Bolt.new Buys Dokai and Aims Its App Builder at Your CRM

Bolt.new's first acquisition brings Dokai's autonomous CRM agents into an app builder whose enterprise customers often build before they sign. Set write scopes and approval gates before the late-fall release.

By Rajesh Beri·September 30, 2026·8 min read
Share:
A laptop on an office desk showing a half-built web app next to a printed Salesforce account record with several fields circled in red pen, a sticky note and a key on a lanyard lying beside it.

Illustration generated using AI

Bolt.new's purchase of Dokai means the apps your business teams generate in a chat box are about to get agents that act inside your CRM. The moment to decide what those apps may write is before the feature ships in late fall, not after. StackBlitz's app builder announced its first acquisition on September 29, 2026: Dokai, a San Francisco startup whose orchestration layer let agents "plan and complete multi-step work inside enterprise systems without a person in the loop." Terms were not disclosed. The announcement says nothing about Dokai's own product or customers.

If your company already has Bolt seats, this is a governance story, not a vendor-news story. The builder that let a marketing analyst ship an internal app in an afternoon is being fitted with the machinery to have that app enrich accounts, tier prospects and update records on its own.

What Did Bolt.new Actually Buy?

Bolt.new bought an agent orchestration layer and the team that ran it in production; the announcement says the technology will be folded into Bolt's platform. Dokai's agents, per Bolt's announcement, handled prospect research, account tiering, CRM enrichment and multi-step workflows inside enterprise systems. Co-founder Gerry Fernando Patia and the Dokai team join Bolt's AI and machine learning organization; the company was backed by Character Capital and ERA, according to Pulse 2.0.

The stated use is twofold. Inside Bolt, the Dokai foundation "will strengthen how the platform's agents handle complex, longer-running builds and how the applications customers create connect to the enterprise systems they already run, from CRMs to internal data sources," the release syndicated via Yahoo Finance says. The first capabilities are promised for "late fall."

CEO Eric Simons framed the deal around reliability: "Enterprise buyers don't care whether an agent demos well. They care whether it does the work every day, inside the systems they already run." That is the right sentence. It is also the sentence that should make your security lead ask which systems, with whose credentials, and who approves the write.

Why the Timing Hits Enterprise Buyers Hardest

The exposure is sharpest because Bolt's enterprise adoption runs ahead of its contracts. By the company's own figure, roughly half of Bolt.new's enterprise customers begin building before contracts are signed, and the average first app deploys within 34 days. That is a vendor claim offered as a growth signal. Read it as a governance signal: in half of those accounts, apps exist before anyone negotiated what they may touch.

The installed base is not small. Bolt reached an estimated $40M ARR by March 2025 and more than 7 million users by December 2025, per Sacra's research, which also reports a claim that 75% of the Fortune 500 use the platform — a figure worth treating as a usage footprint, not a count of governed deployments. Bolt's enterprise page lists Salesforce, HubSpot, Meta, Shopify and Intel among its customers.

The enterprise tier already has the right primitives: SSO via Okta, Azure AD and SAML providers, SOC 2 Type 2, bring-your-own-key deployment to AWS or Azure, and "granular admin controls for provisioning, seats, and domain restrictions," per the enterprise page. The pricing page lists audit logs and data governance policies only on Enterprise. None of that page describes per-app scopes for what a generated application's agent may write into a downstream system — because until now it did not need to.


What Happened the Last Time a Sales Agent Held CRM Tokens?

The last time a sales-automation agent held standing OAuth access to Salesforce at scale, it became the breach vector. Between August 8 and 18, 2025, a threat actor Google tracks as UNC6395 used compromised OAuth tokens from the Salesloft Drift integration to export Cases, Accounts, Users and Opportunities from numerous corporate Salesforce instances, then mined the data for AWS keys, Snowflake tokens and passwords. Google's hardening advice was blunt: restrict connected-app scopes to the minimum, enforce IP restrictions, and remove "API Enabled" from general profiles.

Drift was a sales tool. Dokai was a sales tool. The difference is that Dokai's capability is now headed into a builder where anyone with a seat can create the next integration. We covered the same pattern in the Klue OAuth attack that reached 195 companies and in SalesBleed's Agentforce prompt injection: the agent is rarely the weak point; the standing grant behind it is.

Salesforce has since moved the default. Starting in early September 2025, the platform blocks new users from uninstalled connected apps, and a new "Approve Uninstalled Connected Apps" permission "should only be assigned to highly trusted users." That helps — but only if the Bolt-generated app is forced through an installed, scoped connected app rather than a user's personal authorization.

Where Is the Risk in a Citizen-Built Agent?

The risk is what OWASP calls excessive agency. OWASP's LLM06:2025 defines it as damaging actions triggered by unexpected or manipulated model output, and names three causes: excessive functionality, excessive permissions and excessive autonomy. A Dokai-powered Bolt app can hit all three at once — a builder who asks for "update the account" gets a tool that can update any field, running as the builder's own user, with no human reviewing the write.

