Minimum Permissions Required for SFDC Internal User For SSO

Minimum Permissions Required for SFDC Internal User For SSO

Notes
Standard Object Access

The following table defines the required access for the standard object used in this integration:

Object

Access

Notes

User

Read/Edit as needed

Ensure access to required fields for synchronization.


Notes
Administrative Permissions

These permissions are essential for the integration user to interact with external systems and manage internal data visibility.

Permission

Required

Notes

Apex REST Services

Yes

Required for API integration.

API Enabled

Yes

Required for external system communication.

View All Custom Settings

Yes

Needed if Custom Settings values are referenced.


Notes
Field-Level Security (Minimum Required Fields)

The following fields on the User object must have at least Read Access enabled to ensure proper data syncing:

  • FirstName: Required for user identification.

  • LastName: Required for user identification.

  • Email: Essential for communication and unique identification.

  • Additional Fields: Any additional standard or custom fields required if the integration needs to sync extra details.

Notes
Apex Class Access

Access to the following Apex classes is mandatory for the integration to function correctly:

Apex Class

Required

AMPViewAssetSearchController

Yes

AMPWidgetController

Yes


Idea
Additional Notes

  • This permission setup ensures the Internal User can authenticate, interact via REST, and read or update configuration values depending on the setup.

  • Additional Apex classes or fields may be added based on future package updates.