> For the complete documentation index, see [llms.txt](https://docs.lightbeam.ai/lxqobxw6ak7CTnsQjikH/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lightbeam.ai/lxqobxw6ak7CTnsQjikH/core-features/spectra-ai/data-sources/crm/salesforce.md).

# Salesforce

***

### Overview <a href="#b8lru010a6n7" id="b8lru010a6n7"></a>

LightBeam Spectra users can connect various data sources to the LightBeam application and these data sources will be continuously monitored for PII, PHI data.

**Example**: Salesforce, Hubspot, ADP, Marketo, etc.

After setup, you can review access visibility and activity tracking in [Salesforce Access Governance](/lxqobxw6ak7CTnsQjikH/core-features/governance/access-governance-at-a-data-source-level/salesforce-access-governance.md).

***

### Connecting Salesforce Data Source <a href="#z6dfnxg485jf" id="z6dfnxg485jf"></a>

1. Login to your LightBeam Instance.<br>
2. Click on **DATASOURCES** on the Top Navigation Bar.<br>
3. Click on **“Add a data source”.**

<figure><img src="/files/STIFkZ6FLdKIioTFrsPW" alt="" width="375"><figcaption><p>Figure 1. Add Data Source</p></figcaption></figure>

4. Search for “**Salesforce**”.

<img src="/files/d70cm1GoK7RM0lwt9WDF" alt="Figure 2. Type Salesforce in Search Box" width="375">

5. Click on **Salesforce**.

<img src="/files/86dqZGpPaV3LiMPVjgaw" alt="Figure 2.1 Salesforce" width="139">

6. Fill in the details as shown below and click on **Next**:

**Basic Information**

* **Data Source Name:** This is the unique name given to the data source.
* **Description**: This is an optional field needed to describe the use of this data source.
* **Primary Owner:** An email address of who is responsible for this data source and in case of alerts this email ID will get alerts by default.
* **Entity Creation:** LightBeam Spectra detects and associates attributes based on the context and identifies whose data it is; these are called as entities. **Example**: Jane Doe is an entity for whom LightBeam Spectra might have detected Name and SSN in a monitored data source.
* **Location**: The location of the data source is indicated here.
* **Purpose**: The purpose of why the data is being collected/processed.
* **Stage**: The stage of the data source. **Example**: Source, Processing, Archival, etc.

<img src="/files/XmUCmM4Cu8FMUvHC5CR5" alt="Figure 3. LightBeam Salesforce - Basic Information" width="563">

**Datasource Configuration**

1. Provide the credentials as shown below (If the credentials belongs to a Salesforce sandbox account select the sandbox option) and click on **Test Connection**.

<img src="/files/WQBnIgnRDpzhHoqq7iWb" alt="Figure 4. LightBeam Salesforce - Test Connection" width="563">

2. Verify that you get the message “**Test** **Connection Success**”.

<img src="/files/q91uywiiJu9QnzT3i1CU" alt="Figure 5. LightBeam Salesforce - Connection Success" width="563">

3. Click on **Save**.

Now we are ready to browse through onboarded Salesforce datasource dashboard.

{% hint style="info" %}
**Note**: To get the Salesforce data source details please check Appendix.
{% endhint %}

### Next Steps

* Review the onboarded Salesforce data source in the dashboard.
* See [Salesforce Access Governance](/lxqobxw6ak7CTnsQjikH/core-features/governance/access-governance-at-a-data-source-level/salesforce-access-governance.md) for access visibility and activity tracking.

***

### Appendix <a href="#tybwpwk8cwn7" id="tybwpwk8cwn7"></a>

#### Configuring a “View All Files” Policy for the LightBeam App

Salesforce requires to create a Permission set that would allow assigned users to view all files in the LightBeam app.

To enable this functionality, a dedicated Permission Set must be created that grants access to the “Query All Files” capability. This permission is not automatically enabled—even for System Administrators—so it must be explicitly configured to ensure full file visibility across the application.

Here is the step-by-step to get that box checked and assigned to your user:

**Step 1**: Create the Permission Set

Log in to Salesforce and click the Gear Icon (top right) > Setup.

In the Quick Find box on the left, type Permission Sets and select it.<br>

<figure><img src="/files/Q3s0zempJt84NGr03lnA" alt="" width="375"><figcaption><p>6.1 Click on Permission Sets</p></figcaption></figure>

Click New.

