Case Studies

Salesforce MCP lets AI assistants like Claude query your live org and take actions through natural language. That part works. What nobody's talking about is what the AI can see that your users can't.

A live evaluation of Salesforce's hosted sObject MCP server turned up five real problems: fields hidden by page layout but not FLS are fully exposed; users can self-authorize broad OAuth access with no admin in the loop; AI-driven queries don't appear in standard audit logs; data processed through Claude.ai may leave the Salesforce trust boundary and get used for model training depending on your plan; and there are no native DLP controls stopping sensitive fields from surfacing in a casual conversation with the AI.

These findings were published in a fact sheet, an executive deck, and a LinkedIn post — the post drew direct outreach from Salesforce's Senior Director of Product Management for MCP Servers.

Download the case study.

Ten-plus integrations, all running under personal employee credentials. One of those accounts was already deactivated. This is what Arromatt found during a routine security audit of a mid-market B2B company — and it's a more common setup than most orgs want to admit.

It's what happens when Salesforce grows organically, and whoever sets up each integration just uses their own login because it works. Until someone leaves, changes their password, or gets deactivated, and multiple systems go dark at the same time with no warning and no clear owner.

The fix used Salesforce's five included integration licenses — a feature most orgs never touch — plus one purchased license for broader access. All ten-plus integrations re-authenticated under service accounts. No new license cost. Audit trail intact.

Download the case study.

This engagement had a lot going on. A mobile-friendly Experience Cloud portal for USDA conservation program enrollment. DocuSign integration for federal forms with conditional checkbox logic that pushed against the edges of what the native integration handles cleanly.

An Opportunity pipeline connection was added mid-project. And a parallel dev team working in the same org who had built their own Postman-based integration without looping in Arromatt — which was creating duplicate cases, breaking Contact assignments, and generating 253 automation errors over 48 hours before anyone noticed.

Arromatt diagnosed it, fixed what was in scope, documented the rest, and aligned with the client's operations stakeholder on a pragmatic path forward rather than a technical fight they couldn't win unilaterally. About 75% of errors have been resolved. Phase I delivered. Phase II is scoped and ready. The engagement ended when USDA regional offices were found to have conflicting submission requirements, making the scaling problem significantly harder than anyone had anticipated going in.

Download the case study.