Getting started with VeLens
VeLens is an AI-powered intelligence layer for Salesforce Marketing Cloud. It reads your org and answers questions with real data. Once you confirm, it takes action, so admins, developers, and marketers spend less time clicking through Marketing Cloud and more time getting work done.
VeLens comes in two parts, both backed by the same server-side brain: VeLens Cloud (the web app) and VeLens for Marketing Cloud (the Chrome extension). This guide covers getting started with each. You'll be running in about five minutes.
Choose your surface
Pick whichever fits how you work. They share one account, one connection, and one brain, so you can use both:
- VeLens Cloud: nothing to install on your machine. Open app.velens.cloud in any browser for the AI workspace, Org Health, and team controls. It can also appear inside Marketing Cloud, in SFMC's own app menu, once an admin adds VeLens to your tenant. That's a one-time setup an administrator does, not something each user installs.
- VeLens for Marketing Cloud: the Chrome extension. In-context tools that live right inside Marketing Cloud pages: command palette, lookups, and AI chat next to whatever you're looking at.
Install the extension
VeLens for Marketing Cloud installs like any other Chrome extension:
- Add VeLens for Marketing Cloud from the Chrome Web Store.
- Pin it to your toolbar so the popup is one click away.
- Open the popup and accept the one-time privacy disclosure. VeLens does not touch Marketing Cloud until you do.
- Open any Salesforce Marketing Cloud tab. The extension injects itself into the page automatically.
- Press
Ctrl/Cmd+Shift+Kto open the command palette and confirm it's live.
The command palette and in-page navigation work immediately and free, using the Marketing Cloud session you're already signed into, with no account and no connection required. Subscriber lookup, the error log, and everything AI-powered need the one-time Connect step below.
Connect your org
The AI layer and cross-business-unit features connect through the VeLens Installed Package in your Marketing Cloud account, using OAuth. There's nothing for you to create and no Client ID, Client Secret, or Auth Base URL to paste anywhere. It's a single "Connect SFMC" flow that establishes both your identity and secure API access.
It takes about a minute, once per Marketing Cloud account, and it covers every way you open VeLens. That single sign-in is both your VeLens identity and your Marketing Cloud API access. There is no second account to create and no separate VeLens password.
What happens when you click Connect
Four steps, all of them in a browser window you can see.
- You start it. Click Sign in with Marketing Cloud in VeLens Cloud, or Connect SFMC in the Chrome extension popup.
- Marketing Cloud asks who you are. VeLens sends you to your own Marketing Cloud login page. You sign in there. VeLens never sees your password.
- You allow access. Marketing Cloud shows what VeLens is asking for. Choose Allow. If you are already signed in, this step can pass without a prompt.
- You land back in VeLens. Connected. VeLens stores its access server side, lists your business units, and switches on the AI features.
What you need
- A Marketing Cloud user account you can sign in with.
- The VeLens package present in your Marketing Cloud account. An administrator adds it once, under Setup → Apps → Installed Packages. If it is missing, the sign-in stops and says so.
- That package enabled for the business unit you connect from.
- Permission for your user to authorize it. Some orgs limit this to administrators.
You do not create your own Installed Package, and you never paste a Client ID, Client Secret or Auth Base URL into VeLens. Older instructions asked for that. They no longer apply. Authorization runs through the VeLens package against your own tenant, and no VeLens screen asks for a credential.
Connecting from each surface
Connect once, from wherever you happen to be. The other places pick up the same account and the same connection.
- VeLens Cloud (web app). Open app.velens.cloud and click Sign in with Marketing Cloud. If your Marketing Cloud login lives on a tenant-specific domain, open Advanced: specify your tenant first and type your subdomain so you are sent to the right login page.
- VeLens Cloud, opened inside Marketing Cloud. Open VeLens from the Marketing Cloud app menu. You are already signed into Marketing Cloud there, so the connection usually completes without any typing.
- VeLens for Marketing Cloud (the Chrome extension). Open a Marketing Cloud tab, then open the extension popup and click Connect SFMC. The extension already knows your tenant, so it sends you straight to your login page. A small window opens for the sign-in and closes itself when it finishes.
After you connect
- VeLens creates a workspace for your Marketing Cloud enterprise. The first person to connect that enterprise becomes the owner. Anyone who connects it later joins as an editor. Owners change roles on the Team page in VeLens Cloud.
