# Salesforce

![Salesforce_logo.png|400](https://assets.relyanceuat.xyz/images/docs/34547031546381/34547058666893_white.png)

Salesforce is a cloud-based software company that provides customer relationship management (CRM) services. It provides CRM software and applications focused on sales, customer service, marketing automation, analytics, and application development.

The Salesforce integration property scan examines both standard and custom objects. If the scope is to only scan the data, the Standard API integration Profile can be used. Read only permissions across other objects can be provided via permission sets or any other existing read-only Salesforce profile.

If the DSR functionality is being used, Modify/Delete permissions would need to be provided to this integration user for the objects from which deletion/updates will occur

#### **Choose an authentication method**

Relyance supports five, and the difference that matters is whether the connection
holds a **refresh token** or authenticates server-to-server:

| Method | Authorises as | Needs re-authorising? |
| --- | --- | --- |
| **OAuth Client Credentials** (recommended) | a Connected App, server to server | No — no user, no refresh token |
| **Oauth2 / App Token** | the user who clicked Authorize | Yes, when the refresh token is invalidated |
| **Customer OAuth** | the user who clicked Authorize, on your own Connected App | Yes |
| **Sandbox Oauth2** / **Customer OAuth Sandbox** | as above, against `test.salesforce.com` | Yes |

**Use OAuth Client Credentials unless you cannot.** The user-authorised methods
depend on a refresh token that Salesforce invalidates when the authorising user's
password changes, when their session policy expires it, when an admin revokes the
app's access, or when that person leaves — none of which is a change to the
Relyance side, and all of which present as a connection that worked for weeks and
then stopped. It also ties the data Relyance can see to one person's permissions.

Every method takes **Maximum Number of Records** (required; defaults to 5000) and
an optional **SObject Configuration** naming which objects are treated as
contracts.

Steps for the two most common:

- [OAuth Client Credentials - Two Leg Oauth 2 (Recommended)](#h_01KYJJPAJWY0ZZ03KVH0HZKNQV)
- [OAuth2 / App Token](#h_01KYJJN5KCXB6880YQ6P4H6M24)

#### OAuth Client Credentials - Two Leg Oauth 2 (Recommended)

In order to integrate Relyance AI with Salesforce using the **OAuth Client Credentials Flow**, you will need:

- An **Integration User** (Run-as user) with **API Enabled permissions**
- **Domain** (from your Salesforce instance)
- **Client ID** (generated in Salesforce)
- **Client Secret** (generated in Salesforce)

The Client Credentials Flow is an OAuth 2.0 mechanism that allows Relyance AI (the client application) to authenticate directly with Salesforce using a **client_id** and **client_secret** instead of a user-based login. This ensures secure, server-to-server communication without requiring interactive user consent.

