| Industry Clouds | Health Cloud, Financial Services Cloud, Manufacturing Cloud | Publicly visible on approved ForceFolks sources | Patient or member data model, care coordination, intake | Which Health Cloud data models have you deployed, and in which configuration? |
| Core Clouds | Sales, Service, Marketing, Experience, Commerce, Agentforce Commerce | Publicly visible on approved ForceFolks sources | Contact centre, outreach, patient and member portals | How do you keep console performance acceptable with clinical data present? |
| Data and AI | Data Cloud and Data 360, Agentforce, Einstein, Tableau and CRM Analytics | Visible for Data Cloud, Agentforce, Tableau; Einstein named as a technology, not a Cloud page | Patient or member 360, risk stratification, agent grounding | How is PHI excluded or masked in agent grounding and prompt context? |
| Integration | MuleSoft, REST and SOAP APIs, EHR, claims, ERP and finance systems | Visible; the healthcare case cites Epic integration via HL7 and FHIR | Clinical and claims ingestion, order and referral flows | Which EHRs have you connected, at what volume and error handling? |
| Platform engineering | Salesforce Platform, Apex, Lightning Web Components, Flow, SOQL, sharing | Publicly visible as development and automation service lines | Custom intake screens, clinical alerts, restriction logic | Show a sharing model isolating PHI by care team and consent state. |
| Data migration | Mapping, validation, reconciliation, identity resolution, data quality | Visible, with 91% identity match across 12 million records, retail | Legacy CRM migration, patient deduplication | What match-rate target do you commit to, and how is it measured? |
| DevOps and governance | Source control, CI/CD, Copado, release management, test coverage, UAT | Visible, with a rescue case reporting fourfold deployment velocity | Safe change in a regulated environment | How do you evidence change control to an auditor reviewing a PHI-bearing org? |
| Security and privacy tooling | Salesforce Shield, Platform Encryption, Event Monitoring, Field Audit Trail, Privacy Center | Shield named in the healthcare case, Privacy Center in a fintech case; configuration detail not published | PHI encryption, audit retention, consent handling | Which Shield components did you configure, and what stayed unencrypted? |
| Payer regulatory APIs | CMS-0057-F Patient Access, Provider Access, Payer-to-Payer, Prior Authorization | Evidence not publicly confirmed from approved sources. | January 1, 2027 payer compliance programme | Who has run a Da Vinci-conformant prior-authorisation API in production? |
| Staff augmentation roles | Architects, technical leads, consultants, developers, administrators, MuleSoft, Data Cloud, Agentforce, CPQ specialists | Publicly visible as a named role catalogue | Team extension around an in-house programme | How many of the proposed team have prior PHI-environment experience? |