# A Salesforce org audit you can put a price on.

> SyncOnAI 360 Org Audit runs 55 automated checks across a connected Salesforce org: automation, Apex, permissions, fields, limits, packages, change history, adoption, compliance and AI readiness. Each finding carries its evidence, a severity, an effort band and an estimated cost to fix, and the org receives a letter grade from A to F.

Source: https://synconai360.com/features/org-audit

## Key facts

- **55**: Automated checks in every audit
- **12**: Sections scored on their own
- **A to F**: Letter grade for the whole org
- **$150/h**: Stated rate behind every fix estimate

## Why most Salesforce audits end in a spreadsheet nobody acts on

An org that has been live for a few years carries automation nobody remembers building, fields nobody writes to and permission sets that grew one urgent request at a time. Finding that is not the hard part. Turning it into a decision someone with a budget can make is.

- **Findings without evidence.** A list that says "47 unused fields" invites an argument. Without the query, the metadata excerpt or the audit trail entry behind each line, the review stalls on whether the finding is even true.
- **Severity is not effort.** Deactivating a dormant admin is critical and takes five minutes. Untangling three record-triggered Flows on the same object is medium and takes days. A list ranked by severity alone sends the team to the wrong work first.
- **Silence read as health.** Most tools score what they happened to see. If managed package code or the Apex test run could not be read, the report still looks clean, and nobody knows which parts of the org were never examined.
- **No line from finding to fix.** The audit lives in one tool, the estimate in a spreadsheet, the work in Jira and the change in a deploy log. Nobody can say which finding a given deploy actually closed.

## What does a 55-check Salesforce org audit cover?

The audit runs 55 automated checks across 12 sections, every time the org is refreshed and whenever you ask. Automation and Flows are checked for several Flows on the same object and trigger, missing fault paths, DML inside loops, hardcoded record ids and active Process Builder or Workflow Rules. Apex is checked for SOQL and DML in loops, classes without tests, coverage under 75%, empty catch blocks, ancient API versions and oversized classes.

Permissions checks look for guest user object access, Modify All Data outside admin profiles and API access granted too broadly. Live usage checks read login history and opportunity data to find users who have not logged in for 30 or 90 days, users who never logged in at all, elevated login failures and stagnant pipeline stages. Compliance checks map what they find to SOC 2, ISO 27001 and Essential Eight controls.

- Automation and Flows, Apex and code, permissions and security
- Fields and data quality, limits and performance, installed packages
- Change intelligence: production changes made outside the pipeline
- Adoption: MFA enforcement, Security Health Check score, connected app sprawl
- AI readiness: gaps that would block Agentforce

## How is every audit finding backed by evidence?

Every finding opens to the evidence that produced it, in the form that suits the check: the SOQL query and the rows it returned, the metadata XML excerpt, the Apex source lines, a table of permission grants, the Setup Audit Trail entries, the dependency graph references, the org limit usage, or a before and after comparison.

A check only runs when the data it needs was collected. When it was not, the check is reported as skipped rather than passed, and a skipped check can never close an open issue. The assessment states what it could not see, such as managed package source Salesforce hides, so the score is never quietly flattered by what went unexamined.

- Nine evidence types, from SOQL results to audit trail entries
- Skipped checks are named, never counted as passes
- The same issue is tracked from one audit to the next, never reported twice

## How are Salesforce audit findings priced and graded?

Each finding is given an effort band, minutes, hours or days, from what the fix actually involves rather than from its severity, and the effort is priced at a stated blended rate of $150 an hour so nobody mistakes it for a quote. Findings are ranked by severity against effort, so the quick, serious fixes surface first. The assessment also models the annual carrying cost of leaving a finding alone and its three year exposure, which is the argument for doing the work.

Section scores start at 100 and lose points by severity, with a cap so a single recurring problem cannot sink a whole section. The overall score is a weighted mean of the 12 sections, with automation and permissions weighted highest, and it maps to a letter grade: A from 90, B from 80, C from 70, D from 60 and F below. Dismissed findings, where someone has accepted the risk, are left out of the score.

- Effort bands priced in dollars at a rate shown on screen
- Annual carrying cost and three year exposure for the business case
- A letter grade from A to F with a plain sentence beside it
- Severity and effort shown side by side, not merged into one number

## How do audit findings become fixes and planned work?

Select the findings that matter and turn them into a priced remediation plan or statement of work for your team or delivery partner, with each line written as an outcome rather than as a technical check name. The price is remediation only: carrying cost and exposure stay in the business case and never reach the invoice. The same findings can go straight onto a project board as work items.