**In Salesforce**

1. Login to your Salesforce account.
2. Copy your **Salesforce subdomain** from the browser URL (you will need this later).\
![Screenshot](https://assets.relyanceuat.xyz/images/docs/34547031546381/47686509203853.png)
3. **Go to Setup** on the **Search Setup** search for **App Manager.**
4. Under **External Client Apps**, select External Client App, and click **New External Client App**.\
![Screenshot](https://assets.relyanceuat.xyz/images/docs/34547031546381/47686554914189.png)
5. In the **Basic Information** section, provide:
    - **Connected App Name**: e.g., `Relyance Scan`
    - **API Name**: auto-fills
    - **Contact Email**: an email you have access to (a verification code will be sent here in a later step).
6. In the **API (Enable OAuth Settings)** section:
    - Check **Enable OAuth Settings**.
    - **Callback URL**: `https://root.relyance.ai/api/oauth2` (required by the form but unused by the Client Credentials flow).
    - Under **Selected OAuth Scopes**, add:
        - `Manage user data via APIs (api)`
        - `Perform requests at any time (refresh_token, offline_access)`
7. Under **Flow Enablement**, check **Enable Client Credentials Flow**.
8. In the **Security** section:
    - Uncheck **Require Proof Key for Code Exchange (PKCE)**.
    - Leave **Require Secret for Web Server Flow** and **Require Secret for Refresh Token Flow** checked.
9. Click **Save**. Wait 2–10 minutes for the app to propagate before continuing.
10. Edit the app once created by going to the app and on the **Policies** tab, click **Edit**.
11. Under **OAuth Policies**:
    - **Permitted Users**: `Admin approved users are pre-authorized` (recommended).
    - **IP Relaxation**: `Relax IP restrictions` (unless you have allowlisted Relyance's egress IPs).
12. Under **OAuth Flows and External Client App Enhancements** select **Enable Client Credentials Flow**
13. This will open up a **Run As (Username)** input box, enter the ***email address*** of the preconfigured integration user.
14. Two boxes will appear in the App Policies section. In **Profiles**, select the profile assigned to the preconfigured integration user. In **Permission Sets**, select the [permission sets](https://help.salesforce.com/s/articleView?language=en_US&id=platform.perm_sets_overview.htm&type=5) that user requires — exactly what to include is broken down right below.

##### Object permissions

**Summary**

| Grant | Applies to |
| --- | --- |
| **API Enabled** | All scans — Vendor Discovery, Schema Inspection, Data Inspection, Data Subject Requests (baseline requirement) |
| **Read** (+ [field-level security](https://help.salesforce.com/s/articleView?id=platform.users_fields_fls_permsets.htm&language=en_US&type=5)) | Schema Inspection, Data Inspection — every object below that these features scan |
| **View Setup and Configuration** | Vendor Discovery (`Connected Apps`), Schema Inspection (`Tooling`) |
| **Modify** / **Delete** | Data Subject Requests — only objects included in your DSR configuration; everything else stays read-only |

Whichever authentication method you use, this same grant applies — to the **Integration User** here for OAuth Client Credentials, or to the person who clicks Authorize for OAuth2/App Token, Customer OAuth, or the sandbox variants. The **Overview** step of setup (step 7 under each flow) shows every object Relyance may touch for the features you enable, grouped under **Scope and Permission**. Here's what each group maps to in Salesforce:

| Relyance requests | Salesforce object(s) | What to grant |
| --- | --- | --- |
| Core CRM records | `Account`, `AccountBrand`, `AccountContactRelation`, `AccountTag`, `Case`, `Contact`, `Lead`, `User` | **Read** (object permission + field-level security on scanned fields). Add **Modify**/**Delete** on any of these objects included in your DSR configuration. |
| Your org's custom objects | `Custom Objects` | **Read** (object + field-level security), per object you want scanned. Add **Modify**/**Delete** on any object included in your DSR configuration. |
| Data.com / D&B enrichment | `AccountCleanInfo`, `DatacloudAddress`, `DatacloudCompany`, `DatacloudContact`, `DatacloudDandBCompany`, `DatacloudOwnedEntity`, `DatacloudPurchaseUsage` | **Read** — only applies if your org has Data.com Clean or D&B Optimizer enabled; without that license these objects return no data and don't need a grant. Add **Modify**/**Delete** only if these records are included in your DSR configuration. |
| Chatter feed content | `FeedAttachment`, `FeedComment`, `FeedItem`, `FeedPollChoice`, `FeedPollVote`, `FeedRevision` | **Read** — requires Chatter to be enabled on the org. Add **Modify**/**Delete** only if feed content is included in your DSR configuration. |
| Vendor Discovery | `Connected Apps` | **View Setup and Configuration** (or **Manage Connected Apps** for full OAuth policy detail). Not a DSR target. |
| Metadata scanning | `Tooling` | **View Setup and Configuration** (or **Customize Application**, depending on the metadata being queried). Not a DSR target. |
| Querying, record counts, schema | `Query`, `RecordCount`, `SObjects` | No separate grant — covered by **API Enabled** plus the Read access above on whichever objects are being queried. Not a DSR target. |

All of the above sits on top of one baseline requirement: **API Enabled** on the profile, without which no API access works regardless of object permissions.

