SyncOnAI360

MCP and Integrations

Bring your org into the AI tools your team already uses.

Connect Claude Desktop, Cursor or any Model Context Protocol client to your Salesforce orgs with read-only access, and link delivery to Jira, GitHub and Slack.

Claude Desktop

Connected to SyncOnAI 360 · read only

Read only

In the production org, what uses Account.Rating?

  • List orgs3 orgs this token can read
  • Where usedAccount.Rating: 4 components
  • Audit findingsLatest assessment: 37 open findings

Four components use Account.Rating: two Flows, one report and a validation rule. This covers every component this token can see.

3 calls recorded in your workspace activity log

In one paragraph

SyncOnAI 360 includes a Model Context Protocol server that lets Claude Desktop, Cursor and other MCP clients read your connected Salesforce orgs: list them, search metadata, see what depends on a component and read assessment findings. Access is read-only, scoped per token, logged, and revocable instantly.

To connect Claude Desktop or Cursor
2 minTo connect Claude Desktop or Cursor
Write actions available to an external AI client
0Write actions available to an external AI client
Calls a minute per token, well above normal use
120Calls a minute per token, well above normal use
Call logged with the tool and the token
EveryCall logged with the tool and the token

01The problem

Why connecting AI tools to Salesforce worries security teams

Developers want their AI assistant to understand the org. Security teams see a token that can change production sitting in a config file on a laptop. Most integrations force a choice between useful and safe.

  1. 01

    Tokens with too much power

    A Salesforce connection that can write gives any tool holding it the ability to change production, with no review and no approval.

  2. 02

    No scoping

    A token for one developer's experiment can see every org the workspace has, including the regulated ones.

  3. 03

    No record

    When an AI tool reads an org, nobody knows what it asked for, when, or with which credentials.

  4. 04

    Negative answers you cannot trust

    An assistant that says nothing uses a field may simply have hit a search limit. Without coverage, a negative answer is a guess.

02mcp

What can an MCP client do with SyncOnAI 360?

An AI client can list the orgs its token allows, search their metadata, look up a component and everything that depends on it, and read the findings from a health assessment. Ask Claude "In the production org, what uses the Account object?" and it answers from your org.

Every answer says how much of the org it was based on, which matters most for negative answers: the client is told when a search hit its limit or when its token could only see some orgs. An org that has never been assessed is reported as exactly that, not as an empty list of findings.

  • List orgs, search metadata, find dependencies, read findings
  • Coverage stated with every answer
  • Works with Claude Desktop, Cursor and any MCP client over HTTP

Claude Desktop

Connected to SyncOnAI 360 · read only

Read only

In the production org, what uses Account.Rating?

  • List orgs3 orgs this token can read
  • Where usedAccount.Rating: 4 components
  • Audit findingsLatest assessment: 37 open findings

Four components use Account.Rating: two Flows, one report and a validation rule. This covers every component this token can see.

3 calls recorded in your workspace activity log

03read only

Is the Salesforce MCP connection read-only?

Yes. An external AI client cannot create, edit, deploy or delete anything in a Salesforce org. Changes go through proposals inside SyncOnAI 360, where they are validated and approved; a client holding a token has none of that, so it is not given the ability to write.

Each token is scoped to the orgs you choose, and it is stored in a form that cannot be read back, so copy it when it is created. Revoke a token and it stops working immediately. Tokens are limited to 120 calls a minute, well above normal use and well below anything that could hammer the workspace.

  • No create, edit, deploy or delete
  • Tokens scoped to chosen orgs
  • Instant revocation, one token per client
  • Rate limited per token

Workspace security

Settings · Security

  • Configuration onlyMetadata and code. CRM records stay in Salesforce.
  • Isolated per customerEnforced by the database and tested every release.
  • Keys in Google Cloud KMSCredentials encrypted under a per-customer key.
  • Second admin for productionThe author can never approve their own change.
  • Hosted in the United StatesEvery subprocessor listed with its region.

04logged

How is AI client access recorded?

Every call an AI client makes is written to your workspace's activity log with the tool it used and the token it used, and the settings page shows when each token was last used.

The arguments are not recorded. A search term can describe the shape of your org, and the purpose of the record is accountability for access, not a second copy of what was accessed.

  • Tool and token recorded for every call
  • Last-used time for every token
  • Arguments deliberately not stored

Claude Desktop

Connected to SyncOnAI 360 · read only

Read only

In the production org, what uses Account.Rating?

  • List orgs3 orgs this token can read
  • Where usedAccount.Rating: 4 components
  • Audit findingsLatest assessment: 37 open findings

Four components use Account.Rating: two Flows, one report and a validation rule. This covers every component this token can see.

