Integration guide

Salesforce integration for AI agents and workflows

Swfte Studio has a Salesforce node. Its shipped data shows three actions on leads: query leads, create a lead and get a lead back by its id. A workflow can read your pipeline freely and ask a person to approve before it adds a record.

That is the whole action list this page claims. The shipped template’s description also mentions updating a lead, but its nodes do not do it, so the designs below do not rely on updates. The catalogue lists Salesforce under sales and communication.

Built in Swfte Studio, run as a governed workflow, and held to the same rules as any governed agent.

Salesforce at a glance

Catalogue
Sales, Communication
Actions in the shipped data
3 (2 read, 1 write)
Credential type shown
salesforceOAuth2Api
MCP server
None in the MCP tool list
Shipped templates that use it
Salesforce Lead Workflow

What you can do with Salesforce

Every action below is read from a node in a shipped workflow template. Nothing is listed that the data does not show.

Salesforce actions in the shipped workflow templates
ActionTypeOperationWhat the data shows
Query LeadsReadlead.getAllQueries leads. The shipped template asks for ten and does not return them all.
Create LeadWritelead.createCreates a lead from fields prepared earlier in the workflow.
Get Created LeadReadlead.getFetches the lead that was just created, so the workflow can confirm the write before it reports success.

The object in every action is the lead. Other Salesforce objects may be available in the node, but they are not shown in Swfte’s shipped data, so check the node panel in Studio before you design around one.

The template starts from a manual trigger. A Salesforce-side event, such as a new lead being created, is not in the data: <Salesforce trigger events - founder to fill>.

Why a CRM needs more care than most tools

A CRM holds the records a sales team is measured on: who the lead is, who owns it and what has been said to them. Two agents creating the same lead, or one agent creating a lead the owner has already disqualified, costs time. Where personal data is involved it also creates records that somebody has to find and correct later.

Reading is the safe half. Querying leads changes nothing, and the shipped template caps its query at ten results. Writing is where the controls belong: a created lead enters the pipeline, can trigger whatever assignment rules your Salesforce admin has set, and is visible to the sales team.

How to connect Salesforce

The shipped template names the credential type salesforceOAuth2Api, which is an OAuth 2 connection rather than a pasted key.

  1. 01

    Authorise the connection

    Create a Salesforce credential in Studio and complete the OAuth sign-in with an account that has the access the workflow needs and no more. A dedicated integration user is easier to audit than a person’s own login.

  2. 02

    Check what that user can see

    A workflow reads what its Salesforce user can read, so the field and record visibility you set in Salesforce carries through to every run.

  3. 03

    Query before you create

    Run the query action on its own and read the ten results before you add the create step.

  4. 04

    Gate the write

    Place a human-input step before the create action, addressed to sales operations or the owner of the lead queue.

Three governed Salesforce workflows to build in Studio

Each has a label. A starting point builds on a shipped template, which is an integration test with no approval step. A design is intent only.

Inbound lead intake with a duplicate check

Starting point

Builds on the shipped template “Salesforce Lead Workflow” (6 nodes), which you can find in the template library.

Add a new web-form lead only after a person has seen that it is not already in the pipeline.

  1. A prepare step shapes the form fields into a lead.
  2. The query action looks for leads that could be the same person.
  3. A switch node sends probable duplicates to a human-input step for sales operations. While the rules are new, clear cases go to approval as well.
  4. On approval, the create action adds the lead and the get action reads it back to confirm.

Where the approval sits. The shipped template creates its lead with no gate and no duplicate check. Both are yours to add, and what counts as a probable duplicate is a decision for your sales operations lead.

Weekly lead-quality note for the sales manager

Designed

Give a manager a plain-English read of the week’s leads without anyone exporting a report.

  1. The query action reads the latest leads.
  2. An LLM node groups them by the fields you choose and notes obvious gaps, such as a missing company.
  3. The note goes to the manager through an output step. Nothing is written to Salesforce.
  4. A policy rule redacts personal fields before the text reaches the model, if your data rules require it.

Where the approval sits. Because it only reads, it needs no approval step. What the model is allowed to see is the control that matters.

Lead hand-off message to the owner

Designed

Tell the owning rep, in Slack, that a lead needs a first touch, with the facts they need to start.

  1. After an approved create, the get action reads the lead back.
  2. An agent drafts a two-line hand-off that names the source and the stated need.
  3. For sensitive leads, a human-input step lets sales operations approve the wording first. Ordinary leads skip it.
  4. The Slack post-message action sends the note to the team channel.

Where the approval sits. The first message to each channel needs approval. After enough clean runs you can raise the threshold so only unusual leads need a person, and you should record that decision.

Shipped template
A governed template with its approval step already in it ships in the platform.
Starting point
A shipped template runs the same actions. It is an integration test with no approval step, so you add the gate.
Designed
Design intent. It uses the actions listed above plus generic nodes, and nothing has been built as a template.

Approvals and records for Salesforce

Salesforce is the system of record for customers and prospects. Treat every write as a change to that record.

Needs a person’s approval

  • Creating a lead from any source the team has not used before.
  • Any run that reads lead fields containing personal data and sends them to a model.
  • Widening the query beyond the owner’s own pipeline.

Can run without one

  • Querying leads to build a read-only note for the sales manager.
  • Fetching a lead that the same run created, to confirm it exists.

What is recorded

  • The query and the create actions, in order, for each run.
  • Who approved a create, and when.
  • The policy decision taken before a create: allow, redact, ask or deny.

Salesforce has its own permission model and Swfte does not replace it. The credential decides what the workflow can reach, and the approval step decides whether it should. Where two different people matter, such as requester and approver, assign the gate to a second person yourself: the platform does not check this for you.

A policy step in a design below describes the intent. The policy engine acts only on runs that have a policy attached, and a self-serve way to author policies is not something we describe as built.

Swfte’s own security position and any attestations are on the trust page. How approvals, policy and records fit together is on the governed agents page.

Comparing tools for Salesforce work

These comparison pages are dated and sourced. Each says who should pick the other tool.

  • Agentforce alternatives

    Agentforce is Salesforce’s own agent product. The comparison covers when staying inside Salesforce is the better choice.

  • Workato alternatives

    Workato is an enterprise integration platform. The comparison sets out where Swfte differs.

  • Best automation platforms

    How automation platforms compare on governance, approvals and records, with the method shown.

Salesforce questions

Can Swfte update an existing Salesforce lead?

The actions in Swfte’s shipped data are query, create and get on leads. The shipped template’s description mentions an update, but its nodes do not contain one. Check the Salesforce node in Studio before you design a workflow that depends on updates.

Does the Salesforce connection use OAuth?

The shipped template names the credential type salesforceOAuth2Api, so the connection is an OAuth 2 credential. The scopes are set when you authorise it, so use an integration user with narrow access.

Can an agent create leads without a person approving?

It can if you build it that way, because the approval step is something you add. We recommend a gate at first, and the template shows why: its create step runs with no check at all. Where your policy allows, you can later reduce approval to leads above a risk threshold.

Is there a Salesforce template to start from?

One: the Salesforce Lead Workflow, which queries leads, creates one and reads it back. It is an integration test, so it has no approval step and no duplicate check. Treat it as a starting point.

What is recorded when an agent writes to Salesforce?

The run ledger records the policy decisions, approvals and actions for the run, including the create action. It sits alongside Salesforce’s own field history and does not replace it. There is no dedicated ledger export yet.

Build a governed Salesforce workflow

Begin with a read-only workflow on a test account, then add one write with an approval in front of it.

Build this in Studio

Describe what you need in plain language. Studio builds the agents and workflows, and you keep every version.