Or open any finding in the chat and let the AI draft the fix. It starts from the finding's evidence, is validated against your org without changing it, and is saved as a proposal that waits for approval like any other change. When the fix is deployed the finding moves to fix deployed, and the next audit run confirms it: verified fixed if the check no longer fires, regressed if it comes back.

- Statement of work from selected findings, priced from the same effort model
- Findings to work items on a project board in one step
- Fix with AI produces a validated proposal, never a direct change
- 7 lifecycle states, from detected through verified fixed or regressed

## How the org audit works

1. **Connect the org.** Authorise a sandbox or production org with Salesforce OAuth. The first sync reads its metadata, source and recent Setup Audit Trail.
2. **The audit runs.** All 55 checks run against the synced copy after every refresh, or on demand. The audit reads the copy taken at sync, so it never adds load to your org.
3. **Review the findings.** Read the grade, the section scores and each finding with its evidence, effort and cost. Dismiss what you accept and say why.
4. **Turn findings into work.** Build a remediation plan, put findings on a board, or send one to the AI to draft a fix as a proposal.
5. **Share and verify.** Share a read-only report link with stakeholders and withdraw it whenever you want. The next run confirms each fix or flags a regression.

## An audit, with and without SyncOnAI 360

| Without | With SyncOnAI 360 |
|---|---|
| A list of issues in a spreadsheet | Findings with the query, XML or audit trail entry behind each one |
| Ranked by severity alone | Severity against effort, with the quick serious fixes first |
| Unchecked areas reported as healthy | Skipped checks named, and the score says what it could not see |
| Estimates typed up separately | Each finding priced at a stated rate, then a statement of work in one step |
| Fixes made straight in production | AI-drafted fixes validated and waiting for a second admin's approval |
| No way to tell if a fix held | The next run marks each finding verified fixed or regressed |

## Who runs the audit

- **Consultancies.** Run a full, evidenced assessment of a client org in minutes instead of weeks, then turn the findings into a priced statement of work in one step.
- **Salesforce admins.** Know exactly what is wrong in your org, how serious it is and what it would take to fix, with each finding opened to the evidence behind it.
- **Compliance teams.** Start from findings mapped to SOC 2, ISO 27001 and Essential Eight controls, shared as read-only reports that can be withdrawn.
- **Independent consultants.** Bring a structured, repeatable assessment to every client without building one yourself, and show verified fixes after the re-audit.

## Frequently asked questions

### What is a Salesforce org audit?

A Salesforce org audit reviews how an org is built and used: its automation, code, permissions, fields, limits, packages and change history. SyncOnAI 360 runs 55 automated checks for this and records each finding with the evidence behind it, a severity, an effort band and an estimated cost to fix.

### How long does an audit take?

The audit runs against the copy of the org's metadata that SyncOnAI 360 keeps after each sync, so once the first sync has finished the checks themselves run quickly. It runs automatically after every org refresh and can be started by hand at any time.

### Does the audit change anything in my org?

No. The checks read the synced copy of the org and never write to Salesforce. A fix only reaches the org as a proposal that has been validated against it first, and production changes need an approved proposal.

### How is the cost of a finding calculated?

Each finding gets an effort band of minutes, hours or days based on what its fix involves, priced at a blended rate of $150 an hour that is shown on screen. It is an estimate to support a decision, not a quote. The assessment separately models the annual carrying cost and three year exposure of leaving the finding unfixed.

### How is the letter grade worked out?

Each of the 12 sections starts at 100 and loses points by finding severity, with a cap per problem area. The overall score is a weighted mean of the sections, and it maps to A from 90, B from 80, C from 70, D from 60 and F below 60. Findings you dismiss are excluded.

### What happens when the audit cannot read part of the org?

The affected checks are reported as skipped, not passed. A skipped check never closes an open issue, and the assessment states what it could not see, for example managed package source that Salesforce hides or an org with no Apex test run recorded.

### Can I share the audit with stakeholders or a partner?

Yes. Create a read-only link to the report and send it to anyone who needs it, inside or outside your company. You can withdraw the link at any time, and the record that it existed is kept.

### Can findings become a statement of work?

Yes. Select the findings to include and SyncOnAI 360 builds a priced statement of work from the same effort model the audit uses, with each line written as an outcome. Use it to plan internal work or to brief a delivery partner. Only remediation is priced; carrying cost stays in the business case.

### Does the audit map to compliance frameworks?

The compliance view maps relevant findings to SOC 2, ISO 27001 and Essential Eight controls, such as setup audit gaps, guest user exposure and the number of admin users. It supports a compliance conversation; it is not a certification of the org.

### Is the audit included on the free plan?

Every plan includes every feature, the audit among them. Free covers one user and one production org with its sandboxes, on your own AI provider key.
