Configuring the Connected App
The Connected App is what lets TwoCanConnect's components talk to Salesforce on your users' behalf. It's set up as part of installing, but it's worth confirming before anyone else starts using the integration — a Connected App that isn't validated blocks the rest of the setup.
The two steps
Both are done in Salesforce Setup, not in the wizard — there are no fields, credentials or secrets to enter here. Open Connected App Settings opens Setup in a new tab.
1. Set permitted users
- Open the Connected App settings page
- Select TwoCanConnect for Xero
- Click Edit Policies
- Set Permitted Users to Admin approved users are pre-authorized
- Click OK when prompted, then Save
That setting is the important one. Admin approved users are pre-authorized means access is granted deliberately by profile rather than to anyone who happens to open the app — the same principle as installing for admins only and granting access with a permission set.
2. Assign Connected App access
- On the TwoCanConnect for Xero Connected App page, scroll to Profiles
- Click Manage Profiles
- Tick each profile that should have access — System Administrator at minimum
- Click Save
Then return to the wizard and click Validate Configuration. A green Connected App is configured panel means it's set up correctly and you can move on.
This grants access to the Connected App. It's separate from the TwoCanConnect permission set, which grants access to the app's tabs and components. A user generally needs both — see Permission sets and user access.
If validation keeps failing
Check the permitted-users policy saved correctly, and that the profile of the user you're testing with is ticked under Manage Profiles. Components failing because the Connected App isn't in place produce errors that look like connection or permission faults, so it's worth ruling this out before troubleshooting the sync.
Checking it later
Configuration → TwoCanConnect Configuration → Connected App Configuration, step 2 of the org-wide setup.
A green Connected App is configured panel means it's still set up correctly. That's what most orgs will show, and there's nothing further to do.
If you need to reconfigure it
Reconfigure isn't destructive. It clears the stored validation flag and re-runs a live check — it doesn't change your Connected App's permitted-users policy or its profile assignments. The screen returns to the two steps above with a red validation banner until you click Validate Configuration; if nothing was actually wrong, that puts you straight back to green.
Xero
Real Estate
Equifax