ORG permissions

Permissions the connected user needs

Stood Flows is read-only. The connected org user needs visibility on what you want to analyse, nothing more:

A dedicated read-only integration user with these permissions is the cleanest setup. Anything Stood Flows writes lands on your local machine — never on the org.

Authorize Salesforce CLI

CLI App must be authorized for the ORG: https://developer.salesforce.com/docs/atlas.en-us.sfdx_dev.meta/sfdx_dev/sfdx_dev_auth_web_flow.htm

For that one admin may need to initiate a CLI login from a shell:

sf org login web --alias my-org

Once the CLI is authorized, more actions or permissions appear in "Connected Apps OAuth Usage" (load actions > install for more options) or "Manage connected apps"

Capture d’écran 2026-07-29 à 11.19.57

Published with Nuclino