A profile, permission set, and permission set group matrix with FLS per field, per permission set. Surfaces over-privileged access, unassigned permission sets, and user-level risk in one read-only run.
| Profile / Perm Set | Object | View All | Modify All | Risk |
|---|---|---|---|---|
| Legacy Sales ProfileAnnotated row: Flagged: View All + Modify All on Account granted to a profile assigned to 41 users. | Account | Yes | Yes | High |
| Marketing User | Opportunity | Yes | No | Medium |
| Integration PS_v1 | Contact | Yes | Yes | High |
| Support Tier 1 | Case | No | No | Low |
| Ops Admin Clone | Account | Yes | Yes | High |
| RevOps PS | Opportunity | Yes | No | Medium |
| Legacy API Profile | Lead | Yes | Yes | High |
Flagged: View All + Modify All on Account granted to a profile assigned to 41 users.
The broadest workbook in the suite. Every sheet has a purpose line, a frozen header, and auto-filter on. The Legend defines every risk rating and flag.
High-level summary of the permission audit run.
Profiles and permission sets with broad object access such as View All and Modify All, with assigned user counts.
Fields matching sensitive-data patterns and which profiles or permission sets can read them.
Field-level security exceptions requiring review, with severity, read and edit counts, and breadth of scope.
Object permissions granted to external user types.
Object-level access gaps flagged for review.
Permission sets currently assigned to nobody.
Overlapping profiles that are candidates to merge.
Per-user access risk scoring.
Composite 0 to 100 permission health score for the org.
Prioritized action items with evidence, effort, and risk.
A pre-populated checklist, one row per finding, with Status and Owner columns to fill in.
Object permissions per profile.
Object permissions per permission set.
Field-level security per field, per profile and permission set.
Fields readable only through admin-level access.
Combined effective access per user across profiles, permission sets, and permission set group membership, with source attribution for where each grant comes from.
Definitions for every status band, flag, and risk rating in the workbook.
Plus a branded Cover sheet with the run date and audit scope.
A team preparing an access review ran the audit before changing a single profile. The workbook mapped who can see and edit what, surfaced over-privileged access patterns, and ranked them by risk.
Findings are review candidates. The team worked the Remediation Tracker sheet finding by finding, validating each before making changes.
Run it on your orgA full access map of profiles, permission sets, and FLS, run read-only from the browser with no install.
Open your Salesforce org in the browser. No install, no Connected App.
Read-only checks run in your active session. Findings appear on screen.
Counts, risks, and flagged items, before any payment.
Pay $249 once and keep the full 19-sheet XLSX workbook.
Yes. A sample workbook with fictitious, anonymized demo data is available for download on this page before you connect an org or purchase.
Most audits complete in under two minutes. Collection time depends on the size of your org and the number of objects or fields selected.
System Administrator profile is recommended for complete results. Lower-permission users may receive partial results, since only objects and fields your profile can read are included in the audit.
Yes. The Effective User Access sheet maps combined access per user across profiles and permission sets. No individual Salesforce record values are exported.
Yes. Permission Set Group membership and source attribution are included within the permission analysis — reflected in Effective User Access and the underlying access matrices — rather than as a separate worksheet.
No. The workbook is review-only. KeelCadence diagnostics do not write records, modify metadata, install a package, or create a Connected App.
Field metadata, object schema, and usage exposure. All fields, all objects.
$99View sample workbookFlows, Apex classes, Apex triggers, validation rules, and approval processes in one consolidated inventory.
$149View sample workbookSelected-object readiness before imports, bulk updates, UAT, migrations, or test-data setup.
$149View sample workbookDetected references within evaluated coverage for the custom fields on one selected object.
$149View sample workbookRun the free summary now. No install, no account, no writes to the org. Pay only if the findings earn the workbook.
KeelCadence uses session cookies and Google Analytics 4 for site usage insights. GA4 does not receive Salesforce credentials, Org IDs, Report IDs, or payment data. You can opt out for this browser.