How do I audit who viewed a sensitive Salesforce record?

An employee walks out on a Thursday afternoon. By Friday morning, leadership or IT wants to know whether they opened anything sensitive on the way out, and you're the one who has to answer.

You've done the work on your side. The fields are tagged, the permissions are tight, and you still can't say what that user actually looked at. "Probably nothing" doesn't satisfy anyone, and being wrong means a breach: fines and penalties, legal settlements, or a competitor who now knows your pipeline. If you sell anything to anyone, you're holding somebody's data, so this lands on you whether or not anyone calls you the security team.

Field tags and permissions

Salesforce gives us good tools here. Field-level metadata tags help us keep track of which fields are sensitive, and field level security (FLS) and the rest of the permissions structure make sure users only see what they're supposed to see. Most admins have put real hours into this, and it's the right place to start.

But those tools answer a different question. Tags tell you where the sensitive data lives. Permissions tell you what someone is allowed to see. Neither one tells you what they actually saw, and every admin knows a persistently curious user can still find their way to data they weren't meant to have.

If they do, how would you find out?

The export audit log

You can run an audit log on exports, and it's worth checking when someone leaves. A rep who downloads every open Opportunity on the way out will show up there.

Exporting is also the clumsiest way to take something. Someone who opens a report and hits copy/paste hasn't exported anything. Neither has the person who screenshots a dashboard or a few Account records.

So a clean export log tells you what they didn't download. That's a much narrower claim than "they didn't take anything," and leadership will hear it as the second one.

A record of what was opened

Between permissions and the export log, you can say what someone could see and what they carried out. You still can't say what they looked at. Salesforce has always been missing a true audit trail of which records, reports, and dashboards—and therefore which data—users view in the UX.

That's the gap RecordWatch's out-of-the-box view tracking fills. At the individual user level, you can see who is viewing which records, reports, and dashboards. Each record carries its own list of views, and each view shows whether it happened on desktop or mobile.

Knowing someone didn't export an at-risk Account report is good. Knowing they never opened it is better, and it's an answer you can give leadership, IT, and auditors without a "probably" attached.

It works going forward, too. Pair view tracking with sensitive record flags and you can set up real-time email alerts when users open records they shouldn't. Did the East Coast BDR just open a stack of West Coast Opportunities that have nothing to do with their territory? Did the rep on a PIP work through every report a competitor would find useful?

Those alerts tell you while it's happening, which no permissions review can.

So when the question comes on Friday morning, you have more than a guess. You can pull the list of what that user opened, tell leadership plainly what was and wasn't touched, and if something was, you find out while there's still time to do something about it.

Frequently asked questions

Can field level security tell me who viewed a sensitive Salesforce record?

No. Field level security and other permissions decide what a user is allowed to see, but they don't keep a record of what a user actually opened. Metadata tags on sensitive fields help you track where the data lives, not who looked at it.

Does an export audit log show everything a departing user could have taken?

No. An export log covers exports. A user who opens a report and copies the data, or takes a screenshot of a dashboard or a few Account records, never triggers an export, so a clean export log only proves what they didn't download.

How can I see which users viewed a specific record, report, or dashboard?

RecordWatch's out-of-the-box view tracking shows, at the individual user level, who is viewing which records, reports, and dashboards in Salesforce.

Can I get alerts when someone opens a record they shouldn't?

Yes. Combine sensitive record flags with RecordWatch view tracking to set up real-time email alerts when users access records they shouldn't, such as a rep opening Opportunities assigned to another region.

Why does it matter if a user only viewed a record and never exported it?

A user who looked at sensitive data can still walk away with it through a copy/paste or a screenshot. Proving someone never opened a record is stronger assurance for leadership, IT, and auditors than proving they never exported it, and a breach can bring fines, legal settlements, and lost competitive advantage.

Next
Next

How do I Know if marketing is using the Salesforce Dashboard I built them?