Salesforce Shield Architecture

Salesforce Shield as an architectural choice — Platform Encryption + Event Monitoring + Field Audit Trail as three SEPARATELY-LICENSED components, none of which ship in any standard edition. Covers BYOK vs Cache-Only Key Service (CCKM) tradeoffs, probabilistic vs deterministic encryption schemes, the field-type encryption blocklist (Formula, Roll-Up Summary, indexed External ID), Field Audit Trail's 10-year retention model, and why every Shield design starts with a license confirmation. NOT for setting up one Shield feature — use security/platform-encryption, security/event-monitoring or security/field-audit-trail. NOT for HIPAA control mapping — use architect/hipaa-compliance-architecture. NOT for FedRAMP, FISMA or Government Cloud control mapping — use architect/government-cloud-compliance.

PranavNagrecha 3e74e1e 7 files · 48.2 KB Updated 15 repo stars

File contents

PranavNagrecha/AwesomeSalesforceSkills/tree/main/skills/architect/salesforce-shield-architecture commit 3e74e1e5ba

Frequently asked questions

npx skillmds add pranavnagrecha/salesforce-shield-architecture