Sojournby CloudAlgo Request early access
Release 1 in development, 3 of 9 sprints done. Early access is open.Join early access
Security and trust

Your data never leaves your org.

Sojourn is a native managed package built to pass AppExchange security review on the first submission. Here is what that means in practice, and how we check it on every change.

Building release 13 of 9 sprints done
Beta installsSprint 8
Security reviewSubmitted in sprint 8
Listed on AppExchangeAfter review
Isolation

No outside calls

No callouts, Named Credentials, Connected Apps, or third-party JavaScript. Nothing Sojourn records is sent anywhere.

Enforced: package contents reviewed every pull request
Isolation

No metadata changes

No Metadata API, Tooling API, or session IDs. Setup lives in Sojourn's own records, and the Flows you create stay yours.

Enforced: static rule in CI, zero exceptions
Access

Your permissions apply

Every query and write in a user's context runs in user mode, so people only see and change what their object and field permissions allow.

WITH USER_MODE · AccessLevel.USER_MODE
Access

Two documented exceptions

The capture engine records every change regardless of who saved it. It is designed to run in system context and write only Sojourn's own objects.

Release 1 design: two system-context classes, each with a stated reason
Reliability

Never blocks a save

If tracking fails, your user's save still succeeds. The failure becomes a Tracking Error that an admin can repair in one click.

Tracking_Error__c · repair from the setup app in release 1
Retention

Deletion is your decision

Nothing deletes your data automatically. Purge is opt-in and scheduled, exports first, archives to a big object, and is logged.

Interval_Archive__b · Purge_Run__c
Quality gates on every pull request

Checked by machines, not by promise.

Salesforce Code Analyzer v5, AppExchange rules0 Critical, 0 High
Test coverage, every Apex class90% minimum
Bulk tests200 records
Negative tests prove user mode denies accessRequired
Who can do what

Three permission sets.

Sojourn AdminEnable objects, run backfill and purge, manage goals and business hours.
Sojourn ManagerReports and dashboards on intervals and daily summaries.
Sojourn UserThe timeline on record pages, with read access to goals and tracked objects.