惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
S
Securelist
P
Proofpoint News Feed
H
Help Net Security
S
Schneier on Security
T
Tenable Blog
C
Cisco Blogs
S
Security @ Cisco Blogs
博客园 - 司徒正美
博客园 - 叶小钗
Cisco Talos Blog
Cisco Talos Blog
Google DeepMind News
Google DeepMind News
C
Cybersecurity and Infrastructure Security Agency CISA
Google Online Security Blog
Google Online Security Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Hacker News: Ask HN
Hacker News: Ask HN
NISL@THU
NISL@THU
云风的 BLOG
云风的 BLOG
V
Vulnerabilities – Threatpost
T
The Blog of Author Tim Ferriss
aimingoo的专栏
aimingoo的专栏
W
WeLiveSecurity
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Jina AI
Jina AI
腾讯CDC
WordPress大学
WordPress大学
Simon Willison's Weblog
Simon Willison's Weblog
Vercel News
Vercel News
小众软件
小众软件
N
Netflix TechBlog - Medium
有赞技术团队
有赞技术团队
AWS News Blog
AWS News Blog
雷峰网
雷峰网
Forbes - Security
Forbes - Security
The Hacker News
The Hacker News
博客园 - 聂微东
F
Full Disclosure
量子位
Scott Helme
Scott Helme
宝玉的分享
宝玉的分享
A
About on SuperTechFans
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Schneier on Security
Schneier on Security
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
K
Kaspersky official blog
AI
AI
SecWiki News
SecWiki News
Webroot Blog
Webroot Blog
Martin Fowler
Martin Fowler

