CONTROL, WITH CONTEXT

Head in the cloud.
Hands on the controls.

Headful Cloud connects the orgs you choose and keeps access tied to your account, the Salesforce user, and each agent's consent.

Your account and your orgs

Sign-in links and codes expire, are single-use, and stay bound to the browser that requested them. Browser sessions protect Setup. Salesforce connections and agent grants belong to an individual owner; an org identifier or public URL is never a credential.

Credentials stay behind the service

Salesforce client credentials and access/refresh tokens are encrypted at rest with context-bound AES-GCM envelopes. The encryption key is held separately as a Cloudflare secret. Secrets are not returned in application listings, included in the downloadable plugin, or requested by our chat skills.

Agents get the access you select

Each MCP connection uses OAuth with PKCE and explicit org selection. Read and proposal scopes are separate from user creation, user access assignments, and permission-set definition edits. A grant limits available operations; each provider write still requires an exact human review. Newly connected orgs do not automatically appear in an existing agent grant. Revoke a grant in Setup when its work is finished.

A review before a write

User creation and permission changes show exact inputs or before/after values in an authenticated App or Setup. Your explicit Create or Apply action binds approval to the target, revision, digest, expiry, and current Salesforce state. The service records completion after a provider response and authoritative readback. It does not treat plugin installation or an agent prompt as approval.

If the org changed since preparation, the review becomes stale. If a write outcome is uncertain, it cannot be blindly retried. Use the retained workflow for supported reconciliation or inspect Salesforce directly. If user creation succeeds and access setup later fails, the created user and successful assignments remain. Leads stay read-only.

Salesforce remains the authority

The connected user's Salesforce permissions and application policy govern every request. Headful Cloud does not grant access your Salesforce user lacks. Start with an owned sandbox and a custom permission set before using consequential changes in production.

Beta evidence

Headful Cloud is independent of Salesforce and OpenAI. We do not claim Salesforce certification, AppExchange publication, a compliance certification, or native ChatGPT acceptance from controlled tests. Public plugin directory approval and signed-in provider/host checks are separate work.

Report an issue

Contact reachjalil@gmail.com with the affected route and non-secret reproduction details. Keep credentials, sign-in links, and customer records out of the report.

Read our privacy notice · Connect an org