Issue #66 — Interface in Chat, Data in CRM, and Rules in a Vacuum

Salesforce in Claude, ChatGPT in Word, and missing decision rules.

Dear Reader,

Salesforce announced AIforce at Dreamforce on 16 September, allowing other AI interfaces to use its data and workflows. Salesforce in Claude launches in beta with 37 sales skills. The company says existing permissions and business rules still apply, actions route back through its platform, business data is not retained by the model provider, and no new permissions model is needed (Salesforce).

There is already usage inside Salesforce: the release reports 100,000 Agentforce Coworker activations in 35 days. Fulton Bank describes more than 20 production use cases supporting about 3,000 users. Those figures concern Coworker, not proof that an assistant can reliably run work across several vendors’ systems.

That distinction matters to the buyer. Preparing a document, finding a customer record and changing a commercial commitment require different information and different authority. Putting them in the same chat doesn’t remove those differences.

Claude and GPT — New Ways to Work with Documents

Anthropic also announced changes on 16 September. The Cowork/chat merge starts with Pro and Max; Team and Free follow, and Enterprise administrators will receive at least 30 days’ notice. Separately, Docs and Slides are in beta on paid plans, with Enterprise activation controlled by administrators (Anthropic).

OpenAI’s Word add-in works with the open document and supported connected sources. It uses the user’s ChatGPT account, but history, memory and skills do not carry over from ChatGPT. It cannot read other local files. Usage is token-based; default enablement begins on 1 October, subject to ChatGPT and Microsoft 365 administrator controls (OpenAI).

These are different arrangements. Claude brings document creation into the assistant; OpenAI puts its assistant inside an existing editor. Salesforce makes business operations available through other interfaces. They give employees more choice about where to work, but they don’t yet demonstrate a common understanding of the company behind those interfaces.

The Word limitation makes this unusually concrete. A person can use the same ChatGPT account in two places without the assistant carrying its memory between them. A familiar name and sign-in are no guarantee of continuity.

Company knowledge can stay in several systems

Microsoft describes Work IQ as permission-aware access to information across Microsoft 365 and connected business systems (Microsoft). OpenAI’s Company Knowledge uses connected sources, including custom MCP apps, while respecting source permissions. Some connections are managed by administrators rather than authenticated separately by each employee (OpenAI).

Both approaches let an assistant consult information held elsewhere. Neither description establishes that one repository must replace all the others. A company can keep customer records in its CRM and financial records in its accounting system while allowing an assistant to retrieve what a task requires.

Calling all this “company memory” can hide an important distinction. A source record is the company’s account of a transaction or decision. Retrieved context is the information supplied to the assistant for its current task. The assistant may also retain instructions or summaries for later use. These need different treatment: remembering an earlier answer is not enough to establish that the answer is still correct.

The emerging architecture follows five practical steps: the user works through one assistant, the assistant retrieves context when needed, source systems retain authoritative records and permissions, actions return through those systems and their business rules, and audit logs record which identity accessed which source and changed what.

The practical question is how the assistant chooses among those sources when they disagree. Connecting another repository increases what it can find. It doesn’t, by itself, tell the assistant which record the company treats as authoritative.

Access leaves disagreements unresolved

The proposed architecture allows retrieving current information when needed, then sending any resulting action back through the source system’s rules. But it depends on the company having made decisions about its information that an integration cannot make.

Customer terms, for instance, may appear in a signed contract, a CRM field and an email discussing a proposed change. Finding all three is useful. Treating them as equally authoritative would be a mistake. The assistant needs to distinguish what was agreed from what was merely discussed, and it needs a way to leave the matter unresolved when the evidence isn’t sufficient.

This is where a fluent answer can be less useful than an explicit gap. If the source systems disagree, the employee needs to see the disagreement. A smooth summary that silently selects one version removes information needed to make the decision.

Dates help, but the most recent document is not necessarily the governing one. A draft amendment can be newer than the signed agreement without replacing it. For work involving contractual commitments, the system needs to preserve that distinction when retrieving material and when proposing an action.

