Every email your sandbox would really send. On one page.
The manifest resolves each workflow alert, flow, trigger, and Apex sender in a refreshed sandbox to the inbox it would actually hit — before UAT starts, not after a customer replies.
| Email path | Source | Object | Sender | Resolves to | Risk | Would send | |
|---|---|---|---|---|---|---|---|
| Case_Escalation_Notify | Workflow Alert | Case | support@acme.example | dana.customer@bluebay.example | high | Yes | |
| Renewal_Reminder_90d | Flow | Contract | renewals@acme.example | kim.buyer@stonebridge.example | high | Yes | |
| Opp_Closed_Won_Thanks | Email Alert | Opportunity | sales@acme.example | lee.owner@harborlane.example | high | Yes | |
| OrderConfirmationMailer | Apex Trigger | Order | orders@acme.example | ana.ops@crestline.example | high | Yes | |
| Lead_Welcome_Sequence | Process Builder | Lead | hello@acme.example | sam.lead@fernvale.example | high | Yes | |
| SLA_Breach_Warning | Workflow Alert | Case | support@acme.example | pat@acme-uat.example | medium | Yes | |
| Quote_Approval_Request | Flow | Quote | quotes@acme.example | jordan@acme-uat.example | medium | Yes | |
| Case_Reopened_Owner_Ping | Email Alert | Case | noreply@acme.example | morgan@acme-uat.example | medium | Yes | |
| InvoicePastDueNotifier | Apex Trigger | Invoice__c | billing@acme.example | ap@willowmark.example | high | Yes |
Paths resolve to inboxes, not guesses
Every detected sender is traced to its recipient at send time: a real contact copied in from production, an internal user, or a whitelisted test address. That difference is the whole risk model — and it sits on every row.
- Real-contact recipients rank high by default
- Internal users and test addresses stay ranked, never hidden
- Sender address, object, and sample recipient on each path
Paths by source type
UAT · scan-0158
Risk that trends down, on the record
High, medium, and low counts are kept week over week for every sandbox. When a refresh quietly reactivates an old alert, the ledger shows the exact week it came back — and who cleared it last time.
- Severity counts tracked per sandbox, per week
- Reintroduced paths flagged against their history
- One click from a trend point to the paths behind it
Open risky paths by severity
All sandboxes · last 12 weeks
Block a deploy with one row of evidence
Every release gets a manifest diff: paths added, removed, and changed since the last clear scan. Clear releases ship. Blocked ones name the exact path holding them — no meeting required.
- Added, removed, and changed paths per release
- Gate status your release manager can cite
- Export the diff as PDF or CSV for the audit trail
Release ledger
4 releases · 3 sandboxes
| Release | Sandbox | Date | Manifest diff | Gate |
|---|---|---|---|---|
| R-2026.07 Summer | UAT | 2026-07-10 | +6-1~4 | In review |
| R-2026.06b Hotfix | hotfix-jul | 2026-06-26 | +1-0~2 | Clear |
| R-2026.06 Service Cloud | FullCopy-2026 | 2026-06-12 | +9-3~7 | Blocked |
| R-2026.05 CPQ Rollout | UAT | 2026-05-22 | +4-2~5 | Clear |
- 2,210
- components parsed in a single full-sandbox scan
- 88
- email paths mapped from one metadata export
- 9
- would-send paths flagged before UAT even started
Put a manifest between your sandbox and your customers.
Run the first scan free. The $99 one-time report covers a single org; the $39/mo ledger keeps every sandbox on record, release after release.