Skip to main content
Connecting Salesforce takes about ten minutes and happens in two places: you create an app inside Salesforce, then paste the values it gives you into the Brilo app store. Brilo checks the details with Salesforce before saving them, so you know it worked before you leave the screen.

Before you start

  • Administrator access to the Salesforce org you want to connect.
  • An integration user with the API Enabled permission and read access to Contacts. On Enterprise Edition, Salesforce recommends an API Only User. Most teams use a dedicated integration user rather than a person’s own login.
  • Your My Domain URL. In Salesforce: Setup, then Company Settings, then My Domain, then Current My Domain URL. It looks like https://acme.my.salesforce.com.
  • Access to the App Store in your Brilo dashboard. See Plans and what they include.

Steps

Before you change anything in Salesforce, open the App Store in your Brilo dashboard and check that Salesforce is listed. Salesforce is switched on for each workspace, so if you cannot see it, contact support@brilo.ai and ask for it to be turned on before you go further.
1

Create an External Client App

In Salesforce, go to Setup, type External in the Quick Find box, and open External Client App Manager. Click New External Client App and fill in the basics.
Local is correct. It means the app stays inside your own org, which is what you want.
2

Turn on OAuth and add the callback URL

Expand API (Enable OAuth Settings) and tick Enable OAuth.For Callback URL, enter:
Brilo never actually sends you to that address. Salesforce refuses to save an app with an empty Callback URL, so it has to be filled in.
For OAuth Scopes, move across only Manage user data via APIs (api). Leave refresh_token and offline_access alone, because Salesforce ignores them for the connection type Brilo uses.
3

Enable the Client Credentials Flow

Under Flow Enablement, tick Enable Client Credentials Flow, then click Create.Salesforce can take up to 30 minutes to make a new app available, though it is usually much faster.
4

Copy the Consumer Key and Secret

Open your new app, go to the Settings tab, expand OAuth Settings, and click Consumer Key and Secret. Copy both. You will paste them into Brilo in step 7.
5

Set the Run As user

From the actions list for your app, choose Edit Policies. This is a different screen from Edit Settings, and skipping it is the most common setup mistake.Under OAuth Policies, tick Enable Client Credentials Flow again here, enter your integration user’s username in Run As, and save. The username looks like an email address.
Step 3 tells Salesforce the app is capable of this flow. This step tells Salesforce your org permits it, and which user Brilo acts as. Both are required.
6

Relax IP restrictions, if your org uses them

Still on the Policies tab, if your org restricts logins by IP range, set IP Relaxation to Relax IP restrictions.Skip this step if your org does not use IP restrictions.
7

Connect in Brilo

In your Brilo dashboard, open the App Store, choose Salesforce, and click Connect.Click Continue, then Test connection. Brilo checks the details with Salesforce before saving them. When the test passes, click Install App.

You will know it worked when

  • The test passes and the Install App button becomes available.
  • Brilo shows Successfully connected your Salesforce account! with an Add to an agent button.
  • A Salesforce action added to your agent runs on a test call. See Update your CRM.

What you can do once connected

Each item below is an action you add to an agent on its Actions tab, and it runs as the Run As user you set in step 5. Add only the ones that agent needs. The actions fall into five groups. For setups that use these actions, see Update your CRM and Qualify leads on the call.

If it did not work

Brilo tells you which of these it was. If the app was created less than 30 minutes ago, wait and try again before changing anything. Salesforce takes time to make a new app available. Anything else: An action did not run.

FAQ

Yes. Connect your Salesforce org from the app store using the steps on this page, and your agent can work from the contacts and records your team already keeps there. Setup takes about ten minutes and needs administrator access to Salesforce.
You need a Salesforce edition that allows API access, which rules out the entry level editions. Enterprise Edition and above are fine. Check with your Salesforce administrator if you are not sure which edition your org is on, before you start the setup.
No, but you do need a Salesforce administrator. Every step happens in the Salesforce Setup screens and the Brilo app store, and nothing has to be written or installed. Budget about ten minutes for the whole setup. See Do I need a developer.
Brilo acts as the integration user you set under Run As, so it can do exactly what that user can do and nothing more. Give that user the minimum access your actions need, which for most setups is read access to Contacts.
The usual causes are a Run As user missing from Edit Policies in step 5, and an app created less than 30 minutes ago that Salesforce has not made available yet. Both show up at the test stage, before anything is saved. Work through the table above, which names what Brilo reported and what to change.
No. A workspace holds one Salesforce connection. To use a different org, remove the existing connection from the Salesforce page in your app store, then connect the other org with the steps on this page. Actions you already added keep their settings, so check each one points at what the new org expects.
Disconnecting removes the connection from your workspace. Everything already written into Salesforce stays, because those records belong to Salesforce. To cut off access completely, also delete the External Client App in Salesforce, which retires its Consumer Key and Secret so they can never be used again.
Your Consumer Key and Secret are encrypted before they are stored and are only ever used to reach your own org. Brilo never asks for a Salesforce password. It requests a fresh access token whenever Salesforce stops accepting the old one, so you never have to sign in again.