Loading
Salesforce Enforces New Security Requirements in Summer 2026Read More
Set Up and Maintain Your Salesforce Organization
Scanning Data 360 with Data Detect

Scanning Data 360 with Data Detect

Use Data Detect to scan Data 360 for sensitive data. Data 360 eliminates data silos, creating a single platform to access all of your organization data. Use Data Detect to scan and detect sensitive data in large batches within Data 360 to facilitate the correct handling of sensitive data. Selecting a DLO automatically targets all of its text fields. A single scan policy execution supports up to 100 DLOs.

Required Editions

Available in: Lightning Experience

Available in: Enterprise, Performance, Unlimited, and Developereditions.

Requires the Salesforce Shield add-on subscription or the Data Detect add-on license and Data 360 licenses (Data Cloud Provisioning, Data Spaces , Storage Beyond Allocation).

DLO Access

When selecting a DLO in Data Detect, it perfectly mirrors your data space configurations. You can only view and select DLOs in data spaces you have explicit permission to access. A single scan policy can span across multiple assigned data spaces.

Any users with permission to view Data Detect results see the aggregate metrics for all DLOs included in a scan.

Differences When Scanning Data 360 with Data Detect

  • You need a data stream to use Data Detect with Data 360. For complete information on setting up data streams, see Data Sources in Data 360 and Data Streams in Data 360
  • Creating and running a scan policy is the same for Data 360 and a standard Salesforce Org. Objects in Data 360 are referred to as Data Lake Objects (DLOs) instead of standard objects.
  • Data 360 scan policies can't scan for keywords.
  • Data Detect doesn't support external DLOs and unstructured DLOs.
  • Data Cloud ingests data continuously (with approximately 3-minute latency). Scans on live, actively updating DLOs can yield inconsistent results.
  • Data 360 enforces a maximum limit of 31,072 characters per field value. Values exceeding this limit are truncated at the platform level before reaching the scan engine. The truncation can lead to incomplete scanning coverage for exceptionally long text fields.
Warning
Warning Due to its underlying architecture, Data Detect can't differentiate between a physically deleted Data Lake Objects (DLOs) and structurally inaccessible due to profile permission changes.

If a DLO included in an active policy is deleted or becomes inaccessible, the policy is permanently deadlocked.

A deadlocked policy can't be viewed, run, edited, or cloned. All historical job session results associated with that policy are inaccessible.

To recover from a policy deadlock, create an entirely new policy from scratch or contact support for help with removing the deleted DLO from the policy.

 
Loading
Salesforce Help | Article