Overview

The Salesforce integration reviews who has access to your Salesforce org — the user roster, their admin roles, MFA enrollment, and offboarding status. LowerPlane uses read-only OAuth access and does not modify anything in Salesforce.
LowerPlane matches each account to a person in your HR directory using the user’s Email (not the Salesforce username, which is a login and not a real email). Accounts with no email are skipped.

Prerequisites

You connect as a Salesforce user with these permissions: API Enabled, permission to view all users (e.g. View All Users / Manage Users), and Manage Multi-Factor Authentication in API for the MFA check. Without the MFA permission the roster still syncs, but MFA status is reported as unavailable rather than failing every user.

How to Connect

1

Start the connection

Go to Settings > Integrations in LowerPlane, find Salesforce under Marketing & Sales, and click Connect.
2

Authorize access

You’re redirected to Salesforce. Sign in with a user that has the permissions above and approve the read-only access request.
3

Verify connection

After redirect, LowerPlane resolves your org’s domain and begins syncing the user roster.

What LowerPlane Checks

MFA enabled

Flags any Salesforce user who has not registered a multi-factor authentication method.

Offboarded access removed

Flags Salesforce access still active for an employee who has been offboarded in your HR directory.

User identified

Confirms each account resolves to a named person, not an anonymous or shared account.

Access valid

Verifies each account maps to a current employee in your HR directory whose access has been reviewed.
Admin roles are derived from each user’s Salesforce Profile — an account is treated as an admin if its profile can Modify All Data or is System Administrator.