Salesforce

CRM integration
A verdict on every lead, inside Salesforce.
FormGuard checks each submission as it arrives and writes a verdict, a score and the reasons onto the Lead, mirrored on the Contact when it converts. Lead Status, Owner and every field your team uses stay yours; your assignment rules and Flows do the rest.

NOTHING DELETED
Next
User
Daniel
Lena
Checking
Amira K.
Acme · Paid search
amira.k@example.com
Phone
555-0134
Source
Paid search
Company
Acme
Behaviour
Contact
Consistency
Record
Details
Related
Activity
Amira K.
Acme
FormGuard
Verdict
Score
Reasons
Checked At
Reference
mirrored on the Contact when the lead converts
Lead Status
yoursOwner
yoursRating
yoursnot written by Tapper
five fields on the Lead, nothing else
Illustrative submissions with generic names, in the layout of the FormGuard intake view with the Salesforce lead record.
The verdict belongs where your team does its work.
Verdict, score and reasons land on the lead record your reps open anyway. Nobody checks a second dashboard, and nothing about how your team works in Salesforce changes.
01
The verdict beside the lead, not in another tool
Verdict, score and reasons sit on the Lead record your reps open anyway, in the Details tab next to Lead Status and Owner. Nobody checks a second dashboard to learn which enquiries were never a person.
02
Reasons you can filter and report on
The reasons are a fixed vocabulary in a multi-select picklist, never free text. List views filter on them, reports count them, and a rep can see at a glance why a lead was marked Suspicious.
03
Your rules, Salesforce tools
Lead Assignment Rules and Flow read the verdict and score like any other field. Invalid to a holding queue, Suspicious to a review queue, Genuine to the round robin: the routing is yours and it stays in Salesforce.
04
A fixed field set, written down before it is written
Five fields on the Lead, mirrored on the Contact when it converts, listed in the disclosure your admin reviews before anything is written. Nothing else on the record is touched.
From the form to the Lead record, in three layers.
What leaves Tapper on this path is five fields going back into your own Salesforce.
Your form
on your site, unchanged
Tapper FormGuard
CHECKS
Behaviour · Contact · Consistency
passive, no challenge for the visitor
WRITES
verdict · score · reasons · checked at · reference
nothing else on the record

