> For the complete documentation index, see [llms.txt](https://docs.kernel.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.kernel.ai/integrations/salesforce-integration/package-installation-guide.md).

# Package Installation Guide

## Kernel Salesforce integration installation and setup guide

<figure><img src="/files/tUmN6tC7DMvLJLRJbPhH" alt=""><figcaption></figcaption></figure>

The Kernel team will create an environment and logins for you. You can access this via [app.kernel.ai](https://app.kernel.ai).

## Upgrade an existing installation

Use this path when the **Kernel SF Connected App** package is already installed and you want the latest features.

1. In Salesforce, go to **Setup → Installed Packages** and note the installed Kernel SF Connected App version.
2. In the Kernel app, open your Salesforce integration and select the current package install link.
3. Salesforce recognises the existing package and opens the upgrade flow. Review the package details and continue.
4. Choose **Install for All Users**. This makes the packaged Kernel components, including the structured feedback form, available to end users.
5. Wait for the **Install Complete** confirmation.
6. Return to **Setup → Installed Packages** and confirm the new version.
7. Assign **Kernel Readonly PermissionSet** (`Kernel_Readonly_PermissionSet`) to every user who should access Kernel features in Salesforce, then review any feature-specific page-layout steps in the relevant guide.

For structured feedback, upgrade to **version 3.11.4 or later**, choose **Install for All Users**, assign **Kernel Readonly PermissionSet** to every intended user, and add the **Send Kernel Feedback** action to the Account page. See [Send Kernel Feedback](/integrations/salesforce-integration/report-data-issues.md) for the complete setup and test flow.

{% hint style="info" %}
Package upgrades preserve your existing Kernel connection. You do not need to recreate the integration user or repeat the authorization flow unless Salesforce or the Kernel app prompts you to reconnect.
{% endhint %}

### Step 1: Your instance

You will need to select your CRM and then input your instance URL. This can be a production or sandbox environment. Then press continue.

<figure><img src="/files/9Ck74yg3MStxMNRcKK0l" alt=""><figcaption></figcaption></figure>

This will provide you with the install link for the Kernel package in your CRM. Click to open the install.

<figure><img src="/files/CxLOytnUTCxfmOCuw2tI" alt=""><figcaption></figcaption></figure>

### Step 2: Package configuration

### Prerequisites

* **Salesforce System Administrator** access in your target org
* **Package version**: Use the install link generated in Kernel. The link points to the current released package for your org.

{% embed url="<https://www.loom.com/share/9e212693e9174468b7d7f26707a1878c?sid=cb71e5bc-1aa6-4508-b634-d83ff2113feb>" %}

**Select installation options:**

* Install for: **All Users**

{% hint style="warning" %}
Choose **Install for All Users**, even if only a selected group will use Kernel. This makes the packaged forms and components visible to end users. You will control which users can access them by assigning the appropriate Kernel permission set after installation.
{% endhint %}

* You will be prompted to grant the Kernel API access to the user & permission set you create. (This allows us to sync your CRM to Kernel and we only have access based on Permission Sets)

<figure><img src="/files/DwGtxvNSgFl4GhHCPRp0" alt=""><figcaption></figcaption></figure>

* Click **Install**

<figure><img src="/files/dbUwyZGpvz6zO4wOyQXZ" alt=""><figcaption></figcaption></figure>

* Wait for "Install Complete" confirmation

<figure><img src="/files/WFrmXzmEzjKGY0Z8e6fT" alt=""><figcaption></figcaption></figure>

**Verify installation:**

* Navigate to **Setup → Installed Packages**

<figure><img src="/files/hSJRSQugepxnpXKF1qlG" alt=""><figcaption></figcaption></figure>

* Confirm "Kernel SF Connected App" appears with status "Installed"

<figure><img src="/files/zQ7lp3eelTMoXXejn1E7" alt=""><figcaption></figcaption></figure>

#### Assign end-user access

Assign **Kernel Readonly PermissionSet** to every user who should access Kernel features, including the structured feedback form.

