<aside>
💡
Use this guide to set up a dedicated integration (or "service") user for connecting Salesforce with Notion.
</aside>
Step 1: Create an Integration Profile
To begin, create a custom profile that will define the permissions for your integration user:
- In Salesforce, go to Setup → Users → Profiles → New Profile
- Clone an existing profile with base-level access (e.g., Standard User)
- Give it a clear name like “Integration User - API Only”
- Configure the new profile:
-
No Setup Access
-
Access to Reports (”Create and Customize Reports” = ☑️) ← important for Notion to access reports

-
Modify All on the relevant standard and/or custom objects
-
Password Never Expires (recommended — set a calendar reminder to rotate it regularly)
Step 2: Configure Permissions
There are two key areas to configure:
-
Object Permissions
- Go to Setup → Profiles → [Your New Profile] → Standard Object Permissions
- Since the Notion Salesforce integration is read-only, you can leave Create/Edit/Delete unchecked
- Exclude sensitive objects you don't want accessible
- Optionally select "View All Fields" for broad visibility — note: users still won’t see fields that aren't shared via permission sets
- Apply the same approach to Custom Object Permissions
<aside>
⚠️
Note: If you disable certain fields in the integration setup, make sure they’re also restricted in other Salesforce settings like Object Manager, Page Layouts, Field Accessibility, etc. These settings can override your integration configuration.
</aside>
-
Administrative Permissions
Enable ✅
- Apex REST Services
- API Enabled
- API only user (optional — more secure but limits password reset options)
- Password Never Expires (recommended — just ensure you rotate it periodically)
Disable ❌
- All admin-level functions (permission set management, change sets, user creation)
- Security controls (MFA management, password policies)
- Bulk operations like Bulk API hard delete and Weekly Data Export
Step 3: Create the Integration User
When creating the user:
[Optional] Step 3b: Add Field-Level Access with a new Permission Set