Salesforce
the Lead record
PERMISSION SET
Nothing typed into the form is stored in the clear. Five fields go back to your own Salesforce. Nothing else leaves.
Connect
01
Your admin assigns a permission set with field-level edit on the five FormGuard fields and authorises Tapper through OAuth. The scope is the disclosure, read before anything is written.
Check
02
Three layers on every submission: the session, read by the same monitoring script Block uses; the email and phone, normalised and hashed at ingest; and whether the two agree. No CAPTCHA, no extra step for the visitor.
Write
03
Verdict, score, reasons, checked at and a reference land on the Lead, and follow it onto the Contact when it converts. Lead Status, Owner, Rating and every other field stay yours.
Route
04
Hold an Invalid submission before it reaches your team, or let every lead land flagged and let Lead Assignment Rules, Flow, list views and reports act on the five fields.
A write, and a narrow one.
The Vantage connection is read-only. FormGuard adds field-level edit on its own five fields and nothing else, and the difference is listed in the disclosure your admin reviews before anything is written.
A lead your team can trust before they dial it.
The point is not another dashboard. It is that the list your reps dial and the count your reports show are built from enquiries a person made.
Genuine enquiries reach a rep first
The round robin receives the leads that passed all three layers, so the morning call list starts with enquiries a person made.
Suspicious leads wait in review, not in the queue
A throwaway address or a number that cannot ring lands in a review queue with its reasons attached, and a person decides instead of a dialler.
Reports count what was real
Lead reports and dashboards filter on the verdict, so the count your team is measured against is the count of genuine enquiries, and junk stops inflating it.
Nothing is deleted, merged or archived
An Invalid lead is held or flagged, never removed. It stays in your org with its five fields, reviewable at any time, and every record remains yours.
LEAD ROUTING BY VERDICT
NOTHING DELETED
Holding queue
kept and reviewable, never deleted
Review queue
lands with its five fields
Round robin
Amira K.
Genuineto your assignment rules
TOOLS
Illustrative: the intake submissions routed by verdict, with Salesforce's own tools.
Five fields written, a named set read, and written down.
Scope is a fixed list. The write is the one difference from a read-only connection and it is listed as such. Any CRM gets its own disclosure before it is connected.
PERMISSIONS AS THE DISCLOSURE LISTS THEM
Lead (identity, status, lead source, timestamps, the ad click id)
READ
Contact (the contact fields it checks, hashed at ingest)
READ
Opportunity (the same core set as the Vantage connection)
READ
OpportunityContactRole
READ
OpportunityHistory
READ
Lead (five fields)
WRITE
Contact (mirrored on convert)
WRITE
Notes and Tasks
NEVER
Free text
NEVER
Apex and automation
NONE
Layouts
NONE
Users
NONE
PII AT INGEST
j.doe@example.com
Scope is fixed in code and listed in your disclosure.
Scope, as the disclosure your admin reviews lists it
Objects read
Lead, Contact, Opportunity, OpportunityContactRole and OpportunityHistory: the same core set as the Vantage connection, plus the contact fields FormGuard checks, hashed at ingest. No free-text field is selectable, and no other object is queried.
Fields written
Five on the Lead, mirrored on the Contact when it converts: FormGuard Verdict, Score, Reasons, Checked At and Reference. No create, no delete, no other field, no Apex, no automation, no layouts, no users.
Editions
Enterprise, Unlimited, Performance and Developer include the API. Professional needs the Web Services API add-on. Group and Essentials cannot be connected.
PII handling
Email and phone are normalised and hashed with SHA-256 at ingest, and the raw values are never persisted: not in the database, warehouse, logs or queue messages.
Data out
Only the FormGuard fields, back to your own Salesforce org. No email, phone, hash, name or record content goes to any third party.
Storage
Per-customer stores, never pooled across customers. Credentials are encrypted with AES-256-GCM at rest, and disconnecting revokes the token and deletes them.
Deletion
Never. Nothing in your Salesforce org is deleted, merged or archived by Tapper.
A configuration step, not a project.
No code on your side, no change to how your team works in Salesforce. Your admin authorises the connection and we agree the field set in writing.
Agree the field set
01
We confirm the five FormGuard fields on the Lead, the mirror onto the Contact, and the picklist values your list views and reports will filter on. All of it is written into your disclosure.
Confirm click capture
02
We confirm where your form stores the ad click id on the Lead, so the verdict sits beside the click and campaign that produced it. No form work is required for the verdict to land.
Authorise the connection
03
Your admin assigns the permission set with field-level edit on the five FormGuard fields, then authorises Tapper through OAuth.
Review verdicts before any hold is switched on
04
Every submission lands flagged with its five fields while we read the verdicts with your team and settle the score threshold. Hold is switched on only when you decide.
Editions
Salesforce editions: Enterprise, Unlimited, Performance and Developer include the API. Professional needs the Web Services API add-on. Group and Essentials cannot be connected.
Frequently asked questions
The questions security and CRM teams ask before connecting.
It writes a small field set on the Lead, mirrored on the Contact: verdict, score, reasons, checked at and a reference id.
It reads the same core fields as the Vantage connection: record identity, status, lead source, timestamps, the ad click id where your form stores it, and the contact fields it checks, hashed at ingest. No free-text field is ever requested.
The Vantage connection is read-only and stays that way. FormGuard adds field-level edit on its own five fields and nothing else: no create, delete, Apex, automation, layouts or users.
The difference is listed in the disclosure your admin reviews before anything is written.
No. Status, owner, rating and every field your team uses stay yours. FormGuard supplies the fields your assignment rules and Flows key on.
Lead Assignment Rules and Flow read the verdict and score like any other field. A typical setup sends Invalid to a holding queue, Suspicious to review and Genuine to the round robin.
List views and reports filter on the same fields.
No form work is required for the verdict to land. Where your form stores the ad click id on the Lead, the verdict sits beside the click and campaign that produced it.
Enterprise, Unlimited, Performance and Developer include the API. Professional needs the Web Services API add-on. Group and Essentials cannot be connected.
Only the FormGuard fields, back to your own Salesforce org. No email, phone, hash, name or record content goes to any third party.
Vantage’s conversion values to Google Ads are a separate, separately disclosed path.
Pause or disconnect at any time. Disconnecting revokes the token with Salesforce and deletes the stored credentials, which are encrypted with AES-256-GCM before they are written anywhere.
Fields written before you disconnect stay in your org, because they are yours.
Put a verdict on every lead in Salesforce.
We walk through the field set, the two modes and your routing rules with your CRM and security teams before anything is connected.
FormGuard for HubSpot
The same three layers and the same five fields, in HubSpot’s own vocabulary.
