Security Review
A Salesforce security audit you can run this afternoon
Fourteen modules sweep your org — privileged access, sharing model, field-level security, guest access, Apex, integrations and more — combining deterministic checks with AI analysis to produce a scored report, triaged findings with evidence, and a manual-review guide for the judgement calls.
What you can do
- Fourteen audit modules: org baseline, authentication & SSO, users & licences, privileged access, permissions hygiene, object & field-level security, sharing model, guest & external access, Apex security, automation & flows, integrations, packages & platform, files & data egress, monitoring & audit
- Deterministic checks find the facts; AI analysis groups the evidence and explains the risk
- Every finding carries severity, evidence, and a link to the metadata it came from
- A coverage matrix shows exactly which modules ran and what each one examined
- Triage findings as resolved, accepted, or false-positive — state persists for your whole team
- Export Markdown or CSV for stakeholders, plus an executive summary
- A manual-review guide for the calls a tool should not make alone
- Runs as a detached background job — start it and leave the page
How it works
Start a review
One click on the org’s Security Review page. The run detaches, so you can close the tab and come back to it.
Watch coverage fill in
The matrix ticks off modules as they complete, and findings stream in as they are discovered.
Triage with evidence
Findings arrive severity-ranked with the underlying metadata attached. Resolve, accept, or dismiss — your team sees the same state.
Export and act
Markdown or CSV for the stakeholders who asked, and the manual-review guide for the human judgement calls.
Why it's different
Evidence, not a checklist score
Salesforce Health Check gives you a percentage against a baseline. This walks fourteen modules of real metadata, has AI reason over the collected evidence in groups, and hands you findings you can act on — each with the record, field, or profile behind it. The audit itself only ever reads: it inspects your settings, it never changes them.
Try asking
- Audit an inherited org before you agree to own it
- Answer “who can see what?” with evidence instead of guesses
- Produce a security report for a client, an auditor, or a board pack
- Catch over-permissioned profiles and stale integration users
- Re-run quarterly and compare what changed
Security Review — questions
Works even better with
Permissions Workbench
Compare profiles and permission sets side by side in one matrix — then bulk-edit object CRUD and field-level security and apply the changes.
Learn moreTech Debt Finder
Sweep an org for the flows, fields, templates, and profiles nobody uses any more — then triage what is real and plan safe removals.
Learn moreMetadata Explorer
Your whole org, documented and searchable: objects, Apex, flows, permissions, and 50+ metadata types with an interactive relationship map.
Learn morePut Security Review to work on your org
Start free with the Metadata Explorer — every AI feature is free while the beta runs, and a competitive price is still being worked out.