Protect confidential contract information and retain evidence of access, approvals, and material changes using Salesforce security and audit features.
Security model
Contract security should follow least privilege. Users should receive only the record, field, and file access required for their responsibilities. Salesforce administrators configure the security model; GoldFinch permissions do not automatically grant access to every contract record or file.
Security controls
- Use profiles and permission sets to control object and field access.
- Use organization-wide defaults, roles, sharing rules, teams, or manual sharing to control record access as appropriate.
- Review Salesforce File sharing and linked-record access for confidential documents.
- Restrict export, report-folder and API access according to policy.
- Use separate permissions for contract creation, approval, activation, amendment and close-out when segregation of duties is required.
- Review inactive users, delegated approvers and shared accounts regularly.
Audit evidence
- Approval history can identify approval decisions captured by the configured process.
- Field history tracking can retain changes to selected fields, subject to Salesforce configuration and retention limits.
- Salesforce Files can retain document versions.
- Setup Audit Trail and other Salesforce audit products may provide additional administrative evidence depending on licenses and configuration.
- GoldFinch transaction records provide operational and accounting evidence for related posted activity.
Configure and test access
1. Classify contract data and documents by confidentiality and business purpose.
2. Define access for requesters, contract owners, approvers, finance, legal, auditors, and administrators.
3. Configure object, field, record, file, and report-folder access.
4. Test create, read, edit, delete, approve, export, and file-download access with representative users.
5. Document approved exceptions and complete periodic access reviews.
Retention and legal requirements
The customer is responsible for defining legal hold, retention, deletion, privacy, and evidentiary requirements. Salesforce and GoldFinch configuration should implement the approved policy but should not be described as legal compliance by default.
Comments
0 comments
Please sign in to leave a comment.