# How to run a Salesforce permissions review from evidence.

> Running a Salesforce permissions review with SyncOnAI 360 means reading the audit's permission, security and usage findings, each with its evidence, mapping them to SOC 2, ISO 27001 and Essential Eight controls, sharing the result read-only with reviewers, and fixing access through proposals that flag every access change for the approver.

Source: https://synconai360.com/use-cases/permissions-review

## Key facts

- **30/90**: Day inactivity thresholds checked
- **3**: Frameworks mapped: SOC 2, ISO 27001, Essential Eight
- **Every**: Access change flagged on its proposal
- **0**: Accounts reviewers need to read a report

## Why Salesforce access reviews are painful

An access review means exporting profiles, permission sets and login history into spreadsheets, then arguing about what each grant means.

- **Spreadsheet exports.** Access is reviewed from flattened exports.
- **Hidden exposure.** Guest user access and broad API access are easy to miss.
- **Stale users.** Inactive accounts keep their access.
- **Risky cleanup.** Removing a permission might break someone's job.

## What does a Salesforce permissions review check?

Guest user object access, Modify All Data outside admin profiles, API access enabled too broadly, security that leans on profiles, redundant permission sets, users inactive for 30 or 90 days or never logged in, elevated login failures, MFA not enforced, a low Security Health Check score, connected app sprawl and the number of admin users.

- Elevated and guest access
- Inactive and never-used accounts
- MFA, health check and connected apps

## What evidence comes with each finding?

Each finding has its evidence, such as the table of permission grants behind it, a severity and an estimated cost to fix. The permissions and security section is one of the two most heavily weighted in the org's score.

- Grants behind each finding
- Severity and cost
- Weighted heavily in the score

## How do findings map to compliance controls?

The compliance view maps relevant findings to SOC 2, ISO 27001 and Essential Eight controls, giving reviewers a working list. It supports a compliance conversation; it is not a certification of the org.

- Mapped to three frameworks
- A working list
- Not a certification

## How do you share the review with auditors?

Share the audit as a read-only link that opens without an account, expires, and can be withdrawn when the review closes. The record that it was shared is kept.

- Read-only links
- No account needed
- Withdraw when done

## How do you fix access safely?

Removing a permission or retiring a duplicate set is a proposal like any other. Its Security and access check names what changes and warns the approver, and production needs a second admin's approval. Every change leaves a receipt with rollback.

- Access changes flagged
- Second-admin approval
- Receipts and rollback

## How often should you review Salesforce access?

The live checks read user and login history on every audit, so access can be reviewed whenever the audit runs, not only at the annual review. Inactive users and new admin accounts show up as findings as soon as they appear.

Keep each review: review history stores past results, so an auditor can see the state of access at each point and what changed between them.

- Review on every audit
- New exposure flagged early
- Past reviews kept

## How to run an access review

1. **Audit.** Run the audit and open the security findings.
2. **Review.** Work through elevated access and inactive users.
3. **Map.** Use the compliance view for reviewers.
4. **Share.** Send a read-only link; withdraw it later.
5. **Fix.** Ship access changes as approved proposals.

## An access review, exported versus evidenced

| Without | With SyncOnAI 360 |
|---|---|
| Spreadsheets of exports | Findings with their grants |
| Guest exposure missed | Guest access checked |
| Inactive users keep access | 30 and 90 day checks |
| Cleanup in Setup | Approved, reversible changes |

## Access review checklist

- [ ] Run the audit so the live usage checks are current.
- [ ] Review elevated access, starting with Modify All Data outside admins.
- [ ] Check guest user object access and broad API access.
- [ ] List users inactive for 30 or 90 days and those who never logged in.
- [ ] Look for redundant permission sets granting the same thing.
- [ ] Share the results read-only with reviewers and withdraw the link afterwards.
- [ ] Ship access changes as proposals so each is flagged for the approver.

## Who runs access reviews

- **Security and compliance teams.** Start from evidence mapped to controls.
- **Salesforce admins.** Clean up access without breaking anyone's job.
- **Architects.** Move from profile-heavy security to a cleaner model.

## Frequently asked questions

### Does it find inactive users?

Yes. Users inactive for 30 or 90 days, and users who never logged in.

### Does it check guest user access?

Yes. Guest user object access is a dedicated check.

### Is this a SOC 2 audit?

No. Findings are mapped to controls to support the conversation; it is not a certification.

### Can auditors see the results?

Yes, through a read-only link that can be withdrawn.

### Can it remove permissions automatically?

No. Removals are proposals you approve.

### Will an approver know a change affects access?

Yes. The Security and access check warns on every such proposal.

### Does it read our records?

No. It reads metadata, user and login history and the Setup Audit Trail.

### Is this on every plan?

Yes. Every plan includes every feature.

### Does it check connected apps?

Yes. Connected app sprawl is one of the adoption checks.

### Does it check MFA?

Yes. MFA that is not enforced is flagged.

### Does it check the number of admins?

Yes. The number of admin users is one of the compliance checks.
