If You Use Salesforce, Are You Prepared for the Business Risks?
-
August 18, 2026
-
Salesforce is among the most widely deployed enterprise platforms in the world, housing organizations’ customer data, sales activity, user behavior, and operational workflows that are frequently relevant in litigation, regulatory inquiries, internal investigations, and even compliance reviews. Yet many organizations have not fully considered the investigative implications of how their Salesforce environment is configured.
The core risk is straightforward: Salesforce’s default settings are designed for operational efficiency, not investigative readiness. Without deliberate proactive decisions to extend retention periods, activate tracking features, or implement supplemental monitoring, organizations may find that crucial data simply does not exist when needed. Records can be deleted. Retention windows can expire. Activity that was never tracked cannot be reconstructed. By the time an investigation is triggered, the window to preserve or recover that information may have already closed.
There is also a permissions risk that deserves attention. Certain Salesforce users, particularly administrators or equivalent superusers, have elevated access that can create significant blind spots and risks if misused or left unmonitored. Without the right monitoring in place, organizations may be unable to answer basic questions about who accessed what, when, why, and how.
Five Questions Leaders Should Be Asking Today
Before an investigation occurs, senior executives and legal and compliance leaders should be asking a focused set of questions about their Salesforce environment.
- Can we identify who has been logging into our Salesforce instance, from where, and through what means, and how far back does that history go? Salesforce’s standard installation includes login tracking, which captures successful and unsuccessful login attempts, IP addresses, login methods, and timestamps, for up to six months by default. If your organization has not taken steps to extend that window, six months of data may be all you have.
- Do we know what critical data has changed, who changed it, and when? Salesforce allows organizations to track changes to up to 20 fields per object at no additional cost, with history available for 18 to 24 months. However, tracking must be activated and changes that occurred before tracking was enabled are not captured. If your organization has not turned on field history tracking for the records that matter most, that history does not exist.
- Are we monitoring privileged user activity? Administrator-level access in Salesforce includes the ability to log in as other users, modify security settings, and alter system configurations. Without active monitoring, these actions may go undetected until an investigation reveals a gap that cannot be filled.
- How long has it been since anyone reviewed our Salesforce configuration audit trail? Salesforce tracks changes to system configurations (e.g., profiles, permission sets, field definitions, security settings, etc.) by default. However, only the most recent 180 days of that history can be exported, and only the 20 most recent changes are visible through the standard interface. Organizations that are not intentionally preserving this information on a periodic basis are allowing it to expire.
- What would we be unable to answer if an investigation began tomorrow? This is perhaps the most important question. If the honest answer involves uncertainty about user activity, data changes, or system access on critical information, that uncertainty reflects a governance gap worth addressing now.
Where Salesforce Can Support (and Limit) Investigations
Salesforce provides meaningful investigative capability out of the box, but that capability has boundaries that are not always visible until they matter.
On the positive side, the platform’s standard features support a range of investigative questions. Login history, field-level change tracking, configuration audit trails, and feed tracking are all available without additional cost and can provide a useful foundation for understanding what has happened within the system. For organizations that have maintained these features and preserved the data before retention windows expired, Salesforce can be a productive source of evidence.
The limitations, however, are significant and largely a function of failures in prior planning. Default retention periods are short: 30 days for detailed login event logs, six months for login history, 18 to 24 months for field change history, and 180 days for configuration audit data. Once those windows close, the data is gone unless it was extracted or backed up beforehand. Tracking features that were never activated cannot produce retroactive records. And without premium monitoring capabilities, detailed user activity and particularly any activity beyond the most recent (e.g., which reports were run, which pages were accessed, what files were downloaded, which data was exported, etc.) is simply not logged or retained.
For organizations that have invested in Salesforce’s premium monitoring capabilities, the picture has considerably more resolution. Real-Time Event Monitoring provides extended retention and richer detail on login activity, including administrator impersonation events. The Field Audit Trail expands tracking capacity from 20 fields per object to 200, with indefinite retention. The Event Monitoring add-on captures a broad range of user activity in granular detail, including report execution, data exports, page views, API calls, and file downloads. These capabilities can transform Salesforce from a limited data source into a robust investigative record, but only for organizations that activated them before the investigation began.
The consistent theme is that Salesforce’s investigative value is largely determined in advance. The platform does not automatically preserve everything: it preserves what organizations have configured it to preserve.
Heed the Opportunity to Strengthen Governance and Readiness
For organizations that have not yet taken a deliberate approach to Salesforce data governance, the opportunity to do so is available now. Investigations are infrequent, but when they occur, the absence of data can be far more damaging than the presence of unfavorable information.
There are several areas where proactive governance can meaningfully improve an organization’s position. Establishing a regular cadence of data preservation before the default retention windows expire is a foundational step that requires no additional Salesforce investment. Reviewing which fields and objects should be tracked, and ensuring that tracking is activated for the records most likely to be relevant in a dispute or investigation, is a governance decision that belongs at the compliance and legal level, not just with IT.
For organizations with elevated risk profiles (e.g., heavily regulated industries, complex Salesforce deployments, or organizations that have experienced prior incidents), evaluating the premium monitoring and audit capabilities Salesforce offers is a worthwhile exercise. The question is not whether those tools are technically sophisticated but rather if the organization’s current visibility into its own platform instance is sufficient to meet its legal, regulatory, and fiduciary obligations.
Finally, organizations should consider whether their current Salesforce governance framework reflects the same rigor that is applied to other enterprise systems. For many organizations, Salesforce is not simply a sales tool but a system of record that sits at the center of customer relationships, revenue operations, and business-critical workflows. Decisions like who holds administrative access, how configuration changes are reviewed, and how data retention decisions are made can be critical for answering future questions.
The decisions organizations make today about visibility, retention, and governance define the options available to them when a future investigation occurs. The time to ask these questions is now while choices still exist, and not when a future subpoena arrives or a regulator inquires.
Related Information
Published
August 18, 2026
Key Contacts
Senior Managing Director
Managing Director
Senior Director