SyncOnAI360

Use case: access review

How to run a Salesforce permissions review from evidence.

Find who has more access than they need, which users are inactive, where guest users can reach data and which permission sets duplicate each other, then fix it safely.

Workspace security

Settings · Security

  • Configuration onlyMetadata and code. CRM records stay in Salesforce.
  • Isolated per customerEnforced by the database and tested every release.
  • Keys in Google Cloud KMSCredentials encrypted under a per-customer key.
  • Second admin for productionThe author can never approve their own change.
  • Hosted in the United StatesEvery subprocessor listed with its region.

In one paragraph

Running a Salesforce permissions review with SyncOnAI 360 means reading the audit's permission, security and usage findings, each with its evidence, mapping them to SOC 2, ISO 27001 and Essential Eight controls, sharing the result read-only with reviewers, and fixing access through proposals that flag every access change for the approver.

Day inactivity thresholds checked
30/90Day inactivity thresholds checked
Frameworks mapped: SOC 2, ISO 27001, Essential Eight
3Frameworks mapped: SOC 2, ISO 27001, Essential Eight
Access change flagged on its proposal
EveryAccess change flagged on its proposal
Accounts reviewers need to read a report
0Accounts reviewers need to read a report

01The problem

Why Salesforce access reviews are painful

An access review means exporting profiles, permission sets and login history into spreadsheets, then arguing about what each grant means.

  1. 01

    Spreadsheet exports

    Access is reviewed from flattened exports.

  2. 02

    Hidden exposure

    Guest user access and broad API access are easy to miss.

  3. 03

    Stale users

    Inactive accounts keep their access.

  4. 04

    Risky cleanup

    Removing a permission might break someone's job.

02find

What does a Salesforce permissions review check?

Guest user object access, Modify All Data outside admin profiles, API access enabled too broadly, security that leans on profiles, redundant permission sets, users inactive for 30 or 90 days or never logged in, elevated login failures, MFA not enforced, a low Security Health Check score, connected app sprawl and the number of admin users.

  • Elevated and guest access
  • Inactive and never-used accounts
  • MFA, health check and connected apps

Workspace security

Settings · Security

  • Configuration onlyMetadata and code. CRM records stay in Salesforce.
  • Isolated per customerEnforced by the database and tested every release.
  • Keys in Google Cloud KMSCredentials encrypted under a per-customer key.
  • Second admin for productionThe author can never approve their own change.
  • Hosted in the United StatesEvery subprocessor listed with its region.

03evidence

What evidence comes with each finding?

Each finding has its evidence, such as the table of permission grants behind it, a severity and an estimated cost to fix. The permissions and security section is one of the two most heavily weighted in the org's score.

  • Grants behind each finding
  • Severity and cost
  • Weighted heavily in the score

Org Audit

Acme Production · last run 6 minutes ago

Grade C

C

74 / 100

Fair, technical debt accumulating

Automation & Flows

64

Permissions & Security

71

Apex & Code

78

Fields & Data Quality

82

Limits & Performance

91

Change Intelligence

69

55 checks run · 37 open findings · 2 checks skipped, with the reason shown

04map

How do findings map to compliance controls?

The compliance view maps relevant findings to SOC 2, ISO 27001 and Essential Eight controls, giving reviewers a working list. It supports a compliance conversation; it is not a certification of the org.

  • Mapped to three frameworks
  • A working list
  • Not a certification

Org Audit

Acme Production · last run 6 minutes ago

Grade C

C

74 / 100

Fair, technical debt accumulating

Automation & Flows

64

Permissions & Security

71

Apex & Code

78

Fields & Data Quality

82

Limits & Performance

91

Change Intelligence

69

55 checks run · 37 open findings · 2 checks skipped, with the reason shown

05share

How do you share the review with auditors?

Share the audit as a read-only link that opens without an account, expires, and can be withdrawn when the review closes. The record that it was shared is kept.

  • Read-only links
  • No account needed
  • Withdraw when done

Client portal

Share a read-only view

Read-only health summary

Acme Production · Grade B · 82

synconai360.com/share/org/7f3a...

Expires in 14 days. Viewed 3 times.

06fix

How do you fix access safely?

Removing a permission or retiring a duplicate set is a proposal like any other. Its Security and access check names what changes and warns the approver, and production needs a second admin's approval. Every change leaves a receipt with rollback.

  • Access changes flagged
  • Second-admin approval
  • Receipts and rollback

Proposal: Case intake fault handling

Acme Production

Checks passed
  • Validated against the org without changing it
  • No component outside the change is modified
  • Apex tests pass, coverage 81%
  • No freeze window in effect
  • Policy: production requires a second admin

Blast radius

  • 2 Flows read Case.Priority
  • 1 report filters on it
  • Case_Intake_Route assigns from it

Risk: medium

07cadence

How often should you review Salesforce access?

The live checks read user and login history on every audit, so access can be reviewed whenever the audit runs, not only at the annual review. Inactive users and new admin accounts show up as findings as soon as they appear.

Keep each review: review history stores past results, so an auditor can see the state of access at each point and what changed between them.

  • Review on every audit
  • New exposure flagged early
  • Past reviews kept

Org Audit

Acme Production · last run 6 minutes ago

Grade C

C

74 / 100

Fair, technical debt accumulating

Automation & Flows

64

Permissions & Security

71

Apex & Code

78

Fields & Data Quality

82

Limits & Performance

91

Change Intelligence

69

55 checks run · 37 open findings · 2 checks skipped, with the reason shown

08How it works

How to run an access review

Evidence first, then decisions.

  1. 01

    Audit

    Run the audit and open the security findings.

  2. 02

    Review

    Work through elevated access and inactive users.

  3. 03

    Map

    Use the compliance view for reviewers.

  4. 04

    Share

    Send a read-only link; withdraw it later.

  5. 05

    Fix

    Ship access changes as approved proposals.

09Checklist

Access review checklist

  • Run the audit so the live usage checks are current.
  • Review elevated access, starting with Modify All Data outside admins.
  • Check guest user object access and broad API access.
  • List users inactive for 30 or 90 days and those who never logged in.
  • Look for redundant permission sets granting the same thing.
  • Share the results read-only with reviewers and withdraw the link afterwards.
  • Ship access changes as proposals so each is flagged for the approver.

10Before and after

An access review, exported versus evidenced

Without

With SyncOnAI 360

Spreadsheets of exports

Findings with their grants

Guest exposure missed

Guest access checked

Inactive users keep access

30 and 90 day checks

Cleanup in Setup

Approved, reversible changes

12Questions

Frequently asked questions

Yes. Users inactive for 30 or 90 days, and users who never logged in.

Yes. Guest user object access is a dedicated check.

No. Findings are mapped to controls to support the conversation; it is not a certification.

Yes, through a read-only link that can be withdrawn.

No. Removals are proposals you approve.

Yes. The Security and access check warns on every such proposal.

No. It reads metadata, user and login history and the Setup Audit Trail.

Yes. Every plan includes every feature.

Yes. Connected app sprawl is one of the adoption checks.

Yes. MFA that is not enforced is flagged.

Yes. The number of admin users is one of the compliance checks.

Start in 5 minutes. No card required.

Connect your Salesforce org. Run your first health scan. Ask your first question. See what you've been missing.

  • Anthropic
  • OpenAI