How Data Cloud Works > Governance

Govern data and metadata at high scale.

Data Cloud Governance gives you the tools to simplify your structured and unstructured data management, quickly apply consistent policies across all data, and enable worry-free security.

Data Cloud Governance

Provide native, policy-driven trust controls directly to your unified data foundation, enabling secure data activation across every use case — using tools ranging from AI agents like Agentforce to analytics, personalization, and segmentation.

Diagram showing structured data, unstructured data, and zero copy integrations with various app logos and 3rd party integration features.

Easily govern all your data with AI assistance.

Automate the tagging and classification of unified data and metadata to drive policy-based governance across every use case.

Establish a secure and private connection.

Establish a secure and private connection.

Prevent vulnerabilities and protect sensitive information while providing flexible encryption key management.

Enforce consistent data access across all data sources.

Enforce consistent data access across all data sources.

Empower users to easily author, manage, and consistently enforce policies with clicks across all ingested and zero copy data.

accenture logo

We expect that Data Cloud Governance will help us deliver a safer, smarter and more compliant leap forward in how enterprises manage and secure data in the AI era.”

Stephen Nicolls
Global IT Managing Director, Accenture

Data Cloud Governance Features

Segregate data, metadata, and processes by brand, BU, and region such that each business unit can maintain control over its own data while still only using one instance of Data Cloud.

Securely connect external data sources — data lakes, warehouses, business apps — using Zero Copy technology. This ensures consistent governance and privacy across all platforms, with direct, private connections that enhance data residency and protect against loss.

Enhanced control over your data’s security. Data Cloudoffers flexible key management, including customer or externally managed keys for direct control, and External Key Management for integrating with your AWS KMS accounts. Your data, fully protected.

Additional Features

Easily author, manage, and enforce, fine-grained policies (field, object, record level) consistently across all your data. These policies automatically apply everywhere in Data Cloud, ensuring data access is consistently enforced across all features like Agentforce, analytics, and segmentation.

Automatically label and classify records with AI-recommended tags — marking data as 'HIPAA,' 'GDPR,' or 'PII.' These tags follow a business or compliance framework that fits any organization’s needs.

Intelligent, real-time protection for sensitive information. Data is dynamically masked or revealed based on policy, ensuring users see only what they're entitled to, without altering the underlying data.

Learn how Data Cloud Governance works.

Tag & Classify

Automate tagging and classification of all your data to drive policy-based governance.

Extend Governance with Salesforce Trusted Services.

Strengthen your security posture, simplify data privacy management, and backup your data to prevent data loss with Trusted Services products.

Data Cloud Governance FAQs

Data Cloud Governance is the set of capabilities in Data Cloud that allows users to systematically manage the access, usage, and security of data and metadata across teams and processes in a dynamic and scalable way. It provides tools to simplify your structured and unstructured data management, quickly apply consistent policies across all data, and enable worry-free security. With features like automated tagging and classification, policy-driven trust controls, and flexible encryption key management, Data Cloud Governance helps deliver a safer, smarter, and more compliant approach to data governance in the AI era.

Potential applications include, but are not limited to: restricting AI agents from data access or performing specific actions based on use case and role; limiting data access for non-business-critical teams in areas such as reporting, segmentation, and activation; and utilizing private connections between zero-copy data sources and Data Cloud for enhanced analytics and connected customer experiences.

AI agents are only as good and trustworthy as the data that grounds it. Data Cloud Governance ensures that Agentforce can access and utilize the right data about the right person at the right time for a given use case, and that sensitive data is not misused.

Data Cloud Governance offers significant benefits by enhancing compliance (GDPR, HIPAA, etc.), boosting employee productivity through effective and secure AI agents, and improving data quality. It also helps to reduce reputational risk from data breaches, storage costs, and data latency.

Data Cloud provides capabilities that can address data management challenges for complex organizations: Data Spaces logically separate data and metadata, making them suitable for distinct business units or regions that don't need shared datasets. Granular access-based policies allow for more specific access control within each Data Space, ensuring customized data access while maintaining overall governance.

Data Cloud's policy-based governance framework is built into Salesforce’s metadata framework and allows you to define and enforce data access and usage rules across the entire data landscape in Data Cloud as well as applications that consume the data. These policies are applied dynamically, ensuring that as your data grows and evolves, your governance and compliance standards are maintained automatically.

Yes, encrypting data in core CRM apps does not cover data encryption in Data Cloud. Data Cloud's governance features and Salesforce Shield work together as complementary layers to provide a holistic security and compliance strategy across your entire Salesforce environment.