Salesforce Decode
Salesforcedecode
Back to questions
Data CloudAdvancedtokenizationsecuritypii

Design tokenization for sensitive attributes in profiles

Real World Scenario

Security requires SSN stored tokenized but segments need age band and state for compliance campaigns.

Expected Answer

• Ingest SSN into tokenized field never exposed to segments or activation • Derive age band and geostate at ingestion as separate non-sensitive fields • Restrict raw sensitive field access to break-glass roles • Audit any query attempting access to token vault mappings • Segment on derived attributes only—document prohibited fields list • Align with enterprise KMS rotation policies

Follow-Up Questions & Answers

Click to expand — each follow-up includes a direct, interview-ready answer

Main difference: use case and scale. Ingest SSN into tokenized field never exposed to segments or activation. Derive age band and geostate at ingestion as separate non-sensitive fields. Pick based on your integration pattern and team capability. Derive campaign-safe attributes early—do not segment on raw sensitive fields " temporarily". Optimize for scale and operational observability.

Architect Perspective

Derive campaign-safe attributes early—do not segment on raw sensitive fields " temporarily".