# How to audit a Salesforce org, with evidence for every finding.

> Auditing a Salesforce org with SyncOnAI 360 means connecting it and reading an audit of 55 checks across twelve scored sections. Every finding carries the evidence behind it, a severity, an effort band and a cost at a stated rate, and the result can be shared as a read-only report or turned into a priced statement of work.

Source: https://synconai360.com/use-cases/salesforce-org-audit

## Key facts

- **55**: Checks in every audit
- **12**: Sections scored separately
- **$150/h**: Default rate behind each estimate, changeable
- **Every**: Finding with its evidence

## Why most Salesforce audits take weeks and prove little

A manual audit is a consultant clicking through Setup with a checklist. It takes weeks, depends on who did it, and ends in a slide deck whose claims nobody can check.

- **Weeks of clicking.** Every object, Flow, class and permission set is inspected by hand.
- **Opinion, not evidence.** Findings say what someone thought, not what proves it.
- **No price.** Without an effort and cost, findings never become a plan.
- **Out of date at once.** The org changes the week after the audit is delivered.

## What does a Salesforce org audit check?

55 checks in twelve sections, including automation and Flows, permissions and security, Apex and code, fields and data quality, limits and performance, packages, change intelligence and AI readiness. Some checks read the synced metadata; live checks read user and login history and the last thirty days of the Setup Audit Trail.

Each section is scored on its own, so a strong data model does not hide weak security, and the health score reports its confidence and coverage separately.

- Twelve scored sections
- Metadata and live usage checks
- Confidence and coverage stated

## What does each audit finding contain?

The evidence behind it, such as the Flows that share a trigger or the permission grants that create the exposure, a severity, and an effort band of minutes, hours or days priced at a stated rate you can change.

Findings are written in plain language, so a client or a manager can follow them without reading metadata, and every one opens to the evidence for anyone who wants to check.

- Evidence you can open
- Severity and effort
- Cost at a stated rate

## What do you do with the audit results?

Share the audit as a read-only link that expires and can be withdrawn. Turn selected findings into a priced statement of work in one step, or into work items on a project board, carrying their evidence and estimate.

Fix findings through the AI and the builders, ship the fixes as approved proposals, and run the audit again: each fixed finding is marked verified fixed, or regressed if it came back.

- Share read-only
- Statement of work or work items
- Re-audit to verify

## How do you keep the audit current?

The org refreshes every six hours and on demand, and the audit can be run again whenever it is needed. Review history keeps every past review, so scores and findings can be compared over time.

That turns the audit from a one-off document into a running measure of the org.

- Six-hour refresh
- Run again any time
- Every review kept

## How to audit a Salesforce org

1. **Connect.** Authorise the org, or a sandbox copy, with Salesforce OAuth.
2. **Sync.** Metadata and source are read in the background.
3. **Audit.** Run the 55 checks and read the graded sections.
4. **Prioritise.** Sort findings by severity and effort.
5. **Act.** Share, price, plan, fix and re-audit.

## A Salesforce audit, manual versus SyncOnAI 360

| Without | With SyncOnAI 360 |
|---|---|
| Weeks of clicking through Setup | Minutes after the sync completes |
| Findings as opinions | Findings with evidence |
| No effort or cost | Effort and cost at a stated rate |
| A deck that goes stale | Re-audits that verify each fix |

## Before you audit a Salesforce org

- [ ] Decide whether to audit production or a recent sandbox, and get an admin to authorise the connection.
- [ ] Agree who will read the results and who decides what gets fixed.
- [ ] Check the hourly rate used for estimates matches your own, and change it if not.
- [ ] Read the weakest sections first rather than working through findings in order.
- [ ] Open the evidence behind any finding you plan to act on or present.
- [ ] Note which checks were skipped and why, so nobody reads a gap as a pass.
- [ ] Share the result as a read-only link and set a date to run the audit again.

## Who runs an org audit

- **Consultancies.** Open a client relationship with an evidenced assessment and a priced plan.
- **Salesforce admins.** Find out what is wrong in your own org before someone else does.
- **Architects.** Start a review from scored sections and evidence.
- **IT leaders.** Measure the health of every org in the estate the same way.

## Frequently asked questions

### How long does a Salesforce org audit take?

The first sync of a large org takes several minutes in the background; the audit runs on the synced org.

### Does the audit change anything in the org?

No. It reads. Changes only happen through proposals you approve.

### Can we audit a sandbox instead of production?

Yes. Connect a sandbox; live usage checks reflect that sandbox's own users and history.

### Can we change the rate used for costs?

Yes. The default rate is stated and can be changed.

### Can the audit be shared with a client?

Yes, as a read-only link that expires and can be withdrawn.

### Does it read our CRM records?

No. It reads metadata, plus user and login history and the Setup Audit Trail for the live checks.

### Is the audit a certification?

No. Compliance mappings support a conversation with auditors; they do not certify the org.

### Is the audit on the free plan?

Yes. Every plan includes every feature.

### What happens when a check cannot run?

It says it was skipped. A skipped check never closes an open finding, and missing data is never reported as a pass.

### Which areas does the audit cover?

Permissions, fields, Apex, Flows, legacy processes, limits, packages, compliance, adoption and AI readiness, scored in twelve sections.
