SyncOnAI360

Permissions Analysis

See who can reach what in Salesforce, and what is too broad.

Permission and access risks found from evidence, mapped to common control frameworks, and flagged again on every change that alters who can reach something.

Org Audit

Acme Production · last run 6 minutes ago

Grade C
high

Flow has no fault path

Case_Intake_Route · Automation & Flows · Effort: hours · $600

<!-- Case_Intake_Route.flow-meta.xml -->
<recordUpdates>
  <name>Assign_Queue</name>
  <!-- no <faultConnector> -->
  <object>Case</object>
</recordUpdates>

In one paragraph

SyncOnAI 360 Permissions Analysis finds access risks in a Salesforce org from its own metadata and usage: guest user object access, Modify All Data outside admin profiles, broad API access, profile-heavy security, redundant permission sets, inactive and never-used accounts, and missing MFA. Findings carry evidence and map to SOC 2, ISO 27001 and Essential Eight controls.

Permission and security checks
4Permission and security checks
Control frameworks mapped: SOC 2, ISO 27001, Essential Eight
3Control frameworks mapped: SOC 2, ISO 27001, Essential Eight
Inactive user detection from login history
90dInactive user detection from login history
Proposal flags changes to who can reach what
EveryProposal flags changes to who can reach what

01The problem

Why Salesforce access grows broader every year

Access is granted one request at a time and almost never taken away. Profiles accumulate permissions, permission sets overlap, and nobody can say with confidence who can see what.

  1. 01

    Grants without removal

    Every urgent request adds access. Nothing in the process removes it when the need ends.

  2. 02

    Guest exposure

    Experience Cloud guest users can be given object access that nobody intended to make public.

  3. 03

    Powerful permissions spread

    Modify All Data and API access end up on profiles that do not need them.

  4. 04

    Dormant accounts

    Users who left or never logged in keep their access and their attack surface.

02checks

What permission risks does SyncOnAI 360 check for?

Permission checks look for guest user object access, Modify All Data granted outside admin profiles, API access enabled too broadly, and security that leans on profiles where permission sets are the better practice. Duplicate detection finds redundant permission sets that grant the same thing.

Each finding has its evidence, such as the table of permission grants behind it, a severity and an estimated cost to fix, and the permissions and security section is one of the two most heavily weighted in the org's overall score.

  • Guest user object access
  • Modify All Data outside admins
  • Broad API access
  • Redundant permission sets

Org Audit

Acme Production · last run 6 minutes ago

Grade C
high

Flow has no fault path

Case_Intake_Route · Automation & Flows · Effort: hours · $600

<!-- Case_Intake_Route.flow-meta.xml -->
<recordUpdates>
  <name>Assign_Queue</name>
  <!-- no <faultConnector> -->
  <object>Case</object>
</recordUpdates>

03usage

How are inactive and risky Salesforce users found?

Live usage checks read the org's user and login history to find users inactive for 30 or 90 days, users who have never logged in, and elevated login failures. Adoption checks flag MFA that is not enforced, a low Security Health Check score and connected app sprawl.

Compliance checks look at setup audit gaps, guest user exposure and the number of admin users, the evidence an access review needs before it starts.

  • Inactive and never-used accounts
  • Elevated login failures
  • MFA enforcement and Health Check score
  • Admin user count

Org Audit

Acme Production · last run 6 minutes ago

Grade C

Priced at $150 an hour, shown on screen

  • Admin user inactive for 90+ days

    critical Minutes

    $75

  • Flow has no fault path

    high Hours

    $600

  • SOQL query inside a loop

    high Hours

    $600

  • Production change made outside the pipeline

    high Hours

    $600

  • Three record-triggered Flows on Case

    medium Days

    $2,400

5 selectedCreate statement of work

04frameworks

How do permission findings map to compliance frameworks?

The compliance view maps relevant findings to SOC 2, ISO 27001 and Essential Eight controls, so a compliance team starts from a working list of what to address rather than a blank page.

