Skip to main content
Sticky

Salesforce Security Advisory FAQs

  • November 23, 2025
  • 56 replies
  • 50430 views

Show first post

56 replies

revathimenon
Forum|alt.badge.img+8
  • Gainsight Community Manager
  • December 1, 2025

Hi Team,

During the Gainsight–Salesforce connection issue, the Log to Salesforce option isn’t functioning. Will emails sent during this period, with this option enabled be added to the Salesforce Timeline after the issue is fixed?
 

Hi ​@Sowjanya Adiraju 

I’ve communicated this to our internal team, and they’ve confirmed our engineering team is working on alternatives to backfill such cases. We will share an update once we have a solution.


ryanne.perry
  • Helper ⭐️
  • December 1, 2025

Will data/reports collected in Salesforce from Gainsight via the integration be retroactively restored?


  • Contributor ⭐️⭐️
  • December 1, 2025

Hi Team,

During the Gainsight–Salesforce connection issue, the Log to Salesforce option isn’t functioning. Will emails sent during this period, with this option enabled be added to the Salesforce Timeline after the issue is fixed?
 

Hi ​@Sowjanya Adiraju 

I’ve communicated this to our internal team, and they’ve confirmed our engineering team is working on alternatives to backfill such cases. We will share an update once we have a solution.

Thanks ​@revathimenon 


TMaier
Forum|alt.badge.img+5
  • Helper ⭐️
  • December 1, 2025

Can we get some kind of additional context / detail behind the suggestion that customers switch from Google authentication to a SAML-based SSO option instead?


manu_mittal
Forum|alt.badge.img+3
  • Gainsight Employee ⭐️
  • December 2, 2025

Can we get some kind of additional context / detail behind the suggestion that customers switch from Google authentication to a SAML-based SSO option instead?

@TMaier Two motivations:

  1. Solution for the temporary issue with ‘Log in with Google’. It’s back up now, just needs reauthorization.
  2. General recommendation because SAML provides centralized control and auditing.

TMaier
Forum|alt.badge.img+5
  • Helper ⭐️
  • December 2, 2025

Thanks Manu, this is helpful. Given that the temporary issue is resolved (hooray!) and the longer term concern is more foundational, is it fair to say that we have some time to make this decision individually without exposing our company to increased levels of pre-identified specific risk?

 

I genuinely appreciate your engagement here and Gainsight's continued commitment to supporting their customers. 


Tomas Trijonis
  • Contributor ⭐️⭐️⭐️⭐️⭐️
  • December 2, 2025

Regarding the upcoming Office Hours - will Gainsight provide a recording or transcript / recap for those that are not able to join?


revathimenon
Forum|alt.badge.img+8
  • Gainsight Community Manager
  • December 2, 2025

Regarding the upcoming Office Hours - will Gainsight provide a recording or transcript / recap for those that are not able to join?

Hi ​@Tomas Trijonis 

We are currently not recording any of these sessions. However, all questions asked during the session are being compiled and shared as an FAQ document in the community.


wor_csops
Forum|alt.badge.img
  • Contributor ⭐️⭐️
  • December 3, 2025

Thank you for providing the information for Google users on how to update Gainsight Assist. Can Microsoft users get guidance on how to proceed with updating Gainsight Assist as well? The Microsoft Market shows that it was last updated on 10.31.25.  Are we safe or are there steps we need to take in light of recent events?


john_apple
Forum|alt.badge.img+5
  • Expert ⭐️
  • December 3, 2025

Will a reauthorization be needed to re-enable Sally for Slack once the integration has been cleared by Salesforce?


sshroff
Forum|alt.badge.img+5
  • Gainsight Employee ⭐️⭐️
  • December 3, 2025

Will a reauthorization be needed to re-enable Sally for Slack once the integration has been cleared by Salesforce?

Yes, reauthorization from the Gainsight Admin UI will be needed once our Slack apps are back online.


revathimenon
Forum|alt.badge.img+8
  • Gainsight Community Manager
  • December 4, 2025

Will data/reports collected in Salesforce from Gainsight via the integration be retroactively restored?

Hi ​@ryanne.perry 

Once the Gainsight Connected App is back on Salesforce, you may need to take certain actions to reconcile or restore specific data flows. The exact steps will depend on your configuration and which processes were paused during the downtime. Our Business Continuity team can assist you with this evaluation and with any actions required. For more details, please see the section titled “Support for Business Continuity Needs" in this FAQ.


revathimenon
Forum|alt.badge.img+8
  • Gainsight Community Manager
  • December 4, 2025

Thank you for providing the information for Google users on how to update Gainsight Assist. Can Microsoft users get guidance on how to proceed with updating Gainsight Assist as well? The Microsoft Market shows that it was last updated on 10.31.25.  Are we safe or are there steps we need to take in light of recent events?

The date 10.31.25 shown in the Microsoft Marketplace reflects our last Outlook plugin release. As of now, we are not making any changes to the Outlook plugin in response to this advisory. If you are already on the latest version (5.4.0), you are safe and no action is needed at this time


darkknight
Forum|alt.badge.img+5
  • Expert ⭐️
  • December 5, 2025

The only reference I’ve seen to Slack connection anywhere is in relation to Sally for Slack, but many of us out here are using Slack via Custom Connectors (because the native Slack connector that allows us to send outgoing Slack messages is only available to Advanced Programs, and not Rules Engine.)

