
Hi, I'm Mustafa.
I build AI agents that take real action — then I prove they're safe.
Salesforce developer and ISV Partner. I build Agentforce agents that don't guess — they ground their answers in Data 360, act through custom Apex, and run under the Einstein Trust Layer. And because an agent that acts has to be trusted, I build the proof as well: the corpus that attacks it, the verifier it can't sweet-talk, and the analyzer that reads what its code can really reach. All of it on real revenue systems — CPQ, contracts, billing, SAP — because an agent is only as good as the org underneath it.
Build
Agents that take real action
A live, deployed Agentforce agent explains a customer's bill grounded in Data 360 — then logs the support Case itself. Custom Apex exposed to Claude as MCP tools. An agent loop that builds an entire Salesforce org, verified by its own tests. An Einstein-powered product in AppExchange Security Review.
See the live agentProve
Agents you can actually trust
A pre-install scan that scores whether the customer's data can carry an agent — before a single build hour. A pre-registered German red-team corpus with a deterministic verifier the LLM never controls. A static analyzer that caught a GDPR-labelled field escaping past the running user's permissions — with a live org, not me, as the judge. A runtime watchdog that correlates a live agent's quality drops with the org's change stream, graded by evidence. And an EU AI Act Article 26 evidence pack that turns an agent's traces into an audit-ready case file. The Agent Development Lifecycle, closed end to end.
See the test bench
Projects
All ten case studies →Ten Salesforce builds, ordered as a story.
- 2026ARI · Zero-credit scanIn development
PreFlight — the pre-installation evidence scan for Agentforce
Before anyone builds an Agentforce agent on a customer org, PreFlight scans 12–24 months of real closed cases — LLM-free, zero credits, read-only — and scores whether the history is good enough to prove an agent would succeed: a six-component Agent Readiness Index plus a board-ready German evidence report in which every number is tagged Measured, Observed, Derived or Projected.
Apex (with sharing) + Queueable orchestrationAgent Readiness Index — 6 components, frozen weights 25/20/15/15/15/10View project - 2026Live agent
HanseWatt — Agentforce & Einstein AI service for DACH energy
A live, deployed Agentforce agent that explains a customer's bill grounded in Data 360 — then logs the support Case itself.
Service CloudAgentforce (ReAct planner)View project - 2026Live-tested
Agent Blast Radius — the data an Agentforce agent can really reach
A static analyzer that computes what an agent's code can really reach — and, on an Agent Script agent, traces a GDPR field from the database column into the model's prompt, at a line number.
Agentforce (authority analysis)Agent Script (.agent) — Salesforce's own parserView project - 2026Live-tested
Prüfstand — the test bench that proves an Agentforce agent is safe
I built the agent, then built the thing that tries to break it: a German red-team corpus and a verifier the model can't sweet-talk.
Agentforce (evals & red-teaming)Agent Script (.agent) + tree-sitter ASTView project - 2026Root cause · κ-gateIn development
Nabz — the runtime root-cause layer for live agents
An in-org, zero-egress root-cause watchdog for live Agentforce agents: Nabz (Turkish for 'pulse') correlates a deterministic conversation-quality time series with the org's change stream and names the strongest candidate cause with an evidence grade A–E — never a bare 'root cause' — proposing fixes a human must approve.
Apex + 6 Lightning Web ComponentsEWMA control band + changepoint detection — deterministic, no MLView project - 2026AI Act · Art. 26
Aktenlage — the EU AI Act Article 26 evidence layer
The legal output layer of Agent Blast Radius: a pure-Python tool that turns an agent's operational traces into an EU AI Act Article 26 evidence pack — judging every obligation on two axes, is it documented and does the trace show it actually ran.
EU AI Act — Article 26 (deployer obligations)Pure Python — zero LLM, zero network, zero creditsView project - 2024
Urla Shoes — AI document-compliance engine + multi-feature Salesforce platform
Einstein classifies partner documents into structured JSON — and two Apex actions are exposed to Claude as MCP tools.
Apex (Queueable, Schedulable)Lightning Web ComponentsView project - 2026
Hospital Org — a Salesforce org built by an AI agent loop I designed
A complete Salesforce org built by an agent loop I designed — six MCP tools, with the test runner as the verifier, not the model.
Model Context Protocol (Salesforce-hosted)Loop engineeringView project - 2026In Security Review
Configra — AI deal & configuration builder for Revenue Cloud
My own AI product, in AppExchange Security Review: describe a deal in one sentence and it builds the quote — without polluting the catalog.
Revenue Lifecycle ManagementEinstein Models API (GPT-4o mini)View project - 2025
TechnoStore — Revenue Cloud Quote-to-Cash for the DACH market
The Quote-to-Cash foundation the agents run on — ten external systems orchestrated with MuleSoft, incl. SAP, lexoffice and DATEV.
ApexRevenue Lifecycle ManagementView project