Salesforce Read-Only Capability Proof
Overview
Prove the selected principal, org, API version, object entitlement, and field visibility before any record mutation is considered.
Prerequisites
- An authorized non-production org and secret reference
- Expected org identity, principal, object, fields, and business owner
- Current REST API and authorization documentation
Tool Discipline
Use Read, Glob, and Grep to inspect approved repository and evidence files, WebFetch to re-check current first-party Salesforce documentation, and Write or Edit only for secretless plans, fixtures, configuration, and redacted receipts.
Current Contract
The REST Versions resource lets a client discover versions instead of hard-coding one. Resources, objects, fields, CRUD, sharing, and limits remain org- and principal-specific.
Authentication
Use the approved OAuth client and principal from the onboarding decision. Keep access and refresh tokens out of commands, files, prompts, logs, screenshots, and receipts.
Instructions
- Record the expected org, environment, principal, My Domain, object, fields, and success criteria.
- Resolve credentials only through the approved secret mechanism and verify the returned org identity.
- List supported REST versions and select a supported version allowed by the customer contract.
- Discover available resources, then inspect object metadata and field accessibility for the intended read.
- Run one bounded read-only query with non-sensitive fields and an explicit row limit.
- Preview any proposed create or update with validation, duplicate, automation, ownership, and rollback effects.
- Return a redacted receipt and request separate approval before executing a mutation.
Approval Boundaries
Do not create, update, delete, undelete, merge, or expose records during the proof. Any mutation requires object-owner approval and a recoverable test case.
Output
Return org and principal verification, selected API version, visible resource and field evidence, query result counts, mutation preview, and next approval.
Error Handling
| Condition | Response |
|---|---|
| Org identity differs from expectation | Stop and revoke or isolate the credential before any further request. |
| Object or field is unavailable | Treat the metadata response as authoritative for this principal and revise the request. |
| Read triggers sensitive-data exposure | Discard the data securely and repeat with minimum non-sensitive fields. |
Example
A redacted completion receipt might look like this:
org=developer-sandbox; identity=matched; api=discovered-supported; object=Account; fields=minimum; rows=1; mutation=not-run
Resources
Next Steps
Run the workflow first in the lowest-risk authorized org and preserve its redacted receipt. Schedule a review against the next Salesforce seasonal release and the customer change calendar.