- VeLens reads the business units your connection can reach and saves the list, so the BU picker and BU-aware answers work straight away.
- AI Chat, the AI email tools, Query Studio AI and the cross-business-unit lookups switch on.
- Access refreshes in the background. You do not sign in again unless the connection is revoked or expires.
More than one Marketing Cloud account
Consultants and agencies often work across separate enterprises. That is supported.
- Connect each enterprise once. VeLens keeps a separate connection per enterprise.
- The Chrome extension activates the connection that matches the enterprise you are looking at, so one org's data never shows up while you are in another.
- In VeLens Cloud, an org switcher appears once your user belongs to more than one.
- Child business units belong to their parent enterprise. They do not need a connection of their own.
Turn access off
Either of these is enough on its own.
- From VeLens. Disconnect in the Chrome extension popup, or in VeLens Cloud. The stored tokens are deleted.
- From Marketing Cloud. Go to Setup → Apps → Installed Packages, open the VeLens package, and remove it or take away the business units it can reach. This cuts access from your side, whatever VeLens still holds.
Troubleshooting
These are the messages the connection can actually return, and what to do about each.
| What you see | What it means | What to do |
|---|---|---|
| VeLens isn't installed in this account yet | Marketing Cloud rejected the app rather than your login. The package is not in this account. | Ask an administrator to add VeLens under Setup → Apps → Installed Packages, and to enable it for the business unit you are connecting from. Then connect again. |
| Connection cancelled | Someone chose Deny on the Marketing Cloud consent screen. Nothing in your account was changed. | Start again and choose Allow. If no consent screen appeared, ask an admin whether your user is allowed to authorize the package. |
| Marketing Cloud rejected the connection | The sign-in finished but the final exchange failed, usually because the package is not fully enabled, or the window sat open too long. | Confirm the package is installed and enabled for this business unit, then run the connection through without pausing. The authorization step expires after a few minutes. |
| Your connection attempt timed out | Too much time passed between starting and finishing the sign-in. | Close the window and start the connection again. |
| Couldn't identify your Marketing Cloud account | Marketing Cloud did not return the account details VeLens needs. Often temporary, sometimes a missing permission on the package. | Try again in a minute. If it keeps happening, ask your administrator to confirm the package grants Accounts and Users: Read. |
This connection covers one business unit onlynot_parent_bu |
You connected from a child business unit, and something asked for a different one. | Switch to the parent (enterprise) business unit in Marketing Cloud and connect again. Everything in the child BU keeps working in the meantime. |
VeLens can't reach that business unitbu_not_accessible |
The connection itself is fine, but this business unit is closed to it. | In Marketing Cloud, open the VeLens package and add that business unit to the ones it is enabled for. Check that your own Marketing Cloud user has access to it too. |
Reconnect Marketing Cloudrefresh_failed |
The stored access was revoked or expired, so VeLens can no longer reach your org at all. | Connect again. There is nothing else to repair, and reconnecting keeps your workspace, team and history. |
| No SFMC connection found | A feature asked for a connection this user does not have yet. | Connect from the extension popup or from VeLens Cloud. |
| Multiple SFMC connections found | Your user is connected to more than one Marketing Cloud enterprise and the request did not say which one to use. | Pick the org in the switcher in VeLens Cloud, or open the Marketing Cloud tab for the enterprise you mean and try again. |
Still stuck? Tell us what you saw and we will work it out with you.
AI Chat
AI Chat is the agentic assistant at the center of VeLens. Open it from the floating toolbar on any Marketing Cloud page (or the AI Workspace in VeLens Cloud), then type a question or an instruction.
- Asks pull live data: "Why did the Welcome Series automation fail last night?" or "Which data extensions haven't been touched in 90 days?"
- Actions change something: "Draft a re-engagement email for lapsed subscribers" or "Create a template-based email in the Newsletters folder."
Every reply shows a tool trace: the exact tools the agent called, whether they succeeded, and how long they took. Nothing is a black box. You can see the data the agent worked from.
When you ask the agent to write or change something, it doesn't just do it. It proposes the change and waits: you'll see exactly what it plans to do, with a rendered preview for emails, and a Confirm / Cancel choice. Nothing is written to your org until you confirm.
Tools & actions
Behind the chat sits a registry of 35 purpose-built tools, split into two kinds:
- Reads: list automations and their run history, inspect data extension schemas and row counts, pull recent send performance and bounces, list journeys, business units, folders, and templates, and more. Reads run automatically as the agent works through your question.
