Control Salesforce Data Audit Trails in 2026
- Oct 14, 2025
- 13 min read
Quick Answer
Salesforce provides native auditing through Field History Tracking, Setup Audit Trail, and Event Monitoring — but each has retention limits that leave multi-year gaps for regulated enterprises. HIPAA requires six years. SOX requires seven years. GDPR requires retention for the duration of the legitimate purpose. Closing those gaps requires a layered set of controls that extend native auditing with purpose-built backup infrastructure, continuous monitoring, and evidence production workflows that work under the time pressure of an active regulatory inquiry. This guide covers every control regulated enterprises need — and the specific gaps that make native Salesforce auditing insufficient on its own.
Why native Salesforce auditing is not enough for regulated enterprises
Salesforce provides auditing tools that are genuinely useful for operational visibility. Field History Tracking tells you who changed a field value and when. Setup Audit Trail tells you who modified the org configuration. Event Monitoring tells you who accessed which records and ran which reports. For day-to-day Salesforce administration, these tools provide the visibility that IT teams need.
The problem surfaces during regulatory audits — when the question is not "what happened recently" but "what happened over the past six years." At that point, the native tools' retention windows become the most important fact about them.
Field History Tracking retains 18 months. Setup Audit Trail retains 180 days. Event Monitoring log files default to 30 days. The Salesforce recycle bin retains deleted records for 15 days.
None of these windows satisfy HIPAA's six-year retention requirement. None satisfy SOX's seven-year requirement. None satisfy the multi-year accountability period that GDPR enforcement increasingly expects organizations to demonstrate. And critically — none of these gaps are configurable. They are architectural limits of the platform. No Salesforce administrator can extend Field History Tracking retention beyond 18 months through org configuration. The gap requires supplementary infrastructure.
The audit trail controls that regulated enterprises need are not a replacement for native Salesforce tools. They are a layered architecture that uses native tools for operational visibility and purpose-built infrastructure for compliance-grade evidence retention.
Control 1: Extended field-level change history
What HIPAA and GDPR require
HIPAA's Audit Controls standard requires mechanisms to record and examine activity in information systems containing or using ePHI. For Salesforce environments containing electronic protected health information — Health Cloud implementations, CRM at healthcare payers and providers — this means field-level change history for every ePHI field retained for the full six-year HIPAA retention period.
GDPR's accountability principle requires that organizations demonstrate how personal data has been processed. For Salesforce environments containing contact records, lead data, and customer relationship history, this means producing a complete processing history for any personal data record — every modification, with the user who made it and the timestamp — for any period within the applicable retention window.
What native tools provide
Field History Tracking retains change history for up to 20 fields per object for 18 months. For HIPAA environments where ePHI spans more than 20 fields on a Salesforce object — a common situation in complex Health Cloud implementations — the 20-field cap creates audit gaps that cannot be resolved through configuration.
For the six-year HIPAA and seven-year SOX retention requirements, 18 months is less than a quarter of the required period. The remaining years of change history are simply not available through native tracking.
The control
Purpose-built backup infrastructure that captures field-level change history for every field on every object — no field count limits — and retains that history for the customer-defined period that matches the applicable regulatory requirement.
Sesame Software captures complete field-level change history with no field count limits. Every modification is logged with the previous value, the new value, the user who made the change, and the timestamp — retained for the customer-defined period in the customer's own environment. Deleted records are retained in the audit archive for the same period, enabling compliance teams to produce the complete lifecycle history of any record regardless of when it was deleted.
Control 2: Configuration change history beyond Setup Audit Trail
What compliance frameworks require
SOX compliance for Salesforce environments used in financial reporting requires that the integrity of systems producing financial data be demonstrable. Configuration change history — the permission sets, workflow rules, and validation rules that governed data entry during a reporting period — is part of the SOX evidence package.
HIPAA's Audit Controls standard extends to the security configuration of systems containing ePHI. When a compliance audit requires demonstrating that a permission set was correctly configured during a specific period, or that a validation rule was in place when a specific data entry occurred, the configuration change history for that period must be producible.
What native tools provide
Setup Audit Trail captures configuration and administrative changes — permission set modifications, profile changes, custom field additions and deletions, and workflow rule changes — for 180 days. Six months of configuration change history does not satisfy multi-year compliance requirements.
