Skip to main content

Hi everyone,

I would appreciate some architectural guidance on a Salesforce security requirement.

We need to restrict Sales users from exporting or extracting company-wide financial/reporting data, while they must continue using Salesforce normally, including the Salesforce Mobile App.

Our initial approach was to remove the API Enabled

permission from their corresponding Permission Set Group to prevent API-based extraction tools such as Data Loader or spreadsheet connectors. 

Howeever, I would like to confirm with you, if API Enabled is also required for the Salesforce Mobile App, which Sales users need to use.

Therefore, my questions are:

  1. Is removing API Enabled an appropriate approach for preventing data extraction in this scenario, or would this have unintended consequences beyond the intended restriction?
  2. What would be the recommended Salesforce architecture to restrict API-based data extraction for Inside Sales while keeping access to the Salesforce Mobile App?
  3. Would API Access Control / Connected App allowlisting be a better approach, for example allowing Salesforce Mobile while restricting other API clients?
  4. Are there other Salesforce permissions or security controls that should be considered specifically for preventing report/data export without disabling API access entirely?

The business requirement is specifically to restrict data extraction

, not to prevent Sales users from using Salesforce Mobile or other approved Salesforce functionality. 

 

The focus is on:

  • Reports: No creating, editing, cloning, or exporting.
  • Dashboards: No access to restricted Turnover dashboards.
  • Subscriptions: Prevent receiving Reports/Dashboards via email.
  • List Views: Prevent export/print as an extraction method.
  • Folder Sharing: Prevent indirect access to restricted Reports/Dashboards.

Any guidance or documentation from Salesforce would be greatly appreciated. 

 

@Salesforce Administrators & Developers, @Salesforce Administrators and Developers, @APAC Architects, @Data Quality & Management

 

 

#Trailhead Challenges  #Trailhead  #Salesforce Developer  #Salesforce Admin  #Reports & Dashboards

1 resposta
  1. 25 de set., 17:08

    Hi Lena, 

    Yes, removing API Enabled would impact the Salesforce Mobile App, since the mobile app requires API access. So I wouldn’t use that permission alone as the control for this requirement.  

     

    A better approach is to keep API access for the users who need Salesforce Mobile and use API Access Control to restrict API access to only approved/allowlisted connected apps. Salesforce supports this model specifically for limiting API access while allowing approved apps.  

     

    For report extraction, also control the Export Reports permission separately. Removing that permission prevents users from exporting report data, while folder sharing and report/dashboard permissions can be used to restrict access to sensitive content. 

    I’d therefore treat this as multiple layers: API Access Control + Report/Folder permissions + Export Reports + subscription/access controls, rather than disabling API access entirely. 

0/9000