3 calls recorded in your workspace activity log

05stack

Which delivery tools does SyncOnAI 360 integrate with?

Jira: raise audit findings as Jira Cloud issues, with status checked back on demand. GitHub: record each deployed change as a pull request in a repository you choose. Slack: post every deploy result to a channel. Jira and GitHub are in beta.

Project webhooks send work item events, created, updated, status changed, comment added or attachment added, to any other system you run. Admins set each integration up once for the workspace.

  • Findings raised as Jira issues
  • GitHub repositories connected to the workspace
  • Slack notifications for deploys and audits
  • Project webhooks for everything else

Service Transformation

Projects · Board · Sprint 7

To do 2

Remove 14 unused Case fields

From audit

Consolidate Account triggers

Apex

In progress 1

Fault paths on intake Flows

From audit

In review 1

APAC routing for Service

Flow

Done 1

Retire Process Builder on Lead

Release 24.3

Work items link to the proposals and deploys that delivered them

06outbound

Can the SyncOnAI 360 chat use other companies' tools?

Yes. Alongside the tokens your own AI clients use to read your orgs, a workspace can add another company's tool server, such as Atlassian for Jira and Confluence, and the chat can use its tools. Use Test to check a saved connection before relying on it.

Every call the chat makes to an outside tool is recorded in the activity log, the same way calls from external AI clients are. Connections are managed by admins in the workspace's MCP settings, so what the chat can reach is a decision, not a default.

  • Add tool servers such as Atlassian for Jira and Confluence
  • Test a connection before using it
  • Every outside tool call recorded

SyncOnAI 360

AI architect for Salesforce

Ask SyncOnAI to build flows, rules, Apex, or SOQL...

07How it works

How to connect an AI client

About two minutes from start to the first answer.

  1. 01

    Create a token

    In Settings, name the token after where it will live and choose which orgs it can read.

  2. 02

    Copy it

    Copy the token straight away; it cannot be shown again.

  3. 03

    Add it to your client

    Add the SyncOnAI 360 address and the token to Claude Desktop, Cursor or another MCP client.

  4. 04

    Ask

    Ask which orgs it can see, then ask a real question about one.

08Before and after

AI tools on Salesforce, with and without SyncOnAI 360

Without

With SyncOnAI 360

Tokens that can change production

Read-only access with no write actions

Every org visible to every tool

Tokens scoped to the orgs you choose

No record of AI access

Every call logged with tool and token

Negative answers you cannot trust

Coverage stated with every answer

Delivery tools disconnected from the org

Findings in Jira, deploys in GitHub and Slack

10Questions

Frequently asked questions

A Model Context Protocol server lets AI clients such as Claude Desktop and Cursor call tools to read data. SyncOnAI 360's MCP server lets them read your connected Salesforce orgs' metadata, dependencies and assessment findings.

No. The connection is read-only. An external AI client cannot create, edit, deploy or delete anything. Changes go through validated, approved proposals inside SyncOnAI 360.

Claude Desktop, Cursor and any other client that speaks Model Context Protocol over HTTP, using a bearer token.

Yes. Choose specific orgs when creating a token, or leave it open to all. Prefer narrowly scoped tokens.

Revoke it in Settings and it stops working immediately. Creating a replacement takes seconds.

Yes. Every call is written to the activity log with the tool and the token used. Arguments are not recorded.

Each token is allowed 120 calls a minute. One question typically takes three or four calls.

Yes, in beta. Audit findings can be raised as Jira Cloud issues with their evidence, and status is checked back on demand. Admins connect Jira once for the workspace.

Yes. After connecting Slack, configure channels for deploy outcomes and for audit completion.

Any client that speaks Model Context Protocol over HTTP and can send a bearer token can connect, using the address and token from your workspace settings.

No. It raises findings as Jira issues and checks their status on demand. It is not a two-way synchronisation of tickets.

Not as a conversational bot. Slack receives notifications, such as deploy outcomes and audit completion, in the channels you choose.

Every plan includes every feature. Free covers one user and one production org with its sandboxes, on your own Anthropic or OpenAI key, with no credit card and no time limit. Paid plans include AI and cover more people and production orgs.

Revoke their tokens in Settings. A token is a password: anyone holding it can read the orgs it is scoped to. Create one token per client so revoking one does not disturb the others.

Start in 5 minutes. No card required.

Connect your Salesforce org. Run your first health scan. Ask your first question. See what you've been missing.

  • Anthropic
  • OpenAI