Newer Version Available

This content describes an older version of this product. View Latest

Change Events for Encrypted Salesforce Data

If Salesforce record fields are encrypted with Shield Platform Encryption, changes in encrypted field values generate change events.

Change events are stored in a separate data store in Salesforce for up to three days. Before being stored, they’re encrypted and require you to create an Event Bus tenant secret. To enable encryption and delivery of change events, first create an Event Bus tenant secret on the Key Management page in Setup. Then enable encryption and delivery of change events on the Encryption Policy page.

If you don’t enable encryption and delivery of change events after Change Data Capture is enabled in a Shield Encryption org, event payloads are blocked and aren’t delivered. (Blocked events aren’t stored in clear text.) To prevent event loss, perform the steps to enable encryption of change events.