M ManySignal
MS
SF
Integration

Salesforce Integration

Salesforce Event Monitoring and Shield audit ingestion for CRM security.

What this integration does

Salesforce meets agentic SOC

Salesforce Event Monitoring provides granular logs of user activity, API calls, report exports, and login events. ManySignal ingests Salesforce event logs via the EventLogFile API and Salesforce Shield Real-Time Event Monitoring, enabling detection of CRM data exfiltration, compromised user accounts, and insider threats targeting customer and revenue data.

Salesforce EventLogFile API ingestion for all event log types

Real-Time Event Monitoring via Salesforce Shield Streaming

Login anomaly and new session IP detection

Data collected

  • Login event logs with session details, IP, and MFA status
  • Report run and export events with record count
  • API call logs for REST, SOAP, and Bulk API
  • Lightning component interaction events
  • Connected app OAuth grant and revocation events

Actions supported

  • Terminate active Salesforce user sessions via API
  • Reset user password and force re-authentication
  • Revoke OAuth access token for a connected app
  • Alert on report export exceeding row threshold

Getting started

Set up in minutes

  1. 1

    Enable Event Monitoring

  2. 2

    Create a Connected App

  3. 3

    Configure ManySignal connector

  4. 4

    Set data export alert thresholds

Salesforce Integration: frequently asked questions

Is Event Monitoring included in all Salesforce editions?

Event Monitoring is a paid add-on for Enterprise and Unlimited editions. Basic login history is available in all editions without Event Monitoring. Salesforce Shield provides real-time streaming events.

How frequently are EventLogFiles available?

Hourly EventLogFiles are available within 3 hours of occurrence. Daily EventLogFiles are available the following day. ManySignal ingests hourly files for near-real-time detection.

Can ManySignal detect CRM data exfiltration?

Yes. ManySignal detects mass report exports, bulk API calls extracting large record sets, and data loader usage outside approved IP ranges as data exfiltration indicators.

Does this work with Salesforce sandboxes?

Yes. Configure a separate connector for each Salesforce org (production, sandbox, scratch orgs) using distinct Connected App credentials.

What is Salesforce Shield and how does it differ?

Salesforce Shield adds Field Audit Trail (field-level history), Platform Encryption, and Real-Time Event Monitoring. ManySignal supports all three: EventLogFiles (standard Event Monitoring) and Shield Streaming events.

Can ManySignal detect when a Salesforce admin adds a new user?

Yes. User provisioning events appear in the Setup Audit Trail log type in EventLogFiles. ManySignal ingests these and alerts on unexpected admin-level user creation.

How are Lightning Community (Experience Cloud) events handled?

Salesforce Experience Cloud events appear in EventLogFiles as distinct event types. ManySignal ingests Guest User login attempts, which are a common attack surface.

Does ManySignal support Salesforce connected to external identity providers?

Yes. When Salesforce uses an external IdP (Okta, Entra ID) for SSO, ManySignal correlates Salesforce login events with the IdP authentication events for complete context.

Can I monitor Salesforce API access from third-party applications?

Yes. Connected app OAuth events and API event logs include the connected app name and API user, enabling monitoring of third-party integration activity.

What is the response time from event to ManySignal detection?

For hourly EventLogFiles: up to 3 hours. For Salesforce Shield Real-Time Event Monitoring: under 2 minutes. Shield streaming is recommended for high-priority security monitoring.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.