Rotating means generating a new tenant secret for a given key type. The throttle applies per type, and the destructive option sits on the same page.
- Confirm you hold Manage Encryption Keys
Key Management is gated by the Manage Encryption Keys user permission, which Salesforce groups with high-risk permissions like Modify All Data. Grant it through a permission set you can audit.
- Open Key Management in Setup
From Setup, go to the Key Management page. It lists the tenant secrets in the org with their version, type, status and source, so check what is Active before you add to it.
- Generate a new secret for the type you need
Pick the key type that matches what you are protecting and generate a new tenant secret for it. The new version becomes Active and the one it replaces becomes Archived.
- Leave the archived version alone
Do not destroy the version you just archived. It is what decrypts everything written before the rotation.
Covers encrypted fields, files and attachments, but not the search index. New secrets default to this type.
Covers search index files. On Hyperforce orgs from API version 63.0, create these with the DataEncryptionKey object instead.
Replaces Salesforce key generation with your own material, uploaded under a certificate or fetched from an outside key service.
- You get one shot per window. If the new secret is wrong, you cannot rotate again until the throttle for that type clears.
- Rotation does not re-encrypt existing records, so the archived version stays load-bearing until that data is rewritten.
- Destroying a tenant secret is permanent: encrypted data cannot be decrypted afterwards, and encrypted files cannot be downloaded.
Keep the related term in your library so you can find this topic again.