Projects

What I build with all this.

This site is where I explain Salesforce. This page is what I build with it. These are ten real projects — six of them closing the Agent Development Lifecycle end to end (prove the data before building, build a live agent, bound what its code can reach, attack it, watch its live pulse, file the AI Act evidence), plus an agent-built org, AI over documents, my own AppExchange product, and the Quote-to-Cash depth underneath — each one shipped, tested, and honestly framed.

The full case studies — with screenshots, the live output, and the honest limitations — live on my portfolio. The code is private; a walkthrough is available on request.

See the full case studies on mustafaaksu.dev →

PreFlight

Measured In development

Pre-install evidence · ARI

Before anyone builds an agent, PreFlight scans 12–24 months of the customer’s real closed cases — LLM-free, zero credits, read-only — and scores whether the history can carry an agent at all: a six-component Agent Readiness Index plus a board-ready German evidence report where every number is tagged Measured, Observed, Derived or Projected. 79/79 tests green, 93% coverage.

Read the full case study →

HanseWatt

Live agent

Agentforce · Data 360

A live, deployed Agentforce agent for a German energy utility. It identifies the customer, explains a consumption anomaly grounded in Data 360, and logs the support Case itself — grounded, not guessing, and taking real action under the Einstein Trust Layer.

Read the full case study →

Prüfstand

Live-tested

Agent safety · Red-team

I built the agent — then built the thing that tries to break it. A pre-registered German attack corpus (committed first, so git is the notary) drives a live red-team run, and a deterministic verifier decides pass or fail — the model never grades itself. It found a real weakness in my own agent, and reported it honestly.

Read the full case study →

Agent Blast Radius

Live-tested

Static analysis · GDPR

A static analyzer that computes what an agent’s code can really reach — not what it’s allowed to, but what its Apex actually resolves to at runtime. It caught a GDPR-labelled field escaping past the running user’s permissions into the model, at zero credits. And the judge isn’t me: a runtime oracle deploys each case into a real org and checks the analyzer’s own prediction.

Read the full case study →

Nabz

Live-org tested In development

Runtime root cause · Observability

Salesforce Observability tells you WHAT happened — Nabz (Turkish for “pulse”) tells you WHY. It correlates a live agent’s quality drops with the org’s change stream — including agent edits nobody filed a ticket for — and names the strongest candidate cause with an evidence grade A–E, never a bare “root cause”. Fixes are proposed, never applied. 126/126 tests green on the live pilot org.

Read the full case study →

Aktenlage

AI Act evidence

EU AI Act · Article 26

The legal output layer of Agent Blast Radius: it turns an agent’s operational traces into an EU AI Act Article 26 evidence pack, judging every obligation on two axes — is it documented, and does the trace show it actually ran. Zero LLM, zero network, and it ships with two deliberate gaps, because an audit report where everything is green is marketing, not evidence.

Read the full case study →

Urla Shoes

Einstein AI · MCP

An AI document-classification engine (an Einstein Prompt Template that reads each partner document into structured JSON and closes the matching compliance request), plus two Agentforce actions also exposed to Claude as MCP tools — so one plain-language request can qualify a lead or spin up a full deal.

Read the full case study →

Hospital Org

Agentic delivery · MCP

A complete Salesforce org built by an agent loop I designed — seven objects, triggers and tests — over six custom MCP deployment tools. The verifier is the test runner, not the model: deploy → test → read the real failures → fix → repeat until green. The judgment lives in the loop design.

Read the full case study →

Configra

In Security Review

Revenue Cloud · ISV

My own Salesforce ISV product — a Revenue Lifecycle Management managed package on the AppExchange, currently in Security Review. Reps describe a deal in one sentence and built-in Einstein AI builds the quote, without polluting the catalog. Engineered for the review: PMD-clean, FLS/CRUD enforced, prompt-injection hardened.

Read the full case study →

TechnoStore

Quote-to-Cash · MuleSoft

End-to-end Quote-to-Cash for a B2B supplier targeting DACH (RLM + CLM + Industries CPQ), integrated with ten external systems via MuleSoft — SAP S/4HANA, Stripe, DocuSign, and the German finance stack (lexoffice, DATEV, CAMT.053) — with idempotency and signed-webhook verification. The revenue depth an agent runs on.

Read the full case study →

Let’s talk

Building serious Agentforce? I’d love to help.

I’m open to Salesforce Developer / Forward Deployed Engineer roles in the EU and DACH region — relocation-ready, targeting Cologne / NRW. If you’re building trustworthy AI on Salesforce, or just want to compare notes, reach out.