Salesforce

Scale Your MRR: Subscription Management For Small Business Streamlining Commerce Media Ad Inventory Management 12 AI Sales Strategies for Startups That Actually Work Sell Smarter: Ecommerce Metrics To Track For Your Small Business Shop Apply the Orchestration Density Framework to Your Next Automation Decision Wait, Black Friday Planning In Spring? It’s Time to Start Holiday Promotions AI-First Operations, One Process at a Time How BCU Is Transforming Banking Service with Agentforce Salesforce Headless 360: What the Agent Consumer Means for Your Integration Architecture Meet Customers Where They Are: Agentforce Contact Center Now Offers WhatsApp Voice 11 Free Lead Generation Tips for Small and Growing Businesses SFR-VibeTrain: The Agent That Trains Agents Why Technical Accuracy is the Wrong Metric for Agent Success Strengthening Salesforce Security Against AI-Driven Threats Join Us in the Community Hub at Connections 2026 The Best Way To Build AI Agents That Customers Trust 5 Ways AI is Changing the Communication Game For Startups Trust in the Era of Agents: Highlights from the 2nd Annual Trusted AI Impact Report You Can Be an Agentic Enterprise No Matter What Size Business How to Make Your Email Marketing Accessible for Everyone What is Headless? Don’t Lose Your Head, SMBs: It’s a Good Thing Architect the Future UI: Slack as Your Agentic Surface Point of Sale Innovations to Modernize the Shopper Experience Governing the Agentic Enterprise at Scale with MuleSoft Omni Gateway How to Cut Service Time with Case Routing Automation 5 Tips for Marketers to Get Started with Salesforce Flow No One is Vibe Coding Trade Promotion Management 7th Edition State of Sales Report: 3 Growth Trends for Startups and SMBs How the Architect Vista Brought Architectural Thinking to Life at TDX 2026 5 Steps to Develop an Architect Mindset With AI Why AI Isn’t Replacing Developers, It’s Empowering Them 10 Ways to Make Your AI Agent a Better Communicator AI in Design 2025: What Real Use Taught Us. How Salesforce Personalization Learns Which Offers Drive Revenue The 4-Step Guide to Salesforce Agent and Application Development Get Ready for Connections 2026: Top Sessions and New Reveals 8 Ways AI Agents Are Evolving in 2026 4 Principles to Make the Right Salesforce UI Decisions Apprentice Journey Shines a Light on Talent Pathways at Salesforce Agent Script: The Control Plane for Agentic Decisions Scaling the Agentforce Life Sciences Ecosystem to Drive the Future of Pharma and MedTech Unlocking Unstructured Data: Building AI-Powered Support Triage with Data 360 Asking For a Friend: What Are Rich Communication Services (RCS)? 5 Slack Shortcuts For Small Teams 195% ROI In Field Service? Here’s How They Did It Submit Your Architect Session: The Dreamforce 2026 Call for Participation Is Open What Is an AI Assistant for Small Business? B2C Commerce April release: Transforming the B2C developer experience with agents Meet Your 24/7 Prospecting Partner — And 5 More Stand-Out Features In Our April Release 11+ Small Business YouTube Channels You Need to Follow Today Stop Treating Disputes Management Like IT Tickets Limitless Service: A New Operating Model for Growth in the Agentic Era What is Transactional Reconciliation in Email and SMS Marketing? How to Prepare for National Small Business Week (2026) How to Design a High-Scale Multi-Cloud Incident Journey 10 Ways An AI CRM Can Amplify Your Startup Vibe Code Better Agents with Agentforce Free vs. Paid CRM: Which is Right for Your Business? Salesforce Customer Success Awards 2026: Lead Era of the Agentic Enterprise 12 Free Webinars for Small Business Owners (2026) The Agentforce Life Sciences Consultant Certification Maximize Growth: The Power of Partnerships for SMBs Salesforce AI Research at ICLR 2026 Data Protection For Small Business: How To Safeguard Yourself Beyond 100K Tokens: Evaluating AI Agents in Long-Context Software Engineering Top 32 Small Business Tools To Try Today 6 New Innovations Redefining Salesforce Development How to Win the Battle for Attention in the Agentic Email Inbox Mastering the Eisenhower Matrix: Prioritize Like a Pro 10 Signs It’s Time To Upgrade Your CRM and How To Get Started (2026) Celebrating 10 Years of Financial Services Innovation How SMBs Can Gain An Edge With Agentic AI: Key Trends From Our Marketing Report How MAN Truck & Bus is Shaping the Future of Sales with Salesfive Introducing the Future of Salesforce Data Protection: Backup & Recover Next Stop Making AI Slop – Build a Foundation for Authentic AI Content 5 Tips to Help Marketers Navigate AI Email Summaries Data Sharing: Is it Safe? Is it Secure? Everything You Need to Know Small Business Week Readiness: 4 Things to Do Before May (2026) How Salesforce Employees Make an Impact During Earth Month AI Agents Are Advancing Rapidly… Is Your Testing Strategy Keeping Up? What Is Microproductivity and Why Is It Helping So Many Teams? TDX 2026 Roundup: Agentforce Edition 3 Ways Salesforce Connections Has Boosted My Career AI Agents Don’t Just Answer‌ — ‌They Act. Do You Have a Governance Strategy? The Future of MedTech Field Execution is Agentic 5 Steps to Prepare Your Data For an AI CRM From Break/Fix to Profit Engine: Aftermarket Service for Robot OEMs Building Trusted Human-Agent Collaboration: A Practical Framework ISV Strategy for the Salesforce Summer ’26 Release 5 Email Marketing Tips for Small Business Commerce Shops Should You Give Your AI Agent a Human Name? Creating Pathways into AI for People with Disabilities The Organized Chaos of Upfronts: 3 Hurdles Impacting Your Yield Trying to Scale Beyond ‘One-Off’ AI Tasks? You’re Probably Using the Wrong Interface What is Cost Per Lead (CPL)? The Case for Unified CCaaS and CRM — And Why the Data Makes It Clear In the New Era of AI, You Need to Win Over Both Humans and Agents What Is SPIN Selling? A Way to Build Trust With Your Customers G2 Crowns Salesforce as Best Financial Services Software Hidden Insights: The Guide to Tableau For Small Business Owners
How to Scale Salesforce for 1 Million Concurrent Users
Miriam McCabe · 2026-05-22 · via Salesforce

Imagine you’re an architect handed this brief: a prime-time televised guessing game, launching in weeks, expected to hit 8 million total registrations and 1 million concurrent users. It runs on Experience Cloud. It needs a conversational agent. It cannot go down, especially during the televised peak. 

This is the scenario we worked through in the latest Think Like an Architect episode. In Think Like an Architect, we solve scenarios live so you can build the mental muscles needed to evaluate requirements, weigh options, and justify a solution direction instead of simply reviewing a finished architectural design. This recap walks you through each step of the scenario and the thinking behind it.

The What/How/Why Approach

To design scalable solutions, we use a repeatable three-step method to move from raw business requirements to justified architectural decisions:

  • What: Highlight key phrases in business requirements to paraphrase the essence of the problem into concise High-Level Requirements (HLRs). This ensures you solve the right problem from the start.
  • How: Align technical solution options directly to your HLRs. Use live diagramming to visualize options and digital sticky notes to capture questions, assumptions, and decisions.
  • Why: Capture your rationale to create an Architectural Decision Record (ADR). This ensures stakeholders and your future self understand the “why” behind a specific direction.

