Salesforce Shield: Complete Guide
Quick Summary:
Salesforce Shield bundles three security and compliance tools -- Platform Encryption, Event Monitoring, and Field Audit Trail -- built for organizations with genuine regulatory requirements around data protection and audit retention.
What Is Salesforce Shield?
Salesforce Shield is a separately-licensed bundle of three security and compliance capabilities that go beyond standard Salesforce security features. It's built for organizations -- often in financial services, healthcare, or other regulated industries -- with genuine, specific compliance requirements around data-at-rest encryption, detailed activity monitoring, and extended audit trail retention.
The Three Components
| Component | What It Provides |
|---|---|
| Platform Encryption | Encrypts specified fields/files at rest, beyond application-level access control |
| Event Monitoring | Detailed logs of user activity -- logins, API calls, exports, page views |
| Field Audit Trail | Extended history retention (years) across more trackable fields than standard tracking |
How to Get Started
Confirm your actual regulatory/compliance requirements before adopting Shield speculatively.
Identify which specific fields genuinely need Platform Encryption, considering functional tradeoffs on search/reporting.
Enable Event Monitoring and determine whether data should feed into an external SIEM tool.
Configure Field Audit Trail retention periods matching your compliance requirements.
A Real-World Example
A healthcare technology company handling patient data needs to demonstrate both data-at-rest encryption and multi-year audit trail retention for compliance purposes. Platform Encryption protects sensitive patient fields even from Salesforce's own infrastructure access, while Field Audit Trail extends history retention well beyond the standard tracking window -- together satisfying compliance requirements that standard Salesforce security features alone couldn't meet.
💡 Pro Tip
Encrypt specific, genuinely sensitive fields rather than broadly encrypting by default -- Platform Encryption has real functional tradeoffs on search and reporting, so the right approach is targeted encryption based on actual data sensitivity, not blanket application.
Frequently Asked Questions
What are the three main components of Salesforce Shield?
Platform Encryption, Event Monitoring, and Field Audit Trail -- each addresses a different aspect of security and compliance, and they're commonly licensed together as the Shield bundle.
What does Platform Encryption actually encrypt?
Platform Encryption encrypts data at rest for specified fields and files, protecting sensitive data even from Salesforce's own infrastructure access, which standard field-level security does not address.
What\'s the difference between Platform Encryption and standard field-level security?
Field-level security controls which users can see a field's value within the application; Platform Encryption protects the underlying data at the storage layer, relevant for compliance requirements around data-at-rest protection, not just application-level access control.
What does Event Monitoring track?
Event Monitoring logs detailed user activity -- logins, API calls, report exports, page views -- giving visibility into exactly how users are interacting with the org, valuable for security investigation and compliance auditing.
How is Field Audit Trail different from standard field history tracking?
Standard field history tracking retains a limited history (typically shorter retention, fewer trackable fields); Field Audit Trail extends retention significantly (years) and increases the number of fields that can be tracked, meeting stricter compliance retention requirements.
Is Salesforce Shield required for regulatory compliance?
It's not universally required, but it's commonly adopted by organizations in regulated industries (financial services, healthcare) where data-at-rest encryption and extended audit retention are genuine compliance requirements, not optional enhancements.
Does enabling Platform Encryption affect search and reporting functionality?
Yes, encrypted fields have some functional limitations (certain search and reporting operations behave differently on encrypted data) -- worth reviewing which specific fields genuinely need encryption rather than encrypting broadly by default.
Can Event Monitoring data be exported for analysis in external tools?
Yes, Event Monitoring data can be exported and analyzed in external security information and event management (SIEM) tools for organizations with existing security monitoring infrastructure.
Is Salesforce Shield included in standard Salesforce licensing?
No, Shield is a separately licensed add-on -- worth confirming current pricing and whether your compliance requirements genuinely necessitate it versus standard platform security features.
Can Field Audit Trail retention periods be customized per field?
Retention policies can be configured, letting you set different retention windows appropriate to different data sensitivity and compliance requirements across your org.
Does Platform Encryption protect data in Salesforce backups too?
Yes, encrypted field data remains encrypted in backups, maintaining the same protection level throughout the data's lifecycle, not just in the primary production database.
What\'s a realistic first step for evaluating whether an org needs Shield?
Start with your actual regulatory and compliance requirements (industry-specific mandates around data retention and encryption) rather than adopting Shield speculatively -- it's a genuine cost and complexity addition that should be justified by real requirements.