Salesforce integration, in production

Salesforce holds the truth. We make it usable.

A Salesforce org is a great system of record and a frustrating place to run a business from: reports that can't join, history that expires, formulas that quietly rewrite the past, and integrations nobody can see inside. We run production integrations against a Salesforce-native TMS for a $60M freight brokerage: mirroring it, reverse-engineering it, bridging it to Sage Intacct, and auditing every write.

If your data lives in Salesforce, or a Salesforce-native platform like Revenova, and it needs to go somewhere or come back right, this is the work we do.

See it in production: read the case study →

190K+
Loads mirrored, 5-min freshness
90
Objects mapped in a 5.2K-line spec
2
Audited writers. Everything else read-only
$200K+
Overpayments traced to one rep
What we build on Salesforce

Read everything. Write two things. Audit both.

Every card below is something we've built, run, and fixed in a live org, not a feature list from a vendor deck.

SOQL AT SCALE · 5-MIN FRESHNESS

Live org mirror

Loads, accounts, stops, invoices, and accessorial lines mirrored continuously into Postgres, with 16 materialized views behind the dashboards. Salesforce stays the system of record. Your reporting stops depending on it.

10-SECOND CALLOUT BUDGET

Real-time Flow webhooks

A Flow HTTP callout upserts a single record the moment it changes, bypassing batch latency, with constant-time secret comparison on the receiving end.

CLIENT-CREDENTIALS FLOW

Auth isolation

Nightly jobs use a server-to-server token path so they never contend with the always-on loop's refresh token. That removed a recurring class of 400-level failures.

TOOLING + DATA APIs

Metadata reverse engineering

Full enumeration of objects, fields, relationships, and history tracking into a 5.2K-line spec to rebuild against while paid access lasts. It found the vendor's own plan-margin field under-netting multi-leg carrier settlements.

OUTLIVES 18-MONTH RETENTION

Field-history audit mirror

Daily append-only capture of who changed pay-relevant fields, schema-validated each run so a renamed field degrades gracefully instead of failing silently.

SET-ONLY · MIRRORED TO AUDIT

Scoped write-back

Exactly two sanctioned writers: a qualified-customer flag and a payment writer. Each is set-only and mirrored to an audit table. Nothing else in the platform can write to the org.

IMMUNE BY CONSTRUCTION

Immutable attribution ledger

Rep attribution stamped at ingest, so a retroactive formula recalculation can never silently repay history, a drift class that left six figures of overstamping in the source system.

BASELINE-FIRST

Ownership history

Append-only diff of who owns what on each account, because the source mirror is overwritten nightly. Designed so the first run emits zero false "changed" alerts.

Where the data goes

Salesforce is rarely the end of the pipe.

The value shows up when the org's data meets accounting, payments, inboxes, and dashboards, and each connection is watched for drift.

Salesforce ↔ Sage Intacct

AR / AP / GL bridge

Salesforce → Postgres / Supabase

Live mirror with history

Salesforce ↔ TriumphPay & Stripe

Payment sync, prepay and AR pay links

Salesforce → Dashboards, portals, AI

Answers, not exports

Salesforce → Sage Intacct

The bridge the last vendor couldn't keep alive.

The seam between a Salesforce-native TMS and Sage Intacct is where integrations fail quietly. We took over one that did.

4 API CALLS PER RECORD → 1

Owned replacement for a failing bridge

Behavioral mirroring of an outsourced TMS-to-ERP bridge with no source access, then a replacement with fail-closed dedup, pre-flight validation, verify-after-write readback, and an append-only run journal. The incumbent's silent-skip failure reproduced 24 of 24 times.

903 RECORDS · $2.36M · 0 DUPES

Payment write-back watcher

Finds invoices marked paid without the payment records the TMS roll-ups depend on, and creates them idempotently. A 1,052-invoice outage window backfilled with zero failures.