Label: Call it File Admin Access.

API Name: (This will auto-fill).

License: Leave this as --None-- (this allows you to assign it to any user regardless of their license).

Click Save.

<figure><img src="/files/AUPmuVa1unKlLEW7eRmp" alt=""><figcaption><p>Figure 6.2 Fill required information and click save</p></figcaption></figure>

**Step 2:** Enable "Query All Files"

Inside your new Permission Set, scroll down to the Apps section and click App Permissions.

<figure><img src="/files/iEiPoQpLun2j6Y3o3NWE" alt=""><figcaption><p>Figure 6.3 Click App Permissions</p></figcaption></figure>

Click the Edit button at the top.

Scroll down (or use Ctrl+F / Cmd+F) to find the Content section.

<figure><img src="/files/pOPBRW274vRPkrqkCSDi" alt=""><figcaption><p>Figure 6.4 Select Query All Files option</p></figcaption></figure>

Check the box for Query All Files.

Note: This automatically enables "View All Data" for files.

Scroll back to the top and click Save. A confirmation box will appear; click Save again.

<figure><img src="/files/Kz9i4sGaZJnQRSjrtNlx" alt=""><figcaption><p>FIgure 6.5 Click on Save</p></figcaption></figure>

**Step 3:** Assign it to Yourself

While still in the Permission Set, click the Manage Assignments button at the top.

<figure><img src="/files/QGt2oteOWVt52yA1zUdM" alt=""><figcaption><p>Figure 6.6 Click on Manage Assignments</p></figcaption></figure>

Click Add Assignment.

Find your name in the list and check the box next to it.

Click Next.

<figure><img src="/files/nCLhheEtKLaybknyFS2T" alt=""><figcaption><p>Figure 6.7 Select your name and click Next</p></figcaption></figure>

Click Assign.

<figure><img src="/files/HhcrQAdUxyFIXTFyPw6t" alt=""><figcaption><p>Figure 6.8 Click on Assign</p></figcaption></figure>

Then click on **Done.**

<figure><img src="/files/EINPSaJT5vfEGaKfOAMl" alt=""><figcaption><p>Figure 6.9 Click on Done</p></figcaption></figure>

***

#### Steps to Generate Salesforce Data Source Credentials <a href="#id-1s36sfst6r0w" id="id-1s36sfst6r0w"></a>

{% hint style="success" %}
**Success Tip:** Salesforce editions vary in terms of API access. **Enterprise Edition, Unlimited Edition, Developer Edition,** and **Performance Edition** come with API access, which is essential for integrating LightBeam with Salesforce. However, **Group Edition, Essentials Edition,** and **Professional Edition** do not provide API access by default, although they can be purchased as an add-on for the **Professional Edition**. We recommend using an edition with built-in API access when creating a dedicated **Salesforce Connected App** specifically for integrating LightBeam with Salesforce.
{% endhint %}

1. Log in to Salesforce as an *Administrator*. In the drop-down list of the account (in the upper-right corner), select **Setup**.

<img src="/files/7WG6L7rBwDowto3Hz3Sh" alt="Fig.7. Salesforce - Setup" width="303">

2. In the left-hand pane, go to **`Apps > App Manager`**.

<img src="/files/8p3l7AGgoRtltIa3LRPl" alt="Fig.8. Salesforce - App Manager" width="224">

3. Click on **New External Client App** (in the upper right corner).

<figure><img src="/files/BRX2nm5B3iGxTxzjY5R7" alt="" width="375"><figcaption><p>Fig 9. Salesforce - New External Client App</p></figcaption></figure>

4. On the **External Client App Manager** page, fill in the following required fields under

**`Basic Information:` External Client App Name, API Name, Contact Email.**

<figure><img src="/files/MnWl4HvvW1CygoYB3xjQ" alt=""><figcaption><p>Fig 10. Salesforce - External Client App Manager</p></figcaption></figure>

\
Then, save the app by clicking on the ‘**create**’ button.

After clicking on ‘Create’, it will take you to this page. Then, click on edit app to update Refresh Token Policy and IP Relaxation section to a new value, as shown below.

