Skip to main content

Overview

DeepMask exposes 8 Salesforce actions: 7 composites that assemble schema, search, summaries, and writes on the server, plus a last-resort SOQL query. Every action runs as the signed-in Salesforce user.
One connection is one org. Record links returned by DeepMask (web_url) are Lightning URLs — open them as-is; do not rebuild Salesforce URLs yourself.
Write actions can create or change records. DeepMask previews changes first (dry_run) and requires confirm for updates, upserts, and multi-record creates. There is no delete.

Schema

Records

Insights

Writes

Fallback


Prerequisites

  • A connected Salesforce org — see Salesforce Integration Setup.
  • The signed-in Salesforce user must have API Enabled and access to the objects you ask about.
DeepMask does not implement its own sharing model. If a record is hidden in Salesforce, it is hidden here.

Common parameters

These appear on most actions.

Typical workflows

Find a record, then read it

1

Search

Ask DeepMask to find the account, opportunity, or case. That uses salesforce_find_records_smart.
2

Open the overview

Ask for everything about one of the results. That uses salesforce_get_record_overview.
3

Open in Salesforce

Use the returned Lightning link (web_url) — do not construct the URL yourself.

Change a field safely

1

Inspect the schema

Confirm the field exists and which picklist values are valid (salesforce_explore_schema).
2

Preview

Ask DeepMask to show the change first. The write runs with dry_run: true and returns a before→after diff.
3

Confirm

Approve the change. Updates and multi-creates require confirm: true.

Daily standup

Ask “What’s on my Salesforce plate today?” — that is salesforce_my_day. Follow up with “How many open opportunities by stage?” for salesforce_summarize_records.

Pagination

salesforce_find_records_smart pages with an opaque cursor (next_cursor in the result). Schema listing uses start + limit. salesforce_query returns one page only — add a LIMIT or tighter filters in the SOQL; DeepMask does not follow Salesforce nextRecordsUrl.

Security & Privacy

  • Delegated OAuth — each user is themselves in Salesforce.
  • No delete capability.
  • Write tools are never silently retried by the AI wrapper (a retry could duplicate creates).
  • Disconnect in DeepMask → Connectors → Salesforce, or revoke the External Client App in Salesforce Setup.
See Salesforce Integration Setup for the External Client App, scopes, and revoke steps.
Questions about data residency, compliance, or security? Contact DeepMask support at support@deepmask.io.