Salesforce Solution Architect  /  AI Agent Engineer

I design the systems a business actually runs on.

Fifteen years of business process compressed into one platform. An AI agent that answers a prospect at two in the morning and books the meeting itself. A briefing an adviser can trust before they walk into a client conversation. More than thirty projects delivered, four of them opened up here, across Salesforce core, Field Service, Agentforce and custom integration.

30+Projects
delivered
20Salesforce
certifications held
9Clouds and services
shipped in production
4Recent builds
opened up below
01

Selected work

A shortlist of four recent builds from more than thirty projects, chosen because each turned on a decision worth explaining. Client names are withheld where the engagement was covered by an agreement.

The challenge

  • An empty sales CRM. Spreadsheets and hand-built quotes. No pipeline model, no product catalogue, no quoting engine, no forecast.
  • Marketing cut off from sales. A connector broken in both directions, no verified DKIM, no tracking code, newsletters leaving from a separate tool.
  • No service model at all. Support arriving by phone, email and WhatsApp with no case model, no routing, no SLAs, and no way to tell whether the customer complaining held an active warranty.
  • A blind CRM. Agents could not see what hardware a customer had, whether it was online, whether it had faulted, or where they stood on payments.

What I delivered

  • Phase 1. A connected revenue lifecycle, a custom quoting and invoicing engine with a solar-specific payment split, and a full rebuild of the marketing automation stack.
  • Phase 2. Four case record types, a fault taxonomy mapped to real inverter and battery fault codes, five intake channels and warranty-gated SLAs.
  • Phase 3. Work orders and work plans, contractor resources on restricted access, fleet-scale preventive maintenance and full mobile field execution.
  • Phase 4. Nine platform entities mapped across five sync scenarios, with webhook orchestration, external ID reconciliation and failure alerting.

In a fleet business the cost of a silent integration failure is not a bad record. It is an agent confidently telling a customer their system is fine while it is offline.

Why the integration was built reconciled, not fire and forget
~95%UAT first-pass rate
2,650Numbered test steps
19Discovery sessions
50+Reports and dashboards
9 / 5Entities mapped, sync scenarios

Four faults, four layers

  • Empty summaries. The assistant was told to describe portfolios, opportunities and cases but was never handed that data. Six of nine sections had nothing behind them.
  • It asked which client. The record the adviser had open was available to the agent and never passed into its instructions.
  • Vanishing notes. Notes attach through a link matched on two fields at once. New automation populated only one, so the note saved without error and was invisible to every query.
  • One note only. The retrieval step was set to return the first matching record and stop, so every summary was written from a single note.

How it was fixed

  • Grounding rebuilt. Every data reference moved into a labelled block, live sources added for contacts, opportunities, cases and two portfolio relationships, with an explicit instruction to omit empty sections rather than invent.
  • Root cause, not symptom. A line-by-line comparison proved the context defect was structural, not environmental. Context injection moved to the top level so every topic inherits the open record.
  • Retrieval rebuilt. A sorted collection loop bounded to a limit measured against the busiest account in the org.
  • Delivered safely. Dry-run validated, applied to a single component on an inactive version, re-read from the org and diffed. Activation stayed with the client throughout.

A convincing but invented account balance in a pre-meeting briefing is worse than no briefing at all.

Why silence is designed to be honest
3 of 9 → 9 of 9Briefing sections carrying real data
1 → 17 of 17Notes reaching the briefing
2 of 10,072Malformed records found in audit
ZeroUnplanned production impact

The architecture

  • One planner, six sub-agents. Initial Outreach, Follow-up, Product Q&A, Meeting Response, Manage Opt-Out and Generic Response, each with its own scope boundary and action allow-list.
  • Six grounded actions. Three read, two write and one retrieval-augmented, so product claims come from the client's knowledge base and never from model memory.
  • Thirty instruction blocks written against the client's own positioning, distributed across the topics that need them.
  • Seven conversation variables carrying state across turns, plus channel context mapped across seven messaging surfaces.

The restraint that makes it work

  • Containment by structure. The sub-agent writing a nudge physically cannot reach the action that opts a prospect out. It is not in that topic's allow-list.
  • Compliance as code. Opt-out is a deterministic Flow with inputs forced to context variables, never an identifier inferred from email text.
  • Scarcity that is real. One boolean gates both the sign-off tone and the release of the calendar link, so the final message means something.
  • Silent write-back. Blank fields discovered, extracted from the prospect's own prose, type converted and written, and never mentioned in the reply.

Agents are an architecture problem before they are a prompt problem. Containment is structural and prompting is not.

