Select What Data To Mask
Select which data you want to mask and prevent exposure of sensitive data to the large language model (LLM). These settings are applied to your Salesforce org.
Required Editions
| Available in: Enterprise, Performance, and Unlimited Editions with an Einstein for Sales, Einstein for Platform, Einstein for Service, Einstein 1 Service, or Einstein GPT Service add-on. To purchase add-ons, contact your Salesforce account executive. |
| User Permissions Needed | |
|---|---|
| To select what data to mask: | View Setup |
| AND | |
| Customize Application | |
Einstein Generative AI and Data Masking must be enabled.
Data masking for LLMs is disabled for agents. See Data Masking and Agents. For embedded generative AI features, such as Einstein Service Replies, Einstein Work Summaries data masking is available, and you can configure it in Einstein Trust Layer setup.
At initial setup, the most commonly used entries are turned on, and less frequently used entries are off.
- From Setup, in the Quick Find box, enter Einstein, and then select
Einstein Trust Layer.
Note If you can’t find Einstein Generative AI Setup, ensure that your org meets the prerequisites for any generative AI features you plan to use. For more support, contact your Salesforce Account Executive (AE). - Select Go to Einstein Trust Layer
- Turn on large language model data masking.
- Review the list of data types included in the pattern-based masking section and make changes as needed. Some data types are turned on for data masking by default.
- Turn on data masking for Shield Platform Encryption, compliance categories, and data
sensitivity levels. Confirm that the sensitive fields that must be masked are tagged with the
correct compliance categories and data sensitivity levels in Object Manager.You see the Shield Platform Encryption option in Einstein Trust Layer setup only if you enabled it in your org.
Did this article solve your issue?
Let us know so we can improve!

