Skip to main content

Set up granular Salesforce permissions for Relevize

Optional. Create a dedicated Salesforce user and permission set so Relevize can only read and update the objects and fields you allow.

This guide is optional. It is for security teams who want Relevize limited to specific Salesforce objects and fields. Most customers can connect with their own Salesforce user and skip this.

It applies to both Salesforce uses:

What the Salesforce consent screen controls

New Relevize connections ask Salesforce for two permissions:

  • Access and manage your data (api). Lets Relevize call the Salesforce API.

  • Perform requests on your behalf at any time (refresh_token). Lets Relevize keep the connection without asking you to sign in again.

Those two lines do not choose objects or fields. Salesforce applies the permissions of whichever user signs in on that screen. A System Administrator grants Relevize that administrator’s access. A dedicated integration user grants only what that user’s permission set allows.

Sign in as the integration user when you authorize Relevize. Use a private browser window if you are already signed into Salesforce as yourself.

Step 1: Create the integration user

In Salesforce, click the gear and open Setup.

  1. Go to Users → Users and click New User.

  2. User License: Salesforce. Platform and Chatter licenses cannot access Opportunity or Lead.

  3. Profile: Minimum Access - Salesforce.

  4. Use a shared email your security team owns, not a salesperson’s personal login.

  5. Leave the user Active and save. Do not turn on API Only User. Relevize’s connect flow needs this user to sign in once in the browser.

Step 2: Create a permission set

  1. Go to Users → Permission Sets and click New.

  2. Name it Relevize Integration. Leave License set to --None--.

  3. Open the permission set, then System Permissions, and enable API Enabled.

  4. Leave these off: Modify All Data, View All Data, Author Apex, Manage Users, and API Only User.

  5. Assign the permission set to the integration user (Manage Assignments).

Then add only the object access for the product you use. When you turn on Read for an object, Salesforce often marks every field readable. Open Field Permissions on that object and clear Read for fields Relevize should not see.

Step 3a: Deal Registration access

Relevize reads Opportunities whose Relevize Partner ID is filled in, plus the Opportunity fields we agreed to map (typically Amount, Close Date, Description, Account Name, and the primary contact). Relevize writes only Relevize Deal Id and Relevize Stage. We do not change Salesforce Stage, and we do not create or delete records.

Object

Read

Create

Edit

Why

Opportunity

Yes

No

Yes

Edit is required to update two fields. Field permissions limit which ones.

Account

Yes

No

No

Only if we map Account Name. Read on Name is enough.

Contact

Yes

No

No

Only if we map a contact.

Opportunity Contact Role

Yes

No

No

Only if we map the primary contact.

On Opportunity Field Permissions:

  • Relevize Partner ID — Read. Your reps edit this field with their own profiles. Relevize only reads it.

  • Relevize Deal Id and Relevize Stage — Read and Edit. These are the only fields Relevize writes.

  • Each mapped field (Amount, Close Date, Description, and so on) — Read only.

  • Everything else — Read off, if your org allows it.

Leave View All and Modify All unchecked on the object. If Opportunity sharing is Private, this user only sees Opportunities shared with them. Put the user in a role that can see those records, add a sharing rule, or enable View All Records on Opportunity if every Opportunity you might send has to be visible. View All still does not let Relevize edit fields you marked read-only.

Step 3b: Lead upload access

Skip this section if you only use Deal Registration. Relevize creates Leads, looks up an existing Lead or Contact by email, and can add that person to a Campaign.

Object

Read

Create

Edit

Lead

Yes

Yes

No

Contact

Yes

No

No

Campaign

Yes

No

No

Campaign Member

Yes

Yes

No

On Lead, grant Read (and Edit, if your org requires it to populate a field) only for the Lead fields you map in Relevize. Leave Opportunity access off for a lead-upload user.

Step 4: Authorize Relevize as that user

  1. Sign out of Salesforce, or open a private window.

  2. Open the Relevize connect link and sign in as the integration user.

  3. Approve Access and manage your data and Perform requests on your behalf at any time.

If someone already connected Relevize as a System Administrator, that token keeps the administrator’s access until you connect again as the integration user. Connecting again replaces the token.

Step 5: Optional — only this user may connect the app

After the first successful connect, Salesforce lists the Relevize connected app in your org.

  1. Go to Setup → Manage Connected Apps (or Connected Apps OAuth Usage) and open Relevize.

  2. Set Permitted Users to Admin approved users are pre-authorized.

  3. Assign the connected app to the Relevize Integration permission set, or to this user only.

  4. Set the refresh-token policy to Refresh token is valid until revoked so the connection stays up. Revoke it from this same screen if you ever want to cut Relevize off.

Do this after the integration user has already authorized the app. If you lock the app first, that user has to be pre-authorized or the login will be rejected.

Did this answer your question?