# Salesforce glossary

> Plain-language definitions of Salesforce metadata, deployment, automation, security and AI terms, from Apex test coverage to the Model Context Protocol.

Source: https://synconai360.com/glossary

- [Salesforce metadata](https://synconai360.com/glossary/salesforce-metadata): Salesforce metadata is everything that defines how an org behaves rather than the business records it stores: objects, fields, page layouts, Flows, Apex, Lightning components, permission sets, validation rules and more. Metadata is what admins and developers change, deploy between orgs and keep in source control.
- [Metadata API](https://synconai360.com/glossary/metadata-api): The Metadata API is the Salesforce interface used to retrieve an org's configuration and code and to deploy changes to it. Deployment tools, the Salesforce CLI and change management products use it to move metadata between sandboxes and production, including validate-only deployments that check a change without saving it.
- [Salesforce sandbox](https://synconai360.com/glossary/sandbox): A Salesforce sandbox is a copy of a production org used for development, testing and training. Developer sandboxes copy metadata only; Partial Copy and Full sandboxes also copy some or all records. Changes are built and tested in sandboxes, then deployed to production.
- [Change set](https://synconai360.com/glossary/change-set): A change set is Salesforce's point-and-click way to send metadata from one org to a connected org, typically from a sandbox to production. Components are added by hand to an outbound change set, which is uploaded, then validated and deployed in the receiving org.
- [Salesforce deployment](https://synconai360.com/glossary/salesforce-deployment): A Salesforce deployment moves metadata, such as fields, Flows, Apex and permission changes, into a target org. Deployments to production run Apex tests when the change includes code, and can be validated first without saving. A failed deployment changes nothing in the target org.
- [Validate-only deployment](https://synconai360.com/glossary/validate-only-deployment): A validate-only deployment asks Salesforce to process a deployment against the target org, including running the required Apex tests, and report any errors, without saving anything. It is the most reliable way to know a change will deploy before the moment it matters.
- [Pre-flight check](https://synconai360.com/glossary/pre-flight-check): A pre-flight check is an automated check run on a proposed change before it is approved or deployed, looking for problems such as data loss, unexpected access changes, missing dependencies, deploy order issues or insufficient test coverage. Each check gives a result and a reason.
- [Blast radius](https://synconai360.com/glossary/blast-radius): The blast radius of a change is the set of other components it could affect: the Flows, Apex, validation rules, components, reports and permissions that reference what is being changed. Knowing it before a change ships is the core of impact analysis.
- [Salesforce dependency](https://synconai360.com/glossary/salesforce-dependency): A Salesforce dependency exists when one component references another: a Flow that reads a field, an Apex class that queries an object, a validation rule that compares a picklist value. Dependencies come from code, automation, formulas, layouts and security settings across the org.
- [Impact analysis](https://synconai360.com/glossary/impact-analysis): Impact analysis is the practice of finding everything a proposed change will affect before it is made: the components that reference it, the processes that run through it and the records that rely on it. It turns a guess about risk into a list someone can review.
- [Salesforce rollback](https://synconai360.com/glossary/rollback): A Salesforce rollback returns changed metadata to the version it had before a deployment. Salesforce has no general undo for metadata, so rolling back means redeploying the previous version, which only works if that version was recorded. Records changed along the way are not restored by a metadata rollback.
- [Deploy receipt](https://synconai360.com/glossary/deploy-receipt): A deploy receipt is a record of a single deployment: what changed, the request that produced it, the checks it passed, who approved it and when, and what it can be rolled back to. It turns the question of who changed what, and why, into a lookup.
- [Maker-checker](https://synconai360.com/glossary/maker-checker): Maker-checker is a control in which the person who makes a change cannot be the person who approves it. Applied to Salesforce, it means every production change is reviewed and approved by a second person before it deploys.
- [Change freeze window](https://synconai360.com/glossary/freeze-window): A change freeze window is a period during which production deployments are not allowed, such as quarter end, a major launch or a client's busy season. Freezes reduce risk when the business can least afford an incident.
- [Apex](https://synconai360.com/glossary/apex): Apex is Salesforce's strongly typed, server-side programming language, used for triggers that run when records change, classes that implement business logic and integrations, and tests. Apex runs on the Salesforce platform within its governor limits.
- [Apex test coverage](https://synconai360.com/glossary/apex-test-coverage): Apex test coverage is the percentage of Apex code lines executed by the org's tests. Salesforce requires at least 75% coverage to deploy Apex to production, and every trigger must have some coverage. Coverage measures lines run, not whether behaviour is correct.
- [Salesforce Flow](https://synconai360.com/glossary/salesforce-flow): Salesforce Flow is the platform's declarative automation tool, used to build record-triggered automation, screen flows that guide users, scheduled jobs and autolaunched processes without code. Flow has replaced Workflow Rules and Process Builder as Salesforce's recommended automation tool.
