No, your Zapier integration user doesn't need system admin rights
Today a vendor told me her “understanding” was that we had to give system admin rights to a Zapier integration user… and demanded it be done by tomorrow.
I immediately (and perhaps a bit righteously) refused. And cited recent breaches of billion-dollar corporations coming through Connected Apps just like the one we’re configuring. Her “understanding” came from a subcontractor (Pakistan, Gmail address, no Salesforce integration experience) who was in over his head.
In today’s interconnected world, every external connection into your Salesforce org is a potential attack surface. You cannot afford to hand out permissions based on flippant judgment calls.
Make sure you have someone you trust in your corner to vet these integrations. Otherwise you may find yourself answering uncomfortable questions from your customers—or in our case, the SEC.
————————————————————
Need support like that? Codality has your back—reach out to see how we can help fill the gaps of your in-house expertise.

Jessie Grenfell
Jessie has spent 20+ years architecting and delivering software for organizations where complexity is the norm — financial services, insurance, nonprofits, and regulated industries where getting it wrong isn't an option. She specializes in the hard problems: unique operational workflows, cross-system integrations, and the kind of compliance requirements (HIPAA, CCPA, SOC 2) that most developers treat as someone else's job.
At Codality, she leads every principal engagement from discovery through delivery — because she's seen what happens when that thread gets cut.
