Someone on your sales team wants to connect Grit Board — a sales leaderboard that turns the activity reps already log into team competitions. Salesforce requires a one-time admin approval before a new app can connect. This page is everything you need to make that call: it takes about two minutes.
Grit Board reads a few standard objects on a schedule (every 6 hours, plus a manual “sync now”) and aggregates them into per-rep season totals — dials, conversations, meetings, wins, pipeline. It never writes to Salesforce: no field updates, no record creation, no deletes. Every request it makes is a read-only SOQL query.
It does not read email or message content, notes, attachments, contacts, leads, files, or anything outside the four objects above.
Grit Board connects through the standard OAuth web-server flow with PKCE and requests
two scopes: api (REST API access) and refresh_token (so the
connection stays live without re-authorizing). On the approval screen Salesforce lists
these alongside its standard “access the identity URL service” line — that’s how it
tells us which user and org authorized, not an extra permission. Tokens are stored encrypted by our OAuth
infrastructure provider and are deleted the moment anyone disconnects the integration
inside Grit Board. Each customer’s data is isolated to their own workspace.
You stay in control on the Salesforce side too: the connection acts as the user who authorized it, so it only ever sees what that user’s profile can see, and you can revoke it at any time (see section 04). The flip side matters: connect with a user who can see the whole team’s activity — an admin, or a user with “View All” on activities and opportunities. A rep’s login that only sees its own records makes the boards silently undercount everyone else.
The fastest path — you connect it yourself:
Heads up: the approval screen carries Salesforce’s orange “Security Warning” banner. That’s their standard notice for any app not yet distributed through the AppExchange — it appears for every integration at our stage, and the read-only scopes above are the full extent of the access.
Prefer your teammate to hold the connection? Approve the app for the org instead: after their first (blocked) connection attempt, go to Setup → Connected Apps OAuth Usage, find Grit Board, choose Install, and permit the users or profiles you want. Then have them hit CONNECT again — it goes through immediately. (Their blocked attempt ends on a generic Salesforce “OAuth Error” page rather than anything more helpful — that’s Salesforce’s screen, and it’s expected.) One caveat if a teammate holds the connection: per section 02, they need visibility over the whole team’s activity, or the boards will undercount.
The sync needs Salesforce API access. Enterprise, Unlimited, Performance, and Developer editions include it. Professional edition requires the paid “Web Services API” add-on from Salesforce. Group, Essentials, and Starter don’t offer API access. Grit Board tests this the moment the connection is made and names the problem in plain language if the API isn’t available — nothing silently half-works.
To revoke access later: Setup → Connected Apps OAuth Usage → Revoke, or disconnect inside Grit Board’s settings — disconnecting deletes Grit Board’s access tokens. Your Salesforce data is never modified either way.
Write to hello@gritboard.io — a human who can answer security questions reads it. See also our security overview and privacy policy.