Security Review
A Salesforce security audit you can run this afternoon
Fourteen modules sweep your org (privileged access, sharing model, field-level security, guest access, Apex, integrations and more) combining deterministic checks with AI analysis to produce a scored report, triaged findings with evidence, and a manual-review guide for the judgement calls. The checks are curated from a professional Salesforce security audit that cost over A$10,000 — the same ground, on demand, as often as you like.
9 findings · Health Check 62/100 · by Alex Rivera · 2 Sep 2026, 09:04
Coverage
Which checks ran, and what was skipped or unavailable.
Findings
Ordered by severity. 9 shown.
| Severity | Finding | Area | Status | Source | Triage |
|---|---|---|---|---|---|
| Critical | Modify All Data held by a standard-user profile AU Sales Support (34 active users) has ModifyAllData via the profile, not a permission set. Fix: Remove it from the profile and grant it to the two admins who need it via a permission set. | Privileged access | Fail | Deterministic | Unreviewed |
| High | Guest user can read Contact Broker Portal Site Guest User has Read on Contact; OWD for Contact is Public Read Only. Fix: Set Contact OWD to Private and grant the portal only the records it serves through a sharing set. | Guest & external exposure | Fail | Deterministic | Unreviewed |
| High | Integration user with Password Never Expires svc_creditbureau holds Password Never Expires and API Enabled, last password change 2021. Fix: Move the integration to a connected app with a certificate, or rotate and expire the password. | Privileged access | Fail | Deterministic | Unreviewed |
| High | Sensitive fields readable by every internal profile Account.Bank_Account_Number__c and Contact.Date_of_Birth__c are readable by all 11 profiles. Fix: Restrict field-level security to the Credit and Settlements profiles, then re-run this check. | Object & field-level security | Fail | AI | Unreviewed |
| Medium | 9 stale but active users Nine active users have not logged in for more than 180 days; three hold API Enabled. Fix: Freeze them, reclaim the licences, and deactivate after the retention window. | Users & licenses | Fail | Deterministic | Unreviewed |
| Medium | OAuth tokens issued to inactive users 4 refresh tokens belong to users who are now inactive; the oldest was issued in 2022. Fix: Revoke them in Setup → Connected Apps OAuth Usage. | Connected apps & integrations | Fail | Deterministic | Unreviewed |
| Medium | 23 permission sets with zero assignments None of the 23 is assigned to a user or a group; 11 also have no description. Fix: Delete the ones nobody claims — each is a grant waiting to be assigned by accident. | Profiles & permission-set hygiene | Fail | Deterministic | Unreviewed |
| Medium | Session timeout longer than policy Org session timeout is 12 hours; Health Check flags anything above 2 hours as high risk. Fix: Reduce it to 2 hours and enable "Force logout on session timeout". | Org baseline & Health Check | Fail | Deterministic | Unreviewed |
| Low | Two certificates expire within 90 days sso_signing (expires 14 Oct 2026) and portal_tls (expires 2 Nov 2026). Fix: Renew both before the SSO one takes the login page down with it. | Authentication, SSO & sessions | Fail | Deterministic | Unreviewed |
What you can do
- Checks curated from a professional Salesforce security audit — a real engagement costing over A$10,000 — turned into modules you can re-run whenever you like
- Fourteen audit modules: org baseline, authentication & SSO, users & licences, privileged access, permissions hygiene, object & field-level security, sharing model, guest & external access, Apex security, automation & flows, integrations, packages & platform, files & data egress, monitoring & audit
- Deterministic checks find the facts; AI analysis groups the evidence and explains the risk
- Every finding carries severity, evidence, and a link to the metadata it came from
- A coverage matrix shows exactly which modules ran and what each one examined
- Triage findings as resolved, accepted, or false-positive — state persists for your whole team
- Export Markdown or CSV for stakeholders, plus an executive summary
- A manual-review guide for the calls a tool should not make alone
- Runs as a detached background job: start it and leave the page
How it works
Start a review
One click on the org’s Security Review page. The run detaches, so you can close the tab and come back to it.
Watch coverage fill in
The matrix ticks off modules as they complete, and findings stream in as they are discovered.
Triage with evidence
Findings arrive severity-ranked with the underlying metadata attached. Resolve, accept, or dismiss. Your team sees the same state.
Export and act
Markdown or CSV for the stakeholders who asked, and the manual-review guide for the human judgement calls.
Why it's different
Every finding shows its evidence
Salesforce Health Check gives you a percentage against a baseline. This walks fourteen modules of real metadata, has AI reason over the collected evidence in groups, and hands you findings you can act on. Each with the record, field, or profile behind it. The audit itself only ever reads: it inspects your settings, it never changes them.
Try asking
- Audit an inherited org before you agree to own it
- Answer “who can see what?” with evidence instead of guesses
- Produce a security report for a client, an auditor, or a board pack
- Catch over-permissioned profiles and stale integration users
- Re-run quarterly and compare what changed
Security Review — questions
Works even better with
Permissions Workbench
Every profile and permission set in one matrix. Bulk-edit straight from it.
Learn moreTech Debt Finder
Fields nobody fills. Flows nobody runs. Triage what is real before you delete anything.
Learn moreMetadata Explorer
Fifty-plus metadata types, searchable, with a relationship map you can follow.
Learn moreRead next
- How to run a Salesforce security review: a 14-point checklist
Health Check gives you a score out of 100 and almost no idea what to do next. Here is the fourteen-area sweep that actually surfaces risk.
Put Security Review to work on your org
Every AI feature on your own provider key, from A$19.95 per user per month.
- 14-day free trial
- No credit card required
- Cancel any time