There is no native mechanism to compare the org configuration at two points in time or to restore a previous configuration state. Setup Audit Trail shows what changed — it does not provide a recoverable snapshot of the configuration before the change.
The control
Continuous metadata capture alongside data backup, with version history that enables comparison between metadata states at any two points in the backup history.
Sesame Software captures Salesforce metadata on every backup cycle — object definitions, field configurations, permission sets, profiles, validation rules, workflow rules, flows, and page layouts — alongside data records. The Metadata Compare feature provides visual, side-by-side comparison of org configuration at any two points in the backup history. The configuration change evidence that SOX and HIPAA audits require is accessible from within the customer's own environment without requiring vendor assistance or data engineering resources.
Control 3: User activity monitoring beyond Event Monitoring defaults
What compliance frameworks require
HIPAA's Audit Controls standard requires mechanisms to record and examine activity in information systems containing ePHI. For Salesforce Health Cloud and healthcare CRM environments, this includes login events, report exports that may contain ePHI, record views, and API calls that access ePHI fields — all retained for the six-year HIPAA retention period.
GDPR's accountability principle extends to demonstrating that access to personal data was limited to authorized personnel. An access log that shows who viewed which personal data records, when, and from which location is the evidence that supervisory authorities request when assessing whether an organization's data minimization and access control practices are effective.
What native tools provide
Event Monitoring provides granular user activity data — login history, report exports, API calls, record views, and data access events. It is the most powerful native audit tool Salesforce offers. The default retention for Event Monitoring log files is 30 days, with an option to extend to one year on certain plans.
For HIPAA's six-year retention requirement, one year of Event Monitoring retention is insufficient. For GDPR investigations that span multiple years, 30-day or one-year retention produces gaps in the access history that compliance teams cannot fill from any other source.
The control
External archiving of Event Monitoring log files on a continuous basis, storing them in customer-controlled infrastructure for the full regulatory retention period.
When Sesame Software's backup infrastructure runs continuously alongside native Salesforce auditing, Event Monitoring log files can be extracted and archived before the native retention window expires. Combined with Sesame Software's field-level change history and metadata capture, this creates a complete multi-year audit trail that covers data changes, configuration changes, and user access events — all retained in the customer's own environment for the customer-defined period.
Control 4: Deleted record retention and lifecycle documentation
What compliance frameworks require
HIPAA investigations frequently require producing records that were deleted from Salesforce — to demonstrate that records were protected against unauthorized destruction, or to reconstruct the state of ePHI at a specific point in time. A recycle bin that empties after 15 days does not satisfy a six-year retention requirement for ePHI lifecycle documentation.
GDPR's right to erasure creates a specific tension for deleted record retention. When a data subject requests erasure, the organization must delete the record — and must not restore it. But the organization must also demonstrate that the deletion was executed completely across all storage. This requires retaining documentation of the deletion — not the record itself — for the applicable period.
For litigation holds, the ability to produce records that were deleted months or years ago is a legal requirement that 15-day recycle bin retention cannot satisfy.
What native tools provide
The Salesforce recycle bin retains deleted records for 15 days before permanent removal. After 15 days, there is no native path to recover or produce a deleted record or its contents.
The control
Backup infrastructure that captures soft-deletes continuously and retains deleted records in backup storage for the customer-defined retention period — independent of the Salesforce recycle bin lifecycle.
Sesame Software retains deleted records in the backup archive for the customer-defined period. For GDPR right to erasure compliance, the platform supports governed deletion from backup storage with a documented audit trail of the deletion execution — producing the evidence that GDPR supervisory authorities require when verifying erasure compliance. For litigation holds, deleted records remain accessible in backup storage for the full retention period regardless of when the deletion occurred.
Control 5: Real-time monitoring and anomaly detection
What compliance frameworks require
Compliance frameworks require more than historical audit evidence — they require that organizations detect and respond to incidents in a timely manner. HIPAA's Security Rule requires covered entities to implement procedures to monitor log-in attempts and report discrepancies. GDPR requires that personal data breaches be detected, assessed, and reported to supervisory authorities within 72 hours of discovery.
Detecting an incident requires monitoring. An organization that discovers a breach during an audit — rather than through ongoing monitoring — has already failed the timeliness requirement.