<figure><img src="/files/Q9TC7wB4lPB8vNBe8z2J" alt=""><figcaption><p>Fig. 10.1 Salesforce - Update Refresh Token</p></figcaption></figure>

<figure><img src="/files/DxS4InSyzN0CbdqF7XiI" alt=""><figcaption><p>Fig. 10.2 Salesforce - Edit Plugin Details</p></figcaption></figure>

<figure><img src="/files/VMbO6KTw2ol4KxoEEZef" alt=""><figcaption><p>Fig. 10.3 Salesforce - 10.3 Salesforce - Edit refresh token policy and IP Relaxation</p></figcaption></figure>

<figure><img src="/files/0QJgIinWlRDcZ6UktMas" alt=""><figcaption><p>Fig. 10.4. Salesforce - Click on Save</p></figcaption></figure>

After making those changes, click on ‘**Save**’.

Then on the ‘Settings’, open the ‘Consumer Key and Secret’ button. After Email OTP verification, it will show you the Consumer Key and Secret, save it somewhere.

After copying the client ID and secret, run the script to generate refresh token, using lb-install script to generate and refresh token.

<figure><img src="/files/ZnyydyBSCA3ry091nsEp" alt=""><figcaption><p>Fig. 10.5 Salesforce - Consumer Key and Secret</p></figcaption></figure>

\
For Sandbox Salesforce, we need to whitelist [test.salesforce.com](http://test.salesforce.com/) and the Salesforce url.

For Production, [login.salesforce.com](http://login.salesforce.com/) and the Salesforce url for your tenant is whitelisted in firewall if being used.

**Please Note**: If the SSO is enabled and direct login to Salesforce is not available then use the SSO redirect URL of your organization.

<figure><img src="/files/Cx07eobd2au9oP9p5ydX" alt=""><figcaption><p>Fig. 10.6 Salesforce - OAuth Policies</p></figcaption></figure>

In the Callback URL field, enter the redirect url value[ https://login.salesforce.com](https://login.salesforce.com/)

* Go to API (Enable OAuth Settings), and select Enable OAuth Settings.

\ <br>

5. Go to **`API (Enable OAuth Settings)`**, and select **Enable OAuth Settings**.

In the **`Callback URL`** field, enter the redirect url value [`https://login.salesforce.com`](https://login.salesforce.com/)

{% hint style="info" %}
**Note**: If the **SSO** is enabled and direct login to Salesforce is not available then use the SSO redirect URL of your organization.
{% endhint %}

<img src="/files/IHmEaUxg4eZ4Tc5vXdvV" alt="Fig.11. Salesforce - API Config" width="563">

In the **`Selected OAuth Scopes`** field, select each of the following options, and click on **Add** individually:

* **Access Connect REST API resources (chatter\_api)**
* **Manage user data via APIs (api)**
* **Perform requests at any time (refresh\_token, offline\_access)**<br>

<figure><img src="/files/64Cu2vL6VdhP16Ls537V" alt="" width="563"><figcaption><p>Fig.12. Salesforce - Selected OAuth Scopes<br></p></figcaption></figure>

{% hint style="success" %}
**Success Tip for** **Streamlining API Access and Permissions for Salesforce Integration:**\
To ensure a smooth and secure integration between LightBeam and Salesforce, you'll need specific API permissions. Ensure you have *`read access`* to all the fields in these Salesforce objects:

* `Account`
* `Contact`
* `Case`
* `CaseFeed`
* `EmailMessage`
* `ContentDocument`
* `ContentVersion`

**Note**: These permissions are typically configured during the credential generation process.

For the application to function optimally, the following app permissions are needed:

1. **`Access Connect REST API resources (chatter_api)`**
2. **`Manage user data via APIs (api)`**
3. **`Perform requests at any time (refresh_token, offline_access)`**

If you're planning to use the redaction feature, also secure *`write access`* to the following:

1. `CaseFeed`
2. `ContentVersion`
3. `ContentDocument`
   {% endhint %}

Scroll down and tick the checkbox next to **`Enable Client Credentials Flow`**.

<figure><img src="/files/bSamT1TCtslObimLkzgt" alt="" width="375"><figcaption><p>Fig.13. Salesforce - Enable Client Credentials Flow<br></p></figcaption></figure>

This will open a pop-up as follows. Click on **OK**.

<figure><img src="/files/MuLmzr2HUj1c28UZFJkL" alt="" width="375"><figcaption><p>Fig.14 Salesforce - Enable Client Credentials Flow<br></p></figcaption></figure>

6. In the **Connected Apps `(Apps > App Manager)`** list, find the App that you just created, and then click **Manage**.<br>
7. On the **`Manage`** page, click the **Edit** button.

