> ## Documentation Index
> Fetch the complete documentation index at: https://unify-19-preview.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Required permissions

> Check Salesforce access for Unify.

export const ThemedImageFrame = ({lightSrc, darkSrc, alt, caption}) => <Frame caption={caption}>
    <img className="block w-full dark:hidden" src={lightSrc} alt={(alt ?? caption) ?? ""} />
    <img className="hidden w-full dark:block" src={darkSrc} alt={(alt ?? caption) ?? ""} />
  </Frame>;

## Overview

Salesforce administrators can use this page to prepare an account for a Unify
connection or resolve missing access. The requirements depend on the connection
type and the records and fields Unify needs to read or write.

## Connection requirements

### API access

Your Salesforce organization must have API access, and the connected user must
have the API Enabled permission. Both personal and workspace connections use the
Salesforce API. If API access is unavailable, ask your Salesforce administrator
to check the organization's edition and licensing. See
[Salesforce editions with API access](https://help.salesforce.com/s/articleView?id=000005140\&language=en_US\&type=1).

### Workspace connections

Before workspace setup completes, Unify checks the connected Salesforce account
for the following permissions:

| Setup check | Permissions |
| - | - |
| System permissions | API Enabled, View All Profiles, View All Users, View Setup and Configuration, and Edit Tasks. |
| Each of Account, Contact, Lead, and Opportunity | Read, Create, Edit, Delete, View All Records, and Modify All Records. |

The same checks apply regardless of which workspace sync rules are enabled.
They include delete and broad record-access permissions even when your planned
syncs use a smaller set of operations. Have your Salesforce administrator review
this access before choosing the workspace account.

The account also needs access to the fields and records used by your mappings,
filters, and exclusions. For example, excluding current customers requires
access to the records that identify them. Salesforce checks access to each
record and field when Unify reads or writes it.

### User connections

A personal connection uses the permissions of the Salesforce user who connects
it. That user needs access to the records and fields involved in their actions,
including create or edit permissions for writes. For example, updating an
opportunity requires permission to edit that opportunity and the affected fields.

See [Connection preferences](/reference/integrations/salesforce/connection-preferences)
to require personal connections and choose which account Unify uses for writes.

### Email sync

Writing emails to Salesforce as email messages requires Enhanced Email. It is
enabled by default in most Salesforce organizations. Your Salesforce
administrator can follow Salesforce's
[Enhanced Email setup instructions](https://help.salesforce.com/s/articleView?id=sf.enable_enhanced_email.htm\&language=en_US\&type=5)
to enable it before you configure
[email sync](/reference/integrations/salesforce/bidirectional-syncs).

## Check permissions

You can review the workspace account's permissions from Unify after connecting it.

<Steps titleSize="h3">
  <Step title="Open the workspace connection">
    Open [Salesforce settings](https://app.unifygtm.com/dashboard/settings/integrations/salesforce)
    and select the workspace connection. Click **View Permissions** to see the
    connected account's profile and object permissions.
  </Step>

  <Step title="Review and refresh permissions">
    Review the permissions with your Salesforce administrator and have them
    resolve any missing access. Click **Refresh** to retrieve the account's
    current permissions after making changes in Salesforce.

    <ThemedImageFrame lightSrc="/images/reference/integrations/salesforce/salesforce-permission-checks-light.png" darkSrc="/images/reference/integrations/salesforce/salesforce-permission-checks-dark.png" alt="Salesforce permissions dialog with all displayed profile permissions enabled and the Refresh control visible." />
  </Step>
</Steps>

## Troubleshooting

<Accordion title="Why is setup incomplete when the displayed permissions are enabled?">
  Workspace setup also requires View All Profiles, which is absent from the
  permissions dialog. Ask your Salesforce administrator to check this permission
  on the connected account. The dialog includes Access activities as an
  additional check.
</Accordion>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.