215K CALLS/MO → ~500/DAY

Dual-path Intacct client

REST and XML Web Services in one client, with automatic fallback for XML-only functions. A batched design replaced an abandoned integration burning 215K calls a month.

Full Sage Intacct detail: GL dashboards, budget vs. actual, duplicate-payment scanning, multi-entity AR/AP, and accounting watchdogs.

See the Sage Intacct page →
How we work

Read-only first. Proven before trusted.

1

Look, don't touch

A read-only API connection and an object census: what's in the org, what's stale, what's formula-driven, and what rewrites history when it recalculates.

2

Mirror and reconcile

Land the data in Postgres, then reconcile to a number you already trust, such as your controller's workbook or payroll, to the penny before building on top.

3

Watch it

Heartbeats, credential probes, staleness alerts, and drift checks, so a renamed field or an expired credential pages someone instead of failing silently.

4

Write back only where signed off

Set-only writers with an audit trail. Your business owns the rules. We implement them, test them, and log every change.

Safety by default: every secret in organization-scoped vault storage, nothing in code, commits, or logs; 1,069 regression tests on money-touching rules, each anchored to a verified production vector.

Who it's for

If this sounds like your Salesforce org, we should talk.

Revenova and Salesforce-native TMS brokerages

The TMS is a strong system of record and a weak reporting tool. We add the mirror, the commission engine, carrier monitoring, and portals on top.

Freight brokerage systems →

Salesforce orgs whose accounting doesn't talk to them

Invoices, payments, and customer status that someone re-keys, or that a vendor bridge moves unreliably. Sage Intacct is our home turf.

Sage Intacct bridges →

Teams that need Salesforce data in SQL, BI, or AI

Reports can't join what you need. A live Postgres mirror gives analysts, dashboards, and AI assistants a fast, queryable copy with history Salesforce eventually expires.

SQL data platforms →

Orgs running on a package or integration they can't see inside

Managed packages and vendor-run bridges are black boxes until they fail. We document the behavior from the outside, then give you something you own.

Talk to us →
FAQ

Salesforce integration questions

Do you work with Revenova and other Salesforce-native TMS platforms?

Yes. The work on this page was built and operated against a Revenova / Salesforce-native TMS in production for a $60M freight brokerage. Other Salesforce-based packages follow the same pattern: we start with a read-only object census to learn what is standard, what is vendor-managed, and what is formula-driven.

Can you sync Salesforce to Postgres or Supabase?

Yes. We mirror objects continuously with a five-minute freshness target, add Flow-triggered real-time upserts for single records, and use nightly full-replace pulls where the source data is retroactively editable. Analytics views sit on top of the mirror.

Will you write to my Salesforce org?

Read-only is the default. Write-back is added only where the business signs off, through scoped set-only writers, each mirrored to an audit table. Nothing else in the integration can modify the org.

How do you handle Salesforce authentication?

Scheduled jobs use an OAuth client-credentials path that is isolated from the always-on sync loop's refresh token, so the two never contend. That separation eliminated a recurring class of 400-level failures. Credentials live in organization-scoped vault storage, never in code, commits, or logs.

Can you connect Salesforce to Sage Intacct?

Yes. We run a dual-path Intacct client (REST and XML Web Services), AR/AP/GL sync, and payment write-back, and have taken over a failing outsourced TMS-to-ERP bridge with an owned replacement. See the Sage Intacct page →

How do you prove the numbers are right?

We reconcile against a source you already trust, such as your controller's workbook or payroll, to the penny before anything is built on top. Money-touching rules are covered by regression tests anchored to verified production vectors.

What if a vendor runs our integration and we can't see inside it?

We mirror its behavior from the outside, without source access, document where it fails silently, and then build an owned replacement with pre-flight validation and verify-after-write checks.

Tell us what your Salesforce org needs to talk to.

No pitch decks, no rip-and-replace. Your org stays exactly as it is. You'll hear back from a human, usually the founder.