Loading
Upcoming Mandatory Changes to Public Key Infrastructure (PKI)Read More
Salesforce Enforces New Security Requirements in Summer 2026Read More
Agentforce and Einstein Generative AI
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Select What Data To Mask

          Select What Data To Mask

          Select which data you want to mask and prevent exposure of sensitive data to the large language model (LLM). These settings are applied to your Salesforce org.

          Required Editions

          Available in: Enterprise, Performance, and Unlimited Editions with an Einstein for Sales, Einstein for Platform, Einstein for Service, Einstein 1 Service, or Einstein GPT Service add-on. To purchase add-ons, contact your Salesforce account executive.
          User Permissions Needed
          To select what data to mask: View Setup
            AND
            Customize Application

          Einstein Generative AI and Data Masking must be enabled.

          Data masking for LLMs is disabled for agents. See Data Masking and Agents. For embedded generative AI features, such as Einstein Service Replies, Einstein Work Summaries data masking is available, and you can configure it in Einstein Trust Layer setup.

          At initial setup, the most commonly used entries are turned on, and less frequently used entries are off.

          1. From Setup, in the Quick Find box, enter Einstein, and then select Einstein Trust Layer.
            Note
            Note If you can’t find Einstein Generative AI Setup, ensure that your org meets the prerequisites for any generative AI features you plan to use. For more support, contact your Salesforce Account Executive (AE).
          2. Select Go to Einstein Trust Layer
          3. Turn on large language model data masking.
          4. Review the list of data types included in the pattern-based masking section and make changes as needed. Some data types are turned on for data masking by default.
          5. Turn on data masking for Shield Platform Encryption, compliance categories, and data sensitivity levels. Confirm that the sensitive fields that must be masked are tagged with the correct compliance categories and data sensitivity levels in Object Manager.
            You see the Shield Platform Encryption option in Einstein Trust Layer setup only if you enabled it in your org.
           
          Loading
          Salesforce Help | Article