TL;DR
Salesforce and Microsoft are both moving business applications behind AI agents that read the underlying schema, permissions and data instead of the screen. Edge151 argues the interface has been subsidising organisational capability for two decades, and agentic AI readiness removes that subsidy. Leaders get a clearer test of what their pilot actually assumes, and a way to judge whether their business can build capability fast enough to keep up.
When the interface disappears, the system underneath does the talking
In August 2026, Salesforce and Anthropic announced Claudeforce, a partnership whose first product puts Salesforce inside Claude with thirty-seven prebuilt sales skills, live CRM data and central authentication. The stated aim is that a seller need never open the Salesforce application. It reached pilot customers on the day of the announcement, with open beta stated for September 2026 and live demonstrations scheduled for Dreamforce between 15 and 17 September. Marc Benioff summarised the position on the earnings call the same day: “the UI is the AI.”
The announcement was the packaging rather than the architecture. Salesforce in Claude runs on AIforce, which exposes business data and workflows to any agent through MCP servers, APIs and command line tools, and that in turn builds on Headless 360, the initiative Salesforce introduced at TDX in April 2026. Traffic runs the other way too, with Claude now available as a reasoning model inside the Atlas Reasoning Engine that powers Agentforce.
Microsoft has been building the same thing for longer and with less attention paid to it. The Dynamics 365 ERP MCP server reached general availability on 27 January 2026, reported at the time as a February release. A Sales MCP server followed in July. Microsoft announced general availability of the Customer Experience MCP Server for Service on 30 July 2026, with more than ninety tools covering cases, knowledge, email and Dataverse records. A Commerce MCP server arrived for retail, and the first Workforce Engagement Management tools were added on 3 September 2026. MCP, the Model Context Protocol, is a published standard that lets an AI client connect to a business system and act inside it. Business Central now ships agents that read incoming documents and prepare transactions before a person opens the record.
Almost all of the commentary has been about the agent. The more useful question for a leadership team is what becomes visible when the screen is no longer sitting between a person and their data.
What the screen was actually doing
A well-built form is a set of instructions for a human being. The order of the fields tells you what matters. The tab groupings tell you which pieces of information belong together. The stage bar tells you where the work has got to. The mandatory field marker tells you what the organisation has decided it will not proceed without.
A significant part of it is not in the software at all. It is the colleague who explains that the second Region field should be ignored because it was abandoned during the migration. It is the team leader who mentions that everyone records the renewal date in the notes because nobody wanted to raise a change request in 2019. It is the induction conversation that tells a new starter which report the finance director actually trusts.
None of that context is in the data. It lives in the layout, in the training, and in the heads of the people who use the system every day.
This is the Edge151 proposition in this article. For twenty years, the user interface has been quietly subsidising organisational capability. Screens and training have carried clarity that the business never had to write down, agree, or own. The subsidy was invisible because it worked. It is now being withdrawn by the vendors, on their schedule rather than yours.
What an agent reads instead
Take the screen away and the agent receives the schema. Table names, field names, data types, option set values, and whatever descriptions somebody bothered to write. It receives the permissions of the person asking. It receives the records as they actually are. That is the whole picture.

This produces a specific and underappreciated change. Field descriptions used to be documentation, which is why they were the first thing cut when a project ran short of budget. They are becoming runtime instructions. The description property on a column is now the sentence that tells an agent what the field is for, who owns it, and what it does not mean.
The same shift applies to option sets. A status value labelled 4 means something precise to a person who has worked in the team for three years. It means nothing to an agent, which will either guess or hedge, and the guess will be delivered in fluent, confident prose.
A composite example
The following example is composite. It is assembled from patterns common across mid-market deployments rather than drawn from a single named business.
A manufacturer with about 300 staff has been running Dynamics for six years. Sales, service and a light ERP integration. The system works. Reporting is broadly trusted. The leadership team approves an agent pilot for the sales function on the reasonable grounds that the platform is mature.
Inside the customisation area there are two fields holding a customer’s renewal date. One was created during the original build. The other was created in the second year when the renewal process changed and nobody wanted to unpick the first. The team knows which one is live. The field descriptions are empty for both.
