← Back to Insights

Insight

The Vendor Went Headless

Ariel Agor
•
The Vendor Went Headless

Listen · Read by Leo · click any word to jump

0:00 / —· loading…

On September 15, 2026, on stage at Dreamforce in San Francisco, Salesforce's president of applications and marketing, Patrick Stokes, said something a software company rarely says in public. "The value of Salesforce has never been in the UI," he told the room. "It's been in the platform that stores the way our customers encode their business."

The product he was launching, AIforce, supports the claim. It came with three prebuilt ways to use Salesforce without opening Salesforce. Claudeforce, built with Anthropic, puts Salesforce inside Claude with 37 prebuilt sales skills served over an MCP server, plus a Claude Code plugin with more than 40 skills, in beta for every customer. Slackforce lets people update CRM records by typing a prompt in Slack. Agentforce Coworker sits inside the familiar Lightning interface for anyone who still wants the old screens.

Six days later, Amazon started blocking Meta's new Muse agent from Amazon.com. On the morning this essay was published, Meta announced Meta Enterprise Platform, a new business line that sells Muse, the Muse API, Muse Code and Meta Business Agent to companies. It will be run by CJ Desai, the former CEO of MongoDB.

Those three events look unrelated, but they describe one change. Enterprise software used to come as a bundle: a screen, some business logic, and a database, sold together under one logo and one contract. In September that bundle came apart in public. That changes the question every executive is asking about custom AI versus off-the-shelf tools, and most of the answers in circulation are now out of date.

The bundle came apart in one month

For twenty years, "off-the-shelf" meant you bought the entire stack. You got the screen your people clicked, the rules inside it, and the tables underneath. Customization meant fields, page layouts, and a consulting bill. "Custom" meant you built all three yourself and paid for it every year after.

The choice was binary because the product was solid. You could not buy the database without the screen, because the screen was how the vendor controlled the experience, charged per seat, and kept you. The seat was the unit of revenue because a seat was a human in front of a user interface.

AIforce breaks that link on purpose. Stokes framed the history bluntly in his interview with CIO's Thor Olavsrud: "For the last 50 years or so, we've been using software the same way. As a human, I ask software for what I want, either at the command line or by clicking through these UIs." The new agents, he said, "are able to navigate these applications via the APIs, CLIs, and all sorts of different ways to help us get work done." Earlier in the year, at its TDX developer conference, Salesforce had shipped Headless 360, the raw API-driven layer that AIforce now packages.

Daniel Newman, CEO of The Futurum Group, gave CIO the analyst's reading: "models will provide probabilistic capability that uses the best of breed from your intelligence coupled with the rich, proprietary data that businesses depend on." In plain words, the model comes from somewhere else, and the data stays where it was.

Meta's move completes the picture from the opposite side. Zuckerberg's announcement called the new platform "the next major pillar of our business," and Desai said Meta "is bringing together advanced models and leading agents with a proven track record." Meta has no CRM, no ERP, and no general ledger. It is selling the part that acts, and it expects to act on systems that other companies own.

So the stack now has three layers with three different owners. The system of record sits at the bottom, with Salesforce, Workday, SAP, your bank, and Amazon's storefront. The agent sits at the top, sold by Anthropic, OpenAI, Google, and now Meta. Between them sits a thin band that decides which agent may touch which record, under whose identity, with what limits, and with what trail left behind.

That middle band is where the build decision now lives.

Custom AI versus off-the-shelf tools, redrawn

Most buyer's guides published this year still frame the choice as a spectrum. Buy for horizontal work, build for proprietary workflows, run a hybrid, check the cost tables. None of that is wrong. It simply describes a stack that stopped existing in September. You have three layers to decide on now, and each one gets its own answer.

The record layer: buy it, then read the terms

Nobody reading this should rebuild their CRM because an agent can now drive it. The system of record is the part that got more valuable this month. Stokes said as much: Salesforce is "the platform where our customers store their data, metadata, workflows, and all their permissions and security." Salesforce's own account of AIforce stresses that agents run under existing permissions and business rules, with zero data retention built in.

So buy the records off the shelf, as you always have, but read the contract with a new question in mind. The old question was price per seat. The new one is what happens when something other than a person shows up at the door. Which agents are allowed in? Through which interface? At what rate, and at what price? Can you bring an agent Salesforce did not sell you? A vendor that says the UI was never the value has told you where it plans to make its money next, and that is on the access path.

