Businesses today have access to more knowledge and data than ever before. However, bridging the gap between simply having this wealth of information and acting on it is a common challenge, with 94% of business leaders believing they aren’t yet fully leveraging the value of their data. For security teams in particular, it can be difficult to connect the dots on activity that spans multiple systems, such as an identity compromise across Salesforce and an external provider. Addressing priorities like anomalous API activity or offboarded user logins requires a more unified approach.
To help solve this, we are excited to announce Security Mesh, a new Salesforce-native solution built specifically for Salesforce admins and security teams. Security Mesh is available through Security Center, an add-on security product that gives you centralized visibility and control over your security posture. With Security Mesh, you can quickly and easily unify and normalize disparate security data across multiple systems to give you enhanced visibility.
How Security Mesh works
Security Mesh simplifies threat detection in two ways:
- Connect: You can easily retrieve data from security sources both inside and outside of Salesforce. Security Mesh connects Salesforce’s internal signals, like Real-Time Event Monitoring, with external partner security feeds.
- Normalize: Security Mesh leverages the Open Cybersecurity Schema Framework (OCSF) standard to map your disparate data into a single, unified model. This brings all your data into a simple, queryable format—standardizing attributes like Username, IP Address, Last Login, Location, and Role, regardless of the original source.

By correlating disparate data streams, Security Mesh provides the foundation for you to build powerful custom detections such as:
- Impossible Travel: Flag when a user account is accessed from two geographically distant locations within a timeframe that is physically impossible to navigate, helping you understand the related Salesforce activity. Available out-of-the-box.
- Data Exfiltration: Spot when a user authenticates from an anomalous signal (such as a new location or unusual hours) and subsequently executes bulk API calls or massive report exports that spike above their normal baseline.
- Active Sessions During Endpoint Compromise: Detect whether an endpoint is compromised (e.g., via a credential stealer or malware) when a user has an active, high-activity Salesforce session. Using Real-Time Event Monitoring, you can see exactly what occurred while the “door was open”.
Availability and roadmap
Security Mesh is available with Security Center and requires Data 360 to use. We are excited to share that Real-Time Event Monitoring data and the following external data sources are Generally Available (GA) today:
- Okta ISPM user data
- CrowdStrike endpoint security data
- DigitSec code and pipeline scanning data
Ready to unify your security data? Check out our Security Center page or request a demo today.