There are option set values labelled Type 1 through Type 5, with the meanings held in a spreadsheet on the operations manager’s desktop. There are eleven fields named in the pattern the platform generates when somebody creates a column in a hurry during user acceptance testing and never renames it.
A salesperson asks the agent which accounts are up for renewal this quarter. The agent reads both renewal fields, picks the one whose name looks closest to the question, and returns a confident list built on the dead one. Nobody notices for five weeks, because the answer looked right and arrived quickly.
The pilot is then judged to have failed on accuracy. What it actually did was report, faithfully, what the organisation had written down.
Permissions stop being housekeeping
An agent inherits the permissions of the person running it. Both vendors have designed it this way and it is the correct design. Microsoft routes access through the Agent 365 Tooling Gateway and states that it aligns with existing Dataverse roles and permissions. Salesforce states that every action runs through the permissions and business rules the organisation already enforces, with no separate access layer to configure. It is also the part that surprises people.
Every security role that was quietly too generous, every temporary elevation that was never reversed, every intention to tidy something up after go-live becomes live the first time somebody asks a plain question and gets an answer they were never meant to see. The screen used to provide cover, because finding data required knowing where to look. Finding it now requires asking for it.
Data completeness moves the same way. A person looking at a half-finished opportunity record applies judgement without noticing they are applying it. They can see the last activity was eight months ago and the close date has moved four times, so they discount most of what they are reading. An agent reads the record as fact, reasons from it, and then summarises across two hundred of them for a director who has no way of seeing which records were reliable.
This pattern is not confined to CRM
It is worth being clear that business applications are simply where this arrived first, because they had the most exposed interfaces and the best documented APIs.
The same structure is visible in other industries. In legal services, document review tools read the contract repository directly, and the value moves to whether clauses are tagged consistently. In logistics, planning agents read the master data rather than the planner’s screen, and the value moves to whether locations, lead times and constraints are recorded as the business actually operates. In financial services, the exposure sits in whether product and risk classifications mean the same thing across systems that were merged five years ago and never reconciled.
In each case the pattern holds. AI does not create the weakness. It removes the human layer that was absorbing it, and then operates at speed on what remains. Disruption lands hardest where value was concentrated in a compensating layer that software can now generate. Raw exposure to AI is a weaker predictor by comparison.
Why the answer cannot be a project
The natural response to all of this is a readiness project. Audit the fields, write the descriptions, review the security roles, clean the records that drive decisions, then start the pilot.
That work is right, and on its own it will not hold. Salesforce moved from announcement to pilot access in a single day. Microsoft has shipped six separate MCP surfaces inside eight months and has already retired the first of them, with the original static ERP MCP server going out of service on 1 October 2026 in favour of a dynamic replacement. A readiness project scoped in March is answering a question the vendors have already moved past by September. The business finishes the audit, discovers that several new agent surfaces have appeared in the meantime, and starts the cycle again with less enthusiasm and a thinner budget.
There is a harder version of this point, and Microsoft made it the day before Claudeforce. On 25 August 2026 it announced that release waves are finished. There is no Release Wave 2 for 2026. New Dynamics 365, Power Platform and Dataverse capabilities are published to the AI at Work roadmap as they are committed rather than gathered into a twice-yearly announcement, and Release Planner is withdrawn on 15 November 2026. Microsoft’s stated reasoning is that the pace of change no longer fits the old cadence.
Release waves gave organisations a fixed, twice-yearly moment to gather stakeholders, read what was coming and decide what to adopt. Many mid-market businesses planned their entire system change calendar around it. That moment has been removed by the vendor, which means the planning either becomes continuous or it quietly stops happening. Anyone still intending to respond to agentic AI with a project now has to explain what the project will be scoped against.
What the situation requires is a rate, not a push. Edge151 defines Business Evolution as the deliberate, continuous building of organisational capability at the rate a business’s ambition requires. The test for a leadership team is not whether the field descriptions get written this quarter. It is whether the business can absorb a material change in how its systems are used, repeatedly, without needing a programme each time.
What capability means here, concretely
Capability is a word that dissolves under pressure unless it is broken into parts. Edge151 uses eight: skills, capacity, confidence, authority, data, tools, support and leadership. All eight are load-bearing in an agent pilot, and the ones that usually fail are not the ones the business case worried about.

