Sandboxes
A sandbox is a copy of your organization where you can build and test changes (new fields, page layouts, rules, flows, reports and dashboards) without any risk to the organization your team works in. When the changes are ready, you move them to production with a change set.
At a glance
- Separate data. A sandbox is an organization of its own, in a separate sandbox database in your organization’s region. Nothing you do in it changes production.
- Its own site. Sandboxes are signed in to at sandbox.crmsix.com, never at login.crmsix.com.
- Safe by design. A sandbox emails only its own users and never calls webhooks, so tests can’t reach customers or other systems.
- No extra licences. Up to 5 sandboxes per organization, at no licence cost.
Sandbox types
Choose the type by what you need to test. You can change a sandbox’s type when you refresh it.
| Type | What it copies from production | Refresh at most | Good for |
|---|---|---|---|
| Developer | Setup only: objects and fields, picklists, profiles and permissions, page layouts, validation and workflow rules, flows, email templates, support teams, reports, dashboards and users | Daily | Building new setup |
| Partial copy | Setup, plus the newest 5,000 records of each object (accounts, contacts, leads, opportunities, cases, articles, products and custom objects), with their related records | Every 5 days | Testing with realistic data |
| Full copy | Setup and every record | Every 29 days | Training, user acceptance testing |
Records keep their IDs and case numbers, so a record someone mentions from production is easy to find in a full copy. Record IDs keep their first ten characters and end with the sandbox’s own four-character code.
Before you start
- You need the Manage sandboxes permission (the Admin profile has it).
- Sandboxes are created from the production organization, not from another sandbox.
- If Settings → Sandboxes says sandboxes aren’t set up for your region, CRMSix hasn’t added a sandbox database there yet: contact us.
Create a sandbox
- Sign in to production and go to Settings → Sandboxes (in the Data section).
- Enter a name: 1 to 12 lowercase letters or digits, for example
uatordev2. It becomes part of the sandbox’s sign-in name. - Choose the type. For partial and full copies, decide whether to mask personal data.
- Choose Create sandbox. The copy runs in the background and the page shows its progress; a developer sandbox is usually ready in under a minute, a full copy of a large organization takes longer.
- When the status shows Ready, use Sign in.
Sign in to a sandbox
Go to sandbox.crmsix.com and enter the sandbox’s organization sign-in name: your production sign-in name,
two hyphens, then the sandbox’s name. For example, the uat sandbox of acme is acme--uat. Use your usual
email and password.
- A yellow banner at the top of every page shows you’re in a sandbox, which one, and when it was copied.
- Signing in to a sandbox at login.crmsix.com is refused, with a message pointing to sandbox.crmsix.com, and production can’t be signed in to at sandbox.crmsix.com.
- Single sign-on isn’t copied: sign in with your password.
What’s copied, and what never is
Everything that makes up your organization’s setup is copied, and for partial and full copies, records too. To keep a sandbox from reaching customers or other systems, some things are never copied:
| Never copied | Why |
|---|---|
| API keys and connected apps | Integrations would otherwise reach the sandbox with production’s credentials |
| Single sign-on and MCP settings | They’re tied to production’s identity provider and AI apps |
| Email routing addresses | Customer emails must keep going to production |
| Chat transcripts, field history, logs and sign-in history | Records of what happened in production, not setup |
| Licences and billing | Sandboxes don’t use licences |
And while you work in a sandbox:
- Email goes only to the sandbox’s own users. Messages to anyone else are kept in the Email Log but not sent, so workflow rules and flows can be tested without emailing customers.
- Webhooks from workflow rules and flows are never called.
Mask personal data
For partial and full copies, tick Mask personal data to replace the names, email addresses and phone numbers of contacts, leads and cases, and the addresses on emails, with made-up ones (for example Test Person 3f9a, contacts-1c2d3e@example.invalid). Use it when testers shouldn’t see real customers’ details, for example under India’s DPDP Act or the EU’s GDPR. Company names and the rest of each record are kept.
Refresh or delete a sandbox
- Refresh replaces everything in the sandbox with a new copy of production. Changes made in the sandbox are lost, so deploy anything you want to keep first. You can switch the type when refreshing.
- A sandbox can be refreshed again after its type’s interval (daily, 5 days or 29 days). The Sandboxes page shows when.
- Delete removes the sandbox and everything in it. Its sign-in name can then be used again.
Limits
| Sandboxes per organization | 5 |
| Records per object in a partial copy | 5,000 (the newest) |
| Sandbox name | 1 to 12 lowercase letters or digits; the full sign-in name can be up to 40 characters |
| Licences used | None |
Troubleshooting
- “This organization is a sandbox. Sign in at https://sandbox.crmsix.com”
- You tried to sign in to a sandbox at login.crmsix.com. Go to sandbox.crmsix.com instead.
- “This is the CRMSix sandbox site. Sign in to your organization at https://login.crmsix.com”
- You entered your production sign-in name at sandbox.crmsix.com. Add
--and the sandbox’s name, or sign in at login.crmsix.com. - “Sandboxes aren’t set up for this organization’s region yet”
- CRMSix needs to add a sandbox database in your region first. Contact us.
- An email from a workflow rule never arrived
- In a sandbox, email goes only to the sandbox’s users. Check Settings → Email Log: the message is there with the reason it wasn’t sent.
- “Copy failed”
- Refresh the sandbox to try again. If it fails again, raise a support ticket with the message shown.