What native tools provide
Salesforce provides limited native alerting for suspicious activity. Login History records authentication events that administrators can review manually. Event Monitoring log files can be analyzed for anomalies, but this requires either manual review or a third-party SIEM integration. There is no native real-time alerting for bulk data access, unusual report exports, or permission changes that create unexpected access.
The control
A layered monitoring architecture that combines Salesforce native logging with external SIEM integration and automated alerting for the specific event patterns that regulated enterprises need to detect.
Configure Salesforce to send Event Monitoring data to your SIEM platform — Splunk, Microsoft Sentinel, IBM QRadar — on a continuous basis. Define detection rules for the patterns that matter most in your regulatory context: bulk record access by a single user, report exports containing ePHI fields outside business hours, permission set changes that expand access to regulated objects, and login events from unusual locations or devices.
Configure alerts that notify both the IT security team and the compliance team when these patterns are detected — with enough detail to assess whether the event represents a genuine incident or an expected business activity. The 72-hour GDPR breach notification window and HIPAA's breach response requirements both start from when the organization should have known about the breach — not from when someone manually reviewed a log file and noticed the anomaly.
Sesame Software's continuous backup operation creates an independent record of data state at five-minute intervals that supports incident investigation. When a monitoring alert surfaces a potential data access or modification incident, the Sesame Software backup history provides the point-in-time data snapshots needed to assess what data was in the system before and after the event.
Control 6: Evidence production workflow
What compliance frameworks require
Audit evidence needs to be producible quickly, completely, and without requiring technical data engineering resources to compile. HIPAA audits and GDPR supervisory authority inquiries operate under time pressure. An organization that needs to file a support ticket with a vendor, wait for a data extract, and then spend days compiling an evidence package is not operationally prepared for an active regulatory inquiry.
What native tools provide
Salesforce's native tools store audit data within the Salesforce platform — subject to the same retention limits described above. Producing historical evidence from native tools is limited to the retention windows those tools provide. Beyond those windows, there is nothing to produce.
The control
A documented evidence production workflow that specifies exactly how each category of audit evidence is retrieved from backup infrastructure, who is authorized to retrieve it, and how long retrieval takes under realistic conditions.
The workflow should document the following for each evidence category. Field-level change history for a specific object — retrieved from Sesame Software's backup archive through the visual interface, accessible to compliance managers without data engineering support, available for any period within the customer-defined retention window. Deleted record history — retrieved from the backup archive with the complete lifecycle record including deletion event, timestamp, and user. Configuration change history — retrieved from the metadata version archive using the Metadata Compare feature, showing exact configuration at any two points in time. Access logs — retrieved from the external SIEM archive where Event Monitoring data has been stored.
Test the evidence production workflow under simulated audit conditions before a real audit requires it. A workflow that has never been tested under time pressure has unknown failure modes. A workflow that has been tested quarterly has known performance characteristics and identified gaps that can be addressed before they surface during an active inquiry.
Control 7: Role-based access governance for audit data
What compliance frameworks require
HIPAA's minimum necessary principle requires that access to ePHI — including audit records of ePHI access — be limited to those with a legitimate need. GDPR's data minimization principle applies to audit data containing personal information with the same force it applies to operational data. Audit logs that record who accessed personal data records are themselves personal data under GDPR — they must be protected with access controls proportionate to their sensitivity.
What native tools provide
Salesforce's native audit tools do not provide granular access controls for audit data retrieval. Any user with the appropriate Salesforce permission can access Setup Audit Trail. Event Monitoring log access requires a Salesforce Shield license but is not further restricted at the record or field level within the platform.
The control
Role-based access controls for all audit data — both native Salesforce audit tools and backup infrastructure — that apply the minimum necessary principle to every audit data access decision.
Define explicit roles for audit data access. Compliance officers who review audit evidence during regulatory inquiries need different access than IT administrators who monitor pipeline health, who need different access than legal team members who run data subject access reports. Document each role, the access it grants, and the business justification.
Sesame Software's role-based access controls apply the minimum necessary principle to backup and audit data access — restricting access to backup data by user, by object, and by operation type. Every access to backup audit data generates an immutable log entry — who accessed what, when, and for what operation. This audit log of the audit data is part of the compliance evidence package that HIPAA access control documentation requires.
Implementing all seven controls with Sesame Software
Sesame Software's Backup Scheduler delivers the extended audit trail infrastructure that regulated enterprises need as a complement to native Salesforce auditing — not a replacement for it.
