Without a card
The list of reports you can run. The call is still audited.
Connector · Salesforce
PrivacyFence gives an AI assistant read-only access to Salesforce: records, search and reports. It changes nothing in your org, because PrivacyFence offers no Salesforce write. Every record and every report result is shown to you before the assistant gets it.
What the assistant can do
Every Salesforce tool has a gate fixed in code. The Tools reference lists each one.
The list of reports you can run. The call is still audited.
A record by object type and id, a search across one or more object types (the same search as Salesforce's own search bar), and a report's results.
Nothing, because there is nothing to change: the connector has no write tools. The assistant sees only what your own Salesforce user can see.
Personal data
CRM data is where personal data lives. Before a record or a report is shown to you, PrivacyFence scans the field values and report rows on the card locally for likely personal data in English, German and Hungarian: IBANs, card numbers, ID and tax numbers, salary information and similar. Email addresses and phone numbers are deliberately not flagged, because they are in almost every record.
A match sends the read to a card even if an always-allow rule covers it, highlights what was found, and asks for a second confirmation. On a packaged install, approving a flagged read also asks for your passkey. The audit log records the category, never the matched text.
Routine requests
An always-allow rule lets matching reads run without a card, and each one is still audited. For Salesforce, a rule can trust:
Records and searches of the object types you name, for example Opportunity, when every requested type is one of them.
Running the reports you list by id.
Likely personal data in a read still goes to a card. Every scope is in the scope catalogue.
Set it up
Next
Run PrivacyFence on each person's computer, or centrally on a server your organization controls.