Salesforce
Authorize Salesforce for CRM analytics, lead routing, ownership changes, and meeting activity.
Salesforce can supply CRM analytics and the account, lead, contact, owner, and user information used by lead routing. When routing writeback is enabled, Marcenta can also update ownership and create or update meeting activity.
Choose the connecting Salesforce user
The person authorizing Salesforce does not have to carry the System Administrator profile solely because Marcenta is being connected. However, the Salesforce user must:
- be allowed to use the Salesforce API;
- be permitted to authorize connected applications under the organization's policies;
- have access to the Salesforce org Marcenta should use; and
- have the object, field, and record access required for the enabled Marcenta features.
Some Salesforce organizations restrict connected-app authorization or require administrator pre-approval. In that case, a Salesforce administrator must approve access even if another suitably permissioned integration user completes the connection.
Marcenta does not provide a separate Salesforce user picker. When you select Connect Salesforce, Salesforce opens its authorization flow. Sign in there using the prepared integration user; the Salesforce identity used to approve access becomes the connecting user.
One Salesforce connection is sufficient for the entire Marcenta organization. Individual sales representatives do not need to connect their own Salesforce accounts. Salesforce syncs, routing lookups, and configured writeback operate through the connecting user's authorization and remain limited by that user's Salesforce permissions and record visibility.
Required Salesforce access by feature
Use the least-privileged Salesforce user that supports your intended features.
| Marcenta feature | Salesforce access needed |
|---|---|
| CRM reporting | Read access to the used Lead, Contact, Opportunity, and Event records and fields |
| Account-owner routing | Read access to Account and User records and the fields needed to identify domains and owners |
| Lead/contact-owner routing | Read access to Lead, Contact, and User records used for matching and ownership |
| Ownership writeback | Edit access to the relevant Lead or Contact owner field and records |
| Meeting activity writeback | Create and update access to the Event records and fields used for the booking |
Field-level security, sharing rules, permission sets, and record visibility all apply. A connection can authorize successfully yet later fail on a particular record if that user cannot read or edit it.
Verify the connecting user's access in Salesforce
A Salesforce administrator can cross-check the effective access before connecting. In Salesforce Lightning, select the gear icon, select Setup, and use the Quick Find box for the paths below.
| What to check | Where to find it in Salesforce | What to verify |
|---|---|---|
| Integration user | Setup → Users → Users → [select the user] | The user is active and has the intended Salesforce user license and profile |
| Complete access summary | From the user's detail page, select View Summary | Review the user's profile, permission sets, permission set groups, user permissions, object access, and field access in one place |
| API access | View Summary → User Permissions → API Enabled | API Enabled is granted; use the row action Access Granted By to identify the profile, permission set, or permission set group supplying it |
| Assigned permission sets | View Summary → Permission Sets or User detail → Permission Set Assignments | The intended integration permission set is assigned and, if applicable, not expired or activation-required |
| Object permissions | View Summary → Object Access | Account, Lead, Contact, Opportunity, Event, and User have the Read, Create, or Edit access required by the feature table above |
| Field permissions | View Summary → Field Permissions | Required fields are readable; fields used for ownership or meeting writeback are editable |
| Permission-set configuration | Setup → Permission Sets → [select permission set] → Object Settings → [select object] | Review the permission set's object permissions and field permissions directly |
| Record visibility | Setup → Sharing Settings → Organization-Wide Defaults and the sharing rules on the same page | The integration user can access the required records, including records it does not own; also account for role hierarchy, territories, teams, ownership, and manual sharing |
| Existing Marcenta authorization | Setup → Connected Apps OAuth Usage → [find Marcenta] | Review whether the app is installed or blocked and select the user count to confirm which Salesforce user authorized it |
| Connected-app policy | From Connected Apps OAuth Usage, select Manage App Policies; alternatively use Setup → Manage Connected Apps → [Marcenta] → Edit Policies | If Permitted Users is set to Admin approved users are pre-authorized, confirm the integration user's profile or permission set is assigned to the app |
If View Summary does not appear, the person reviewing access lacks Salesforce's View Setup and Configuration permission. A Salesforce administrator should perform the check instead.
Salesforce permissions are cumulative, so do not check only the user's profile. A required permission may come from the profile, a permission set, or a permission set group. Salesforce documents how to view and manage a user's permission-set assignments, configure object permissions, and configure field permissions.
