FR
live

AWS and Salesforce wire CRM data and AI agents into Slack and Amazon Quick without data migration

On September 15, 2026, AWS and Salesforce expanded their partnership to push CRM data and AI agents into the tools teams already use every day: Amazon Quick, Slack, and voice. Access is zero-copy — no migration, no duplication — with model choice through Amazon Bedrock.

A narrow glass walkway bridging two identical concrete towers in grey weather, a single amber beacon lit at the bridge’s midpoint.

September 15, 2026. AWS and Salesforce announced an expansion of their partnership, a decade after the two first aligned. The announcement distills into a single formula: put CRM data and AI agents into the tools teams already use — Amazon Quick, Slack, voice — without asking anyone to migrate anything. Why it matters: enterprise AI has so far hit two walls — CRM data stayed locked inside the CRM, and agents lived in separate consoles. These announcements aim squarely at both walls.

Agents where people already work

The first move takes agents out of their consoles. Amazon Quick, AWS’s work AI assistant, can now natively reach Salesforce context — pipeline health, account summaries, service cases — with no custom integration. The mechanics are open: it runs on the Model Context Protocol (MCP) and Salesforce’s headless architecture, which lets the two worlds interoperate without a proprietary gateway.

The second move targets Slack. AWS’s frontier agents — starting with the AWS DevOps Agent, followed by the Security, FinOps, and Partner Central agents in the fall — arrive directly inside Slack channels. Instead of switching to a separate console to dig into an incident or a security finding, a team questions the agent in the very thread where the conversation is already happening.

The third concerns model choice. Agentforce customers, Salesforce’s agent layer, now reach the frontier model catalog of Amazon Bedrock — Anthropic, NVIDIA, and soon OpenAI, already available on Bedrock. Governance is locked at both ends: Bedrock enforces Zero Data Retention (no data stored or used for training), while Salesforce’s Trust Layer adds dynamic grounding and toxicity detection. For regulated industries, that ships with HIPAA, PCI, SOC 2, and ISO 42001 compliance.

Early adopters are already citing the productivity gain. DXC Technology, which runs Salesforce as a central system of record, says Amazon Quick’s agentic capabilities now pull customer data and surface insights without its consultants leaving their daily tools; GoodRx’s engineering leadership points to the AWS DevOps Agent in Slack as a way to spot and resolve issues without breaking flow. Those testimonials matter less as endorsements than as a signal: the integration is designed for the tools where work actually happens, not for yet another dashboard.

Zero-copy: read without moving

The second move attacks the data question. Salesforce Data 360 Zero Copy now extends to AWS Glue-managed Apache Iceberg tables, Iceberg tables on S3, Amazon Aurora, Amazon RDS, and SageMaker Lakehouse, on top of existing Redshift and S3 support. In practice: agents are grounded in enterprise data without migration or duplication, and without touching the security controls already established on either side.

The two companies are also exploring bidirectional semantic sharing with the Glue Data Catalog, laying groundwork for AI experiences with richer context and no migration cost. Informatica rounds out the picture: its MCP servers — platform administration, catalog discovery, data-quality scoring — become reachable from Amazon Bedrock AgentCore and Amazon Quick.

For data leadership and compliance teams, the zero-copy argument goes beyond the migration saving. Not moving the data means not re-qualifying its hosting, not duplicating access controls, and avoiding an extra copy becoming a leak surface. That is exactly what CISOs ask for when they slow down AI projects: governed access to existing data rather than a new silo to secure.

Voice as the next frontier

The most forward-looking piece is voice. Agentforce Voice and Amazon Connect Customer will communicate in real time over the Agent2Agent (A2A) protocol, with bidirectional audio exchanged over WebSockets. A Salesforce agent and an AWS agent will be able to coordinate on a single customer call with no human handoff. Availability is slated for fall 2026.

Along the same lines, Salesforce AI Research optimized its speech models on AWS Trainium chips to deliver voice dictation in Slack at very low latency, available now. The economics are explicit: purpose-built silicon lowers inference cost, and the saving is passed to the customer.

What is available now, and what waits for fall

The availability split is something teams should read before planning. Available now: Salesforce context in Amazon Quick, the AWS DevOps Agent in Slack, Agentforce model choice through Amazon Bedrock, the Data 360 Zero Copy expansion, the Informatica expansion, and Slack voice dictation optimized on Trainium. Announced for fall 2026: the Security, FinOps, and Partner Central agents in Slack, plus the Agent2Agent voice orchestration between Agentforce Voice and Amazon Connect Customer.

That calendar has a direct consequence for anyone driving a roadmap. The documentary and conversational use cases — summarizing an account, prepping a meeting, questioning an agent from a Slack channel — can go to production today. The voice and multi-agent cases remain preview: prototype them, do not industrialize them. The line is not technical, it is contractual — “fall” availability can still slip.

The implicit bet: young standards

The whole announcement rests on two protocols — MCP and A2A — whose maturity is not that of established standards. MCP was widely adopted in 2025, but its security profile is still debated, especially around exposing capabilities between agents and tools. A2A is newer and less deployed at scale. By building their interoperability on top of them, AWS and Salesforce are betting these standards will carry enterprise load. For a CISO, the consequence is clear: auditing these integrations means examining the content of MCP and A2A connections — which capabilities are exposed, to which agents, with what authentication — not just the traditional network perimeter.

What this says about the two vendors’ strategy

The announcement is more than a catalog of integrations. It reveals a shared architectural bet. MCP and A2A play the role of open standards that make interoperability viable without ad-hoc integration, and zero-copy replaces “where does the data live?” with “who accesses it, under what control?”. Both vendors are selling the same promise: AI moves from pilot to operating mode, and buying becomes as easy as building — Salesforce Clouds are now available in the AWS Marketplace across 33 countries, with eligible AWS spend commitments applying to Salesforce products.

The commercial convergence matters for procurement teams, too. Being able to apply AWS spend commitments against Salesforce licenses removes a classic objection to cross-vendor adoption — “we already have a commitment elsewhere” — and shortens the path from decision to deployment. That is the quieter half of the announcement: the two vendors are not only wiring their agents together, they are wiring their billing together, which is often the real gating factor in the enterprise.

Verdict

If you already run AWS and Salesforce, this announcement removes the main tradeoff you used to face — migrate the data or duplicate it — in favor of governed, grounded zero-copy access: adopt it for Quick and the Slack agents, both available now. If voice is your priority, note that A2A orchestration between Agentforce and Amazon Connect does not arrive until fall: do not build production on it today. The thing to watch is the cross-vendor governance — Zero Data Retention on one side, Trust Layer on the other — because it, more than the integrations, will decide whether these agents enter regulated environments at all.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

Azure pushes platforms agent-first and isolates every agent execution in a hardware microVM

On September 23, 2026, Mike Hulme, Azure’s GM of product marketing, describes the shift from request-response applications to continuously acting multi-agent systems, and Microsoft’s answer: govern the agent on Foundry, execute it in an isolated Azure Container Apps sandbox. For platform teams, it is a concrete framework for what must change when the agent replaces the request.

AWS EventBridge replaces multi-account buses with a single shared bus

On September 24, 2026, AWS announced an enhanced custom event bus in Amazon EventBridge: one centralized bus shared across every account in an AWS organization, with ordering guarantees, a Subscriber resource, and a new ingress/egress pricing model. For a multi-account platform still juggling cross-account rules, the workaround is officially over.

← Back to the feed

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss