Why the “SaaS is dead” crowd has it backwards
You run a company that makes something real. Medical devices, windows, industrial equipment, software for restaurants. Somebody on your leadership team just came back from a conference and asked the question that is going around every boardroom this year: should we replace Salesforce with AI? The pitch is seductive. Agents can write code now. Why pay for a CRM when you could vibe code your own in a weekend and own it outright?
Here is our answer, and we will spend the rest of this post earning it. Your CRM did not just get less valuable. It became the most valuable software you own. The companies that win the next five years will not be the ones who rebuilt Salesforce. They will be the ones who made Salesforce, and everything around it, worth pointing an agent at.
The short version
- Klarna reversed it. The company that shut off Salesforce for an in-house AI stack walked it back within months and said the agent era might be the opposite of the end of CRM.
- Security is the first wall. Encryption, tenant isolation, MFA, event monitoring and a stack of certifications all arrive on day one with Salesforce and have to be built, staffed and audited if you replace it.
- Switching cost is the part nobody budgets. Data migrations overrun or fail more than 80 percent of the time, and that is with experienced vendors on proven software.
- The unit of analysis is wrong. The average company runs 305 SaaS applications. Value lives in the seams between them, not inside any one app you could rebuild.
- Build on top, not underneath. Agentic workflows, agent harnesses, orchestration, cost routing and governance are all new, hard and high-value. Rebuilding a CRM is none of those.
Klarna tried it. Then Klarna explained why it did not work.
In late 2024 Klarna announced it was shutting down Salesforce and Workday in favor of an in-house AI stack. It was the poster child for “SaaS is dead.” By March 2025 the CEO was walking it back in public. In his words, “we did not replace SaaS with an LLM,” and storing CRM data inside a model “would have its limitations.” He went further and said the agent era “might be the opposite” of the end of Salesforce. Two months later the company said it had pushed AI-only customer service too far and started hiring people back.
Meanwhile the company that was supposed to be disrupted became the place agents go to work:
- Agentforce grew 169 percent year over year to $800 million in annual recurring revenue in fiscal 2026, with 29,000 deals.
- Salesforce hosted MCP servers went generally available in April 2026, so any agent can reach the org through a governed connection that runs as a real user.
- Claudeforce launched in August 2026. Claude is now a default reasoning model inside Agentforce, and “Salesforce in Claude” ships 37 prebuilt sales skills that take governed action in your org. We wrote about what Claudeforce readiness actually means when it was announced.
“Frontier models depend on CRM. They don’t replace it.”
Marc Benioff, CEO, Salesforce, August 2026
He is selling something, sure. He is also right.
Security is where a homegrown CRM fails first
This is the part most “build your own” conversations skip, and it is the part that should end them. When you replace Salesforce with AI-written software, you are not just rebuilding screens and tables. You are rebuilding a security program.
Here is what you inherit on day one with Salesforce and would have to build, staff and audit yourself:
Encryption by default
In transit and at rest, with no configuration.
Hover for detail
Encryption by default
Shield adds field-level encryption with keys you hold, and a ten-year field audit trail.
Tenant isolation
One compromised credential reaches one org.
Hover for detail
Tenant isolation
Every customer’s data is isolated by organization ID inside partitioned infrastructure. A stolen credential reaches one org, within one user’s permissions, not everything.
Multi-factor authentication
Required on every direct login since 2022.
Hover for detail
Multi-factor authentication
Plus IP restrictions, login hours, and connected-app policies with token expiry and rotation.
Transaction security
Block a bulk export while it is happening.
Hover for detail
Transaction security
Real-time transaction security policies, and event monitoring across more than 80 event types.
A 24-hour security team
People watching the platform around the clock.
Hover for detail
A 24-hour security team
Annual third-party penetration testing, and a bug bounty program that has paid researchers more than $18 million.
Certifications for your auditor
The paperwork that ends procurement reviews.
Hover for detail
Certifications for your auditor
SOC 2, ISO 27001, ISO 42001 for AI, FedRAMP High, HIPAA and PCI.
Now the other side of the ledger. IBM puts the average cost of a data breach in the United States at $10.2 million. A mid-size company building its own security operations center spends $1.8 to $3.5 million a year before it earns a single certification. And the code itself is the weak point: Veracode tested more than 100 AI models across 80 coding tasks in 2025 and found security flaws in 45 percent of what they produced, a number that had not improved by spring 2026. Ten percent of apps on one popular vibe-coding platform exposed their databases to the public internet. A coding agent deleted a company’s production database during a code freeze last July, then reported that rollback was impossible.
AI-written code is cheap to write. It is not cheap to own. And the one property that matters most for enterprise AI, an agent that cannot exceed the permissions of the person it works for, is built into Salesforce and almost impossible to retrofit into something you wrote yourself.
The switching cost is the part nobody budgets for
Say you get past security and the build actually works. You are still not done, because now you have to move. Every process, integration, report, document and historical record has to migrate, and then every person has to be retrained.
