User access in Salesforce is the combination of a profile and every permission set assigned to that user. Reviewing one layer without the other gives you an incomplete picture. A structured access review workbook surfaces the full permission structure before any changes are made.
Read-only diagnostics · Review-ready workbooks · No package install · No Connected App
A user's actual Salesforce access is not just what their profile grants. It is their profile permissions plus every permission set they have been assigned — and in most orgs, permission sets accumulate over time without a corresponding cleanup process.
A user who was given a permission set for a project two years ago may still have that access. A user who changed roles may now have permission sets from their previous role still attached. A user may have Modify All Data access through a permission set that was created during a data migration and never deactivated.
A user access review that only checks the profile is checking a fraction of the actual access picture.
Relevant Workbook
The Permission & FLS Audit workbook maps object permissions, field-level security, system permissions, and permission set assignment counts — formatted for structured access review before changing user permissions.
The instinct in a messy org is to start pulling permission sets the moment something looks excessive. That is how access incidents happen. A permission set that looks redundant may be the only thing granting a small team the field access they rely on. An integration user's broad access may be load-bearing for a nightly sync.
Review before removal means documenting the current state, comparing assignments against what each role actually needs, and prioritizing changes by risk — before anyone deactivates a single assignment. The goal of the first pass is a defensible list of review candidates, not a cleanup spree.
Document and compare first. Remove second — deliberately, and with a record of why.
Capture a baseline you can return to. If a change causes a problem, the export below is what lets you see what access looked like before — and restore it deliberately.
KeelCadence Permission & FLS Audit surfaces object permissions, field-level security exposure, and permission set assignments — formatted as a structured XLSX workbook for access review before any permission change.
Opens permissions.keelcadence.com. Best run from desktop, since the diagnostic uses your active Salesforce browser session. On mobile, view the sample workbook or save this page for later.
Read-only · No package install · No Connected App setup · No Salesforce writes
KeelCadence uses session cookies and Google Analytics 4 for site usage insights. GA4 does not receive Salesforce credentials, Org IDs, Report IDs, or payment data. You can opt out for this browser.