> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Salesforce

<div className="page-title-row">
  <img src="https://mintcdn.com/klef/xJ0kXbcegZOD2G3h/images/connectors/salesforce.svg?fit=max&auto=format&n=xJ0kXbcegZOD2G3h&q=85&s=83dbc44776ae091781b99cee3e71ea99" alt="" noZoom width="24" height="24" data-path="images/connectors/salesforce.svg" />

  <h1>Salesforce</h1>
</div>

## Connection

Connecting sends you to Salesforce to approve Klef's access.

To connect a Salesforce sandbox, choose **Sandbox** when you connect.

### Permissions

Minimum permissions the connection requires.

| Capability                        | Required | Granted by (any one)  |
| --------------------------------- | -------- | --------------------- |
| Provision users                   | Yes      | `api`, `Manage Users` |
| Read profiles and permission sets | Yes      | `api`, `Manage Users` |

## salesforce.user

### Fields

| Field                    | Type              | Required | Description                                                                                               |
| ------------------------ | ----------------- | -------- | --------------------------------------------------------------------------------------------------------- |
| `userName`               | string, up to 80  | Yes      | Username, in the form of an email address. Unique across every Salesforce org.                            |
| `email`                  | string, up to 128 | Yes      | Email address the user receives mail at.                                                                  |
| `givenName` (First name) | string, up to 40  |          | First name.                                                                                               |
| `familyName` (Last name) | string, up to 80  | Yes      | Last name.                                                                                                |
| `title`                  | string, up to 80  |          | Job title.                                                                                                |
| `department`             | string, up to 80  |          | Department the user works in.                                                                             |
| `division`               | string, up to 80  |          | Division the user belongs to.                                                                             |
| `employeeNumber`         | string, up to 20  |          | Employee number from the HR system.                                                                       |
| `active`                 | bool              |          | Whether the user can sign in. Salesforce never deletes a user, so an inactive user is how one is removed. |
| `profile`                | enum              | Yes      | Profile ID. A user holds exactly one, and it decides the license they use.                                |
| `permissionSets`         | grant             |          | Permission sets assigned to the user. One row grants one permission set.                                  |
| `permissionSets[]`       | string            |          | Permission set ID.                                                                                        |

### Default Account Matching Rules

When Klef [adopts](/docs/adoption) an account that already exists in Salesforce, it works out whose it is by trying these in order. A connection can override them.

| Account field | Worker field            |
| ------------- | ----------------------- |
| `email`       | `worker.business_email` |

## Examples

### Salesforce users

A Salesforce user with the profile their department maps to, deactivated on leave and when they go.

```hcl theme={null}
stage active {
  target salesforce.user {
    userName       = worker.business_email
    email          = worker.business_email
    givenName      = worker.legal_name.given
    familyName     = worker.legal_name.family
    title          = worker.job.name
    department     = worker.department.name
    employeeNumber = worker.employee_id
    profile        = lookup(table.salesforce_profiles, worker.department.name)
    active         = true
  }
}
```
