Tighten your agents' guardrails in your customers' Salesforce with External Client Apps | Ampersand Changelog

Tighten your agents' guardrails in your customers' Salesforce with External Client Apps

Enterprise buyers are getting stricter about what third-party agents can access. They want integration permissions to be least-privilege, and are more hesitant to hand over their master keys.

Until now, the standard path was a Salesforce Connected App, which required the customer’s admin to grant “Use Any API Client” access. Many enterprise security teams are now reluctant to approve this high-privileged access.

Now Ampersand supports deploying your Salesforce integration through External Client Apps (ECAs). Once you’ve set up your ECA, it ships as a managed package that each of your customers installs into their own org.

Because the app lives inside their org, the customer’s admin installs it directly, with no org-wide “Use Any API Client” master key.

Setting it up

1
Create your ECA

Register an External Client App in Salesforce.

2
Package it

Publish it as a managed package and get an install URL.

3
Customer installs

Your customer's admin installs the package into their org.

4
Connect

They authorize, and your integration is live with scoped access.

Salesforce has phased out creating new Connected Apps, so your agents will need to move to External Client Apps. Ampersand still supports existing Connected Apps, so you can migrate on your own timeline.

A new take on native product integrations