SyncOnAI360

Deploy Receipts

A receipt for every Salesforce deploy, ready for any auditor.

Every deploy records what changed, the request that produced it, the checks it passed, who approved it and when, and the version it replaced, so no one has to reconstruct a release from memory.

Deploy receipt

Acme Production

Deployed
Change
Case_Intake_Route: fault path added
Requested
"Add fault handling to the intake Flow"
Checks
5 of 5 passed
Approved by
M. Okafor, admin
Deployed
Today, 14:22 to Acme Production
Previous version recorded

In one paragraph

A SyncOnAI 360 deploy receipt is the record of one deploy to a Salesforce org: the components changed, the request or prompt that produced them, the pre-flight checks and their results, the approver and the time, and the recorded previous version used for rollback. Workspace actions are kept in a separate activity log.

Deploy has a receipt
EveryDeploy has a receipt
Facts per receipt: change, request, checks, approver, time
5Facts per receipt: change, request, checks, approver, time
Click from receipt to rollback
1Click from receipt to rollback
Activity log filters: deploys, logins, settings, scans
4Activity log filters: deploys, logins, settings, scans

01The problem

Why "who deployed that on Friday?" is so hard to answer

Salesforce shows that a deployment happened. It does not tell you why, who asked for it, what was checked, who approved it, or what the components looked like before. That context lives in chat threads and memories.

  1. 01

    No reason recorded

    The deploy log shows components, not the request or ticket behind them.

  2. 02

    No approval evidence

    Who signed off is buried in a message, if anyone did.

  3. 03

    AI-built changes untraceable

    When AI writes the change, nobody can later say which prompt produced it.

  4. 04

    Post-mortems start from scratch

    Every incident review begins by reconstructing what shipped.

02receipt

What is recorded on a Salesforce deploy receipt?

What changed, the prompt or request that produced it, the pre-flight checks and their results, who approved it and when. Open a receipt from Deploys or from the org it changed.

Because the request is recorded, a change the AI built can always be traced back to what was asked for, which is the question that matters most when reviewing AI-assisted delivery.

  • Components changed
  • The request or prompt behind them
  • Checks and results
  • Approver and time

Deploy receipt

Acme Production

Deployed
Change
Case_Intake_Route: fault path added
Requested
"Add fault handling to the intake Flow"
Checks
5 of 5 passed
Approved by
M. Okafor, admin
Deployed
Today, 14:22 to Acme Production
Previous version recorded

03rollback

How does a receipt support rollback?

Each receipt keeps the version of every component recorded before the deploy. Roll back from the receipt and those versions are redeployed. Rolling back production needs an admin, and a deploy can only have one rollback in progress.

Components the deploy created are not deleted by a rollback; they are removed separately, so a rollback never deletes something it cannot be sure about.

  • Previous version recorded
  • Rollback from the receipt
  • Created components removed separately

Deploy receipt

Acme Production

Deployed
Change
Case_Intake_Route: fault path added
Requested
"Add fault handling to the intake Flow"
Checks
5 of 5 passed
Approved by
M. Okafor, admin
Deployed
Today, 14:22 to Acme Production
Previous version recorded

04log

What does the workspace activity log add?

The activity log records who did what across the workspace: deploys started, succeeded or failed, org metadata refreshes, settings changes such as an AI key or team change, and org connections, with filters for each.

Every call an external AI client makes through the MCP connection is logged too, with the tool and token it used. The log covers privileged actions rather than every read, and says so.

  • Deploys, refreshes, settings and connections
  • External AI client calls
  • Filterable

Claude Desktop

Connected to SyncOnAI 360 · read only

Read only

In the production org, what uses Account.Rating?

  • List orgs3 orgs this token can read
  • Where usedAccount.Rating: 4 components
  • Audit findingsLatest assessment: 37 open findings

Four components use Account.Rating: two Flows, one report and a validation rule. This covers every component this token can see.

3 calls recorded in your workspace activity log

05linked

How do receipts connect to the rest of the work?

Work items on project boards link to the proposals and deploys that delivered them, so a release report can point at receipts rather than card movements. Components deployed are read back into the repository immediately after a successful deploy.

The audit flags production changes made outside the pipeline, so changes without a receipt stand out instead of blending in.

  • Work items linked to receipts
  • Deployed components read back
  • Changes without receipts flagged

Service Transformation

Projects · Board · Sprint 7

To do 2

Remove 14 unused Case fields

From audit

Consolidate Account triggers

Apex

In progress 1

Fault paths on intake Flows

From audit

In review 1

APAC routing for Service

Flow

Done 1

Retire Process Builder on Lead

Release 24.3

Work items link to the proposals and deploys that delivered them

06ai

How do receipts help with AI-assisted delivery?

When AI drafts changes, the question reviewers ask is what was requested and whether the result matches it. The receipt answers both: the request that produced the change sits next to the files that changed and the checks they passed.

That makes AI-built work reviewable after the fact, by an auditor, a client or a new team member, without relying on anyone's memory of the conversation.

  • Request beside the result
  • Reviewable after the fact by anyone

Proposal: Case intake fault handling

Acme Production

Checks passed
  • Validated against the org without changing it
  • No component outside the change is modified
  • Apex tests pass, coverage 81%
  • No freeze window in effect
  • Policy: production requires a second admin

Blast radius

  • 2 Flows read Case.Priority
  • 1 report filters on it
  • Case_Intake_Route assigns from it

Risk: medium

07How it works

How a receipt is created

Automatically, on every deploy.

  1. 01

    Request

    A change is asked for in chat, a builder or by a teammate.

  2. 02

    Check and approve

    Pre-flight checks run; an admin approves production.

  3. 03

    Deploy

    The deploy runs and the previous version is recorded.

  4. 04

    Receipt

    Change, request, checks, approver and time are written.

08Before and after

Deployment records, with and without receipts

Without

With SyncOnAI 360

A list of deployed components

Components, request, checks, approver and time

No idea which prompt built it

The request behind every AI-built change

Approval in a chat thread

The approver named on the receipt

Rollback from memory

Rollback from the recorded version

Side-door changes blend in

Changes outside the pipeline flagged

10Questions

Frequently asked questions

The record of one deploy: what changed, the request behind it, the checks, the approver and the time, plus the previous version for rollback.

Yes. The prompt or request that produced a change is recorded on the receipt.

From Deploys, or from the org the deploy changed.

Yes. Roll back redeploys the version of each component recorded before the deploy.

Yes. The activity log records deploys, org refreshes, settings changes and connections, plus external AI client calls.

No. It records privileged activity rather than every read, and the Trust Center says so.

They provide the change evidence auditors typically ask for: what, why, checks, approver and time. They do not certify compliance on their own.

Yes. Every plan includes every feature.

Start in 5 minutes. No card required.

Connect your Salesforce org. Run your first health scan. Ask your first question. See what you've been missing.

  • Anthropic
  • OpenAI