How it works
Connect your org in about ten minutes
Your own External Client App, a user you choose, and an OAuth grant you can revoke at any time. No package to install.
- 1
Create your account
Sign up with your work email. You get 50K free tokens — no credit card.
- 2
Create an External Client App in your org
The setup wizard walks the exact Setup screens and shows the callback URL to paste. About five minutes, once.
- 3
Choose the user it runs as
We recommend a dedicated integration user with a read-only profile, so Salesforce itself enforces that SF2BI can only read.
- 4
Paste the keys and authorise
Paste the Consumer Key and Secret, log in to your own org and click Allow. Dashboards fill from your live org; connect UAT and sandboxes the same way.
Production, UAT and sandboxes
Connect as many orgs as you like — each is its own read-only connection, and you switch between them from the header. Teammates you invite work on the same connections; nobody needs their own Salesforce keys.
Security
Exactly what SF2BI can see
Taken from the code, not from marketing.
How SF2BI connects
You create an External Client App in your own org and authorise it as a user you choose. There is no managed package to install. The handshake is OAuth 2.0 authorization code with PKCE; you can revoke it at any time in Setup → Connected Apps OAuth Usage, or disconnect in SF2BI’s Settings.
OAuth scopes requested
api— Run SOQL queries through the REST API. Salesforce’s api scope does not separate reading from writing, which is why we recommend connecting a user with a read-only profile: then Salesforce itself guarantees SF2BI can only read.refresh_token, offline_access— Keep the connection working without you logging in each time. The refresh token is exchanged for a short-lived access token when a report runs.
What it reads
- Users and licences: User, UserLicense, PermissionSetLicense and its assignments, PackageLicense, UserPackageLicense, Profile
- Permissions: PermissionSet, PermissionSetAssignment, PermissionSetGroup and its components, ObjectPermissions, FieldPermissions
- Logins and sessions: LoginHistory, UserLogin, AuthSession, multi-factor registrations (TwoFactorMethodsInfo)
- Configuration and audit: SetupAuditTrail, Organization, OauthToken, ConnectedApplication, NamedCredential, ExternalDataSource, AuthProvider, SamlSsoConfig, EmailDomainKey (DKIM), and the list of Event Monitoring log files (type, date, size — not their contents)
- Billing: SalesforceInvoice (number, dates, totals, balance) and SalesforceContract (terms, renewal)
- Case and AgentWork are referenced only inside two licence reports, to find which users own a case or handled work in the period. No case or work-item fields are read.
What it never does
- No Account, Contact, Lead, Opportunity or Order records, and no files — not their contents and not their names.
- Nothing is created, changed or deleted: every call is a SOQL SELECT. No Apex, no Metadata API, no package.
- The AI copilot never writes SOQL. It picks one report from the reviewed catalog; your question and the catalog’s descriptions are what the model sees — not your org’s records.
Where your keys and data live
- Your External Client App’s Consumer Key and Secret, the refresh token, your org’s login and instance URLs, and any negotiated licence rates you enter are kept in AWS Secrets Manager (encrypted at rest), one secret per connection under your workspace. Only the SF2BI service can read them.
- Access tokens are never stored: they live in the service’s memory for up to 50 minutes.
- Report results are not stored. To spare your API allocation, an identical report repeated within a minute may be answered from the service’s memory.
- Invoices you upload are kept in a private, encrypted S3 bucket under your workspace, with the extracted lines and reconciliation stored alongside so you can reopen them. You can delete any invoice from the Invoice reconciliation page. The invoice text is read by an AI model on Amazon Bedrock to extract its lines.
- Disconnecting in Settings either clears the refresh token (one-click reconnect) or wipes the connection’s secret entirely — your choice, effective immediately.
- Salesforce tokens, report rows and the text of your questions are never written to our logs.
Full details in our Privacy & security page.
See where your Salesforce spend leaks — and who holds too much access.
Read-only. No package to install. 50K free tokens, no credit card.