Create a data detect policy in your Salesforce org.
Add detection rules to identify sensitive data patterns.
Run the policy and review the results.
Introduction
You've learned about the power of Data Detect for identifying sensitive data across your Salesforce org. Now it's time to put that knowledge into action by creating your own data detect policy.
In this unit, you create a data detect policy, add detection rules, configure the scan scope, run the policy, and review the results. By the end, you'll have a working policy that identifies sensitive data patterns in your org.
Before you start, make sure you have a Trailhead Playground ready. If you need to create one, follow the instructions in Trailhead Playground Management.
This hands-on challenge requires the following prerequisites:
A Trailhead Playground with Data Detect enabled
System Administrator permissions
Familiarity with Salesforce Setup (the previous unit covers the basics)
Hands-On Challenge
This unit includes hands-on steps you complete in your own Trailhead Playground. Check each challenge as you go to verify your work before moving on.
Create a Data Detect Policy
A data detect policy is a container that groups your detection rules and scan configurations together. Think of it as a project that defines what sensitive data to look for and where to look.
Follow these steps to create your first policy.
From Setup, enter Data Detect in the Quick Find box, then select Data Detect Policies.
Click New Policy.
For the policy name, enter Sensitive PII Detection.
For the description, enter Scans org data for personally identifiable information including SSN, email, and phone patterns.
Leave the status set to Draft.
Click Save.
The New Policy form in Setup with the policy name and description fields filled in.
Check ChallengeDemo check
Add Detection Rules
Detection rules define the sensitive data patterns your policy looks for. Each rule targets a specific type of data, like Social Security numbers, email addresses, or credit card numbers, using pattern matching.
Add three detection rules to your policy.
Rule 1: Social Security Number
On the policy detail page, click the Detection Rules tab.
Click Add Rule.
For the rule name, enter SSN Pattern.
For the detection type, select Regular Expression.
In the pattern field, enter the pattern below.
Set the sensitivity level to High.
Click Save.
\b\d{3}-\d{2}-\d{4}\b
Rule 2: Email Address
Click Add Rule again.
For the rule name, enter Email Pattern.
For the detection type, select Built-in Classifier.
From the classifier dropdown, select Email Address.
Set the sensitivity level to Medium.
Click Save.
Rule 3: Phone Number
Click Add Rule once more.
For the rule name, enter Phone Pattern.
For the detection type, select Built-in Classifier.
From the classifier dropdown, select Phone Number (US).
Set the sensitivity level to Medium.
Click Save.
You should now see three rules listed on the Detection Rules tab. Each rule shows its name, detection type, and sensitivity level.
Check Challenge ProgressDemo check
Configure the Scan Scope
The scan scope tells Data Detect which objects and fields to scan. Rather than scanning everything in your org (which can take a long time), you target specific objects where sensitive data is most likely to live.
Configure the scan scope for your policy.
Click the Scan Scope tab on your policy.
Click Add Objects.
In the object search, find and select Contact.
Select the following fields to scan:
Description
Email
Phone
MailingStreet
Click Save.
Repeat the process to add the Lead object with the same field types: Description, Email, Phone, and Street.
Click Save.
Tip
Start with a narrow scope when testing your policy. You can always expand the scope later to include additional objects and fields once you've verified your detection rules work correctly.
Check Challenge ProgressDemo check
Run the Policy
Now that your policy has detection rules and a scan scope, you're ready to activate and run it. When you run the policy, Data Detect scans the configured objects and fields for matches against your detection rules.
Navigate back to the Details tab of your policy.
Change the policy status from Draft to Active.
Click Save.
Click the Run Policy button in the upper-right corner.
In the confirmation dialog, review the scan scope summary, then click Run Now.
Wait for the scan to complete. You can monitor progress on the Scan History tab. The scan typically takes 1 to 3 minutes for a small org.
The Run Policy confirmation dialog shows how many objects and fields will be scanned.
Check ChallengeDemo check
Review Results
After the scan completes, Data Detect presents the findings in a results dashboard. You can see how many matches were found, broken down by detection rule, object, and sensitivity level.
Review your scan results.
Click the Results tab on your policy.
Review the results summary at the top. Note the total number of matches and the breakdown by sensitivity level.
Click on the SSN Pattern rule in the results list to see which records matched.
For each match, Data Detect shows:
The object and field where the match was found
The record ID so you can navigate directly to it
The sensitivity level assigned by the detection rule
A confidence score indicating how closely the data matched the pattern
Navigate back to the results summary and verify that all three rules produced results.
If any rule shows zero matches, that's expected. It means your org's sample data doesn't contain that pattern. The important thing is that your policy ran successfully and produced a results report.