1. In Salesforce Setup, go to **Permission Sets**.
2. Open **Kernel Readonly PermissionSet** (`Kernel_Readonly_PermissionSet`).
3. Select **Manage Assignments**, then **Add Assignments**.
4. Select the users who should have access and click **Assign**.

The permission set includes the **Kernel: Submit Feedback** permission and the access required to open the feedback form. Installing for all users makes the packaged components available; the permission set controls who can use them.

**Open App Launcher** (9-dot grid icon)

<figure><img src="/files/K5W1EAszsTjlm2PxfFPR" alt=""><figcaption></figcaption></figure>

1. **Select "Kernel Integration"** app
2. **Click the "Kernel Setup"** tab

### Step 3: Create integration user

The integration user is a dedicated System Administrator account that Kernel uses to access your Salesforce data securely.

#### Creating the user

1. **In the Kernel Setup tab**, locate the **Integration User** panel
2. **Review default settings:**
   * Email: `integrations@kernel.ai`
   * First Name: `Kernel`
   * Last Name: `Integration`
   * Username Prefix: `kernel-integration`
3. **Click "Create Integration User"**

   * The system creates a unique username: `kernel-integration@{OrgId}.kernel.ai`
   * A password reset email is sent to the specified email address
   * The user is created with the System Administrator profile. This is for authorizing the app/user and can be changed to minimum access after a successful connection.

   <figure><img src="/files/kdxrTLJmwlpKTfh1DNkv" alt=""><figcaption></figcaption></figure>
4. **Verify user creation:**

   * You'll see a success message with the user details

   <figure><img src="/files/ItBusdPtZ6LEVfJnjdr8" alt=""><figcaption></figcaption></figure>

#### Permission set assignment

| Object            | Read                     | View-All                 | Edit              |
| ----------------- | ------------------------ | ------------------------ | ----------------- |
| Account           | ✓ (All or select fields) | ✓ (All or select fields) | ✓ (Kernel fields) |
| Lead\*            | ✓ (All or select fields) | ✓ (All or select fields) | ✓ (Kernel fields) |
| Contact           | ✓ (All or select fields) | ✓ (All or select fields) | <p><br></p>       |
| Opportunity       | ✓ (All or select fields) | ✓ (All or select fields) | <p><br></p>       |
| **Task/Activity** | ✓ (All or select fields) | ✓ (All or select fields) | <p><br></p>       |
| SystemUser        | ✓ (Limited fields)       |                          |                   |

The system automatically assigns the `Kernel_SF_Connected_App_PermissionSet` to the integration user, which provides:

<figure><img src="/files/gkh2gtK83RVzRhG8j6we" alt=""><figcaption></figcaption></figure>

* API access
* Read access to standard and custom objects
* Access to Kernel-specific settings

You can also choose to assign your own custom permission set

<figure><img src="/files/Kv2x6pPTSYsIHOxTtm7z" alt=""><figcaption></figcaption></figure>

### Step 4: Authorize Kernel connection

Before authorizing the connection, you need your Kernel API credentials. These will now be shown in the Kernel App via the original page:

* **Tenant ID**: Your unique organization identifier (e.g., `tenant_abc123xyz`)
* **API Key**: Your secure API key for authentication

1. **In the Kernel Setup tab**, locate the **Authorize Access** panel
2. **Enter your Kernel credentials:**

   <figure><img src="/files/LJIpmEkuoMjzuUFjQU50" alt=""><figcaption></figcaption></figure>
3. **Click "Sync with Kernel"**

   <figure><img src="/files/oe4oN6qEvx9Ys5DlNHUU" alt=""><figcaption></figcaption></figure>

Finally, back in the Kernel app you will need to log in to the Salesforce instance to authorize the connection. On completion you will see our default fields to be mapped to your CRM. This means the installation is complete.

You can now proceed to set up the Kernel [Custom Object](/integrations/salesforce-integration/custom-object.md).

### Configuration options

#### Custom permission sets

By default, Kernel uses its standard permission set. For custom requirements:

1. **In the Permission Sets panel:**
   * Select **"Choose Custom Permission Sets"**
   * Select your organization's permission sets
   * Click **"Save"**
2. **The selected permission sets will be assigned** to the integration user

For full compatibility we recommend using the default Kernel permission set.