Think Like an Architect: Scaling for the Big Game

Step inside the architecture behind a high-stakes, large-scale digital experience designed to handle millions of users in real time. Use the What/How/Why method to diagram Big Game–level scale challenges and learn how the team tackled extreme volume considerations and lessons learned.

What: Formulate High-Level Requirements (HLRs)

In the “What” step, let’s look at the specific challenge from this episode.

We start with a raw business requirement and use highlighting to indicate the key parts, as shown below.

Business requirement paragraph with key phrases highlighted in yellow

From those highlights, four High-Level Requirements emerge:

  1. Support 8M total registrations and 1M concurrent users on Experience Cloud, US and Canada only.
  2. Conversational agent to answer questions on rules and provide hints.
  3. Real-time toxicity detection.
  4. Zero downtime and a defined strategy for scale testing and load balancing.

Note that HLRs paraphrase rather than use the exact words from the business requirement. This is essential in validating with the business stakeholders that you understood the intention of their requirement.

Two groupings made sense as we moved into the “How” step. HLRs 2 and 3 are closely related as toxicity detection needs to happen in the conversational layer. HLR 4’s load balancing concern belongs with HLR 1, because you can’t talk about supporting 1 million concurrent users without talking about how they’re distributed. So we tackle HLR 1 + load balancing together, then HLRs 2 + 3 together, then the scale testing and zero-downtime strategy.

To continue with evaluating solution options, let’s move into the “How” step by following the trail of questions, assumptions, and decisions captured during our live session.

How: Aligning Solutions to Your HLRs

In the “How” step, we evaluate solution options for the HLRs. To keep your thinking organized, track your Questions, Assumptions, and Decisions alongside drawing the system landscape piece by piece.

HLR 1 + Load Balancing: Supporting 8M registrations and 1M concurrent users

The first question that comes to mind is: what’s the org strategy? Closely tied to that is the license strategy, because different Experience Cloud license types have very different scalability implications.

The requirement doesn’t suggest advanced sharing or complex permission models — it’s a public game. That points to a CC (Community Cloud) license. But even with a CC license, the platform has limits on both total users per org and concurrent users per org. At 8 million registrations and 1 million concurrent, a single org won’t work. We’re in multi-org territory.

  • Decision: Multi-org with CC licenses.
  • Reasoning: Platform limits on concurrent and total Experience Cloud users per org mean the volume can’t be handled in a single org. Multiple orgs distribute the load.
Salesforce multi-org architecture with Experience Cloud

With multi-org confirmed, the registration question comes next: what are the registration considerations? Three assumptions surface:

  • Data Manipulation: Creating millions of users generates significant DML load, user creation is an especially heavy DML operation, even in a distributed org model. So we need to ensure this is well distributed.
  • IP Detection to Ensure Eligibility: Only US and Canada players are allowed. That check needs to happen before the user reaches the org.
  • Low Latency for Static Content: Rules, terms, hints are static pages that need to load fast for millions of users also during peak.

These assumptions point to a CDN. Akamai is the decision here, sitting in front of the orgs and handling three things: IP-based geo-filtering for US/Canada eligibility, fast delivery of static content, and a waiting room to manage traffic spikes at peak.

  • Decision: CDN (Akamai) in front of Experience Cloud.
  • Reasoning: Handles IP-based eligibility checks, serves static content with low latency, and provides a waiting room to gracefully manage surge traffic rather than letting load hit the orgs directly.
Akamai is now added to the landscape as CDN, not yet connected to the Salesforce orgs

The next question is: how do we route users to the correct org? New users need to land in an org that has capacity for their registration. Returning users need to be routed back to the specific org where their account lives also known as what we call shard registration.

The decision is a pre-login infrastructure layer hosted on AWS. This is a natural fit because AWS shares a trust boundary with Salesforce. For new users, round-robin distribution ensures registrations are spread evenly across orgs. For returning users, a shard registry stored in AWS DynamoDB  maps each user to their org so they’re routed back correctly on every subsequent visit.

  • Decision: AWS pre-login infrastructure with DynamoDB for shard registration.
  • Reasoning: Provides round-robin load distribution for new registrations and persistent shard mapping so returning users are always routed to the correct org. AWS shares a trust boundary with Salesforce.
Architecture diagram showing Akamai CDN receiving user traffic, routing through AWS pre-login infrastructure with DynamoDB for shard registration, which then routes to multiple Salesforce orgs each containing Experience Cloud instances

HLR 2 + 3: Conversational agent with real-time toxicity detection

With the scale and routing architecture in place, we move to the agent. The first question is: what kind of agent?

