A nonprofit arts and philanthropy organization partnered with Trinity Relationship Management to create a secure Salesforce Experience Cloud solution that would allow donors and other constituents to review and update approved information without requiring a Salesforce login. The project focused on simplifying data maintenance while maintaining strict controls around access to personal and organizational information.

Secure Salesforce Self-Service for Donor & Constituent Data

  • Allowing donors and constituents to update their own information without creating paid Salesforce user accounts.

  • Ensuring each recipient could access only their own approved Contact or Account information.

  • Creating a simple experience that did not expose Salesforce record IDs or unrelated customer data.

  • Allowing links to remain reusable for future updates while supporting expiration and revocation when needed.

  • Protecting core Salesforce records from direct public-user access.

CHALLENGES

SOLUTION

  • Salesforce Experience Cloud Portal: Designed a public Experience Cloud page where recipients could review and update a defined set of approved Contact or Account fields without logging in.

  • Secure Recipient-Specific Access: Generated unique, non-guessable tokens for each recipient rather than exposing Salesforce record identifiers in public URLs.

  • Controlled Data Boundary: Introduced a staging object between the public experience and core Salesforce Contact and Account records, limiting guest access to only the data required for the update process.

  • Flow-Based Record Updates: Used Salesforce Flow to validate requests and write approved changes back to the correct Contact or Account rather than allowing direct guest-user edits.

  • Reusable Self-Service Links: Designed links that could be reused for subsequent updates while supporting revocation and optional expiration.

  • Security & Validation Testing: Included testing for valid, invalid, revoked, and repeated submissions along with Contact and Account scenarios, followed by security review and deployment validation.

RESULTS

  • Created a self-service path for donors and constituents to maintain approved Salesforce information without requiring a traditional Salesforce login.

  • Reduced the need for staff to manually collect and enter routine constituent updates.

  • Established controls designed to ensure recipients could access only their own approved information.

  • Protected core Salesforce records by separating public access from direct Contact and Account editing.

  • Created a reusable framework for securely collecting future constituent data updates through Salesforce.

We are commited to your success