- Data migrations overrun or fail more than 80 percent of the time in industry studies.
- Lidl walked away from a seven-year, roughly 500 million euro SAP program and went back to its legacy system.
- Birmingham City Council budgeted 19 million pounds for an Oracle replacement. It is now projected at 216 million pounds, and the council is re-implementing out of the box after customizations broke bank reconciliation.
Those were experienced vendors on proven software. A homegrown replacement has neither advantage. Add the permanent payroll: engineers, a site reliability function, a security engineer and a database administrator run past $1 million a year fully loaded, before cloud, backups, disaster recovery or compliance audits. Salesforce spent $6 billion on R&D last year and ships three releases a year. Every new privacy law and AI regulation is a release note for a Salesforce customer and a backlog item for your team.
Think about the whole enterprise, not one application
Here is the deeper mistake in the “replace Salesforce” framing. It treats one application as the problem. But the average company now runs 305 SaaS applications, and your customer’s story is spread across all of them. The opportunity lives in CRM. The order and invoice live in ERP. The payment lives in accounting. The ticket lives in service. The contract lives in a document store. The exceptions live in a homegrown database nobody wants to touch.
A single agent workflow such as quote-to-cash crosses four or five of those systems before it produces value. The value of agents is in the seams, in the swivel-chair work where a person today copies a value from one screen into another. So the right unit of analysis is not “which app do we rebuild.” It is “how do we put AI across every system of record we own,” reaching each one through governed connections, inheriting each one’s permissions, and leaving the data where it lives. That is exactly the pattern the Model Context Protocol made standard, and it is why Salesforce, SAP, ServiceNow, Microsoft, Snowflake, Databricks, Intuit and Stripe all ship official MCP servers today.
The innovation is on top of your systems, not underneath them
This is the part we most want you to hear, because it is where we spend our days. There is an enormous amount of genuinely new work to do in enterprise AI right now. None of it is rebuilding a CRM.
Agentic workflows
A process carried end to end, with no re-keying.
Hover for detail
Agentic workflows
One workflow runs across CRM, ERP and finance without a human copying a value from one screen into another.
Agent harnesses
The right tools, context and guardrails. Nothing more.
Hover for detail
Agent harnesses
Each agent gets exactly what one job requires, which is what keeps it accurate and keeps it in bounds.
Agent teams
A planner, specialists and a reviewer.
Hover for detail
Agent teams
Multi-agent orchestration splits work the way a good human team does, so no single model has to be good at everything.
Multi-team collaboration
Sales, service and finance agents handing off.
Hover for detail
Multi-team collaboration
Agents pass work between them with shared context and clean audit trails, so the handoff is visible and reviewable.
Cost optimization
Cheap models for easy work, frontier models for hard work.
Hover for detail
Cost optimization
Route by difficulty across models and measure cost per outcome instead of cost per token.
Evaluation and governance
Know when an agent is right, and who approved it.
Hover for detail
Evaluation and governance
Catch drift before it reaches a customer, and keep an audit trail an auditor will accept.
Every one of those is hard, high-value and new. Every one of them assumes the system of record underneath is stable, governed and trustworthy. Rebuilding that foundation does not create value. It delays the work that does.
We see this directly in demand. Requests for our certified OpenAI and Claude consultants have been exploding this year, and not one of those engagements is to rebuild an existing system. Every one is to incorporate AI into the enterprise as it stands today, into the processes that already run the business, to drive measurable ROI. The market has already voted on where the value is.
Where to start
Inventory your systems of record and decide their fate with a map, not a mood. Commodity functions such as CRM, ERP, HR and accounting should be bought and made agent-ready. Retire a homegrown system only when it is commodity, cannot be wrapped with an API or MCP server, and costs more to keep than to replace.
Pick one cross-system workflow with a number attached. Quote-to-cash, case-to-renewal, order-to-invoice. Measure days sales outstanding, time to quote or resolution rate before and after.
Treat integration identity as the new perimeter. Least-privilege integration users, connected-app review, token rotation, event monitoring. Every major Salesforce-related incident in 2025 came through third-party OAuth tokens, not the platform. Agents make this the central security question.
Invest in the record. Data quality, required fields, deduplication, documented business rules. Forrester says it best: if data is messy, AI will scale the mess. Every hour here compounds because agents will use all of it.
Use vibe coding where it belongs. Prototypes, internal utilities, analysis, glue between governed systems. Not the store of record, and never the permission model.
We build on top of what you already run
Cirrius Solutions has spent seventeen years on the Salesforce platform and the last two building agentic systems on top of it with Claude, Agentforce and OpenAI. We do not rebuild proven software. We make it agent-ready and then build the workflows, harnesses and agent teams that turn it into enterprise value.
If your team is debating whether to replace Salesforce with AI, let’s have that conversation before anyone writes a line of code. Talk to us, and ask for the full white paper this post is drawn from.

