Salesloft Integration Security Boundary
Overview
This skill reviews how credentials, tenant context, prospect data, mutations, and webhook deliveries move through an integration. It produces remediations tied to evidence and named owners.
Prerequisites
- Architecture, data-flow, scope, and secret inventories
- Named Salesloft teams, environments, and data owners
- Current webhook subscription configuration
- Incident and credential-rotation procedures
Tool Discipline
Use Read, Glob, and Grep to inspect auth, logging, storage, routing, and signature code. Use WebFetch only for official Salesloft security contracts. Use Write or Edit only after the remediation target is confirmed.
Current Contract
- Every API credential is a Bearer secret and must remain server-side.
- Authorization-code refresh rotates the refresh token; client credentials have no refresh token.
- API keys act as the issuing customer user and are not the partner application path.
x-salesloft-signatureis a hex SHA-1 HMAC of the exact request body usingcallback_tokenas the key.- Salesloft does not document a timestamp header in the general delivery-header contract, so do not invent timestamp replay verification.
Authentication
Bind each encrypted credential record to one Salesloft team, flow, scope set, environment, owner, and rotation state. Fail closed when tenant context is missing or mismatched.
Instructions
- Trace credential acquisition, storage, decryption, refresh, injection, revocation, and audit events.
- Verify least-privilege scopes against every used method and path.
- Enforce explicit tenant context across queues, caches, jobs, logs, and database keys.
- Redact Authorization, token, callback-token, email, phone, and CRM fields from diagnostics.
- Verify webhook HMAC over exact raw bytes with equal-length constant-time comparison.
- Validate the event type and callback token, then apply durable deduplication before side effects.
- Test rotation, tenant-confusion, invalid-signature, deletion, and incident paths.
Approval Boundaries
Do not broaden scopes, export customer data, create or revoke credentials, delete Salesloft records, or rotate production secrets without named owner approval and rollback planning.
Output
Return tenant and data-flow findings, scope delta, secret lifecycle, webhook-verification result, redaction gaps, prioritized fixes, owners, and verification evidence.
Error Handling
| Condition | Response |
|---|---|
| Tenant mismatch | Fail closed and investigate cross-team exposure. |
| Signature length differs | Reject before constant-time comparison. |
| Credential exposure | Revoke or rotate, contain logs, and follow incident procedure. |
| Uncertain delete | Stop; Salesloft documents person deletion as not normally reversible. |
Examples
The example below shows the minimum redacted evidence expected from a successful invocation of this operator workflow.
tenant-binding=pass; scopes=least-privilege; webhook-hmac=pass; pii-log-gaps=0