DataMaskPolicy

Represents a masking policy for use with Data Mask & Seed.

This type extends the Metadata metadata type and inherits its fullName field.

Use this metadata type to deploy and manage masking policies as org metadata, enabling programmatic configuration without the Setup UI. Use this metadata type when:

  • You want to version-control your policies, promote them through a release pipeline, or consistently copy the same set of policies across many orgs or sandboxes.
  • You're running automated operations, such as CI or CD pipelines or agentic AI tools, that create and manage masking policies without the Setup UI.

Use the Data Mask & Seed Setup UI to set the scheduled start time (ScheduledStart), view when a policy last ran (LastRunDate), run masking jobs, and monitor masking jobs. These tasks aren't available by using Metadata API. The API manages the policy definition and run frequency. Use the Setup UI for scheduling, execution, and run history.

Prerequisites

Before deploying DataMaskPolicy components, confirm these prerequisites.

  • Salesforce CLI installed and authenticated to your org
  • Familiarity with Metadata API, the sf deploy metadata CLI command, or both
  • A target sandbox for testing

    The Data Mask & Seed app is available for production orgs and sandboxes. Run masking jobs on sandboxes only, not in production orgs.

    Note

  • The required permissions described in Special Access Rules
  • API version 61.0 or later

File Suffix and Directory Location

DataMaskPolicy components have the suffix .dataMaskPolicy and are stored in the dataMaskPolicies folder.

Version

DataMaskPolicy components are available in API version 61.0 and later.

Special Access Rules

Before deploying DataMaskPolicy components, your Salesforce admin must configure these permissions. If you don't have admin access, work with your admin.

Production org requirements:

  • The org must have the Salesforce Data Mask license.

User requirements:

  • The user must be assigned the DataMaskAndSeedUserPsl permission set license (PSL).
  • The user must be assigned the DataMaskAndSeedUser permission set.
    • Assign the DataMaskAndSeedUserPsl PSL before assigning the DataMaskAndSeedUser permission set. The permission set requires the PSL to be in place first.

Server-side validation and access controls enforce all business rules across all access paths, including Metadata API.

Note

Fields

Field Name Description
description
Field Type
string
Description
Optional. A description of the masking policy.
label
Field Type
string
Description
Required. The master label for the masking policy.
runFrequency
Field Type
enum
Description
Optional. The frequency at which the masking job runs. Valid values are: once, daily, weekly, and monthly. If a value is omitted, the policy has no scheduled run frequency and must be triggered manually from Setup or the Connect API.
runOnRefresh
Field Type
boolean
Description
Optional. Indicates whether the masking policy runs automatically when a sandbox is either created or refreshed (true) or doesn't run automatically (false). The default value is false.

Troubleshooting

Deploying a runOnRefresh policy to a production org
DataMaskPolicy components with runOnRefresh set to true deploy successfully to production orgs, but the masking job never runs in production. Masking executes only when a sandbox is created or refreshed. Production data is never masked. To run a masking job or set a recurring schedule, use a sandbox.
Missing permissions
If required permissions are missing, you'll receive an insufficient-access error, or the Data Mask management screens won't be available. Confirm that both the org and the user have the permissions listed in Special Access Rules.
Run frequency and scheduled start time
Valid values for runFrequency are once, daily, weekly, and monthly. A recurring frequency requires a scheduled start time to execute. Set the scheduled start time in the Data Mask & Seed Setup UI. The ScheduledStart field isn't configurable by using Metadata API. A recurring schedule runs only in a sandbox, not in a production org.

Versioning and Compatibility

  • DataMaskPolicy is available starting in API version 61.0. DataMaskSettings is available starting in API version 67.0. If your client uses an API version below the minimum required version for either type, that metadata type isn't visible. You can neither retrieve it nor deploy it.
  • The two metadata types were introduced in different releases and work independently. If your use case requires only masking policies, API version 61.0 is sufficient.
  • If the production org's release doesn't include the metadata type, the deployment is rejected as an unknown or unsupported metadata type. Target an API version at or above the minimum required version, and confirm the org is on a release that supports the type.

Wildcard Support in the Manifest File

This metadata type supports the wildcard character * (asterisk) in the package.xml manifest file. For information about using the manifest file, see Deploying and Retrieving Metadata with the Zip File.