In an Experience Cloud context with a public-facing site, not an employee portal, the answer is an Agentforce Service Agent. It’s designed for external engagement, and it lives where the users are.

Next question: where does the knowledge live? Two categories of knowledge matter here. The rules and hints need to be consistent across all orgs. The conversation history is per-user, so it lives naturally in whichever org the user is registered in that’s already solved by the multi-org routing layer.

For the rules and hints, the simplest approach is a prompt template deployed to all orgs. The assumption here is that the rules and hints are not enormous documents but bounded content that fits cleanly into a template. 

  • Decision: Agentforce Service Agent with a prompt template deployed across all orgs for rules and hints knowledge.
  • Reasoning: Prompt templates are the lightest-weight knowledge distribution mechanism. Deploying the same template to each org keeps knowledge consistent without building a separate cross-org knowledge service. Conversation history is stored per org and is already scoped correctly by the shard registration layer.

For toxicity detection, the answer is already built in. The Agentforce Trust Layer handles bidirectional content filtering — it applies to both what the agent says and what players type. This is out-of-the-box behavior, not a custom build.

  • Decision: Agentforce Trust Layer (OOB) for real-time toxicity detection.
  • Reasoning: The Trust Layer is already part of the Agentforce platform and operates bidirectionally, covering both agent outputs and user inputs. No custom integration required.
Architecture diagram showing Agentforce Service Agent within the Salesforce orgs, connected bidirectionally to the Agentforce Trust Layer with LLM connection shown, and prompt templates and conversation history also within each org.

HLR 4: Zero downtime and strategy for scale testing

This is a prime-time televised event, so the core question is: how can we have assurance that this will scale? The answer is to test at 3x the expected peak. If the architecture holds at 3x, you have a meaningful safety margin for game day.

  • Assumption: 3X peak capacity as the scale testing target.
  • Decision: Use Scale Test to validate the architecture at 3x peak capacity before launch.

When you run a scale test at that volume, you will find things. That leads to the next question: when findings come in, how do you tackle them? This is where Scale Center and Apex Guru come in. Scale Center provides observability meaning that you can see where the system falls apart and holds under pressure. Apex Guru gives you targeted recommendations for Apex code that needs to be rewritten or optimized to perform at scale.

  • Decision: Scale Center for observability + Apex Guru for Apex optimization.
  • Reasoning: Scale Center surfaces bottlenecks across the platform layers. Apex Guru translates those findings into specific code-level recommendations, turning insights into actionable fixes rather than guesswork.

Last question for this HLR: what’s the environment strategy? Given that we’re already in a multi-org setup at this scale, the only meaningful testing environment is a Full Copy Sandbox. The 3x target makes this clear as well, you need a production-grade environment to validate production-scale load.

  • Decision: Full Copy Sandboxes for scale testing.
  • Reasoning: A standard sandbox doesn’t reflect production infrastructure. Scale Test is available as an add-on to Full Copy, and Salesforce will inflate the sandbox to production grade so the test results are accurate.

Why: Justify Your Design with ADRs

During the live stream, we emphasized that an architect’s value is not in the solution, but in the rationale. The questions, assumptions, and decisions you capture during the “How” step are the raw material for an Architectural Decision Record that explains your thinking to stakeholders, to other architects, and to yourself six months from now.

A few specific ADR principles worth internalizing from this episode:

  • Tie assumptions to decisions: If an assumption proves wrong, the decision may need to change. In this architecture, the prompt template decision assumes that rules and hints are bounded in size. If that assumption is later invalidated, the knowledge management approach needs to shift eg toward a knowledge base instead.
  • Document why you ruled things out: During the discussion with the experts, we talked about how we considered platform cache for user registration handling but then decided on Platform Events instead. That is the type of information that matters for the next architect who looks at this design.
  • Scale testing cost is an architectural decision: The cost of a 3x scale test on an AI-heavy solution isn’t trivial as it involves LLM calls at 3x volume. A good architect estimates that cost upfront, brings it to stakeholders, and gets buy-in. The alternative is a much more expensive outcome if the project fails.

For a step-by-step guide to building ADRs, including how to use LLMs to help, see this blog on how to create an Architectural Decision Record with the help of LLMs.

Expert Q&A

Joining us for this episode were Karishma Lalwani, Salesforce Certified Technical Architect and Senior Director of Product at Salesforce, and Sebasten Raffal, Certified Technical Architect and Director AI Architect at Salesforce. Here’s a selection of the questions from the session.

