22 Salesforce Connector
Use this guide for a customer Salesforce connector. The customer creates a Salesforce integration user credential. Nous indexes the selected Salesforce objects.
22.1 What is indexed or searched live
The connector indexes Salesforce objects and supported child records that the configured user can read. The simple form lets you list requested objects. The advanced form accepts a JSON query configuration.
22.2 Administrator role and authentication
A Salesforce administrator should create or review the integration user and grant it the least-privilege read permissions needed for the selected objects. The customer supplies the Salesforce username, password, and security token. Use a sandbox checkbox when the source is a Salesforce sandbox.
22.3 Provider setup and permissions
Create a dedicated integration user. Grant object and field read access for the data to index. Reset the security token when the user’s trusted network changes or when policy requires it. Keep the password and token in the credential store, not in a document or chat.
22.4 Setup form fields
| Field | What to enter |
|---|---|
| Name | A unique workspace connector name. |
| Salesforce Username | The integration user’s Salesforce username. |
| Salesforce Password | The integration user’s password. |
| Salesforce Security Token | The security token for that user. |
| Configuration Type | Choose Simple or Advanced. |
| Requested Objects | In Simple mode, list object names such as Account or Opportunity, one per line. |
| Custom Query Config | In Advanced mode, enter the JSON object and child-field configuration. |
| Who has access | Choose Everyone in the workspace or Specific Teams. |
If Requested Objects is empty, Nous uses its default object selection. Validate custom JSON before saving and keep only fields the integration user can read.
22.5 Workspace and Team access
Salesforce permissions control what the integration user can read. Nous access controls who can search the indexed result. Use Specific Teams for a limited audience. Portal manages Team membership. A Team share cannot grant access to fields the Salesforce user cannot read.
22.6 Test the connection
- Save the connector and wait for source sync and search indexing.
- Search for a known record from each selected object.
- Search for a distinctive field value and confirm the record link.
- Test as an intended Workspace or Team member.
22.7 Common errors
| Error | Action |
|---|---|
| Login fails | Check username, password, security token, and that the credential belongs to the intended Salesforce production account. |
| An object is empty | Grant the integration user object and field read permission. |
| Custom JSON is rejected | Validate JSON, use singular object names, and remove unsupported fields. |
| The security token is invalid | Reset it in Salesforce, save the replacement, and test again. |
22.8 Reconnect, rotate, and remove
Rotate the Salesforce password or security token in Salesforce first. Save the replacement in the connector and run a test search before disabling the old credential. Before removal, check document sets, agents, and Team shares.