← All work

Global food safety and testing company

Onboarding a 7th country into a live multi-country org

Added a seventh country to a shared production org in a 3-hour window: ~240 components, zero downtime, no post-go-live defects.

Period
July 2024 – February 2025
Role
Salesforce developer — build, release planning, go-live execution

Context

A global food safety and testing company runs its business on a single multi-country Salesforce org. Six countries were already in production — United States, France, Spain, Portugal, Brazil and India — sharing one data model, one sample-handling process, and one Experience Cloud community for customers.

The business needed a seventh country onboarded. My role covered the internal org and the community: profiles, permission sets and public groups, cross-country data privacy, mirrored-field translation, the Knowledge base, reports and dashboards, and the release itself.

Problem

The difficulty was never the new country. It was the six already live.

In a shared org the interesting configuration is common: one global sample process, one set of mirrored translated fields, one Knowledge base, one permission architecture. Adding a country means touching exactly the metadata that every existing country depends on — and there was no maintenance window long enough to take a global business offline while it was sorted out.

So the real requirement was not 'make country seven work'. It was 'make country seven work while proving nothing changed for the other six'.

What I built

  • Access model

    Profiles, permission sets and public groups for the new country's internal users and community users, following the existing per-country pattern rather than inventing a new one.

  • Data privacy across countries

    Sharing configuration so the new country's records stay visible to the new country, and existing countries gain no new visibility. Cross-country leakage was the failure mode I was most concerned about, so it was tested in both directions.

  • Mirrored-field translation

    Local-language display through the existing mirrored-field approach, so records read natively for the new region without forking the data model.

  • Knowledge, reports and dashboards

    A localized Knowledge base for the community, plus the reporting layer the new region needed on day one.

  • The shared sample process

    Extended the global process to accept the new country as a valid path, keeping every existing country's behavior byte-for-byte identical.

Constraints and trade-offs

The de-risking strategy came down to three rules.

  • Additive, not editive

    Wherever possible I added new metadata records and values instead of editing shared ones. New rows are invisible to existing code paths; changed rows are not.

  • Gate what must change

    Where shared logic genuinely had to change, the change was keyed by country so the six live countries continued down their original branch. That buys safety at the cost of extra configuration surface — a clean refactor of the shared process would have been more elegant and considerably more dangerous. I chose the boring option deliberately.

  • Rehearse the whole release, not just the deploy

    The go-live was dry-run in a sandbox mirroring production, in the real order, including the manual steps that do not live in metadata. That rehearsal is what turned a ~240-component deploy into a predictable sequence instead of a discovery exercise.

Outcome

The seventh country went live on schedule inside a ~3-hour window: pre-steps, roughly 240 metadata components, post-steps, then live end-to-end testing before sign-off.

Zero downtime for the six countries already in production, and no post-go-live defects raised against the release.

Go-live, hour by hour

  1. 00:00Pre-steps

    Manual configuration that cannot be carried in metadata.

  2. 00:20Metadata deploy

    ~240 components, deployed in dependency order.

  3. 01:40Post-steps

    Data loads, assignments, activation of the new country path.

  4. 02:20Live testing

    End-to-end on the shared sample process, new country and existing countries.

  5. 03:00Sign-off

    Zero downtime, no post-go-live defects.

Stack

ApexLightning Web ComponentsFlowExperience CloudSalesforce KnowledgePermission sets & profilesSharing rulesTranslation WorkbenchSandbox-to-production release management

Want the parts I can't put on a public page?

Happy to walk through the data model, the trade-offs, and what I would do differently. Open to Salesforce roles, 30-day notice.