
Key Considerations After Deploying Salesforce ShieldThe short answer: Salesforce Shield is an add-on suite of four security products: Platform Encryption, Event Monitoring, Field Audit Trail, and Einstein Data Detect. Deploying it is the easy part. Getting lasting value requires ongoing work on encryption key management, event log review, audit policy upkeep, and user training, which is what this guide covers.
The short answer: Salesforce Shield is an add-on suite of four security products: Platform Encryption, Event Monitoring, Field Audit Trail, and Einstein Data Detect. Deploying it is the easy part. Getting lasting value requires ongoing work on encryption key management, event log review, audit policy upkeep, and user training, which is what this guide covers.
Many organizations buy Salesforce Shield to satisfy a compliance requirement, switch it on, and never revisit it. That leaves most of its value on the table and can create a false sense of security. Here is what Salesforce Shield includes, and the considerations that matter most once it is live in your org.
What is Salesforce Shield?
Salesforce Shield is a set of security and compliance products that extend the platform’s built-in protections. It is licensed as an add-on to your existing Salesforce subscription, either as the full bundle or as individual products. Shield is most common in regulated industries such as healthcare, financial services, and government, where encryption at rest, long-term audit history, and detailed activity monitoring are compliance requirements rather than nice-to-haves.
What are the four Salesforce Shield products?
| Product | What it does |
|---|---|
| Platform Encryption | Encrypts standard and custom fields, files, and attachments at rest with AES 256-bit encryption, while preserving functionality like search and validation rules. Supports Salesforce-managed keys or Bring Your Own Key (BYOK) |
| Event Monitoring | Captures detailed logs of user and system activity across 50-plus event types: logins, API calls, report exports, Apex executions, and more, for analysis in tools like Tableau or Splunk |
| Field Audit Trail | Extends field history tracking to 60 fields per object (versus the standard 20) and retains archived history for up to ten years, so you can prove the state of any record at any point in time |
| Einstein Data Detect | Scans your org for sensitive data patterns such as credit card numbers, Social Security numbers, and email addresses, wherever they live, so you can classify and protect fields you did not know were sensitive |
What should you focus on after deploying Salesforce Shield?
1. Encryption key management
Platform Encryption is only as strong as your key management. Establish a key rotation policy and calendar, decide who owns key administration, and if you use Bring Your Own Key, document the recovery process. Also revisit which fields are encrypted at least annually: business processes change, and new fields holding sensitive data appear over time.
2. Actually reviewing Event Monitoring data
Event Monitoring generates logs; it does not watch them for you. Decide which events matter to your security posture (large report exports, off-hours API activity, repeated failed logins), route the logs into a tool your team already monitors, and set up alerts through Transaction Security policies for the events that warrant immediate action.
3. Audit and compliance configuration
Field Audit Trail only retains what your retention policy tells it to. Confirm the policy covers every object and field your regulators care about (GDPR, HIPAA, SOX, or industry-specific rules), and run periodic checks that the archive actually contains what auditors will ask for. Finding a gap during an audit is the expensive way to learn this.
4. User training and security awareness
Shield protects data at the platform level, but people remain the most common failure point. Train admins on responding to Event Monitoring alerts and reading audit history, and train end users on data handling policies. A well-configured Shield deployment plus untrained users is still a risk.
5. Ongoing optimization
Revisit your Shield configuration on a schedule, not just after incidents. As data volumes grow and new features roll out (Shield encryption now extends to Data 360, Salesforce’s data platform formerly called Data Cloud), your original setup will drift out of date. Run Einstein Data Detect scans periodically to catch sensitive data that has crept into unclassified fields.
6. Performance monitoring
Encryption and monitoring carry some overhead. Watch page and report performance on objects with heavily encrypted fields, especially as record counts grow, and adjust your encryption scope if a field never actually needed protection.
Where does Shield fit in a broader security strategy?
Shield complements, rather than replaces, the fundamentals: profiles and permission sets, sharing rules, multi-factor authentication, and Health Check. If those are weak, fix them first. For a look at which industries and scenarios benefit most from Shield, see our companion post on the best use cases for Salesforce Shield, or learn more about our Salesforce platform consulting services.
Frequently Asked Questions
What is included in Salesforce Shield?
Salesforce Shield includes four products: Platform Encryption (encrypts data at rest), Event Monitoring (detailed activity logging), Field Audit Trail (extended field history retention), and Einstein Data Detect (finds sensitive data patterns in your org). They are sold as a bundle or individually.
Is Salesforce Shield included in my Salesforce license?
No. Salesforce Shield is an add-on product licensed on top of your existing Salesforce subscription, with pricing that scales with your Salesforce spend. Standard Salesforce licenses include baseline security features, but not Shield’s encryption, extended auditing, or event monitoring.
Does Platform Encryption break Salesforce functionality?
Mostly no. Salesforce Shield Platform Encryption is designed to preserve core functionality like search, workflow, and validation rules on encrypted fields. Some features have limitations with encrypted fields, so test your critical business processes in a sandbox before encrypting widely.
How long does Field Audit Trail keep data?
With Salesforce Shield’s Field Audit Trail, you can define retention policies that keep archived field history for up to ten years, compared with 18 to 24 months of field history retention on a standard Salesforce license.
Client Success Stories

JPMorgan Chase
One of the world’s largest financial institutions. See why their team says working with CloudMasonry is a relationship, not a transaction, and why they keep coming back.

Millennium Trust
A leading provider of retirement and custody solutions in a heavily regulated industry. Their team calls the collaboration clear, communicative, and easy to work with.

TaxRise
A fast-growing tax-resolution company running streamlined, automated customer processes on Salesforce. See how they scaled service without scaling headcount.

Mercer Advisors
A national fiduciary wealth-management firm serving families from mass affluent to ultra-high-net-worth. Read how their advisory business builds on Salesforce.
