
Salesforce Field Audit Trail monitors 60 fields per object, which is three times the limit of standard field history tracking. When hitting this threshold, rank fields by compliance impact and change frequency. Financial amounts, personal data, and approval workflows demand tracking since auditors focus on these areas. Field Audit Trail from Salesforce lets companies know the state and value of their data for any date, at any time. Whether for regulatory compliance, internal governance, audit, or customer service, Field Audit Trail helps companies create a forensic data-level audit trail with up Retained Earnings on Balance Sheet to ten years of history.
Additional Resources

Give it a name like “View Event Monitoring Data”, and give it the View Real-Time Event Monitoring Data permission. Back to the land of clicks instead of code (or command line), it’s time to enable Shield Event Monitoring. Salesforce’s Field Audit Trail Implementation Guide gives additional information and examples about the steps to properly enable and set up Field Audit Trail.
Track Up to 60 Fields Per Object
Enabling an extra level of data management and protection to support internal security best practices and increase customer trust. Most companies in highly regulated industries have carefully defined and articulated Data Retention Policies (established protocols for retaining information for operational or regulatory compliance needs). Laws and regulations often require companies to archive their data for auditing purposes or keep records for a specific number of years. Before we get into the specific tools Salesforce offers for audit prep, it’s worth reviewing what, exactly, auditors want to see. Unfortunately, there’s no clear answer for this; it’s only been in the past few years that auditors have started to look more closely at Salesforce, and each will bring a different level of familiarity with the platform. Going forward, the best practice to hide sensitive data from users, is field-level security, i.e. defining which fields are readable/editable for which users.

Shield Pricing
Enabling Salesforce Field Audit Trail on objects with extensive field history can trigger large background jobs. Schedule these changes during low-usage periods to minimize impact on user performance. The detailed timestamp and user attribution data let you reconstruct events with precision, supporting both internal investigations and external audit requirements. Select your retention period (up to 10 years) and enable tracking for up to 60 fields per object.
Step 2: Platform Encryption
This allows any records containing “San Diego” to be matched when using filtering capabilities. Salesforce Shield brings the Compliance & Security Team and Salesforce Admins together, helping everyone stay on normal balance the same page when it comes to critical compliance measures. Turning on Salesforce Shield doesn’t guarantee success – sure, it’s a security control, but it’s not the sole security control you need to consider. Implementing Health Check and Shield into your Salesforce app development workflow helps you develop securely. Secure app development processes are the best way to protect your company and customer data.
Platform Encryption has a few key steps (you’ll understand shortly why ‘key’ steps are funny). The way you do this is by creating Permission Sets and granting them to the users who require them. Data Detect is great for identifying where you might have sensitive data stored in those unknown places. Back to the Case example – we do have credit card information stored, and we can see in specific fields which patterns have been detected. Data Detect is showing me that there are credit card numbers stored in the description field.

Customers
- When enabled, field history data is copied from the History-related list into theFieldHistoryArchive big object.
- This feature extends the standard field history tracking capabilities, enabling organizations to retain a comprehensive audit trail of field changes over an extended period.
- Large organizations can align Shield configurations to their regulatory control matrix.
- You can monitor trends by user, which reports are being downloaded, or how users are accessing certain reports.
- Together, they provide the oversight, recovery, and compliance controls enterprise environments demand.
Luckily, field-level security is tracked individually for every field, and even more so, other permissions are as well. For example, enabling a System Permission within a Permission Set will appear as being changed from disabled to enabled. Field History Tracking can be enabled on individual Salesforce Objects and allows you to track when and how up to 20 fields are changed on a record. On the other hand, while Setup Audit Trail follows a similar concept of reviewing changes, it applies to – you guessed it – setup changes. This means that this audit trail functionality tracks updates to metadata rather than just record data.
- Next, you’ll need to generate the tenant secret – again, these are used to derive your keys, so they must be protected at all costs, which is why we limit who has access to this functionality.
- Explore our solutions to ensure comprehensive security for critical data in your Salesforce org.
- Salesforce Field Audit Trail extends Salesforce’s standard field history tracking with enterprise-grade audit capabilities designed for regulated environments.
- In Setup, head over to the Encryption Settings page, and scroll down to the Advanced Encryption Settings section.
- Again, note that you can purchase the “full umbrella” (all Shield components), or each component can be purchased separately based on what suits your regulatory and business requirements.
- Reco enhances these capabilities by providing real-time threat detection, automated responses, and comprehensive monitoring.
Key benefits include enhanced data security, support for regulatory compliance, improved data governance, and effective risk mitigation. By continuously monitoring and identifying sensitive data, organizations can avoid costly data breaches and maintain robust data protection practices. Record modification, login history, field history tracking and setup audit trail are the four ways used for Auditing salesforce.