NEWFreshservice is now a Ploy integrationSee what shipped
INTEGRATIONSSAAS
Salesforce28 OF 28 CAPABILITIES ASSESSED

Salesforce profiles and permission sets are granted from Ploy

Profiles, permission sets, roles and territories, granted and revoked from Ploy with the licence seats in view.

TYPE · SAASAUTH · OAUTHDOMAIN · SALESFORCE.COM
Salesforce connectorHOURLY SYNCCAPABILITIES
WHAT PLOY DOES
Sync users, their state and last loginEvery Salesforce user arrives with whether the account is still active and when they last signed in.
READ
Discover profiles, roles, permission sets and territoriesLicences, profiles, roles, permission sets, permission-set groups and territories all land as grantable resources in the access graph.
READ
Map who holds which permissionThe profile, role, permission sets and territories behind each user, so an administrator is visible as one rather than reading as an ordinary seat.
READ
Read licence types and seat countsPurchased and available seats for each licence, which is what puts an unused seat in front of someone before the renewal does.
READ
Create usersPloy creates the Salesforce user when policy or an approved request calls for one.
WRITE
Update users and deactivate accountsProfile attributes are written back, and deactivation runs through the same update by clearing the active flag: Salesforce has no separate disable action.
WRITE
Grant and revoke permission sets, roles and territoriesMembership of permission sets, permission-set groups, roles and territories is added and removed from Ploy, so an approval lands where the permission actually lives.
WRITE
Assign and remove admin rolesAdministrative rights are granted and pulled back the same way as any other entitlement, with the same approval and the same record.
WRITE
2.1WHAT IT UNLOCKS

Three jobs this connector does on day one

ACCESS

A permission set is a request, not a quiet edit

Someone asks for a permission set or a territory, the owner approves, and Ploy writes it in Salesforce. The grant can carry an expiry that removes it when the window closes.

REVIEWS

Reviewers see the profile, not just the name

Each row carries the profile, the permission sets behind it and the last login. A revocation executes in Salesforce and lands in the certificate.

LEAVERS

Deactivated on the last day

Offboarding clears the active flag on the Salesforce user and pulls their permission sets, roles and territories with it, verified rather than assumed.

2.3

SETUP

TYPICALLY 10 MINUTES
STEP 01

Authorise the app

An admin approves the Ploy connected app in your Salesforce org. Read only to begin with.

STEP 02

Watch the first sync

Users, profiles, roles, permission sets, territories and licences land in the graph.

STEP 03

Turn on writes

Pick which permission sets and roles Ploy may change, and who approves. Everything else stays read only.

2.4OFTEN CONNECTED TOGETHER
OktaIDENTITY PROVIDERSlackAPPROVALS
BROWSE ALL 62 INTEGRATIONS

Connect Salesforce, see it in 10 minutes.