The agent layer: rent it and keep it replaceable

The agent at the top is the part changing fastest and the part you should own least. In a single month, the options for a sales team working in Salesforce went from "Agentforce" to Claude, Slack, a Lightning coworker, and whatever Meta Business Agent turns into once Desai's team ships it. Meta seeded Muse to consumers with 100 million free tokens a week, according to reporting collected by AI Agent Store. When the most aggressive entrant is giving away usage to buy position, any long commitment to one agent is a bet you do not need to make.

Rent agents. Pay by use where you can. Keep every integration written so that a different agent could sit in the same chair next quarter. The companies that customized one vendor's agent deeply in 2025 are finding that they bought a very expensive coat for a body that keeps changing shape.

The middle: build it

This is the layer that gets the word "custom" now. It is small. It holds your map of which records each class of agent can read and write. It holds the identity each agent carries when it acts, so a downstream system can tell a human from a machine working on that human's behalf. It holds the spending and action limits, the escalation rules, and the logs you will want the first time an agent does something expensive at two in the morning.

Salesforce calls its version of this band the "Enterprise AI Harness." It describes the harness as a composable architecture combining data, business knowledge, workflows and control. That is a good description, and it is also a sales pitch. Every vendor in the stack now wants to sell you the middle, because whoever owns it decides which agents get used, which records get touched, and whose meter runs.

Amazon showed who holds the gate

If you want to see what the middle is worth, look at what happened when a company tried to skip it.

Meta launched Muse on September 8 as its first consumer agent. It books travel, manages email and calendars, and checks out purchases using Stripe's Link. According to GeekWire, Amazon asked Meta to keep Muse off its site. Meta declined, and around September 20 Amazon began blocking it. Shoppers using Muse got pop-ups telling them they were breaking Amazon's terms. Amazon's statement was short: "Continued access by an unauthorized AI agent violates Amazon's Conditions of Use, to which our customers have agreed." The company added that third-party applications buying on a customer's behalf "should operate openly and respect service provider decisions."

Amazon's complaint, as reported, was that Muse did not identify itself as automated while browsing, and that it handled customer logins. Meta's answer was that credentials "go into secure storage, so Muse can use them without seeing them." Both statements can be true together. That is the point. The fight is over who controls the band between the agent and the record, and Amazon was defending its band.

The legal background makes this sharper. Amazon won a preliminary injunction against Perplexity's shopping agent in March 2026. It lost that injunction on August 4, when the Ninth Circuit ruled that the user, and not the AI company, had accessed Amazon's computers. The court denied Amazon's petition for rehearing on September 10. With the courtroom route narrowing, Amazon went back to the tools it controls outright: its terms of use and its servers. GeekWire noted that Amazon took more than $68 billion in advertising revenue last year, money that depends on humans looking at pages. Its own agents play by rules it chose. Buy for Me, for example, identifies itself to brands and lets them opt out.

Now apply that to your company. Amazon is a system of record for a large share of American retail. Your ERP, your bank, your payroll provider and your CRM are systems of record for you. Every one of them can make the choice Amazon made. They can let in the agents they sell or approve, and block the rest under terms your employees already clicked through. Salesforce is doing the friendly version: it approved Claude, built the connector, and shipped 37 skills. The friendly version still means Salesforce picked the agent.

A company with no middle layer of its own learns about these decisions when a workflow breaks. A company that owns the middle has already mapped which systems accept which agents, has a fallback path for each, and can move an agent from one vendor to another without renegotiating access record by record.

Why the middle is small, and why that matters

Executives hear "build" and picture a platform team of forty engineers and an eighteen-month roadmap. That picture came from the old stack, where building meant rebuilding the screen and the database. The middle layer is much smaller. In most companies I have looked at, it amounts to four things.

The first is an agent register. Every agent acting in your systems gets a name, an owner, a human sponsor, and a list of what it may touch. Dataiku announced agent-management tooling on September 24 for exactly this, with an inventory that spans AWS Bedrock, Databricks, Vertex, Copilot Studio, Azure Foundry and Agentforce, per AI Agent Store's summary. The fact that a vendor has built a product to answer "how many agents do we have" tells you most companies cannot answer it.

The second is a permission map that you author and the vendors enforce. Salesforce's promise that agents run "under existing permissions" helps only if your permissions were designed with agents in mind. Most were designed for people, who tire, forget, and act slowly. An agent with a sales rep's permissions and no fatigue will exercise every one of them.

The third is identity. Amazon's complaint about Muse came down to disclosure. Your systems of record will increasingly ask the same thing: is this a person or an agent acting for one? You want that answer to come from your own identity layer. If it comes from each vendor's opinion of the other vendors, you will spend next year untangling it.

