Security & Trust

Governed AI for Salesforce teams that need control, review, and audit.

ConvoPro lets users create and share prompt buttons inside admin-defined boundaries. Salesforce permissions control access, admins define what AI can see and do, and data-changing actions route through human review before they run.

Start with one workflow. Define the boundaries. Keep human review where required. Expand what proves useful.
Governed workflow pathAdministrator controlled
1

Access policy

Approved data and users

2

Allowed action

Configured tools and changes

Human review

Required where configured

4

Approved update

Salesforce or connected action

5

Activity record

Reviewable workflow status

Salesforce aware access

Uses the Salesforce access model your team already manages

Boundary first governance

Admins define what AI can see, use, and trigger

Human review on write

Create, update, send, delete, and trigger actions require review by default

Usage and audit visibility

Review who ran what, what was reviewed, and what was promoted

Governance model

Model and connector control without unmanaged sprawl.

Model flexibility only works when admins can govern providers, credentials, connectors, tools, and usage visibility.

01

Access

Define the information and capabilities available to each workflow.

  • Salesforce records and objects
  • Connected systems and data sources
  • Approved model configurations
  • User, role, and team availability
02

Actions

Control what a workflow is permitted to do after it prepares an output.

  • Permitted tools
  • Record creation and updates
  • External-system actions
  • Restricted or sensitive operations
03

Review

Set where a person must confirm an output or proposed action.

  • Required human confirmation
  • Approval thresholds
  • Exception and escalation paths
  • Source and output review
04

Lifecycle

Manage a workflow after it becomes available to a team.

  • Workflow ownership
  • Publishing and versioning
  • Usage and activity visibility
  • Central update or disablement
Workflow data flow

Clear data flow for evaluation teams.

ConvoPro is designed around a clear operating path: Salesforce access first, admin-defined boundaries second, approved processing third, and human review before data-changing actions execute.

01

User starts in Salesforce

A user runs a prompt button, workflow, or Studio request from the Salesforce work context.

02

Access and boundaries are checked

The request is evaluated against Salesforce access and ConvoPro admin policy.

03

Approved context is processed

Approved context, instructions, and tools needed for the task move through the configured processing path.

04

Result returns for review or action

Read and draft results return to the user. Data-changing actions route through review before execution.

ConvoPro installs in your Salesforce org and calls approved AI models through admin-configured connectors. Detailed data flow documentation is available for evaluation teams. Security, retention, and model-provider details depend on the selected ConvoPro configuration and customer requirements.

Human review

Fast for read and draft work. Reviewed when actions change data.

ConvoPro is designed so teams can move quickly on read, summarize, classify, analyze, and draft tasks. When a prompt button creates, updates, sends, deletes, or triggers an action, review rules can require a human to confirm before the action runs.

Prepare the work

Move quickly on read, analysis, and draft tasks

Employees can use approved workflows to prepare work without turning every repeated request into an admin or development ticket.

  • Summarize a case or account
  • Draft a customer follow-up
  • Extract information from a file
  • Classify or route a request
  • Prepare a handoff or next-step recommendation
Confirm sensitive actions

Keep a person in control where the workflow changes data

Configured review points let the organization decide which proposed actions require confirmation before execution.

  • Create or update a Salesforce record
  • Send a customer-facing message
  • Trigger a downstream workflow
  • Push data to an external system
  • Handle exceptions or restricted operations
Activity visibility

See what was used, reviewed, and promoted.

Audit visibility should help answer practical questions: who used AI, what context was used, what action was proposed, who reviewed it, and what changed.

ConvoPro workflow activity and review view
Workflow activity, review status, and resulting action.
Security review

What evaluation teams can review before deployment

Use the public summary to understand the operating model. Use the security review to confirm the details of your selected workflow and configuration.

Salesforce access model

Public summary

ConvoPro is designed to work within Salesforce access and administrator-defined workflow policy.

Confirm during evaluationReview the permission-check approach, installation scope, and workflow-specific object and field access.

Data flow and handling

Security review

Approved Salesforce context is processed through the configured workflow path and returned for review or action.

Confirm during evaluationReview the selected workflow's data path, hosting, model providers, connector path, and handling requirements.

Models and connectors

Configuration-specific

Administrators define which model and connector configurations are available to approved workflows.

Confirm during evaluationConfirm provider terms, customer-key options, connector permissions, and external-system boundaries.

Retention and deletion

Security review

Salesforce remains the operational system of record for the workflows described on this page.

Confirm during evaluationConfirm current prompt, output, file, activity, and audit retention, plus deletion and termination handling.

Subprocessors and infrastructure

Security review

Current provider, hosting, and subprocessor information is available to qualified evaluation teams.

Confirm during evaluationReview the current list, data locations, encryption details, tenant isolation, and incident-response terms.

AppExchange and compliance

Security review

ConvoPro publishes certification and compliance claims only when they are current and documented.

Confirm during evaluationConfirm current AppExchange, legal, privacy, and compliance status for the intended deployment.
Security documentation

Request the security packet.

Share the intended Salesforce workflow and your review requirements. We will provide the current documentation relevant to that configuration.

The review package can include

  • Architecture and workflow data-flow overview
  • Salesforce permission and access approach
  • Model-provider and connector handling
  • Current retention and deletion terms
  • Current subprocessor and infrastructure information
  • Human-review and action-control model
  • Activity and audit visibility details
  • Current AppExchange, legal, and compliance status
FAQ

Security FAQ

Answers for CIOs, Salesforce admins, security reviewers, and implementation teams.

Does ConvoPro bypass Salesforce permissions?

No. ConvoPro is designed around Salesforce access first, then ConvoPro admin-defined boundaries for data, tools, models, connectors, and actions.

What actions require human review?

Data-changing actions such as create, update, send, delete, or trigger style actions require human review according to configured rules.

Can users share prompt buttons without admin approval?

Yes. Prompt buttons can be shared inside admin-defined boundaries. Human review is tied to data-changing actions, not sharing itself.

What data leaves Salesforce?

Approved context and instructions move through the configured processing path for the task. Evaluation teams can request the current data flow documentation for their selected configuration.

Is customer data used to train AI models?

Model-training and provider-handling details are documented for the selected configuration. Evaluation teams can request the current security packet before rollout.

Does ConvoPro require Data Cloud?

ConvoPro can often start without a broad Data Cloud program for the core prompt button and governed workflow model described on this page. Final architecture depends on the workflow, data sources, and customer configuration.

Can we choose which model provider is used?

Yes. ConvoPro is model-flexible. Admins choose which approved models are available for each workflow from the Console — with governed access to Claude (Anthropic), OpenAI, and Google models provided through ConvoPro’s keys. No customer API keys are required.

Is AppExchange Security Review complete?

Current AppExchange review status is provided during evaluation and should be confirmed with the ConvoPro team before procurement.

What gets logged?

Audit visibility includes usage, prompt button, review decision, action status, and promotion path. Specific fields and retention behavior are documented in the security packet.

Can we limit rollout by team or role?

Yes. Rollout can be planned by team, role, workflow, and policy needs during implementation.

Review ConvoPro with your security and Salesforce teams.

Start with the control model: Salesforce permissions, admin-defined boundaries, human review for data-changing actions, audit visibility, and documented data flow.