Skip to main content

Configure Security Settings for the Backstory Integration

A guide for security administrators to configure Backstory.

Overview

This article provides the necessary information to complete a security review of the Backstory platform. You can find the required IP ranges for your firewall, clarification on application behavior within Salesforce, and answers to other common security questions.

Configure Your Firewall for Backstory Services

To ensure proper communication, you must add specific Backstory IP ranges to your organization's firewall allow list.

Follow this procedure to update your firewall rules:

  1. Navigate to your firewall configuration settings.

  2. Add the following IP ranges to your allow list:

    • Backstory Production Environment (US-East-1)

      • 35.174.76.124/32

      • 34.206.190.238/32

      • 34.236.123.133/32

    • PeopleGlass Production Environment (US-West-2)

      • 100.20.91.88/32

      • 54.245.186.172/32

      • 54.214.81.150/32

  3. Save your changes.

To ensure continuous service, Backstory will proactively notify you of any future changes to these IP ranges, providing you with ample time to update your firewall configurations.

Understanding Application Behavior in Salesforce

The Backstory integration includes several components that operate in specific ways within the Salesforce ecosystem.

Use this list to understand the behavior of each application:

  • Backstory Canvas App: This application is embedded within a Salesforce iframe and authenticates users via SAML. Any necessary communication from this app will use the Backstory Production Environment IP ranges listed in the section above.

  • ClosePlan Connected App: This app is designed for internal Salesforce use only and does not communicate externally. For this reason, whitelisting is not necessary for this application to function.

  • PeopleGlass App (User Login): This app manages user authentication for the PeopleGlass application. You should focus on this app if your users are reporting errors when logging in to PeopleGlass.

Other Important Information

This section addresses common concerns about the security of your Backstory integration.

  • Data Access Restrictions: You have complete control over data access through Salesforce Profiles and Permission Sets. We encourage reviewing the permissions granted to the Backstory integration user to ensure they meet your business and security policies.

  • Sandbox Availability: Our solution is compatible with Salesforce Sandbox environments; however, our Services and Implementation team can advise on whether that is the best approach for field testing solutions for your business.

  • OAuth Token Management: The Canvas App uses SAML. For services that do use OAuth (like PeopleGlass), our client is engineered to automatically refresh tokens without interrupting the user, ensuring a seamless experience.

For any further questions, our technical support team is here to help. You can reach us at support@backstory.ai.

Did this answer your question?