SyncOnAI360

Use case: safe deployment

How to deploy Salesforce changes to production without the fear.

Every change checked, validated against the org, approved by someone other than its author and recorded with a way back.

Proposal: Case intake fault handling

Acme Production

Checks passed
  • Validated against the org without changing it
  • No component outside the change is modified
  • Apex tests pass, coverage 81%
  • No freeze window in effect
  • Policy: production requires a second admin

Blast radius

  • 2 Flows read Case.Priority
  • 1 report filters on it
  • Case_Intake_Route assigns from it

Risk: medium

In one paragraph

Deploying safely with SyncOnAI 360 means every change is a proposal that runs named pre-flight checks and a validation against the target org, production waits for an approved proposal from a second admin where there is one, the deploy policy enforces freeze windows, and every deploy leaves a receipt with rollback.

Named pre-flight checks
6Named pre-flight checks
People on production in multi-admin workspaces
2People on production in multi-admin workspaces
Rules that can pass a failed check
0Rules that can pass a failed check
Deploy with a receipt
EveryDeploy with a receipt

01The problem

Why Salesforce production deploys go wrong

Most failed deploys were preventable: data discarded by a narrowed field, an access change nobody noticed, a dependency nobody checked, coverage that fell short.

  1. 01

    Unchecked changes

    Changes go to production because they worked in a sandbox.

  2. 02

    One pair of eyes

    The author approves their own work.

  3. 03

    Bad timing

    Deploys land during quarter end or a client freeze.

  4. 04

    No way back

    Reverting means rebuilding the old version by hand.

02checks

Which checks run before a Salesforce deploy?

Destructive operations, security and access, field presence, cascading dependencies, deploy order and test coverage. Each returns pass, warn or fail with a plain reason, and the proposal carries an overall risk of low, medium or high.

  • Six named checks
  • Pass, warn or fail with reasons
  • Overall risk

Proposal: Case intake fault handling

Acme Production

Checks passed
  • Validated against the org without changing it
  • No component outside the change is modified
  • Apex tests pass, coverage 81%
  • No freeze window in effect
  • Policy: production requires a second admin

Blast radius

  • 2 Flows read Case.Priority
  • 1 report filters on it
  • Case_Intake_Route assigns from it

Risk: medium

03validate

How is a change validated before deploy?

After the named checks, the change is validated against the target org without saving anything, Salesforce's own validate-only deployment. The errors shown are real errors from the real org.

  • Validate-only against the target
  • Real Salesforce errors
  • Nothing saved

Proposal: Case intake fault handling

Acme Production

Checks passed
  • Validated against the org without changing it
  • No component outside the change is modified
  • Apex tests pass, coverage 81%
  • No freeze window in effect
  • Policy: production requires a second admin

Blast radius

  • 2 Flows read Case.Priority
  • 1 report filters on it
  • Case_Intake_Route assigns from it

Risk: medium

04approve

Who approves a production deploy?

Production needs an approved proposal, and in a workspace with two or more admins the approver must be someone other than the author. A single-admin workspace can approve its own change, and the activity log records that it did.

  • Maker-checker for production
  • Single-admin approvals recorded
  • Sandboxes stay quick

Proposal: Case intake fault handling

Acme Production

Checks passed
  • Validated against the org without changing it
  • No component outside the change is modified
  • Apex tests pass, coverage 81%
  • No freeze window in effect
  • Policy: production requires a second admin

Blast radius

  • 2 Flows read Case.Priority
  • 1 report filters on it
  • Case_Intake_Route assigns from it

Risk: medium

05policy

How do you stop deploys at the wrong time?

The deploy policy sets freeze windows, required approvers and auto-approval for low-risk work. A policy can make deploys harder but can never let through a change that failed its checks or was rejected.

  • Freeze windows
  • Required approvers
  • Never overrides a failed check

Proposal: Case intake fault handling

Acme Production

Checks passed
  • Validated against the org without changing it
  • No component outside the change is modified
  • Apex tests pass, coverage 81%
  • No freeze window in effect
  • Policy: production requires a second admin

Blast radius

  • 2 Flows read Case.Priority
  • 1 report filters on it
  • Case_Intake_Route assigns from it

Risk: medium

06record

What is left behind after a deploy?

A receipt: what changed, the request behind it, the checks, who approved it and when, and the version of each component recorded before. Roll back from the receipt; components the deploy created are removed separately and data changes cannot be reversed.

  • A receipt per deploy
  • Rollback to recorded versions
  • Limits stated

Proposal: Case intake fault handling

Acme Production

Checks passed
  • Validated against the org without changing it
  • No component outside the change is modified
  • Apex tests pass, coverage 81%
  • No freeze window in effect
  • Policy: production requires a second admin

Blast radius

  • 2 Flows read Case.Priority
  • 1 report filters on it
  • Case_Intake_Route assigns from it

Risk: medium

07ai

How do AI-built changes deploy safely?

Changes the AI or the agents draft go through exactly the same path as hand-built ones: a proposal with named checks, validation against the org, approval for production, and a receipt that records the request that produced the change.

Anything that would change records directly, such as anonymous Apex, waits for a person to press Allow, because data changes cannot be rolled back.

  • Same path as hand-built work
  • The request recorded on the receipt
  • Data changes need Allow

SyncOnAI 360

AI architect for Salesforce

Ask SyncOnAI to build flows, rules, Apex, or SOQL...

08How it works

How to deploy safely

The same path for every change.

  1. 01

    Propose

    Build or describe the change.

  2. 02

    Check

    Read the named checks and risk.

  3. 03

    Validate

    Validate against the target org.

  4. 04

    Approve

    A second admin approves production.

  5. 05

    Deploy

    Deploy with a receipt and rollback.

09Checklist

Pre-deployment checklist

  • Make sure the change exists as a proposal, not an edit in Setup.
  • Read every named check, and resolve anything that fails.
  • Look at warnings, especially access changes, and confirm they are intended.
  • Validate against the target org and read any Salesforce errors.
  • Check the deploy policy's freeze windows.
  • Get approval from an admin other than the author.
  • Know the rollback limits before you deploy.

10Before and after

Production deploys, hopeful versus governed

Without

With SyncOnAI 360

It worked in the sandbox

Validated against the target org

The author approves

A second admin approves

Deploys at quarter end

Freeze windows enforced

Rebuilding the old version

Rollback from the receipt

12Questions

Frequently asked questions

Yes, after validation against the org and approval.

No. A change that fails a check cannot deploy, whatever the policy says.

No. Members can deploy to sandboxes freely.

Salesforce's reason is shown, and Fix in chat opens the conversation with the error.

Yes, on its receipt.

No. It restores recorded metadata.

Yes. Every deploy result can post to a Slack channel.

Yes. Every plan includes every feature.

Yes. Promoting a proposal to production brings it under the production org's policy and approval.

The checks, risk, policy decision, affected components and a before and after of every file.

One of the named checks: it confirms the components in a change will deploy in an order Salesforce accepts.

Auto-approval rules can approve low-risk work, but never a change that failed a check.

Start in 5 minutes. No card required.

Connect your Salesforce org. Run your first health scan. Ask your first question. See what you've been missing.

  • Anthropic
  • OpenAI