Naxis Technologies Docs
Live demo

Databases & CRM

Set up Salesforce (CRM)

Connect a Salesforce org with your own Connected App. It reads your accounts, contacts, opportunities, cases and leads and how they relate, and turns each into a record the assistant reasons over — account health, open opportunities and their amounts, recent activity — with the tasks, events and files logged against them brought in. Read-only.

Before you start

  1. Documents → Salesforce: enter Instance URL (your org's My Domain) and paste Consumer key (client credentials) and Consumer secret.
  2. Set Org type to Sandbox only when connecting a sandbox — it changes which host sign-ins refresh against.
  3. Under Advanced: Include activity chooses whether tasks, events and their files come in — on by default; Only these objects narrows which of Account, Contact, Opportunity, Case and Lead sync — blank syncs all five.
  4. Choose access groups, Test, then Sync.

What comes in

Org typeProduction or Sandbox — sandboxes authenticate against test.salesforce.com; the wrong choice fails every sign-in refresh.
Include activityWhether tasks, events and their attached files become searchable, or just the records themselves.
Only these objectsOptional — Salesforce object names to sync, one per line; blank syncs Account, Contact, Opportunity, Case and Lead.
Access tokenLast resort — a raw session token for quick testing; expires within hours, unlike the consumer key/secret pair.

Access

Records on an object Salesforce shares openly — the usual default — stay visible to the access groups you choose. Where an object's sharing is set to Private, each of its records instead follows Salesforce's own sharing exactly — its owner, anyone reached by a manual share or sharing rule, and every role above the owner — in place of the chosen groups for that record, not on top of them. Switch How access works to “One list for everything” under Permissions to put everything this source brings in under the chosen access groups instead.

The consumer-key/secret pair never expires on its own; a pasted access token dies within hours, so treat it only as a quick proof of connection. Records, activity and files are each capped at 5,000, and a field the integration user can't see (hidden by field-level security) is simply synced without it, named in the sync summary rather than failing the sync.

Was this page helpful?
Was this page helpful? Sign in with Google Sign in to tell us — or leave a comment.

Last updated 20 Sep 2026