- [Record-triggered Flow](https://synconai360.com/glossary/record-triggered-flow): A record-triggered Flow runs automatically when a record is created, updated or deleted, either before the save to update fields on the same record quickly, or after the save to update other records, send notifications or call other automation.
- [Process Builder](https://synconai360.com/glossary/process-builder): Process Builder is a legacy Salesforce automation tool for updating records and triggering actions when records change. Salesforce has replaced it with Flow and recommends migrating existing processes, but many orgs still run active processes alongside newer Flows.
- [Workflow Rule](https://synconai360.com/glossary/workflow-rule): A Workflow Rule is Salesforce's original declarative automation: when a record meets criteria, it can update a field, send an email, create a task or send an outbound message. Salesforce has replaced Workflow Rules with Flow and recommends migrating them.
- [Validation rule](https://synconai360.com/glossary/validation-rule): A validation rule is a formula that runs when a record is saved and blocks the save with an error message if the formula is true, for example requiring an amount once an opportunity reaches a certain stage. Validation rules enforce data quality without code.
- [Picklist](https://synconai360.com/glossary/picklist): A picklist is a Salesforce field whose values come from a defined list, such as opportunity stage or case status. Picklist values are often compared as text in Flows, validation rules, Apex and reports, so changing or retiring a value can affect automation far from the field itself.
- [Lightning Web Components](https://synconai360.com/glossary/lightning-web-components): Lightning Web Components (LWC) is Salesforce's framework for building custom user interface components with standard web technologies. Each component is a bundle of files, typically JavaScript, HTML and metadata, and can call Apex and be placed on pages with Lightning App Builder.
- [Lightning page](https://synconai360.com/glossary/lightning-page): A Lightning page is a Salesforce page assembled in Lightning App Builder from standard and custom components arranged in regions, such as a record page, an app page or a home page. Visibility rules can show or hide components for different users or conditions.
- [Permission set](https://synconai360.com/glossary/permission-set): A permission set is a collection of Salesforce permissions, such as object access, field access and system permissions, that can be assigned to users in addition to their profile. Salesforce recommends granting access through permission sets and permission set groups rather than profiles.
- [Salesforce profile](https://synconai360.com/glossary/salesforce-profile): A Salesforce profile defines a user's baseline settings and permissions, including object access, page layouts and login settings. Every user has exactly one profile; additional access is usually layered on with permission sets.
- [Guest user](https://synconai360.com/glossary/guest-user): A guest user is the Salesforce user that represents unauthenticated visitors to a public site or Experience Cloud page. Whatever the guest user's profile allows can be reached without logging in, which makes its object access a common source of accidental data exposure.
- [Managed package](https://synconai360.com/glossary/managed-package): A managed package is an application installed into a Salesforce org, often from AppExchange, whose components are maintained and upgraded by the publisher. Publishers can hide the source of their Apex, so the org can see that the components exist but not always what they do.
- [Setup Audit Trail](https://synconai360.com/glossary/setup-audit-trail): The Setup Audit Trail is Salesforce's log of configuration changes made in an org, recording who changed what in Setup and when. It keeps a limited recent history and records that something changed rather than the full before and after.
- [Org drift](https://synconai360.com/glossary/org-drift): Org drift is the gradual divergence between orgs that are meant to match, most often a sandbox and production, caused by changes made in one and not the other. Drift means a change tested in one environment may behave differently, or overwrite something, in the other.
- [Salesforce technical debt](https://synconai360.com/glossary/technical-debt): Salesforce technical debt is the accumulated configuration and code that makes an org slower and riskier to change: duplicated rules and fields, overlapping automation, unused metadata, legacy Workflow Rules and Process Builder, and code that ignores best practice.
- [Salesforce org health](https://synconai360.com/glossary/org-health): Salesforce org health describes how well an org is built and maintained across areas such as security, automation, code quality, data model, limits and adoption. A useful health measure says not only how good the org is but how much of it was examined.
- [Salesforce org audit](https://synconai360.com/glossary/salesforce-org-audit): A Salesforce org audit is a structured review of an org's configuration, code, security and usage that produces findings about what is wrong and what to fix. The useful ones attach evidence to each finding and estimate the effort to fix it.
- [Statement of work](https://synconai360.com/glossary/statement-of-work): A statement of work is the document that defines the scope, deliverables, effort and price of a piece of consulting work. In Salesforce consulting, a good statement of work ties each line to a specific problem in the client's org.
- [SOQL](https://synconai360.com/glossary/soql): SOQL, the Salesforce Object Query Language, is the language used to query records in Salesforce, similar to SQL's SELECT statement but built around Salesforce objects and their relationships. It is used in Apex, integrations, the developer console and reporting tools.
- [Model Context Protocol](https://synconai360.com/glossary/model-context-protocol): The Model Context Protocol (MCP) is an open standard that lets AI clients such as Claude Desktop and Cursor connect to external tools and data sources through servers that expose a defined set of actions. It gives an AI client access to context it would not otherwise have.