The fourth is the trail. When an agent changes a price, sends a contract, or moves money, someone will ask why. The log has to survive a change of agent vendor, which means it cannot live only inside that vendor.

None of this needs a model of your own. It needs clear decisions and a modest amount of code, owned by people who report to you.

Every vendor wants the middle, and that is the risk

Here is the trap in September's announcements. Each one offers to handle the middle for you, and each offer is reasonable.

Salesforce's harness governs agents touching Salesforce. Meta's platform will govern agents Meta sells. Google's agents govern themselves inside Workspace. Accept all three and you end up with three middles, each loyal to its owner, and none able to see what the others are doing. Your finance agent in one stack cannot be stopped by a policy written in another. Your security team reads three logs in three formats. When a regulator or an auditor asks who approved an action, the answer is scattered across three vendors' consoles.

This is what off-the-shelf now costs. The price of the tool looks low. The cost shows up as fragmented control over what machines do in your company. A bundled SaaS product in 2015 locked in your data. A bundled agent harness in 2026 locks in your authority, meaning your ability to say yes or no to an action taken in your name.

So let vendors enforce your policy, and do not let them write it. Salesforce's harness is a fine place to apply a rule. The rule itself should come from a source you control, in a form you could hand to Meta or Anthropic tomorrow.

What to do before the end of the quarter

Change the procurement question

Every renewal for a system of record in the next six months should include a short agent-access schedule. Ask which third-party agents the vendor supports today, and which it plans to block. Ask whether you can connect an agent the vendor did not sell. Ask what an agent's access costs if it is priced differently from a human seat. Ask what identity an agent must present. And ask whether your logs of agent actions can be exported in full.

Vendors will answer vaguely at first, because most have not priced this yet. That vagueness gives you leverage. Terms written into contracts during this transition will be harder to win back once the pricing hardens.

Run the swap drill

Pick one live workflow that an agent already touches. Sales follow-up is a good candidate, since Claudeforce, Slackforce and Agentforce Coworker all compete for it. Then try to move it from one agent to another in a week. Record every step that breaks. Each break shows you a place where your middle layer belongs to a vendor.

If the move takes a week, you own your middle. If it takes a quarter, you rented it without knowing.

Write the policy once

Take your ten most sensitive actions (issuing refunds, changing prices, signing contracts, paying suppliers, and the rest) and write down who, or what, may do each one, up to what limit, and with what approval. Put that document under version control, owned by a named executive. Then map it into each vendor's controls. When a new agent vendor arrives, and Meta arrived this morning, you map the same document once more, and the policy stays the same.

The objection worth answering

The strongest argument against all this is speed. Salesforce shipped Claudeforce to every customer in beta on day one. A company that turns it on today gets value today. A company that stops to design its middle layer loses a quarter.

That argument holds for a pilot. It fails at scale, for the same reason Amazon blocked Muse. Access that someone else grants, someone else can take away, or reprice, or restrict to their own agent. A pilot on vendor defaults is cheap to run and cheap to abandon. A company that runs its entire revenue operation through agents on vendor defaults has handed the off switch to a party whose incentives changed this month.

The sensible sequence is to pilot on defaults this quarter and write your policy alongside the pilot. By the time the pilot scales, the middle is yours. The cost is a few engineers and some executive attention. The alternative is renegotiating your authority with each vendor, one renewal at a time, after they have seen how dependent you are.

Architecting the split

This month the software industry admitted that the screen was never the product. Salesforce said it outright. Meta entered the agent business without owning a single system of record. Amazon showed what a record owner does when an agent arrives uninvited. Every company that runs on SaaS is now living inside that three-way split, whether or not anyone there has drawn it.

Buying another tool will not fix this, because every tool on offer comes with its own middle attached. The job is architecture. You decide which layer you rent, which you buy, and which you hold, and you write the rules for the held layer before a vendor writes them for you. Custom AI in 2026 is small and specific. It is the band of policy, identity and record-keeping that lets you replace any agent and keep every decision.

This is the work Agor AI Advisory does. We map your systems of record against the agents already touching them, write the permission and identity layer you will own, rewrite procurement terms for agent access, and run the swap drill with your team until moving vendors is a routine task. The vendors all shipped their plans this month, and you need a plan of your own that doesn't depend on any of them.

Sources

Want this kind of automation working for your business?

Agor AI designs and ships the systems these posts describe, scoped in weeks, not quarters.

Book a Free Strategy Call