What Salesforce integration architecture and permissions do you recommend?
Last updated: August 29, 2026
Applies to: Pylon's core Salesforce CRM integration.
Pylon recommends authorizing the core Salesforce integration with a dedicated Salesforce integration user. For the core integration, the authorizing user needs the api, refresh_token, and offline_access OAuth scopes, plus the Salesforce API Enabled permission.
The core integration requires object permissions for Account, Contact, User, and Organization. Account and Contact need Create, Read, and Edit access. User and Organization need Read access only. Pylon does not require Assign Permission Sets, Manage Users, View Setup and Configuration, or Modify All Data for the core integration.
Field-level security also matters. Any Salesforce field that Pylon needs to read or write must be visible to the integration user. Beyond the core objects above, additional object permissions are only needed if you use optional features such as task creation, file attachments, opportunity contact associations, or Salesforce queue resolution.