Concept and mechanism
SOQL answers structured queries over known objects and relationships, including filters and aggregation. SOSL searches text expressions across multiple objects and organizes results by type. In Apex, selecting some fields does not automatically make all others available: the query contract must match the data that code will read. In dynamic queries, binding handles values; field names and other structural parts require separate validation, normally an allowlist. Escaping quotes is not a universal solution. DML changes data and has its own rules: upsert can insert, update, or fail on multiple matches, depending on the key and existing records.
Guided application
In an operational load, preserve the association between each input and its returned result. Database.insert with allOrNone false supports observing per-record successes and failures, but code must inspect SaveResult. Partial operation success still does not prove commit if the outer transaction later fails. Operator messages should distinguish expected rejection, technical failure, and confirmed completion. Handle only exceptions that can be resolved; do not return success with empty data to conceal problems. For Lightning interfaces, a controlled message can explain necessary correction without exposing internal details. Preserve diagnostics suitable for investigation and present only information useful to the person who performed the action.
A search accepts the customer value through binding and permits sorting only by approved fields. During the next load, two records match one key: the system holds that input for reconciliation instead of arbitrarily choosing the newest record.
Common pitfalls
Binding treated as identifier protection; unselected fields treated as zero; no exception treated as total success; SaveResult treated as a final commit guarantee.
Related topics: Data model, identity, and metadata · Collections and choosing configuration or code · Triggers, limits, and asynchronous processing
Query explicitly, validate dynamic structure, and reconcile each result. Success messages must correspond to confirmed states.
Reference: Manipulate Records with DML · Platform Developer guide Summer 25