Platform

Security Center, Shield, and Data Governance

Christine Bauer

Security Center Metrics: Global AI Opt Out

Enables admins to track tenant AI data-sharing status across their org, with auditability. Updated in July: Enterprise (Multi-tenant) features a 90-day state swimlane/Gantt chart and audit log; SMB (Single-tenant) displays

current status

and change history, serving as the Security Center Essentials version.

Security Center Metrics: 3rd party MCPs

Monitors near real-time risk for 3rd-party MCPs and tools across all connected tenants. JTBD: Enable admins to assess and respond to security anomalies without switching tools.

Steps taken

Developed multi-tenant views for different and "all data" metrics, including score change tracking and tool-level drill-downs.

Security Center Tools: Field Classification

This centralized dashboard automatically scans, tracks, and bulk-classifies sensitive field-level data using templates and advanced filtering to manage PII and compliance risks. Updates include a redesigned filter menu (listbox and pills) and an improved tooltip system for better classification clarity. Navigation and layout are approved.

Shield App: Encryption Sync

This dashboard monitors encryption status and flags records using outdated keys, enabling compliance scans and re-encryption. Recent updates include a modernized Shield App interface, refined Zero Day states, improved filters for JTBD workflows, and comprehensive logic diagrams, now pending engineering review for key management compliance.

Shield App: Field Level Encryption

Secures sensitive data at rest in standard and custom fields by converting plaintext to ciphertext, ensuring compliance through restricted access. Recent updates include usability and accessibility fixes from the May bug blitz (264 release) and a new limit of 1,000 fields per analysis.

Project Guardian: TSP for Data Classification

A component of the Project Guardian initiative, this feature enhances secure-by-default protocols. It allows admins to create Transaction Security Policies (TSPs) that monitor real-time user activities based on data classification, enabling them to block unauthorized actions, require MFA, or trigger instant notifications.

Field Audit Trail for Data Cloud

This feature provides up to ten years of forensic history, tracking data changes to support compliance and lineage. Completing the governance loop with Event Monitoring, Data Detect, and Platform Encryption, it starts with the Individual DMO and is available via credit-based opt-in. A dedicated FAT space and opt-in functionality were introduced in Q2, with Beta launching in October.