Global food safety and testing company
Onboarding a 7th country into a live multi-country org
Added a seventh country to a shared production org in a 3-hour window: ~240 components, zero downtime, no post-go-live defects.
- Period
- July 2024 – February 2025
- Role
- Salesforce developer — build, release planning, go-live execution
~240
metadata components deployed
3 hrs
go-live window
0
downtime and post-go-live defects
6 → 7
countries live on one org
Context
A global food safety and testing company runs its business on a single multi-country Salesforce org. Six countries were already in production — United States, France, Spain, Portugal, Brazil and India — sharing one data model, one sample-handling process, and one Experience Cloud community for customers.
The business needed a seventh country onboarded. My role covered the internal org and the community: profiles, permission sets and public groups, cross-country data privacy, mirrored-field translation, the Knowledge base, reports and dashboards, and the release itself.
Problem
The difficulty was never the new country. It was the six already live.
In a shared org the interesting configuration is common: one global sample process, one set of mirrored translated fields, one Knowledge base, one permission architecture. Adding a country means touching exactly the metadata that every existing country depends on — and there was no maintenance window long enough to take a global business offline while it was sorted out.
So the real requirement was not 'make country seven work'. It was 'make country seven work while proving nothing changed for the other six'.
What I built
Access model
Profiles, permission sets and public groups for the new country's internal users and community users, following the existing per-country pattern rather than inventing a new one.
Data privacy across countries
Sharing configuration so the new country's records stay visible to the new country, and existing countries gain no new visibility. Cross-country leakage was the failure mode I was most concerned about, so it was tested in both directions.
Mirrored-field translation
Local-language display through the existing mirrored-field approach, so records read natively for the new region without forking the data model.
Knowledge, reports and dashboards
A localized Knowledge base for the community, plus the reporting layer the new region needed on day one.
The shared sample process
Extended the global process to accept the new country as a valid path, keeping every existing country's behavior byte-for-byte identical.
Constraints and trade-offs
The de-risking strategy came down to three rules.
Additive, not editive
Wherever possible I added new metadata records and values instead of editing shared ones. New rows are invisible to existing code paths; changed rows are not.
Gate what must change
Where shared logic genuinely had to change, the change was keyed by country so the six live countries continued down their original branch. That buys safety at the cost of extra configuration surface — a clean refactor of the shared process would have been more elegant and considerably more dangerous. I chose the boring option deliberately.
Rehearse the whole release, not just the deploy
The go-live was dry-run in a sandbox mirroring production, in the real order, including the manual steps that do not live in metadata. That rehearsal is what turned a ~240-component deploy into a predictable sequence instead of a discovery exercise.
Outcome
The seventh country went live on schedule inside a ~3-hour window: pre-steps, roughly 240 metadata components, post-steps, then live end-to-end testing before sign-off.
Zero downtime for the six countries already in production, and no post-go-live defects raised against the release.
Go-live, hour by hour
00:00Pre-steps
Manual configuration that cannot be carried in metadata.
00:20Metadata deploy
~240 components, deployed in dependency order.
01:40Post-steps
Data loads, assignments, activation of the new country path.
02:20Live testing
End-to-end on the shared sample process, new country and existing countries.
03:00Sign-off
Zero downtime, no post-go-live defects.
Stack
ApexLightning Web ComponentsFlowExperience CloudSalesforce KnowledgePermission sets & profilesSharing rulesTranslation WorkbenchSandbox-to-production release management
Want the parts I can't put on a public page?
Happy to walk through the data model, the trade-offs, and what I would do differently. Open to Salesforce roles, 30-day notice.