Customer's Salesforce connected app refresh token policy was set to 'expire on first use,' which invalidated the refresh token every time Helix rotated access tokens. Changed policy to 'refresh until revoked.' Recommended switching to a service account long-term. Stable for 2+ weeks after fix.