture roadmap.

Mandatory Security Enforcements and Legacy Authentication Retirements

According to the guide, several changes in Winter ’27 raise the platform's baseline security floor. Legacy authentication methods are being retired to close weak entry points, while refresh tokens will expire after inactivity to prevent forgotten credentials from lingering. In addition, External Client Apps expose less by default and replace Connected Apps, which require action to restrict user access. These changes can reduce security risks, but integrations relying on retiring methods may stop functioning without action:

  • Refresh Token Inactivity Expiration: Starting November 4, 2026, the idle time-to-live (TTL) for refresh tokens in production environments will expire after 30 days of inactivity. This change may affect low-frequency integrations that assume the token remains valid indefinitely. Architects must identify these integrations, confirm how they renew credentials, and design for token rotation or re-authentication.
  • Retirement of Legacy Authentication Patterns: It is necessary to map the authentication pattern of each integration and move it to the most secure option supported by the system. The OAuth 2.0 Device Flow will be restricted beginning November 30, 2026, while Username-Password, User-Agent, and Hybrid User-Agent flows will be retired on February 20, 2027.
  • Retirement of Salesforce Connect Cross-Org Adapter and Salesforce to Salesforce: Both changes take effect in the Spring ’27 release. The Salesforce to Salesforce capability will be fully retired and will no longer function, and legacy Cross-Org adapter authentication will require migrating to Named Credentials.
  • External Client Apps: Support for Connected Apps will end by Summer ’27. External Client Apps operate with a default-closed posture and separate application settings from administrative policies.

Capacity Updates, Platform Limits, and Automation Enhancements

The guide details that platform limit shifts allow revisiting solutions previously designed around system constraints, in order to support higher workloads:

  • Apex Heap Limits: The synchronous Apex heap limit increases from 6 MB to 10 MB, and the asynchronous heap limit increases from 12 MB to 25 MB. The guide suggests revisiting code that chunks or streams data primarily to stay under the old ceiling, and simplifying it where the added headroom makes those workarounds unnecessary.
  • Expansion of Elastic Async Apex Jobs (Beta): The capability now covers batch jobs in addition to future methods and Queueable jobs. This additional capacity is capped at either the licensed asynchronous Apex job limit or 2 million jobs, whichever is lower.
  • Overriding Async Job Limits in Non-Production Environments: A feature enabling the override of the standard asynchronous Apex limit in non-production environments to test how workloads are processed within the elastic limit.
  • Flow Improvements and Record Locking: A record-lock retry mechanism and loop-free filtering allow revisiting automations implemented in Apex code due to CPU constraints or locking in Flow.
  • Retaining Manual Shares on Record Transfers: Sharing Settings now allow the organization to retain manual shares when record ownership changes, providing an opportunity to revisit replacing Apex or Flow processes that recreated shares after transfers.

Designing Agentforce Agentic Architecture

The guide highlights that most capabilities for building agentic systems arrive in Winter ’27, with Multi-Agent Orchestration having become generally available (GA) in August 2026:

  • Multi-Agent Orchestration: Composing specialist agents as a supported pattern instead of relying on custom glue code, including streaming responses and handoffs or escalations across channels such as Embedded Chat v2, WhatsApp, and mobile.
  • API Catalog: Enables registering and activating Model Context Protocol (MCP) servers and APIs that agents are authorized to invoke, including interfaces for MuleSoft, Heroku, and Apex.
  • Resolving Parent-Child Relationships in Data 360: Enables grounding agents on complete record hierarchies, spanning zero-copy data model objects (DMOs) from BigQuery, Databricks, and Snowflake.
  • SLDS AI Skills and ApexGuru: Capabilities for standardizing AI-generated code in agentic development environments, using static analysis and portable AI skills.

Evaluating New Governance and Observability Features

The Winter ’27 release introduces dedicated control points for continuous security posture, oversight of agent connections, and org-wide performance, with availability varying by edition, license, and support plan:

  • Security Health Review: Replaces the point-in-time Health Check PDF report with continuous in-Setup findings, remediation, and an audit trail. This feature is limited to Signature Success Plan customers, and the Health Assessments Agent requires the Salesforce Foundations add-on. Organizations without access can continue using Health Check in Setup on a scheduled manual basis.
  • Monitoring Org Health with Scale Center: Surfaces org-health alerts and Agentforce-assisted root-cause analysis in Slack, alongside direct links to Apex investigations and usage insights. The feature is not supported in Government Cloud Plus. Organizations not using it can continue utilizing debug logs, ApexGuru, and Setup usage insights.
  • MCP Server Monitoring in Security Center (Beta): Centralizes visibility into configured MCP servers across connected Salesforce instances, including risk scores, suspicious URLs, and configuration changes.
  • Security Mesh: Unifies security data from Salesforce and external sources into a common format within Security Center.