Data is the obvious one and rarely the binding constraint. Authority is more often the problem. Somebody has to be permitted to decide that a field is deprecated and say so in the system, and in many organisations no such person exists. Confidence matters because a team that has been told twice that a technology will change everything will pilot the third one carefully and without commitment. Capacity matters because the people who know which renewal field is live are the same people running the quarter.
You can find the fuller argument in what Business Evolution means in practice.
What this argument does not claim
Vendor timelines are not delivery timelines. The claim that thousands of clicks will disappear is marketing, and complex or regulated processes will keep deterministic screens for years because an auditable, repeatable path through a decision is worth more than a fast one. Somebody still has to build those screens.
Nor is every business exposed equally. An organisation with a young, well-governed implementation and a small user base may find the readiness work takes a fortnight. The argument here is about the distribution of that work, which is uneven and mostly invisible until it is tested.
There is a brake on the vendor side as well. Reporting at the end of August noted that some storage and access controls for regulated buyers remain unfinished, which means the organisations with the strictest data handling obligations are among the last able to take agent access at all. Their readiness window is longer than the announcement suggests.
And there is a reasonable counter-position worth stating. Some argue that the agents themselves will improve fast enough to cope with poor context, inferring meaning from data patterns rather than descriptions. That may partly happen. It does not help with permissions, and it does not help when two fields both plausibly hold a renewal date and only one is maintained.
Conclusion
The interface was the part of the system you could see. It was also the part that was doing work nobody accounted for, holding meaning that was never written down and covering for decisions that were never made.
That layer is being removed by vendors moving faster than most organisations plan. What sits underneath will start doing the talking, and it will talk in exactly the terms the business wrote down, at whatever speed it is asked to.
The question worth putting to your own leadership team is how quickly you could become ready for an agent pilot, and then how quickly you could do it again in six months when the next surface ships.
Before you approve the pilot, assess the capability it assumes. Edge151 runs a Business Evolution Assessment that tests the eight capability components against a specific workflow, and produces a rate you can plan against rather than a list you will not finish.
Agentic AI readiness is the state in which a business system can be operated by an AI agent without producing confident errors. It covers four things: field and table descriptions written in business language, security roles that reflect current intent, data completeness on the records that drive decisions, and a documented process that matches how the work is actually done
Because an agent reads them at runtime. In a screen-driven system, the description property was documentation that an auditor might read once. In an agent-driven system it is the instruction that tells the agent what a field holds, who owns it and what it excludes. It directly determines answer quality.
Salesforce and Microsoft have designed agent access to inherit the permissions of the person running it. The exposure comes from the fact that finding data no longer requires knowing where to look, so over-generous roles that were previously harmless become visible immediately.
Data quality is necessary and rarely sufficient on its own. Permissions, field meaning and process truth usually cause more pilot failures than incomplete records. A short readiness assessment across all four is more useful than a long data cleansing exercise on its own.
A transformation programme is an event with a start, an end and a budget. Business Evolution is the deliberate, continuous building of organisational capability at the rate a business’s ambition requires. Vendors are now shipping agent surfaces every few months, and in September 2026 Microsoft retired its twice-yearly release wave cycle in favour of continuous disclosure, removing the fixed planning moment that programmes were usually timed against. A rate is more useful than an event under those conditions.
The most exposed industries are those where value sat in a layer that software can now generate: interface configuration, navigation training, document review, first-line summarising and manual reconciliation. Exposure follows the compensating layer rather than the sector.
Pick one workflow that an agent will touch. Write plain business descriptions for every field and option set value in it, mark the dead fields as deprecated in the description itself, and review the security roles for that workflow as though every user now has a fast, literal assistant with their exact access. That is a fortnight of work and it will tell you what the rest will cost.
Alastair Jupp writes on organisational capability and the practical adoption of AI. The argument here is developed at length in Workflows, Decisions, Discipline: The Operating System Behind Every High-Performing Business, published by Edge151 later this year. Details and publication updates.
Discover more from Edge151
Subscribe to get the latest posts sent to your email.
