UserGems Required Salesforce Permissions - Integration User (Managed Package)

Salesforce Object Permissions for UserGems Integration User

While the permissions outlined below are the minimum required permissions for your UserGems <> Salesforce Integration User, we encourage you to also give UserGems Read All access to fields on your Contact, Lead, Account, and Opportunity objects so that your team can leverage your data within UserGems segmentation reporting, workflow building, notifications, and attribution reporting with ease.

Note: If you are using a "Salesforce Integration" User License type, please pay special attention to the image at the bottom of the article.

Read/Create/Edit access

  • Contact: OwnerId, Name, Email, Phone, Title, LeadSource, Mailing Address, LinkedIn Profile (or similar), All UserGems fields (with the UG Label Prefix or API name prefix UserGems__) [from the UserGems Managed package] + any other fields that you would like us to update or have mapped.
  • Lead: OwnerId, Company, Name, Email, Phone, Title, LeadSource, Address, LinkedIn Profile (or similar), All UserGems fields (with the UG Label Prefix or API name prefix UserGems__) [from the UserGems Managed package] + any other fields that you would like us to update or have mapped.
  • Account: OwnerId, ParentId, Account Name, Website, Employees, Account Source, Type, Billing Address, ‍All UserGems fields (with the UG Label Prefix or API name prefix UserGems__) [from the UserGems Managed package] + any other fields that you would like us to update or have mapped
  • Opportunity Contact Role: ContactId, OpportunityId, Role
    • ^ Edit access only required if you utilize Meeting Assistant (otherwise, Read access is ok)
  • Campaign: Object access -> Read, Edit, View All
  • CampaignMember: Status, LeadId, ContactId, CampaignId (if you’d like UserGems to create Campaign Member records)
    • ^ Please note that the UserGems Integration User would also need to have the “Marketing User” box checked on the user detail page.
  • UserGems Object: Modify All, including Read/Edit/Create/Delete at the object-level and access to edit all fields on the object (note that your Salesforce end users need write access, not only the UserGems/SFDC integration user).
  • TaskANDEvent Objects [aka Activities]:
    • Read, Create, Edit, View All (+ access to any Record Types)

Read access

  • Opportunity: Account Name (AccountId), Amount, Close Date (CloseDate), Lead Source (LeadSource), Opportunity Name (Name), Opportunity Owner (OwnerId), Stage (StageName),Type
    ‍‍
    • Note: It's encouraged to include access to any custom Opportunity currency fields that you use to determine the USD value and/or ARR of an Opportunity for ROI reporting

System Permissions

  • API Enabled
  • Run Reports
  • Access Activities
  • View Setup & Configuration
  • View Roles and Role Hierarchy (required for View Setup & Configuration)

We also suggest ensuring that your Salesforce integration user has a Role that is higher in the role hierarchy than your reps (so that we can update the Past Lead/Contact who is no longer at company even if there are sharing rules in place).

Lastly, the integration user should have access to any relevant record types on your lead, contact, and account objects.

Report Sharing & Permissions

  • Please ensure that the integration user has access to the "UserGems" report folder as well as any folder containing reports that UserGems should be tracking.
  • The integration user must also have access to all objects/fields referenced within any reports we are tracking (as columns or filters).
    • This includes any references to other objects/fields via Lookup or Formula fields being utilized in the report.

Making Permissions Changes & License Types

"Salesforce Integration" User License Type

  1. First, navigate to the Integration User's user record, then edit its "Permission Set License Assignments" (not "Permission Set Assignments"), and add the default permission "Salesforce API Integration"
  2. Then, create a Permission Set (e.g. "UserGems Integration User Access") with permissions outlined  A couple other notes:
    • DO NOT select a "License" on the "Permission Set" creation screen...leave it as "--None--"
    • DO NOT check the box for "Session Activation Required"
  3. Finally, assign the new permission set to the Integration User

"Salesforce" User License Type

  1. Simply follow the steps to create and assign the Permission Set to this user if not on the System Administrator profile
  2. Create a Permission Set (e.g. "UserGems Integration User Access") with permissions outlined. A couple other notes:
    • DO NOT select a "License" on the "Permission Set" creation screen...leave it as "--None--"
    • DO NOT check the box for "Session Activation Required"
  3. Assign the new permission set to the Integration User

Connecting your Salesforce Integration User

Your CSM will provide the sign-up links for you to access the UserGems application for both yourself and the Salesforce integration user.

To connect your Salesforce Integration User:

  1. Login to Salesforce as your integration user (we suggest using an Incognito window so that there is only one active Salesforce session in your browser). Please note that:
    • You cannot use the "Login As" feature to impersonate a user; you need to actually login as the integration user.
    • You can connect an integration user that has SSO, 2FA, or is API Only. If the User is API only, you will see an error related to that when you login, but you will still be able to successfully authorize UserGems once your session is active.
  2. Then, in the same browser session, follow the signup link provided by your CSM, and simply click “Sign in with Salesforce”

Once your integration user is connected to UserGems, your CSM will approve the connection and you will be notified.

Connecting your Salesforce Integration User (SSO)

If you are an Elite or Enterprise package customer using SSO to log in to UserGems, follow the instructions below to connect Salesforce to UserGems.

  1. Login to UserGems with the Integration User you have set up in your IdP (ex. Okta, Microsoft)
  2. Navigate to Settings > Connected Applications
  3. Click “Connect to Salesforce”
  4. You will be redirected to your Salesforce instance
  5. Login as the Integration User from Step 1 in your Salesforce environment
  6. This could open up a connection settings page or immediately redirect you back to the UserGems application
  7. The Salesforce Connection should show as active

Was this article helpful?