The guide recommends that architects create an Architectural Decision Record for every feature or change in the Winter ’27 release notes that requires an architectural decision, whether a mandatory enforcement or a new capability on the roadmap, to capture the question being answered, the assumptions behind it, the option chosen, and the business outcome it is meant to support.

Was this useful for your business?

Questions & Answers

FAQ

This article was produced by our AI-assisted system through translation, summarization, and automated quality controls based on original reporting by Salesforce Blog. Read about our editorial process. Link to the original source.

Get useful AI updates by email

A concise digest from our news desk.

More from Salesforce Blog

All articles from Salesforce Blog
מדריך כלי ה-AI ללא קוד לעסקים קטנים לפי Salesforce
מדריך
4 דקות
מ־Salesforce Blog

מדריך כלי ה-AI ללא קוד לעסקים קטנים לפי Salesforce

מאמר שפורסם על ידי חברת Salesforce סוקר את תחום כלי ה-AI ללא קוד (No-Code AI) עבור עסקים קטנים ובינוניים. לפי נתוני דוח המגמות המצוטט במאמר, 75% מהעסקים הקטנים משקיעים בבינה מלאכותית, אך 88% מתוכם עדיין נמצאים בשלב הבחינה. המאמר מפרט קריטריונים לבחירת כלים, סוקר פתרונות בתחומי המכירות, השיווק, האוטומציה, השירות והדוחות, ומדגיש את היתרון של פלטפורמה מחוברת שבה 91% ממשתמשי ה-AI מדווחים על גידול בהכנסות לעומת שימוש בכלים נקודתיים מבודדים.

קרא עוד
עקרונות לעיצוב בינה מלאכותית קולית ומסגרת איכות השיחה
ניתוח
4 דקות
מ־Salesforce Blog

עקרונות לעיצוב בינה מלאכותית קולית ומסגרת איכות השיחה

מאמר מקצועי מציג את עקרונות העיצוב של בינה מלאכותית קולית (Voice AI), המבוססים על דינמיקות שיחה בזמן אמת. המאמר סוקר את מסגרת איכות הקול (Voice Quality Framework) הכוללת שלושה רבדי כשל ו-15 היוריסטיקות להערכת חוויית המשתמש, ומפרט את יישום העיצוב ב-Agentforce באמצעות שילוב של הנחיות פרומפט, לוגיקה דטרמיניסטית והגדרות ערוץ קולי.

קרא עוד
סיילספורס מציגה את סוכן התזמון של Agentforce לשירות שטח
מוצר חדש
4 דקות
מ־Salesforce Blog

סיילספורס מציגה את סוכן התזמון של Agentforce לשירות שטח

סיילספורס הציגה את Scheduling Agent במסגרת Agentforce Field Service, סוכן בינה מלאכותית הפועל 24/7 לתיאום, שינוי וביטול פגישות שירות שטח. הסוכן מחובר לנתוני הלקוחות, ללוחות הזמנים של הטכנאים ולמנוע האופטימיזציה של הארגון, ופועל בערוצי תקשורת מגוונים בהם וואטסאפ, דוא"ל, SMS, iMessage ושיחות קוליות. המערכת מבוססת על Agent Script לקבלת החלטות דטרמיניסטית ואכיפת כללים עסקיים ללא ניחושים של מודלי שפה, ומספקת מענה לפניות לקוחות, סדרנים, טכנאים וטריגרים מנכסים. המערכת תוצג בכנס Dreamforce וב-Salesforce+.

קרא עוד
שלושה סימנים לכך שסוכן AI יחיד אינו מספיק בארגון
מוצר חדש
4 דקות
מ־Salesforce Blog

שלושה סימנים לכך שסוכן AI יחיד אינו מספיק בארגון

לפי פרסום של צוות Agentforce מבית Salesforce, תזמור מרובה-סוכנים (Multi-agent orchestration) זמין כעת באופן כללי. הפרסום מציג שלושה סימנים לכך שסוכן AI בודד הגיע לקצה גבול היכולת שלו: הסוכן מנסה לבצע משימות רבות מדי וסובל מהתנגשות כוונות (Intent collision), הנתונים הנדרשים נמצאים מחוץ לגבולות ה-Salesforce org, או שצוותים שונים נדרשים לנהל חלקים שונים של הסוכן. המאמר מציג ארבעה נתיבי ארכיטקטורה ושאלות מוכנות לבחינת המעבר, ומציין כי בבדיקות פנימיות בעיות הסקה מתרחשות לרוב מעבר לשבעה תת-סוכנים.

