Frequently asked questions
The questions prospects ask most. For hands-on product questions, see the documentation.
Security & architecture
Does any data leave our Salesforce org?
No. ControlLayer is 100% Salesforce-native - no external services, no callouts, no data exfiltration paths. Everything (windows, enforcement state, audit history) lives in your org as regular Salesforce records and settings.
Does ControlLayer modify our automations?
No. Your validation rules, flows, and triggers stay exactly as deployed. You add a one-line ControlLayer check to each automation you want governed - once - and from then on all bypass behavior is data-driven. Nothing is deactivated in Setup, ever.
What if the value controlling enforcement gets edited by hand?
The engine treats manual edits to enforcement state as drift and corrects them automatically within one cycle (about five minutes). The set of active bypass windows is the single source of truth - that's the point of the product.
Can someone just bypass everything?
No blanket bypass exists. Every window must name its automation category and specific objects, carry a required reason, and respect org guardrails like maximum duration and required end dates. Specificity is enforced by design.
Who can create bypass windows?
Access is governed by packaged permission sets you assign like any other Salesforce permission. Most orgs grant window creation to a small group of admins and leave everyone else read-only.
Behavior
What happens when a window expires?
The engine marks it expired and recomputes enforcement immediately - your rules, flows, and triggers are enforcing again without anyone touching anything. Start/end times are preserved on the record as a historical audit fact.
What if we need a bypass right now?
Submit the wizard with no start time and the window activates immediately. Scheduled windows are for planned work - pre-stage Friday's data load on Tuesday.
Can a bypass apply to just one user?
Yes - organization, profile, and single-user scoping are all supported, using Salesforce's native settings hierarchy. A user-level window supersedes broader windows for that user while it's active, which is exactly what you want for a data-loader account.
What's the safety net if something goes wrong mid-window?
Windows that hit errors retry automatically up to a configurable ceiling, then wait visibly in an error state for an admin - surfaced on the dashboard and the engine-health banner. The engine also reconciles enforcement every cycle, and its own health is monitored so a stalled scheduler can't go unnoticed.
How granular are bypasses?
Bypasses are object-level per category: for example, "validation rules on Account and Contact." Object-level matches how teams actually run data operations; per-automation-name granularity is on the roadmap radar if real cases demand it.
Practicalities
Which Salesforce editions are supported?
Enterprise Edition and above.
How long does setup take?
Install and initial configuration take minutes. Instrumenting automations is a one-line change per automation - most teams start with the handful of rules that regularly block data work and expand from there.
Do we have to instrument everything at once?
No. Ungoverned automations behave exactly as they always have. Adopt incrementally, starting where the pain is.
How do we buy it?
ControlLayer is currently in early access - request access and we'll set you up in a sandbox with guided onboarding. An AppExchange listing with self-serve trial is planned for general availability.
Still have questions?
Ask directly - you'll get an answer from the people building the product.
Email us