DataMaskPolicy
This type extends the Metadata metadata type and inherits its fullName field.
Use this metadata type to deploy and manage masking policies as org metadata, enabling programmatic configuration without the Setup UI. Use this metadata type when:
- You want to version-control your policies, promote them through a release pipeline, or consistently copy the same set of policies across many orgs or sandboxes.
- You're running automated operations, such as CI or CD pipelines or agentic AI tools, that create and manage masking policies without the Setup UI.
Use the Data Mask & Seed Setup UI to set the scheduled start time (ScheduledStart), view when a policy last ran (LastRunDate), run masking jobs, and monitor masking jobs. These tasks aren't available by using Metadata API. The API manages the policy definition and run frequency. Use the Setup UI for scheduling, execution, and run history.
Prerequisites
Before deploying DataMaskPolicy components, confirm these prerequisites.
- Salesforce CLI installed and authenticated to your org
- Familiarity with Metadata API, the sf deploy metadata CLI command, or both
-
A target sandbox for testing
- The required permissions described in Special Access Rules
- API version 61.0 or later
File Suffix and Directory Location
DataMaskPolicy components have the suffix .dataMaskPolicy and are stored in the dataMaskPolicies folder.
Version
DataMaskPolicy components are available in API version 61.0 and later.
Special Access Rules
Before deploying DataMaskPolicy components, your Salesforce admin must configure these permissions. If you don't have admin access, work with your admin.
Production org requirements:
- The org must have the Salesforce Data Mask license.
User requirements:
- The user must be assigned the DataMaskAndSeedUserPsl permission set license (PSL).
- The user must be assigned the DataMaskAndSeedUser permission set.
- Assign the DataMaskAndSeedUserPsl PSL before assigning the DataMaskAndSeedUser permission set. The permission set requires the PSL to be in place first.
Fields
| Field Name | Description |
|---|---|
| description |
|
| label |
|
| runFrequency |
|
| runOnRefresh |
|
Declarative Metadata Sample Definition
The following is an example of a DataMaskPolicy component.
1<?xml version="1.0" encoding="UTF-8"?>
2<DataMaskPolicy xmlns="http://soap.sforce.com/2006/04/metadata">
3 <label>Sample Data Mask Policy</label>
4 <description>This policy executes weekly to mask standard fields.</description>
5 <runFrequency>weekly</runFrequency>
6 <runOnRefresh>true</runOnRefresh>
7</DataMaskPolicy>This example runs the masking policy automatically on sandbox refresh, so sandbox data is masked and free of personally identifiable information (PII) as soon as the sandbox is created or refreshed.
Include DataMaskPolicy components in your package.xml manifest file when deploying with the Salesforce CLI. This package.xml manifest deploys the Sample_Data_Mask_Policy component.
1<?xml version="1.0" encoding="UTF-8"?>
2<Package xmlns="http://soap.sforce.com/2006/04/metadata">
3 <types>
4 <members>Sample_Data_Mask_Policy</members>
5 <name>DataMaskPolicy</name>
6 </types>
7 <version>61.0</version>
8</Package>Troubleshooting
- Deploying a runOnRefresh policy to a production org
- DataMaskPolicy components with runOnRefresh set to true deploy successfully to production orgs, but the masking job never runs in production. Masking executes only when a sandbox is created or refreshed. Production data is never masked. To run a masking job or set a recurring schedule, use a sandbox.
- Missing permissions
- If required permissions are missing, you'll receive an insufficient-access error, or the Data Mask management screens won't be available. Confirm that both the org and the user have the permissions listed in Special Access Rules.
- Run frequency and scheduled start time
- Valid values for runFrequency are once, daily, weekly, and monthly. A recurring frequency requires a scheduled start time to execute. Set the scheduled start time in the Data Mask & Seed Setup UI. The ScheduledStart field isn't configurable by using Metadata API. A recurring schedule runs only in a sandbox, not in a production org.
Versioning and Compatibility
- DataMaskPolicy is available starting in API version 61.0. DataMaskSettings is available starting in API version 67.0. If your client uses an API version below the minimum required version for either type, that metadata type isn't visible. You can neither retrieve it nor deploy it.
- The two metadata types were introduced in different releases and work independently. If your use case requires only masking policies, API version 61.0 is sufficient.
- If the production org's release doesn't include the metadata type, the deployment is rejected as an unknown or unsupported metadata type. Target an API version at or above the minimum required version, and confirm the org is on a release that supports the type.
Wildcard Support in the Manifest File
This metadata type supports the wildcard character * (asterisk) in the package.xml manifest file. For information about using the manifest file, see Deploying and Retrieving Metadata with the Zip File.