Hi everyone,
I would appreciate some architectural guidance on a Salesforce security requirement.
We need to restrict Sales users from exporting or extracting company-wide financial/reporting data, while they must continue using Salesforce normally, including the Salesforce Mobile App.
Our initial approach was to remove the API Enabled
permission from their corresponding Permission Set Group to prevent API-based extraction tools such as Data Loader or spreadsheet connectors.
Howeever, I would like to confirm with you, if API Enabled is also required for the Salesforce Mobile App, which Sales users need to use.
Therefore, my questions are:
- Is removing API Enabled an appropriate approach for preventing data extraction in this scenario, or would this have unintended consequences beyond the intended restriction?
- What would be the recommended Salesforce architecture to restrict API-based data extraction for Inside Sales while keeping access to the Salesforce Mobile App?
- Would API Access Control / Connected App allowlisting be a better approach, for example allowing Salesforce Mobile while restricting other API clients?
- Are there other Salesforce permissions or security controls that should be considered specifically for preventing report/data export without disabling API access entirely?
The business requirement is specifically to restrict data extraction
, not to prevent Sales users from using Salesforce Mobile or other approved Salesforce functionality.
The focus is on:
- Reports: No creating, editing, cloning, or exporting.
- Dashboards: No access to restricted Turnover dashboards.
- Subscriptions: Prevent receiving Reports/Dashboards via email.
- List Views: Prevent export/print as an extraction method.
- Folder Sharing: Prevent indirect access to restricted Reports/Dashboards.
Any guidance or documentation from Salesforce would be greatly appreciated.
@Salesforce Administrators & Developers, @Salesforce Administrators and Developers, @APAC Architects, @Data Quality & Management
#Trailhead Challenges #Trailhead #Salesforce Developer #Salesforce Admin #Reports & Dashboards
The Salesforce Mobile App doesn't need API Enabled, so removing it won't break mobile. Just check that no other tools your sales team uses, like Outlook/Gmail integrations or AppExchange apps, depend on it.
For extra control, use API Access Control to allowlist only approved connected apps like Salesforce Mobile. Also make sure users don't have "Use Any API Client" or "Approve Uninstalled Connected Apps."
For reports, remove the Export Reports permission and limit report subscriptions. The best protection is still sharing and field-level security: if users shouldn't extract financial data, they probably shouldn't see it at all.