The mapping supports a compliance conversation; it is not a certification of the org. Reports can be shared as read-only links with auditors or stakeholders and withdrawn at any time.

  • SOC 2, ISO 27001 and Essential Eight mapping
  • Read-only reports for reviewers
  • Not a certification

Org Audit

Acme Production · last run 6 minutes ago

Grade C

C

74 / 100

Fair, technical debt accumulating

Automation & Flows

64

Permissions & Security

71

Apex & Code

78

Fields & Data Quality

82

Limits & Performance

91

Change Intelligence

69

55 checks run · 37 open findings · 2 checks skipped, with the reason shown

05changes

How are access changes reviewed before they deploy?

Every proposal runs a Security and access check. If a change alters permissions, sharing or external access, the check names the components involved and asks the approver to confirm the access is intended.

Granting access is a normal thing to deploy, so the check warns rather than fails: its job is to make sure an approver knows they are approving a permission change, without training people to override it.

  • A Security and access check on every proposal
  • Components that change access named
  • Warns so approvers notice, never hidden

Proposal: Case intake fault handling

Acme Production

Checks passed
  • Validated against the org without changing it
  • No component outside the change is modified
  • Apex tests pass, coverage 81%
  • No freeze window in effect
  • Policy: production requires a second admin

Blast radius

  • 2 Flows read Case.Priority
  • 1 report filters on it
  • Case_Intake_Route assigns from it

Risk: medium

06review

How do you run a Salesforce access review?

Start from the permission and usage findings for the org: who has elevated access, who has not logged in for 30 or 90 days, where guest users can reach data and which permission sets duplicate each other. Each finding links to its evidence, so the review works from facts rather than an export.

Changes that come out of the review, such as removing a permission or retiring a duplicate set, are proposed like any other change, with the Security and access check, the blast radius and a second admin's approval for production.

  • Start from evidenced findings
  • Fixes proposed and approved
  • Access changes flagged for approvers

Org Audit

Acme Production · last run 6 minutes ago

Grade C

C

74 / 100

Fair, technical debt accumulating

Automation & Flows

64

Permissions & Security

71

Apex & Code

78

Fields & Data Quality

82

Limits & Performance

91

Change Intelligence

69

55 checks run · 37 open findings · 2 checks skipped, with the reason shown

07How it works

An access review

From evidence to reduced access.

  1. 01

    Scan

    Run the audit's permission, usage and compliance checks.

  2. 02

    Review

    Read each finding with its evidence and mapped controls.

  3. 03

    Plan

    Turn findings into work items or a statement of work.

  4. 04

    Change

    Reduce access through proposals that flag access changes.

  5. 05

    Verify

    The next audit confirms each fix.

08Before and after

Access reviews, with and without SyncOnAI 360

Without

With SyncOnAI 360

Exporting profiles to spreadsheets

Permission risks found with evidence

Dormant accounts found by accident

Inactive and never-used users from login history

Controls mapped by hand

Findings mapped to SOC 2, ISO 27001 and Essential Eight

Access changes slipped into releases

Every access change flagged to the approver

No proof of remediation

Fixes verified by re-audit

10Questions

Frequently asked questions

Who can reach what: profiles, permission sets, guest access, powerful permissions such as Modify All Data, API access, user activity and MFA.

Yes. Guest user object access is checked in both the permissions and compliance sections.

Yes. Usage checks read login history for users inactive 30 or 90 days, users who never logged in and elevated login failures.

The compliance view maps relevant findings to SOC 2, ISO 27001 and Essential Eight controls. It supports compliance work; it does not certify the org.

Yes. Duplicate detection finds permission sets that grant the same access.

Yes. Every proposal's Security and access check names changes to permissions, sharing or external access for the approver.

Usage checks read user and login history to find inactive accounts. CRM records such as accounts and cases are not stored.

Yes. Every plan includes every feature.

Start in 5 minutes. No card required.

Connect your Salesforce org. Run your first health scan. Ask your first question. See what you've been missing.

  • Anthropic
  • OpenAI