Complete field-level change history with no field count limits and customer-defined retention periods fills the gap between native 18-month Field History Tracking and HIPAA's six-year requirement. Continuous metadata capture with Metadata Compare fills the gap between native 180-day Setup Audit Trail and multi-year SOX and HIPAA requirements. Deleted record retention in the customer's own environment satisfies both GDPR erasure documentation requirements and litigation hold obligations beyond the 15-day recycle bin window. Customer-controlled storage in the customer's own environment satisfies data residency requirements and simplifies GDPR Article 30 documentation. Role-based access controls with comprehensive audit logging satisfy HIPAA's minimum necessary principle for backup data access. Non-technical evidence retrieval through the visual interface supports evidence production under the time pressure of active regulatory inquiries.
With 23+ years of enterprise data management expertise and a customer base that includes Procter & Gamble, Bank of America, and the U.S. Government, Sesame Software is built for the compliance requirements that regulated enterprise Salesforce environments present.
Predictable annual pricing based on connectors — no per-row charges or consumption-based billing surprises as data volumes grow.
Talk to a Sesame Software data expert today at sesamesoftware.com.
Set up your pipeline in under an hour. No coding. No maintenance. No surprises.

Salesforce Data Audit Trails Frequently asked questions
What are Salesforce data audit trails and what do they cover?
Salesforce data audit trails are the records of who accessed, modified, or deleted data within a Salesforce environment — field-level change history through Field History Tracking, configuration change history through Setup Audit Trail, and user activity data through Event Monitoring. Each native tool has retention limits — 18 months for Field History Tracking, 180 days for Setup Audit Trail, and 30 days to one year for Event Monitoring — that leave multi-year gaps for regulated enterprises subject to HIPAA, SOX, or GDPR.
Why is native Salesforce auditing insufficient for HIPAA and GDPR compliance?
Native Salesforce auditing is insufficient because its retention windows do not match regulatory retention requirements. HIPAA requires six years. SOX requires seven years. Field History Tracking retains 18 months. Setup Audit Trail retains 180 days. These gaps are architectural — they cannot be closed through Salesforce configuration. Closing them requires purpose-built backup infrastructure that captures and retains audit data for the customer-defined period in the customer's own environment.
How does extended field-level audit history support HIPAA compliance?
HIPAA's Audit Controls standard requires mechanisms to record and examine activity in systems containing ePHI — retained for the six-year HIPAA retention period. Extended field-level audit history captures change records for every field on every object containing ePHI — not just the 20 fields that native Field History Tracking covers — and retains them for six years in the customer's own environment. This produces the audit evidence that HIPAA investigators request when examining whether an organization monitored and protected ePHI access correctly.
What is the difference between Setup Audit Trail and metadata backup?
Setup Audit Trail records configuration changes for 180 days. Metadata backup captures the complete org configuration state on every backup cycle and retains version history for the customer-defined period. The critical difference is recovery capability — Setup Audit Trail shows what changed but provides no mechanism to restore the previous configuration. Metadata backup enables both evidence production — showing exactly what the configuration was at any historical point — and configuration recovery through Metadata Restore, which restores specific metadata components to their previous state.
How should regulated enterprises approach GDPR erasure requests when backup data exists?
GDPR Article 17 requires that erasure requests extend to backup copies of personal data. The erasure workflow should propagate the deletion to backup storage with a documented audit trail of the deletion execution — producing evidence that the erasure was complete. Sesame Software supports governed deletion from backup storage as part of a complete GDPR erasure workflow. The deletion audit trail — confirming when the deletion was executed, by whom, and across which storage — is the evidence GDPR supervisory authorities require when verifying erasure compliance.
How long does it take to produce compliance audit evidence from Sesame Software?
Evidence retrieval through Sesame Software's visual interface does not require data engineering resources or vendor support tickets. Compliance managers and legal team members access audit history, retrieve field-level change records, and produce point-in-time data snapshots directly through the platform interface. For well-documented audit evidence requests — a specific date range, a specific object, specific data subject records — evidence retrieval typically takes minutes rather than days. Testing the evidence production workflow quarterly under simulated audit conditions establishes realistic retrieval time expectations before a real inquiry requires them.
Found this post helpful? Share it with your network using the links below.