<figure><img src="/files/sisuSu1vpKgm9sLZQ3Di" alt=""><figcaption><p>Fig.15 Salesforce - Connected Apps - Manage</p></figcaption></figure>

* Under **`OAuth policies`**, select **All users may self-authorize** in the **`Permitted Users`** list, and then click the **Save** button.

This is where our ‘**new**’ service account user should be ‘**applied**’ to the **Connected App** previously created within SFDC.

To embed the service account within the connected app, click on **Users** on the main Home page of Salesforce.

<figure><img src="/files/DdYqHsGdZFIy1zVlE4P4" alt=""><figcaption><p>Fig 16. Salesforce - Sample User set up</p></figcaption></figure>

For ‘**Connected Apps**’ -> **Lightbeam app**, under ***Client Credentials Flow*** select a user to return the **access\_token,** select ***Integration User*****.**

LightBeam will generate Access Token to access Salesforce, and it will be tied to the account which approves the app while generating the refresh token(at the time of running the script).

We recommend that we use the integration account: <https://admin.salesforce.com/blog/2023/best-practices-for-configuring-your-integration-user> to approve this step so the access token is always tied to this account instead of any real user.

**Please Note**: you are using a dedicated integration user, please add this user in View All Files permission set. Follow the steps mentioned under section “**Configuring a “View All Files” Policy for the LightBeam App**” earlier in this document at the beginning of the Appendix section.

<figure><img src="/files/ThqJAhHH13p4NzI9v6ac" alt=""><figcaption><p>Fig 17. Salesforce - Select integration user</p></figcaption></figure>

After linking the service account to the Connected App, the service account should now show the connection in the OAuth Apps section, like shown below:

<figure><img src="/files/8mf95k6xxQLA5P3XxK66" alt=""><figcaption><p>Fig 18. Salesforce - Service account visible in the OAuth Apps section</p></figcaption></figure>

**Please Note**: Best practice is one integration user per one integration, for auditing and security. For access and permissions required in order for the LightBeam connection to work properly, see listed access permissions after *Figure 11* of this document.

8. Return to the **Connected Apps `(Apps > App Manager)`** list, find the App you just created, and click on **View**.<br>
9. Note down the **Consumer Key** and **Consumer Secret under API (Enable OAuth Settings)**. These will be used for the configuration of Credential in LightBeam's Salesforce integration.

<figure><img src="/files/uTdrHEfK6rsaLUDGbPaf" alt=""><figcaption><p>Fig.19 Salesforce - Consumer Details</p></figcaption></figure>

#### Generate Refresh Token using the credentials mentioned

<figure><img src="/files/OjAvgZiGh0wvy8maiSOv" alt=""><figcaption><p>Fig. 20. Salesforce - Credentials</p></figcaption></figure>

10. Obtain the authorization code by following these steps:<br>

**Unix/Linux/MacOS**:

1. **Copy the Refresh Token Generation Script:** Save the script to your local system.

{% embed url="<https://github.com/lightbeamai/lb-installer/blob/master/salesforce/generate-salesforce-refresh-token.sh>" %}
Script to generate Salesforce refresh token
{% endembed %}

2. **Make the Script Executable:** `chmod +x generate-salesforce-refresh-token.sh`
3. **Run the Script:** Execute the script by running the following command in your terminal`bash generate-salesforce-refresh-token.sh`
4. **Provide Required Information:**&#x54;he script will prompt you for the following information: `Instance URL`, `Consumer Key`, `Consumer Secret`, and `Redirect URL`.

**Retrieve the Refresh Token:** The script will generate a Refresh Token. Please save this token as you will need it during the Lightbeam registration process.<br>

**Windows**:

1. **Copy the Refresh Token Generation Script:** Save the script to your local system.

{% embed url="<https://github.com/lightbeamai/lb-installer/blob/master/salesforce/generate-salesforce-refresh-token-powershell.ps1>" %}
Script to generate Salesforce refresh token
{% endembed %}

2. **Run the Script:** Right-click on the script and select "Run with PowerShell" from the context menu.
3. **Provide Required Information:** The script will prompt you for the following information: Instance URL, Consumer Key, Consumer Secret, and Redirect URI.
4. **Retrieve the Refresh Token:** The script will generate a Refresh Token. Please save this token as you will need it during the Lightbeam registration process.