15. Click **Save**.
16. Click on the **Settings** tab and scroll to the **OAuth Settings** section. Click on the **Consumer Key and Secret** button - this will send a verification code to the apps configured email address.\
![Screenshot](https://assets.relyanceuat.xyz/images/docs/34547031546381/47686554915597.png)

**In Relyance AI**

1. **Login** to your Relyance AI account.
2. Navigate to the **Settings Menu** (bottom left-hand side).
3. Select **Integrations**.
4. Find **Salesforce** in the integration catalog and click **Add Integration**.
5. Provide a **Connection Name**.
6. Go through the wizard and continue with the recommended settings
7. Select **OAuth Client Credentials** as the connection type.\
![Screenshot](https://assets.relyanceuat.xyz/images/docs/34547031546381/47686509208077.png)
8. Enter the **Domain**, **Client ID**, and **Client Secret** obtained from the Salesforce setup above.
9. Click **Authenticate**
10. Once authentication is successful, click **Finish**.
11. **Congratulations!** You are now connected to Salesforce.

#### OAuth2 / App Token

To integrate Salesforce with Relyance AI, you will need to follow an **OAuth2** flow.

##### Permissions

Two different things are being granted here, and it's easy to conflate them:

- **OAuth scope**, on the Connected App: `api` and `refresh_token` (`offline_access`). These are what let Relyance call the Salesforce API at all — they're not specific to any object.
- **Object-level access**, on the user who clicks Authorize: read permission on the objects Relyance scans, granted through that user's Profile and Permission Sets — not through OAuth scope. See [Object permissions](#object-permissions) in the OAuth Client Credentials steps above for exactly which objects map to which grant, including `Connected Apps` (used for Vendor Discovery) and your org's `Custom Objects`.

#### In the Relyance AI application:

1. Login to your Relyance account.
2. Navigate to the **Settings** (bottom-left corner).
3. Select **Integrations**.
4. Search and locate the **Salesforce** integration card and click on it.
5. Click on the **Add Connection** button on the top right
6. Provide a meaningful name for the integration and click on the **Add** button
7. In the **Overview** section, select the integration features you wish to enable for the integration, review the **Scope and Permission**, and **Endpoint** details and click on **Continue**. For more details, see [Integration Features](/docs/introduction-to-relyance-ai/integration-features/).\
![Screenshot](https://assets.relyanceuat.xyz/images/docs/34547031546381/34547031532173.png)
8. In the **Connection** section, provide the appropriate values and click on **Continue**.
    - **Connection Name**: This property allows you to update the integration specified in Step 6. If you have multiple integrations for the same vendor, you may want to assign distinct names to each. This helps streamline filtering by **Discovery Source** across the **Inventory**, **Visual Maps**, **Assets**, and **Data Flow Analysis** pages.
    - **Rescan Frequency**: This property allows you to configure how often Relyance executes scans against this Vendor connection.
    - **Business Atlas Associations** (required): the business entities or products that newly discovered third parties, services and assets from this integration are attributed to. Choose at least one from the **Select Associations** dropdown — the wizard will not advance past this step without one. For more details, see [Business Atlas](/docs/other-settings/business-atlas-overview/).\
    ![Screenshot](https://assets.relyanceuat.xyz/images/docs/34547031546381/34547058669069.png)
9. In the Authentication section, select **Oauth2/App token** and click on **Continue**  Login to Salesforce and follow any prompts to accept the connection.\
![Screenshot](https://assets.relyanceuat.xyz/images/docs/34547031546381/40707719996813.png)
![Salesforce-2.png](https://assets.relyanceuat.xyz/images/docs/34547031546381/34547058671117.png)
10. **If the Data Inspection check box is checked from step 7,** in the Data Inspection section, provide the appropriate values and click on **Continue**
    - **Minimum Confidence Level:** This property adjusts the sensitivity of the Data Inspection feature. Lower likelihoods (e.g., unlikely) offer more coverage but may produce false positives, while higher sensitivity (e.g., very likely) provides greater accuracy but less coverage.\
    ![Screenshot](https://assets.relyanceuat.xyz/images/docs/34547031546381/34547031542029.png)
11. Review the configuration summary from the Completion section and click on **Finish**.\
![Screenshot](https://assets.relyanceuat.xyz/images/docs/34547031546381/34547031542797.png)
12. Confirm the integration Status reflects **Connected**

