Architecting Secure Enterprise AI Agents with Salesforce and Model Context Protocol (MCP) A Reference Architecture and Risk-Governance Framework for Enterprise Agentic CRM
Keywords:
Salesforce, Model Context Protocol, MCP, enterprise AI, agentic AI, AI security, authorization, OAuth 2.0, least privilege, prompt injection, CRM, governance, auditability, risk managementAbstract
Enterprise adoption of generative AI is moving from conversational assistants toward autonomous agents capable of reading enterprise data, invoking business logic, and performing operational actions. In a Salesforce environment, this evolution creates a security problem that differs materially from conventional API integration: an AI agent can interpret natural-language intent, select tools dynamically, construct parameters, and execute multi-step workflows, while the underlying CRM contains highly sensitive customer, financial, and operational information. Model Context Protocol (MCP) provides a standardized interaction layer between AI applications and external capabilities, but protocol-level connectivity does not by itself solve identity, authorization, data minimization, action governance, or audit requirements. This paper proposes a security-oriented reference architecture for enterprise AI agents interacting with Salesforce through MCP. The architecture combines per-user authentication, least-privilege authorization, Salesforce-native object and field controls, tool-level governance, context minimization, human approval for high-impact actions, continuous audit, and a five-factor risk model covering data impact, security impact, automation impact, integration impact, and reversibility. The paper maps these controls to current Salesforce Hosted MCP security capabilities and contemporary AI security guidance, then defines a practical evaluation framework for testing confidentiality, integrity, authorization correctness, prompt-injection resilience, operational safety, and auditability. The contribution is a reusable architectural pattern for enterprises that want to expose Salesforce capabilities to agentic AI without replacing established CRM governance with an opaque AI-specific security layer.