קרא עוד

More articles you might like

All articles
סוכני AI בהודעות טקסט: פתרונות בולטים הפועלים ללא אפליקציה נפרדת
חדשות
5 דקות
מ־TechCrunch

סוכני AI בהודעות טקסט: פתרונות בולטים הפועלים ללא אפליקציה נפרדת

לפי TechCrunch, שורה של סוכני בינה מלאכותית פועלים ישירות דרך ערוצי הודעות טקסט מוכרים כמו iMessage, וואטסאפ, טלגרם ו-SMS ללא צורך בהורדת אפליקציות נפרדות. סוכנים אלה מבצעים משימות מגוונות, החל מניהול יומנים, מעקב טיסות וביצוע שיחות טלפון ועד ניהול משק בית, יצירת תוכן ומשימות מקצועיות. בין הפתרונות הבולטים נכללים Instinct שהגיע לשווי של 10 מיליארד דולר, Caddy, Folk, Town, Fambot ו-Wajo, הפועלים במודלים שונים של בטא, מנויים בתשלום ורמות אוטונומיה שונות.

קרא עוד
OpenAI מציגה יכולות אפליקציה ב-ChatGPT וסוכני AI בשם Dots
חדשות
4 דקות
מ־TechCrunch

OpenAI מציגה יכולות אפליקציה ב-ChatGPT וסוכני AI בשם Dots

באירוע Dev Day הציגה OpenAI שורת עדכונים שמטרתם להפוך את ChatGPT לפלטפורמה לגילוי, להפעלה ולשימוש באפליקציות ובסוכני AI. החברה הודיעה על שילוב אפליקציות ישירות בשיחה, השקת "Sign in with ChatGPT" עם 16 שותפות ראשוניות, ופתיחת זירת מסחר לאפליקציות ארגוניות עם יותר מ-30 שותפות. בנוסף הושקו סוכני AI אוטונומיים בשם Dots, הפועלים בענן ומסוגלים להתחבר למעל 4,000 אפליקציות.

קרא עוד
שנה למעבדת המחקר של מיקרוסופט בסינגפור: קידום מחקר וטאלנטים ב-AI
חדשות
4 דקות
מ־Microsoft Research

שנה למעבדת המחקר של מיקרוסופט בסינגפור: קידום מחקר וטאלנטים ב-AI

לפי פרסום של Microsoft Research, מעבדת המחקר Microsoft Research Asia – Singapore השלימה שנה להקמתה כמעבדת המחקר הראשונה של מיקרוסופט בדרום-מזרח אסיה. במהלך השנה התמקדה המעבדה בארבעה תחומים מרכזיים: מודלי AI מתקדמים ומערכות סוכנים, בינה מלאכותית לתחומים ספציפיים, שיטות מחקר מבוססות AI ופיתוח טאלנטים. המעבדה יזמה תשעה פרויקטי מחקר חדשים עם האוניברסיטאות NUS ו-NTU, הכשירה מעל 300 סטודנטים בבית ספר לקיץ, והרחיבה שיתופי פעולה עם סוכנויות ממשלתיות בסינגפור כגון EDB ו-IMDA. בשנתה השנייה מתכננת המעבדה להרחיב את שיתופי הפעולה ולתרגם מחקר בסיסי ליישומים מעשיים.

קרא עוד
כתבת TechCrunch יצרה אווטאר AI אינטראקטיבי באמצעות Synthesia
חדשות
4 דקות
מ־TechCrunch

כתבת TechCrunch יצרה אווטאר AI אינטראקטיבי באמצעות Synthesia

כתבת TechCrunch, דומיניק-מדורי דייוויס, יצרה אווטאר דיגיטלי אינטראקטיבי של עצמה בשיתוף סטארטאפ האווטארים Synthesia. החברה, שהגיעה להערכת שווי של 4 מיליארד דולר ופיתחה פלטפורמות הדרכה ותרגול מבוססות AI, בנתה עבור דייוויס אווטאר אישי המקריא תסריטים ואווטאר אינטראקטיבי המשיב לשאלות על מאמר שפרסמה. המערכת משלבת מודלי המרת דיבור לטקסט, מודל שפה סוכנותי, מודל המרת טקסט לקול ומודל וידאו להנפשה. דייוויס בחנה את המערכת עם בני משפחה וחברים והעלתה שאלות לגבי מקומם של אווטארים בעיתונות ובסביבה התאגידית.

קרא עוד