- Writes: create or update emails, build a layout template, save a bookmark. Writes always propose first. The agent describes what it's about to do, you review it, and only your confirmation executes it. There's no auto-retry and no silent write.
Subscriber lookups deliberately never go through the AI. They run as a direct, no-LLM query from the Subscriber Lookup panel, so no subscriber record ever enters a model prompt.
Because you're viewing your own org, the agent only ever touches data your connected package has permission to reach.
Business units
VeLens is business-unit aware. In the extension it follows the BU you're currently viewing in Marketing Cloud, and in VeLens Cloud you pick the BU from a switcher. Answers and actions are scoped to that context automatically, with no accidental cross-BU writes.
When you move between business units in SFMC, VeLens keeps up. Certain read features, like subscriber lookup, can also search across the business units your package can access when you need the full picture.
The business unit you are sitting in when you connect decides how far VeLens can reach.
- Connect from your parent (enterprise) business unit if you can. VeLens then works across every business unit your user can reach, and you get a BU picker.
- Connect from a child business unit and VeLens works in that one business unit only. Cross-BU features stay off. The success screen tells you which of the two you got.
- To go from child-only to full reach, switch to the parent business unit in Marketing Cloud and connect again.
- Access is scoped per business unit. Every request VeLens makes is checked against the business unit you are working in, so a question asked in one BU cannot read or write in another.
Keyboard shortcuts
Three features have dedicated shortcuts; everything else opens from the floating toolbar.
| Shortcut | Action |
|---|---|
Ctrl/Cmd+Shift+K | Command palette |
Ctrl/Cmd+Shift+L | Subscriber lookup |
Ctrl/Cmd+Shift+E | Error log |
VeLens Cloud (web app)
VeLens Cloud is the browser companion to the extension: same server-side intelligence layer, no extension required. Sign in with the same SFMC connection and you get:
- AI Workspace: the full agent chat, with a business-unit picker and the same write-confirmation guardrails.
- Org Health: a daily snapshot of contacts against your limit, send volume, automation failures, and active journeys.
- Features & Team: owners and admins can enable or disable features org-wide; owners manage member roles.
VeLens Cloud also opens inside Marketing Cloud, from SFMC's own app menu. It's the same app, signed in with the same connection, so your team can reach it without leaving the interface they already work in. An administrator adds VeLens to your Marketing Cloud tenant once to make it appear there; after that it's one click for everyone, with nothing for individual users to install.
If you've already connected the extension, VeLens Cloud recognizes the same organization, so there's nothing extra to set up.
Privacy & security
Privacy is a design constraint, not an afterthought:
- No subscriber row data ever reaches the model. The AI works from schemas, counts, headers, and errors only, never the contents of individual subscriber records. Cell values are masked at the tool boundary, before any result reaches the model or is stored in your conversation history.
- Credentials are encrypted at rest using AES-256-GCM, and the extension never holds your refresh tokens. They live server-side.
- Writes are confirm-gated. The agent can propose changes, but only your explicit confirmation writes them.
- Short-lived access tokens are issued for the business unit in use and expire on their own.
- VeLens never receives your Marketing Cloud password. Sign-in happens on Marketing Cloud's own pages.
Full detail is in the Privacy Policy.
FAQ
Is VeLens free?
Yes, to start. The command palette and in-page navigation work the moment you install the extension, with no account and no connection required. Everything that reads your org through the API, including subscriber lookup, the error log, and all AI features, needs the one-time Connect step.
What do I get when I connect my org?
Connecting unlocks the API-backed features: AI Chat, subscriber lookup and the error log, send performance and engagement, the subject scorer, Query Studio AI, DE Inspector's AI descriptions, and cross-business-unit features. All of it runs server-side and needs the one-time OAuth connection.
Does it work on my stack?
Yes. VeLens works across every SFMC stack, including modern mc.exacttarget.com instances with no stack number, and it resolves the right SOAP and REST endpoints for your tenant automatically.
Is it affiliated with Salesforce?
No. VeLens is an independent product. It is not affiliated with, endorsed by, or sponsored by Salesforce, Inc.
How do I revoke access?
Disconnect from the extension popup or VeLens Cloud, or revoke the Installed Package at any time from SFMC Setup → Installed Packages. Once revoked, VeLens can no longer reach your org.