Steel-man Bolt's side: the whole value is that agents do work "without a person in the loop," and an approval step on every CRM write kills the productivity case. That is true for enrichment of low-risk fields. It is not true for owner changes, stage changes, pricing fields or bulk updates. The answer is not a blanket gate — it is a split between reversible, low-value writes that run freely and consequential writes that queue for a person, which OWASP recommends explicitly.

Salesforce gives you the enforcement point for free. Its Integration User license, introduced in March 2023, is API-only, and Performance, Enterprise and Unlimited editions include five free licenses, per Gearset's breakdown, with "one user per integration" as the recommended practice. Pair each Bolt-built app with its own integration user and a permission set naming only the objects and fields it needs. Enforcement then lives in the CRM, not in the model's judgement — which is where standing privilege stops being the whole problem.

What Dokai's Customers Were Not Told

Dokai's existing customers got no continuity statement. The announcement describes the team joining Bolt and the technology being folded into the platform; it names no sunset date, no export path and no support commitment for the standalone product. That is the acqui-hire pattern we have tracked in Meta's Stilla deal and Adobe's Rilo acqui-hire, whose Slack token never expired: the people move, the product stalls, and the OAuth grants sit live in customer tenants.

If you ran Dokai agents against your CRM, those grants are the first thing to find. An agent vendor whose engineers now work elsewhere is precisely the unattended token Google warned about. It is the same continuity question ZoomInfo's DoubleO.ai purchase left open for another GTM agent layer.

What to Do Before the Late-Fall Release

This Week:

  1. Inventory Bolt tenants and apps. Ask procurement for every Bolt contract, and IT for every workspace on a corporate domain. Given half of enterprise customers build pre-contract, assume there are apps no one registered.
  2. If you used Dokai, revoke its grants. Pull the Connected Apps OAuth Usage list in Salesforce (and the equivalent in HubSpot or Google Workspace), find Dokai, and revoke. Export any records you depend on first.
  3. Check who holds "Approve Uninstalled Connected Apps" and "Use Any API Client." Both bypass Salesforce's new default. Restrict them to administrators.

This Month:

  1. Write the CRM write policy for generated apps. One integration user per app, API-only, a named permission set, IP restrictions — Google's post-Drift list, applied before the first Dokai-powered feature exists.
  2. Classify fields into free-write and approval-required. Enrichment fields run freely; ownership, stage, amount and bulk operations queue for a person. Put the list in front of your RevOps lead and get a sign-off.
  3. Ask Bolt in writing what scopes the late-fall features request, whether agents act as the builder or as a service identity, whether every agent write lands in the Enterprise audit log, and whether admins can disable the capability per workspace.

Before Renewal:

  1. Put it in the contract. An admin-controlled off switch for autonomous agent actions, audit-log export for every write to a third-party system, and notice before new integration scopes are enabled. If you are on Teams rather than Enterprise, note that audit logs and governance policies are Enterprise-only per Bolt's pricing — that alone may justify the upgrade conversation.

The Bottom Line

Low-code went through this a decade ago: citizen developers built fast, and IT spent the next five years discovering what the apps could reach. The 44% visibility gap on business-built agents says the pattern already repeated once for agents. Bolt buying Dokai is the point where an app builder gets hands inside the system of record.

Simons is right that buyers care whether an agent does the work every day. The better question is whose name is on the write. Answer it before late fall does it for you.

Continue Reading

Share:

Frequently Asked Questions

What did Bolt.new buy when it acquired Dokai?

Bolt.new, StackBlitz's natural-language app builder, acquired Dokai's agent orchestration technology and team on September 29, 2026. Dokai built autonomous agents for sales workflows such as prospect research, account tiering and CRM enrichment. Terms were not disclosed and the team joins Bolt's AI and machine learning organization.

When will Dokai features appear in Bolt.new?

Bolt.new says the first capabilities built on Dokai's technology are expected in late fall 2026. They are meant to help Bolt's agents run longer builds and connect customer-built apps to enterprise systems such as CRMs and internal data sources.

What happens to existing Dokai customers?

The acquisition announcement makes no statement about Dokai's standalone product, customer support, an export path or a sunset date. Customers who connected Dokai agents to Salesforce, HubSpot or Google Workspace should find and revoke those OAuth grants after exporting any data they depend on.

How should enterprises limit what Bolt-built apps can write into Salesforce?

Give each generated app its own API-only Salesforce Integration User with a permission set naming only the objects and fields it needs, apply IP restrictions, restrict the Approve Uninstalled Connected Apps and Use Any API Client permissions to admins, and require human approval for consequential writes such as owner, stage or bulk changes.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Latest Articles

View All →