Enable missing permissions for a non-admin user
The connection user should not be given the System Administrator profile solely to connect Marcenta. If that user lacks access, a Salesforce administrator—or another Salesforce user with permission to manage profiles and permission sets—should:
- Go to Setup → Permission Sets. Open a dedicated Marcenta integration permission set, or select New, enter a label, and save it.
- In the permission set, open System Permissions → Edit, enable API Enabled, and save.
- Open Object Settings, select each required object, and select Edit. Grant only the object permissions required by the feature table above.
- On the same object page, use Field Permissions to grant read access to required fields and edit access only to fields Marcenta must update. Save each object.
- From the permission set, select Manage Assignments → Add Assignments, select the integration user, select Next, and then select Assign. The user's Salesforce license must support every permission being assigned.
- If records are still unavailable, go to Setup → Sharing Settings and review Organization-Wide Defaults and sharing rules. Use the narrowest approved sharing change; do not make all CRM data public merely to resolve an integration error.
- If Salesforce blocks Marcenta under a connected-app policy, go to Setup → Connected Apps OAuth Usage, find Marcenta, and review its status. An administrator can install or unblock a trusted app and use Manage App Policies → Edit Policies to authorize the appropriate profile or permission set.
- Return to Marcenta, reconnect Salesforce if authorization was blocked or changed, and run the relevant sync or routing-directory refresh.
The integration user cannot grant itself these permissions unless it already has the Salesforce administrative permissions required to manage and assign permission sets. If the user cannot open Setup or make the changes above, ask the Salesforce administrator to complete them.
Authorization requested
Marcenta requests Salesforce API access plus refresh access so scheduled syncs and configured routing activity can continue after the interactive sign-in ends. It does not need the Salesforce user's password.
Connect
- Decide which Marcenta features will use Salesforce.
- Prepare a dedicated or suitably governed Salesforce user with the required API, object, field, and record permissions.
- Open Connections → Salesforce.
- Select Connect Salesforce.
- Review and approve the Salesforce authorization.
- Return to Marcenta and confirm the connection is active.
- Run the initial sync or history import needed for CRM reporting.
- Refresh the routing directory before configuring Salesforce ownership steps.
Connecting Salesforce does not itself create leads, change ownership, or enable routing rules. Those behaviors require separate routing configuration and an actual matching submission.
Data used by CRM analytics
Salesforce analytics can read the accessible Lead, Contact, Opportunity, and Event data needed for supported reporting. Results reflect the connecting user's Salesforce visibility. If that user cannot see a business unit, field, or record type, Marcenta cannot import it through that connection.
Use with lead routing
Salesforce routing steps can:
- match an Account from a submitted company domain and route to its owner;
- match an existing Lead or Contact and route to its owner;
- map the Salesforce owner to a Marcenta routing member and connected calendar;
- update a matched Lead or Contact owner where configured; and
- create or update Salesforce meeting activity where configured.
The Salesforce owner must also be represented by an eligible Marcenta routing member for calendar-based booking. Refresh the routing directory after ownership, user, account-domain, or relevant CRM record changes.
See Routing Groups and Rules for rule order and fallbacks, and Calendar Booking for calendars and booking behavior.
Manage
The Salesforce connection can support:
- a recent sync;
- historical CRM import;
- reconnection;
- disconnection; and
- routing-directory refresh.
Reconnect after the integration user's permissions, password policy, session policy, connected-app access, or employment status changes.
Troubleshooting
| Symptom | What to check |
|---|---|
| Salesforce blocks authorization | Check connected-app policy, API access, login restrictions, and required administrator approval |
| CRM records are missing | Confirm object, field, record, and sharing access for the connecting user |
| Account-owner routing does not match | Verify the submitted domain, Account data, owner, directory freshness, and Marcenta user mapping |
| A Lead or Contact is found but cannot be updated | Confirm record edit access and field-level access to the owner field |
| Meeting activity cannot be written | Confirm Event create/update permission and required field access |
| A former employee authorized the connection | Reconnect using an approved active integration user |
Test Salesforce routing and writeback with non-production records first. Confirm that the connecting user cannot access more Salesforce data than Marcenta needs.