#### Other

For **Customer OAuth** method of authentication provide the **Client ID and Client secret** and click on **Continue**. Refer to the [documentation](https://support.relyance.ai/hc/en-us/article_attachments/39633972319117) on steps to configure connected apps to retrieve the Client ID and Client Secret.

![Screenshot](https://assets.relyanceuat.xyz/images/docs/34547031546381/40707736601741.png)

### Check the connection after setup

Open the connection to see what Relyance is authorised for and what the last scan
actually covered — a missing scope or a partial grant shows up here rather than as
an error:

![A connection's detail view: what Relyance is authorised for, and what the last scan covered](https://assets.relyanceuat.xyz/images/docs/ui/salesforce/08-connection-detail.png)

<!-- terraform-examples:begin (generated from the integration catalog; do not hand-edit) -->

## Manage this integration with Terraform

Connections for this integration can be managed as code with the [Relyance Terraform provider](https://registry.terraform.io/providers/Relyance/relyance/latest). Non-secret fields go in `auth.params`; secret fields go in `auth.secrets_wo`, which is write-only — never stored in Terraform state. Rotate secrets by bumping `auth.secrets_wo_version`.

### OAuth (browser authorization)

The **OAuth (browser authorization)** method uses a browser authorization flow, so the connection is created in the Relyance app. Manage it in Terraform afterwards by importing it (`terraform import relyance_integration_connection.example salesforce/<connection_id>`) or reading it with the `relyance_integration_connection` data source.

### OAuth (browser authorization) — Sandbox Oauth2

The **OAuth (browser authorization) — Sandbox Oauth2** method uses a browser authorization flow, so the connection is created in the Relyance app. Manage it in Terraform afterwards by importing it (`terraform import relyance_integration_connection.example salesforce/<connection_id>`) or reading it with the `relyance_integration_connection` data source.

### OAuth (browser authorization) — Customer OAuth

The **OAuth (browser authorization) — Customer OAuth** method uses a browser authorization flow, so the connection is created in the Relyance app. Manage it in Terraform afterwards by importing it (`terraform import relyance_integration_connection.example salesforce/<connection_id>`) or reading it with the `relyance_integration_connection` data source.

### OAuth (browser authorization) — Customer OAuth Sandbox

The **OAuth (browser authorization) — Customer OAuth Sandbox** method uses a browser authorization flow, so the connection is created in the Relyance app. Manage it in Terraform afterwards by importing it (`terraform import relyance_integration_connection.example salesforce/<connection_id>`) or reading it with the `relyance_integration_connection` data source.

### OAuth client credentials

```hcl
resource "relyance_integration_connection" "salesforce_4" {
  vendor = "salesforce"
  name   = "<your connection name>"

  auth = {
    method = "oauth-client-credentials"
    params = {
      domain = "<domain>"
      maximum_number_of_records = "5000"
      data_storage_location = "us"
    }
    # Secret fields are write-only: sent to Relyance, never stored in state.
    secrets_wo = {
      client_id = var.salesforce_client_id
      client_secret = var.salesforce_client_secret
    }
    secrets_wo_version = 1
  }

  scans = { "data-inspection" = { enabled = true } }
}
```

<!-- terraform-examples:end -->