Why six narrow topics beat one capable prompt
67Leads worked with no human in the thread
81Emails written by the agent
11.9%Reply rate on cold outreach
98.5%Delivery, one hard bounce
186Cadence steps executed

Four layers, one responsibility each

  • Salesforce owns the conversation. Routing and consent must both sit with Salesforce for BYOC, so Omni-Channel decides when the agent is on a thread and every temptation to put routing in the connector was refused.
  • The connector is transport. Inbound webhook adapter, durable Pub/Sub subscriber, per-extension credential resolution, burst coalescing, reply delay queue, opt-out enforcement and two-way idempotency.
  • Per-record enablement. Nothing is automated until a rep opts a specific prospect in from a component on the record page. Unassign is one click.
  • Rep takeover. If a rep texts the prospect directly, the connector detects it, stands the agent down and cancels the cadence, so human and AI are never live on one thread.

Problems worth reading

  • A stream that failed silently. The gRPC subscription stopped delivering events while reporting itself healthy. No exception, no disconnect, no log line. Fixed with keepalive plus a stall watchdog.
  • Linking on the wrong field. MessagingEndUser links on MessagingPlatformKey, not Name. Undocumented, and the kind of detail that costs a full sandbox cycle if guessed.
  • Fragmented replies. Real people text in bursts. A debounce window coalesces a burst into one interaction so the agent answers the whole thought.
  • A compliance gate, raised early. Automated sending on standard business lines needs the vendor's written position. Surfaced as a gate in the design rather than discovered at go-live.

Silent failure in a streaming subscriber is a design assumption, not an edge case. Every long-lived stream in the service now has liveness monitoring.

What the hardest defect in the build taught
80+Build register findings logged
17 / 17Test scenarios sandbox verified
20Rep lines supported by design
5Documentation artefacts delivered
02

Capabilities

Everything listed here was shipped on a real engagement, not studied for a certification.

Salesforce Platform

  • Sales Cloud and Service Cloud
  • Field Service Lightning
  • Financial Services Cloud
  • Marketing Cloud Account Engagement
  • Enhanced Omni-Channel and BYOC
  • Entitlements, milestones and SLAs

Agentforce and AI

  • Employee and Service Agent design
  • Topics, actions and allow-lists
  • Prompt Builder and grounding
  • Anti-hallucination instruction design
  • Runtime context variables
  • Agent versioning and safe activation

Build and Integration

  • Apex, triggers and invocable actions
  • Lightning Web Components
  • Flow across every trigger type
  • REST, webhooks and Platform Events
  • Change Data Capture and Pub/Sub
  • Python, FastAPI and gRPC services

Delivery Craft

  • UPN process mapping and ERDs
  • Solution design and build runbooks
  • Living build registers
  • Test matrices and role-scoped UAT
  • Data migration and external ID strategy
  • Admin and end-user enablement
03

Certifications

Twenty active Salesforce credentials, spanning the architect track, the developer track and the consulting range. All verifiable.

Holds both Application Architect and System Architect, the two credentials that sit above the seven designer certifications beneath them.

The full architect track, earned end to end

Architect

7 credentials
  • Application Architect
  • System Architect
  • Integration Architect
  • Identity and Access Management Architect
  • Sharing and Visibility Architect
  • Data Architect
  • Development Lifecycle and Deployment Architect

Platform and Development

5 credentials
  • Platform Developer II
  • Platform Developer I
  • Platform App Builder
  • Platform Administrator
  • Platform Foundations

AI and Agentforce

2 credentials
  • Agentforce Specialist
  • AI Associate

Consulting and Analytics

6 credentials
  • Data 360 Consultant
  • Agentforce Service Consultant
  • Agentforce Sales Consultant
  • Agentforce Field Service and Operations Consultant
  • Tableau Consultant
  • CPQ Administrator

Every credential above is active and independently verifiable on my Trailblazer profile.

Verify on Trailhead
04

How I work

Four rules that survived contact with production orgs, live prospects and regulated advice.

Evidence over assumption

Object provenance, field population rates and record counts are queried before a change is designed. Nothing is assumed from a configuration screen, and no fix is reported as working because the setup looks correct.

Honest failure over plausible fiction

Where the platform cannot supply data, the system says so. An absent section means no such records exist. In financial services a plausible invented figure is a liability, not a feature.

Safe delivery by construction

Production changes are validated offline, applied narrowly, verified afterwards and never activated without the client's decision. When I introduced a fault, my own process caught it before any user did.

Diagnosis is the job

Four faults across four layers can look like one broken feature. Separating them and proving each one independently is usually most of the work, and it is the part that stops the problem returning.

05

Happy to walk through any of it, including the parts that went wrong.

Architecture diagrams, process maps, configuration documentation and recorded system demonstrations are available on request. References on request.