Skip to main content

Benefits of connecting Salesforce to Windmill

Connecting Salesforce to Windmill brings sales and customer-impacting work directly into recaps, performance reviews, and 1:1s — without requiring reps or managers to manually summarize activity.
  • Automatically captures deal progress, account work, and follow-through
  • Makes sales activity available for weekly recaps when those activities are relevant
  • Ensures employees get credit for the relationship-building and momentum they drive
  • Reduces prep time for performance reviews and calibration cycles
  • Helps managers coach more effectively using real customer context
  • Makes evaluations more fair, consistent, and grounded in measurable outcomes
Windmill transforms ongoing Salesforce activity into structured insight for coaching, development, and recognition.

Connected data

When Salesforce is connected, Windmill securely reads high-signal revenue and customer interaction data:
Windmill syncs only the fields required to provide performance context — not your entire CRM dataset.

Permissions

Windmill requests only two OAuth scopes from Salesforce: Windmill uses these scopes to read opportunities, accounts, contacts, and activity metadata — it never writes, edits, or deletes any data in Salesforce.
Windmill follows least-privilege access and stores only what is necessary for coaching and evaluation.

Connect with a Salesforce integration user

Use a dedicated Salesforce integration user to control the data that Windmill can read. Salesforce calls this user an integration user. Some teams use the term ISU.
1

Create the integration user

In Salesforce, create a dedicated integration user. Assign the Salesforce Integration user license and the Minimum Access - API Only Integrations profile. See Give Integration Users API Only Access.
2

Assign the permission set license

Assign the Salesforce API Integration permission set license to the user.
3

Create a Windmill permission set

Create a permission set for Windmill. Grant Read access to the Salesforce objects that Windmill syncs.
4

Grant field-level access

In the same permission set, grant Read Access to the fields in the table below. Object access alone is not sufficient.
5

Assign the permission set

Assign the permission set to the integration user.
6

Connect Salesforce to Windmill

Go to Settings > Integrations in Windmill. Select Salesforce and enter your Salesforce Instance URL. Then, sign in as the integration user.

Minimum field-level access

The integration user needs Read Access to these fields: The integration user also needs record access to each record that you want Windmill to sync. Salesforce sharing rules and role hierarchy settings control this access.

Enabling field tracking history

To ensure Windmill can track changes to Salesforce objects, you need to enable field tracking history:
  1. Go to Object Manager in Salesforce
  2. Select the object you want to track (e.g., Lead, Account, Contact)
  3. Go to Fields & Relationships
  4. Click Set History Tracking
  5. Select Enable History
  6. Select the fields you want to track
Enable field tracking for all objects you want Windmill to monitor for activity.

Prerequisites

A Salesforce administrator must prepare the integration user. You also need your Salesforce Instance URL.

FAQs

No. Windmill syncs metadata (e.g., that a follow-up occurred), not message bodies.
No. Windmill does not provide a pipeline, team, or object selector. The integration syncs its supported Salesforce data for records that the connected account can read. Use a Salesforce account with limited access if you must limit the scope.
Yes. When Salesforce is connected, Windy can use synced activity and stats, including logged calls, to inform weekly recaps when that context is relevant.Asking Windy to include Salesforce call metrics in a single recap does not save that request as an ongoing rule. For future recaps, ask again during recap confirmation or reuse a saved skill.
No. The integration is strictly read-only.
Approximately once per hour. Updates appear after an incremental sync.
Yes. All data is encrypted in transit and at rest. Windmill maintains SOC 2-level security standards and uses scoped OAuth tokens.
Their historical contributions remain visible for review context, but Windmill stops attributing new work once they are deactivated.