Some knowledge will be missing altogether. Much operational reality is completely absent from structured systems: an exception agreed in a hallway conversation, an unwritten credit term, or an informal customer priority may never reach the records an assistant can search. Adding connectors cannot recover a decision that nobody recorded. This limits how much responsibility an organisation can safely assign to an assistant, even when its search works exactly as designed.

These are reasons to test with unresolved and conflicting cases. A demonstration using a complete, consistent account history won’t show how the assistant behaves when part of that history is absent.

Managing Permissions

Salesforce’s promise that AI will retain existing user permissions is useful, but existing permissions can be too broad. An assistant could make improperly accessible information easier to find. That increases exposure.

Actions taken by AI require additional permissions. Permission to read a contract does not grant permission to amend it. A request that crosses systems needs the relevant approval at the point of change, including when the employee could retrieve all the information without asking anyone.

For that reason, I would expect read-only search and synthesis to spread first. Narrow actions inside one vendor’s domain will follow. Cross-system autonomy will remain much more difficult because identity, permissions, semantics and accountability differ fundamentally across systems. Regulated companies in particular are far more likely to deploy several controlled, bounded assistants than a single universal corporate agent.

The audit record should make the action reconstructable: which sources were used, whose authority applied, what was approved and what changed. A transcript of the conversation alone may omit what happened in the connected application. Buyers need evidence of those operations, without assuming that an assistant’s explanation is a complete account of its internal reasoning.

Salesforce has an advantage, but pricing is unresolved

Salesforce can let another company’s assistant handle the conversation while it keeps the customer records and the rules for changing them. That gives it a reason to welcome these integrations. Systems-of-record vendors may build more durable value than model providers, because they control identity, permissions, and the state of business processes in the organisation. Whether that also lets Salesforce keep its existing seat prices up is harder to say. The announcement doesn’t tell us what customers will pay, or which licences they’ll still need.

The assistant provider has a plausible advantage too. If employees begin their work there, it can become the place where they choose which applications to use. Existing software vendors retain valuable records and processes; the assistant provider may gain a closer relationship with the people using them. Neither position guarantees the better commercial outcome.

For the customer, dependence can also accumulate outside the underlying records. Instructions, saved context and workflow definitions may require work to move to another assistant even if the original data stays accessible. A contract allowing data export does not, on its own, demonstrate that these working arrangements will transfer.

I would judge portability by moving an actual workflow and checking what has to be rebuilt. The claim that models are interchangeable is too broad to settle that question. The relevant cost is changing the assistant in the company’s working environment, including its integrations and evaluations.

Briefing

Anthropic and Accenture each expect to invest at least $1bn over five years in evaluation capacity. Evaluators are to have employee-comparable access; reporting arrangements remain unsettled. Anthropic will fund Accenture’s work directly, leaving buyers a concrete independence question: what will evaluators be free to publish? (Anthropic, 18 September)

OpenAI published six training and evaluation cases. In one, a model calculated lake identifiers correctly, then uploaded the result without permission so it could cite it. A correct answer can therefore still involve an unauthorised action; these cases do not establish how often that happens in deployed products (OpenAI, 16 September).

EY surveyed 202 US senior AI decision-makers at publicly traded companies with at least $1bn in revenue. Some 47% said their organisation had bypassed its governance process for urgent deployments. Among respondents using agentic AI, 26% said their organisation could not detect unauthorised agents. Formal policies leave that detection problem unresolved (EY, 15 September).

Summary

The products announced this week offer more ways to bring business information into an assistant. The harder test is whether it can identify the record that governs a decision, recognise missing information and act within the right authority.

A company can make progress without collecting all its knowledge in one place. It does need to decide which sources govern which decisions. Where that remains unclear to employees, connecting an assistant will leave it unclear to the assistant too.

Stay balanced,
Krzysztof

Krzysztof Goworek is founder of Quintant — AI advisory that gets enterprises from experiment to production value.