{% hint style="info" %}
For additional guidance or troubleshooting, you can refer to the documentation at <https://github.com/lightbeamai/lb-installer/blob/master/salesforce/README.md>.
{% endhint %}

11. If you encounter an error that reads "**REST API is not enabled for this Organization**", follow these steps:

* Click on **Setup** in the top right corner.
* Go to **`ADMINISTRATION > Manage Users`** and click on **Profiles**.
* Click **Edit** on the specific profile you want to update.
* Scroll down to **`Administrative Permissions`** and check the **`API Enabled`** checkbox.
* Save your changes.

With these steps completed, you will have all the required configuration parameters like **Consumer Key, Consumer Secret, Access Token,** and **Refresh Token** to onboard the Salesforce data source to LightBeam.

{% hint style="success" %}
**Success Tip:** We recommend creating a dedicated **Salesforce Connected App** specifically for integrating LightBeam with Salesforce. This application should be exclusively used for this purpose and not shared or repurposed for any other clients or applications. By doing so, you ensure secure and efficient access control, as well as maintain proper management of the LightBeam-Salesforce connection
{% endhint %}

### Steps to generate the Salesforce Refresh token

#### **For Unix and MacOS Operating System**

1. Login to Salesforce from an account with admin access.
2. Run script bash generate-salesforce-refresh-token.sh
3. Enter the value of InstanceUrl, Consumer Key, Consumer Secret and redirect\_uri from the connected-app details.
4. Open the printed URL in the browser and accept the connected-app permissions.

<figure><img src="/files/YHiYxvFHOFd0q0QqsSz0" alt="" width="375"><figcaption><p>Fig. 21. Salesforce - Allow Access</p></figcaption></figure>

5\. Copy the code parameter from the redirected URL and paste it in the console. If SSO URL is used then check the note below.

<figure><img src="/files/WYNpSmq20d3tN790rmNm" alt=""><figcaption><p>Fig. 22. Salesforce - Copy code</p></figcaption></figure>

6\. Refresh token will be printed on the console.

#### **For Windows Operating System**

1. Login to Salesforce from an account with admin access.
2. Run script generate-salesforce-refresh-token-powershell.ps1 with powershell.
3. Enter the value of InstanceUrl, Consumer Key, Consumer Secret and redirect\_uri from the connected-app details.
4. Open the printed URL in the browser and accept the connected-app permissions.<br>

<figure><img src="/files/RtkwG8RTew8BM0tBhVQx" alt="" width="375"><figcaption><p>Fig. 23. Salesforce - Allow Access</p></figcaption></figure>

5\. Copy the code parameter from the redirected URL and paste it in the console. If SSO URL is used then [check the note below](https://github.com/lightbeamai/lb-installer/blob/master/salesforce/README.md#note).<br>

<figure><img src="/files/frUinVoW2sWjt2ktpw6L" alt=""><figcaption><p>Fig. 24. Salesforce - Copy code</p></figcaption></figure>

6. Refresh token will be printed on the console.

#### Note

If the redirect URL configured in the Salesforce application is your organization's SSO URL, the code parameter will be sent to your SSO portal. To retrieve this code, quickly stop the browser immediately after opening the URL generated by the script to prevent an automatic redirect to authentication. In the developer console, you'll find a request containing the code parameter. Use this code in the script to obtain the refresh token.

***

### About LightBeam

LightBeam automates Privacy, Security, and AI Governance, so businesses can accelerate their growth in new markets. Leveraging generative AI, LightBeam has rapidly gained customers’ trust by pioneering a unique *privacy-centric* and *automation-first* approach to security. Unlike siloed solutions, LightBeam ties together sensitive data cataloging, control, and compliance across structured and unstructured data applications providing 360-visibility, redaction, self-service DSRs, and automated ROPA reporting ensuring ultimate protection against ransomware and accidental exposures while meeting data privacy obligations efficiently.\
\
LightBeam is on a mission to create a secure privacy-first world helping customers automate compliance against a patchwork of existing and emerging regulations.

For any questions or suggestions, please get in touch with us at: <support@lightbeam.ai>.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lightbeam.ai/lxqobxw6ak7CTnsQjikH/core-features/spectra-ai/data-sources/crm/salesforce.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
