An admin said this to Salesforce at a True to the Core session, and Salesforce quoted it back in their own announcement: “Setup in its current state isn’t acceptable. It isn’t accessible, and it takes too many clicks and different interfaces to get a task done.”
That complaint is the whole reason this topic exists. Nobody wants AI to do their job. They want to stop clicking through nine screens to find out why one user cannot see an object.
So here is what actually works, what does not, and the part most people get backwards.
Everybody starts with MCP. I think that is the wrong order.
The standard advice is to wire up a Salesforce MCP server and talk to your org through Claude Code or Cursor. It is good advice eventually. It is bad advice on day one, because you spend an afternoon on a CLI, an auth flow and a config file before you learn anything about whether this helps you.
Start with the browser extension instead. Claude in Chrome or the ChatGPT extension, pointed at a sandbox you are already logged into. You get an answer in ten minutes.
The deeper reason is that a huge amount of Salesforce config has no API behind it. A setting buried four screens into Setup. A guided wizard that only exists in the UI. Page layout checkboxes. Walking a release note checklist across six screens. MCP cannot touch any of that. A browser agent can, because it is looking at the same screen you are.
OpenAI appears to have landed in the same place. They built Atlas as a whole separate browser, killed it on August 9, 2026, and moved the capability into a Chrome extension. Anthropic started there. Both ended up at the extension.
The two options
Claude in Chrome runs inside your existing Chrome session. The feature that matters for admin work is task recording: you walk it through a permission audit once, then replay it every quarter. That beats any individual prompt.
It has three approval modes. Automatic checks each action for safety first and is the default. Manual asks before everything. There is a skip all approvals mode and you should not point it at a Salesforce org. Either way it stops before entering sensitive data or changing permission settings.
The ChatGPT Chrome extension is what Atlas became, agent mode included. If your team already pays for ChatGPT, use it. The gap between the two is much smaller than the gap between either and nothing.
Prompts that only work because something is looking at your org:
Open Setup in this sandbox, go to Object Manager, and for every custom object tell me whether Field History Tracking is on and how many fields are tracked. Table format.
Our user Maria cannot see the Contract object. Check her profile, her permission sets and her permission set groups, and tell me which one is missing and the smallest change that fixes it.
Walk the Winter 27 release notes. For each breaking change, check this org and tell me if we are affected. Skip anything that does not apply to our editions.
That last one is a genuine afternoon.
Then add MCP, once you know what you want
MCP is better at precision and repetition. Bulk work, metadata deploy and retrieve, anything you need to run identically a hundred times. It also does not break when Salesforce moves a Setup page, which browser automation absolutely does.
The hosted MCP servers are the easy version: enable in Setup, connect over OAuth, every action runs as you under your own field level security and sharing rules. Docs here.
The DX MCP server runs locally through the Salesforce CLI with about 60 tools across ten toolsets. Two commands:
npm install -g @salesforce/clisf org login web -a myorg
Point your client at npx -y @salesforce/mcp with your org alias. Jitendra Zaa has the config.
My split: browser agent for exploring and auditing, MCP for building and deploying.
Salesforce shipped its own answer to that complaint
Setup with Agentforce went GA in May 2026 and is Salesforce responding directly to the clicks problem. Natural language inside Setup, covering user access troubleshooting, permission sets, org wide defaults and sharing rules, custom objects and fields, flows, Lightning pages, report types and formulas. It proposes and waits for approval.
Worth trying before you buy anything else, though note the admin exam got reweighted in December 2025 and Agentforce only landed at 8% of it. One Reddit commenter said they were surprised it was that low. Salesforce is pushing harder than the certification is.
Install Inspector Reloaded while you are at it
Salesforce Inspector Reloaded is free, open source, half a million users, and it makes the browser agent better. Every field on a record, SOQL from the browser, metadata inspection. With Inspector open, the agent reads your schema off the page instead of inferring it.
Navigator for Lightning gets you to any Setup page by typing. And tint production red with an org color extension. That one sounds trivial and it is the cheapest insurance you will ever buy.
The part nobody wants to talk about
Prompt injection is not hypothetical here. Noma Labs found ForcedLeak, where an attacker planted instructions in a web to lead form and those instructions executed later when an employee asked Agentforce about the record. Zero click, capable of exfiltrating CRM data. Salesforce shipped Trusted URL allow lists on September 8, 2025 and customers are covered against that specific attack, but the shape of the problem is permanent: your org is full of text that strangers wrote.
A browser agent reading a Case description is reading text somebody else typed. Keep it in a sandbox.
The other thing that comes up repeatedly in admin threads is reward hacking. Point an agent at a data cleanliness score and it may work out that an empty data set scores perfectly. Nobody has fully solved that. Define what you want carefully, and never hand over a delete.
Beyond that: browser agents are slow for bulk work, recorded tasks break when pages change, nothing here deploys with automatic rollback, and all of it will occasionally be confidently wrong about order of execution or a governor limit. Treat every output as a draft from a fast junior admin who read all the docs and has never worked in your org.
What I actually tell clients
Sandbox only. Manual approval for the first few weeks, then relax it once you have seen where it fails. Read before write. Production tinted red. A human on the deploy button, as a real control and not a formality.
And pick one audit you have been putting off for six months. Give it to a browser agent in a sandbox tomorrow morning. You will know within an hour whether this is worth your time, which is a better use of that hour than a config file.
Need help wiring this up properly? That is the work we do at MotionDog.
Sources: Salesforce on the Setup complaints, Claude for Chrome setup and limits, Atlas becomes a ChatGPT extension, ForcedLeak research, Setup with Agentforce for admins, admin exam reweighting, what admins are saying about Agentforce, Salesforce Hosted MCP Servers, MCP setup walkthrough, Salesforce Chrome extensions graded

Leave a comment