Most admins appear to be using token-based authorization with custom Slack apps, which I understand not to be as secure as OAuth 2.0.  I’m, however, having trouble getting it to work via OAuth 2.0 (I have a support ticket open on this).

Wanted to point this out as something that would be great to guidance for in the connectors information - how to secure our custom connections with Slack.


sshroff
Forum|alt.badge.img+5
  • Gainsight Employee ⭐️⭐️
  • December 5, 2025

The only reference I’ve seen to Slack connection anywhere is in relation to Sally for Slack, but many of us out here are using Slack via Custom Connectors (because the native Slack connector that allows us to send outgoing Slack messages is only available to Advanced Programs, and not Rules Engine.)

Most admins appear to be using token-based authorization with custom Slack apps, which I understand not to be as secure as OAuth 2.0.  I’m, however, having trouble getting it to work via OAuth 2.0 (I have a support ticket open on this).

Wanted to point this out as something that would be great to guidance for in the connectors information - how to secure our custom connections with Slack.

 

@darkknight I’ve relayed this feedback to the appropriate team to include in the guidance we will be providing. Thanks! 


romihache
Forum|alt.badge.img+9
  • VIP ⭐️⭐️⭐️⭐️⭐️
  • December 11, 2025

When/how will the forensic report(s) be available?


sshroff
Forum|alt.badge.img+5
  • Gainsight Employee ⭐️⭐️
  • December 12, 2025

@romihache Please reach out to your CSM and they’ll be able to get you access to this report. 


darkknight
Forum|alt.badge.img+5
  • Expert ⭐️
  • December 19, 2025

It’s great that Gong is now restored, but what will be the process for getting meetings that have occurred since the 11/21 revocation of Gong synced over to Gainsight?

In our case, we’re still on the pre-Staircase Gong integration.  Will we be required to move to the Staircase-linked connector in order to backfill the missing meetings?


sshroff
Forum|alt.badge.img+5
  • Gainsight Employee ⭐️⭐️
  • December 19, 2025

@darkknight It’ll automatically backfill for both the older and newer version, but we do recommend taking the opportunity to move over to the newer version. 


amasica1217
Forum|alt.badge.img+8
  • Contributor ⭐️⭐️⭐️
  • December 23, 2025

Is there any ETA or update on Zendesk? I feel will all the other connectors coming back I have missed something, but I can’t seem to find it.


sshroff
Forum|alt.badge.img+5
  • Gainsight Employee ⭐️⭐️
  • December 23, 2025

@amasica1217 We are close! We will update this Community post/Status page as soon as it’s re-enabled. Thanks!


darkknight
Forum|alt.badge.img+5
  • Expert ⭐️
  • January 13, 2026

For the new reauthorization window issue, it says “Customers using the Salesforce connector may see their connection become disconnected and require reauthorization after approximately 30 days

But then says: 

“We observed that Salesforce is currently enforcing a fixed 30-day authorization window that starts from the time the connector is authorized.”

Which is it? Approximately 30 days or exactly 30 days?

 


sshroff
Forum|alt.badge.img+5
  • Gainsight Employee ⭐️⭐️
  • January 14, 2026

@darkknight It’s exactly. We’ve updated the verbiage. 


alizee
Forum|alt.badge.img+13
  • VIP ⭐️⭐️⭐️⭐️⭐️
  • January 21, 2026

Following up on ​@darkknight’s latest comment and more specifically this statement that our dedicated resource made: 

While it was initially believed that reauthorization would extend or refresh the authorization window, Salesforce is enforcing a fixed 30-day authorization period. This means the authorization cannot be extended early and reauthorization must occur only after the 30-day window has expired.

When that window expires, Salesforce will stop data syncs until the connector is reauthorized.

 

This approach is extremely difficult to justify from an operational standpoint.

A fixed 30‑day authorization window with no ability to refresh early creates an entirely avoidable risk. What happens when day 30 lands on a weekend, a public holiday, or when the responsible team member is on planned or unplanned leave (what about one-man bands - thinking about ​@Ester.Memoli)? 

The business impact of this “design” is only felt by customers (not by GS). That’s not a sustainable model.

The minimum acceptable would be the ability to reset or refresh the authorization before the expiration window. The current approach not only reduces the platform’s reliability, but also places additional pressure on teams (many of whom do not operate on an on‑call basis unlike support teams) to monitor an inflexible countdown that can’t be mitigated in advance.

This isn’t just a minor inconvenience; it materially impacts the platform’s usefulness. Full stop.

When can we expect a fix to address this?


Ester.Memoli
Forum|alt.badge.img+10
  • Helper ⭐️
  • January 21, 2026

@alizee is absolutely right, and furthermore there’s an issue with the 5 tries then failure of rules based on SFDC objects. This already happened last week, after the first failure, as it was on 11th January - a Sunday - and a rule had all the time to run 5 times in that day and fail.

 

This is not sustainable. We need better solutions.

Thanks