#### Non-admin sync access

Admins can enable **Allow Non-Admin Sync** to let users with `Kernel_Readonly_PermissionSet` run, configure, and schedule syncs through `Kernel_Sync_User_PermissionSet`, without granting the broader `Kernel_Admin_PermissionSet`. Sync schedules can run all active sync configs or only selected configs.

Because sync configuration requires Salesforce Metadata API permissions, only enable this for users who should be allowed to manage sync configuration.

### Security and compliance

#### OAuth scopes

The Kernel Connected App requests these OAuth scopes:

* `api` - Access and manage your data
* `refresh_token` - Perform requests while you're offline
* `openid` - Access unique user identifier
* `profile` - Access basic profile information
* `email` - Access email address

#### Data access

* Access is logged and auditable
* All API calls are tracked in Setup Audit Trail
* Data transmission is encrypted via TLS 1.2+

### Troubleshooting

#### Common issues and solutions

| Issue                                | Solution                                                                         |
| ------------------------------------ | -------------------------------------------------------------------------------- |
| **App not visible in App Launcher**  | Assign the Kernel Integration app to your user profile via Setup → App Manager   |
| **"Authorize" button disabled**      | Ensure Tenant ID and API Key are entered correctly                               |
| **Permission Set assignment failed** | Check if integration user is active; manually assign via Setup → Permission Sets |

### Managing the integration

#### Revoking access

To temporarily or permanently disconnect:

1. **Revoke OAuth Token:**
   * Setup → Connected Apps OAuth Usage
   * Find "Kernel SF Connected App"
   * Click **"Revoke"**
2. **Deactivate Integration User:**
   * Setup → Users
   * Find the kernel-integration user
   * Uncheck **"Active"**
   * Click **Save**

#### Re-establishing connection

1. **Reactivate the integration user** (if deactivated)
2. **Return to Kernel Setup tab**
3. **Click "Authorize Kernel"** again
4. **Complete OAuth flow**

#### Updating credentials

If your Kernel API credentials change:

1. **Obtain new credentials** from Kernel
2. **In Salesforce Kernel Setup:**
   * Click **"Disconnect"** (if connected)
   * Enter new Tenant ID and API Key
   * Click **"Authorize Kernel"**
   * Complete OAuth flow

### Support

#### Getting help

* **Email**: <support@kernel.ai>
* **Include in your support request:**
  * Organization ID
  * Environment type (Sandbox/Production)
  * Integration user username
  * Error messages or screenshots
  * Sync job IDs (from Kernel Portal)

### Package components reference

#### What gets installed

| Component            | Purpose                                  |
| -------------------- | ---------------------------------------- |
| **Connected App**    | OAuth 2.0 authentication with Kernel     |
| **Lightning App**    | Kernel Integration application container |
| **Custom Tab**       | Kernel Setup configuration interface     |
| **Apex Classes**     | Integration logic and API handlers       |
| **LWC Components**   | User interface for setup and management  |
| **Permission Set**   | Default access configuration             |
| **Custom Settings**  | Store integration configuration          |
| **Static Resources** | Application icons and assets             |

#### Recent package changes

* **v3.11.4**
  * Standardises the structured feedback action as **Send Kernel Feedback**
  * Lets users submit structured feedback from a standard Account without a linked Kernel Account
* **v3.9.0**
  * Adds **Allow Non-Admin Sync** for granting sync access via `Kernel_Sync_User_PermissionSet`
  * Adds per-config sync scheduler selection
* **v3.8.0**
  * Improves package install and test reliability by isolating package tests from subscriber Account DML
* **v3.7.1**
  * Adds the Standard sync direction toggle
  * Grants readonly users external credential access needed for enrichment callouts
* **v3.7.0**
  * Adds role-based permission sets and access gating
  * Adds the Account backfill setup step
* **v3.6.0**
  * Adds `KERN ID` on Account
  * Adds Kernel Search Accounts
  * Improves enrichment freshness and logging permissions

***
