# Connect Salesforce

> Connect the Salesforce org a push writes to, by signing in to Salesforce as the user sanda writes as.

A push writes into a Salesforce org you connect once. You connect by signing in to Salesforce and allowing sanda. There is no app to create in your own org and nothing to copy.

## Before you start

- **Choose who sanda writes as.** sanda can change exactly what the Salesforce user you sign in as can change, field by field. Use a Salesforce integration user (the API-only licence) rather than a person's own login, and give it edit access to only the fields your pushes write. Then a push never depends on one person staying in the job, and sanda's access is as narrow as you choose.
- **Let that user allow sanda.** Your org hasn't installed sanda's app, and Salesforce only lets a user allow an app the org hasn't installed if the user holds the **Approve Uninstalled Connected Apps** permission. A Salesforce admin can give it to the integration user.
- **Be an owner or admin in sanda.** Only owners and admins connect an org.

## Connect an org

:::steps
1. **Open Push.** In the console, go to **Activate · Push**.
2. **Start connecting.** Press **Connect Salesforce**. For a Salesforce sandbox, press **Connect a sandbox** instead.
3. **Sign in to Salesforce.** Salesforce asks which user to sign in as even when this browser is already signed in to Salesforce, because the org open in another tab is often not the one you mean. Sign in as the user sanda should write as.
4. **Allow sanda.** Salesforce shows what sanda asks for: to manage data through the API, and to do so at any time. Press **Allow**.
5. **Check the org.** You land back on **Push** with a note naming the org and the user. The org is listed under **Salesforce orgs**, marked **connected**.
:::

Connect each org once, however many pushes write to it. Connecting the same org again keeps its pushes and replaces the old connection.

## If connecting doesn't finish

You land back on **Push** with a sentence saying what happened, and nothing is connected.

| What happened | What to do |
|---|---|
| You pressed **Deny** on Salesforce's screen | Press **Connect Salesforce** again and choose **Allow**. |
| sanda couldn't match Salesforce's answer to the tab | Connecting started in another tab or another workspace, or was left too long before it finished. Press **Connect Salesforce** again from this tab. |
| Salesforce refused, or didn't finish signing sanda in | Try again. If it happens again, sanda support can see why. |
| Only owners and admins can connect | Ask an owner or admin of the workspace. |

## What sanda keeps

- **One token per org**, which lets sanda sign in to Salesforce for a run. It is stored encrypted, used only to start a run or read your objects and fields, and never shown in the console.
- **The org's name and address, and the user you signed in as**, shown under **Salesforce orgs**.
- **The org's API usage at its last reading**, shown beside the org, so you can see how much of the day's allowance is left. See [your API allowance](https://docs.sanda-os.com.au/push/runs#your-salesforce-api-allowance).

## Connect again

Salesforce can stop accepting sanda's connection: an admin revoked it, a policy expired it, or the user sanda signs in as was deactivated. The org is then marked **connect again**, and its pushes are skipped, not failed, until you connect it again. The first run after catches up.

The run that found it fails and says so, and owners and admins get the failed-run email if it is turned on (see [when runs fail](https://docs.sanda-os.com.au/push/runs#when-runs-fail)). It doesn't count toward a push pausing itself, because the cause is the org's connection rather than the push. To carry on, press **Connect again** beside the org and sign in as before.

## Disconnect

:::steps
1. **Find the org.** Go to **Activate · Push**. The org is under **Salesforce orgs**.
2. **Disconnect.** Press **Disconnect** beside it, then **Disconnect** again to confirm.
:::

sanda revokes its token at Salesforce and forgets it. The pushes that write to the org stay, marked **waiting**, and run again once you connect it. Nothing in Salesforce changes: the values pushes already wrote stay where they are.