Agent design

Should you use one big agent action that handles multiple steps, or multiple smaller actions? Multiple smaller actions is the better design. It gives the agent more flexibility to orchestrate and makes each action reusable across multiple contexts. As Sebasten noted, consumption-based licensing in Agentforce is tied to what you use, not how you structured the actions so there’s no architectural penalty for composability.

Would you consider a standby conversational agent on a different LLM vendor as a failover? Salesforce already handles this within the platform. Every conversation goes through the LLM gateway, and within that gateway, Salesforce has load balancing and failover infrastructure across LLM vendors.

Scale and Multi-Org

Why can’t a single org handle 8M users? The total number of Experience Cloud users a single org can support is in the hundreds of thousands, not millions. The concurrent user limits compound this further. Multi-org isn’t a preference or a default, but based on the scale of the solution, it is the only viable architecture. 

What are the governance implications of a multi-org strategy? The primary complexity is release management. You need to ensure the same deployment packages, configurations, and customizations go out to every org consistently. In this scenario, each user belonged to exactly one org and no data sync between orgs was required beyond the prompt template. For a long-lived multi-org deployment, the administration overhead is more significant. Packaging the Experience Cloud definition and deploying it uniformly across orgs (as mentioned by audience participants during the session) is the right approach.

What about aggregating data across orgs to create a leaderboard? This requires an aggregation layer outside the individual orgs. One approach used successfully in practice: MuleSoft extracts data from each org on a scheduled basis and writes it to a central repository org. Tableau or CRM Analytics on top of that gives you the dashboard, and you can expose it externally if needed.

What are some other real-world uses of org sharding? Karishma shared from direct experience. During the COVID-19 vaccination rollout, multiple states and countries used Salesforce as their booking platform, implementing the same CDN + waiting room + org sharding pattern to manage sudden surges in traffic. She also talked about how this is a common experience that she encountered as a consumer when ordering international soccer tickets. These aren’t edge cases and any scenario with high-burst, time-sensitive public access hits these architectural constraints.

Waiting rooms and user experience

Isn’t a waiting room a frustrating user experience? It’s an industry-standard pattern for high-burst scenarios, and users have come to recognize it. The alternative of showing an error page when the system is overwhelmed is a much worse experience. A waiting room that tells you “your turn in 9 minutes” is manageable. One pre-registration strategy can reduce waiting room friction significantly: register users ahead of the event opening. If they’ve already completed the OTP flow and account setup in advance, the surge at launch is much smaller, because the high-cost part of registration is already done.

Bot prevention

How do you ensure applicants are real people? The defense is layered. Akamai handles the first gate with IP-based filtering and traffic pattern detection. AWS has built-in threat detection for request blasting from single IPs. Inside Salesforce, an email-based OTP flow adds another verification step. In previous real deployments, users were also asked to upload verifiable identity documents. Each layer catches something the others don’t and the combined strategy is what makes it robust.

Scale testing cost

How do you handle the cost reality of 3x scale testing with AI in the mix? Testing at 3x volume on an AI-heavy solution means 3x LLM calls, and that has a real cost. The right framing is that this is an investment in derisking the launch. Estimate it upfront, bring it to stakeholders with context, and let them make an informed decision. The comparison to make: what does one minute of downtime cost during a live televised event? Karishma cited analysis showing that for high-stakes launches, this can be in the thousands of dollars per minute in lost customer acquisition. 

Scale testing doesn’t need to be weeks-long. For most projects, the strategy is one x volume for the bulk of testing, then a dedicated three- to four-day scale test budget to stress the full end-to-end stack in this case Akamai, AWS, Salesforce app layer, database, LLM gateway.  This is especially important for recurring peak events like Black Friday, tax season, or major sporting events, where a quarterly or annual scale test cadence makes sense.

Final wrap-up

An important takeaway for any architect is to first solve the problem with the simplest, most standard tool or functionality available, then prove why it won’t work before moving to more custom or made-to-measure solutions. In this architecture, that principle shows up repeatedly, such as leveraging prompt templates before Salesforce Knowledge, and Platform Events before Kafka.

  • Next Episode: Join us on May 28, same time, same channel, for the next Think Like an Architect.
  • Vote on future episodes: Help us shape the future of the series. Tell us what topics you want to see and how we can provide more value to you.

Subscribe to the Salesforce Architect Digest on LinkedIn

Get monthly curated content, technical resources, and event updates designed to support your Salesforce Architect journey.