TL;DR: Salesloft and Gainsight showed how compromised integration tokens and OAuth scopes can bypass MFA, enter Salesforce legitimately, and expose downstream secrets such as Snowflake tokens and cloud keys, according to Hush Security. The real problem is not platform weakness but over-trusted non-human identities whose scopes and persistence outlive the controls built around them.
Editorial analysis by NHI Mgmt Group, based on content published by Hush Security: “Why Storm the Castle When You Already Hold the Keys to the Kingdom?”.
Key questions
Q: What breaks when a stolen OAuth token is used against a trusted integration?
A: The trust model breaks because the system still sees a valid credential, even though the actor behind it is no longer trustworthy.
Q: Why do service accounts and integrations increase breach impact?
A: Service accounts and integrations often hold broad permissions, long-lived credentials, and weak human oversight.
Q: How do security teams know whether integration scope is too broad?
A: Scope is too broad when the integration can reach systems, secrets, or functions that are not essential to its business purpose.
Practitioner guidance
- Inventory all premium-scope integrations Build a complete register of service accounts, bots, and third-party apps that touch Salesforce and adjacent cloud systems.
- Reduce OAuth scope to task minimums Review every integration for scopes that exceed the business workflow it supports, then narrow access so a single token cannot traverse unrelated data sets or administrative functions.
- Treat token revocation as incident containment When an integration is suspected compromised, revoke active and refresh tokens first, then rotate downstream secrets and invalidate any credentials exposed through the connected workflow.
Bottom line: The breach pattern shows that trusted integrations can become the primary entry point even when MFA and SaaS hardening are in place.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Integration trust debt is now the core governance problem: The Salesloft and Gainsight incidents show that organisations have allowed third-party integrations to accumulate authority that is never revalidated against current business need. OAuth scopes, refresh tokens, and app permissions are treated as plumbing, but they behave like durable identities with real blast radius. The practitioner conclusion is that integration trust has to be governed as a lifecycle, not accepted as a one-time onboarding decision.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Who should own NHI offboarding when development teams change?
A: NHI offboarding should be owned by a named control function, not left to whichever team used the credential last. Shared use without accountable ownership is how access survives project changes, team moves, and vendor transitions. A clear owner is the only practical way to prove revocation happened.
👉 Read our full editorial: Salesloft and Gainsight breaches expose integration NHI trust gaps