Skip to main content
When you connect Salesforce, you’ll see an OAuth screen listing a broad set of permissions, along with a warning about the scope of access being granted. That warning is standard Salesforce behavior for any app requesting this breadth of access — it isn’t unique to Piper, and it doesn’t mean anything is misconfigured. Piper’s Connected App requests the same fixed set of permissions for every customer, regardless of which Salesforce products your org actually has. That’s because one app definition serves every Piper customer, across every Salesforce edition and license mix. So you may see permissions tied to products you don’t use — those simply go unused if you don’t have the matching license.

What Piper Actually Requests

In broad terms, the permissions fall into two groups: Core access — used by every Piper customer, on any standard Salesforce edition with API access:
  • Reading and writing records for Contacts, Accounts, Opportunities, and Leads, so Piper can log meetings, sync notes, and fill deal fields.
  • Confirming who’s signed in and issuing a refresh token, so you don’t have to reauthenticate constantly.
  • Standard API and browser-based session access, including posting to Chatter feeds.
Product-specific access — only relevant if your org already has these Salesforce add-ons licensed. If you don’t, these permissions are simply unused:
  • Data Cloud — customer profile data, segmentation, and identity resolution.
  • Pardot / Account Engagement — marketing automation data.
  • CRM Analytics (Tableau CRM) — dashboards and datasets.
  • Agentforce / Einstein — generative AI and agent-to-agent features.

Who Can Approve the Connection

This depends on your org’s own Connected App policy, not on anything Piper controls:
  • Self-authorize orgs — any logged-in user can approve the connection for themselves.
  • Admin-approved orgs — only users already assigned to a pre-authorizing profile or permission set can complete the connection.
Separately, Salesforce’s 2025 security update means the first person to connect an uninstalled Connected App needs the Approve Uninstalled Connected Apps permission (included in the standard System Administrator profile). After that person connects, an admin can install the app from Setup → Connected Apps OAuth Usage, and the rest of the team can connect normally.
Have your Salesforce admin complete the first connection, then install the app for the team — this avoids the generic approval error non-admins can hit on uninstalled apps.