Permission & FLS Audit · Sample Workbook

SALESFORCE PERMISSION & FLS AUDIT.

A profile, permission set, and permission set group matrix with FLS per field, per permission set. Surfaces over-privileged access, unassigned permission sets, and user-level risk in one read-only run.

$249Free on-screen summary first
No package installNo Connected AppRead-only
Permission & FLS Audit19 review-ready sheetsKeelCadence_Permission_FLS_Audit_Sample_Report.xlsx
Over-PrivilegedExecutive SummaryFLS MatrixRecommendationsRemediation Tracker
Profile / Perm SetObjectView AllModify AllRisk
Legacy Sales ProfileAnnotated row: Flagged: View All + Modify All on Account granted to a profile assigned to 41 users.AccountYesYesHigh
Marketing UserOpportunityYesNoMedium
Integration PS_v1ContactYesYesHigh
Support Tier 1CaseNoNoLow
Ops Admin CloneAccountYesYesHigh
RevOps PSOpportunityYesNoMedium
Legacy API ProfileLeadYesYesHigh

Flagged: View All + Modify All on Account granted to a profile assigned to 41 users.

67 over-privileged access patterns surfaced
Sample. Demo data.
Download this sample workbook (XLSX) →
Use before:Access reviewProfile cleanupPermission set cleanupOver-permissioned user reviewClient security discovery
What's inside

19 review-ready sheets.

The broadest workbook in the suite. Every sheet has a purpose line, a frozen header, and auto-filter on. The Legend defines every risk rating and flag.

Executive Summary

High-level summary of the permission audit run.

Over-Privileged

Profiles and permission sets with broad object access such as View All and Modify All, with assigned user counts.

Sensitive Exposure

Fields matching sensitive-data patterns and which profiles or permission sets can read them.

FLS Exceptions

Field-level security exceptions requiring review, with severity, read and edit counts, and breadth of scope.

External User Exposure

Object permissions granted to external user types.

Object Gaps

Object-level access gaps flagged for review.

Unassigned Perm Sets

Permission sets currently assigned to nobody.

Profile Consolidation

Overlapping profiles that are candidates to merge.

User Risk Score

Per-user access risk scoring.

Permission Health Score

Composite 0 to 100 permission health score for the org.

Recommendations

Prioritized action items with evidence, effort, and risk.

Remediation Tracker

A pre-populated checklist, one row per finding, with Status and Owner columns to fill in.

Profile Permissions

Object permissions per profile.

Perm Set Permissions

Object permissions per permission set.

FLS Matrix

Field-level security per field, per profile and permission set.

Admin-Only Fields

Fields readable only through admin-level access.

Effective User Access

Combined effective access per user across profiles, permission sets, and permission set group membership, with source attribution for where each grant comes from.

Legend

Definitions for every status band, flag, and risk rating in the workbook.

Plus a branded Cover sheet with the run date and audit scope.

Example outcome

From permission sprawl to a ranked remediation list.

A team preparing an access review ran the audit before changing a single profile. The workbook mapped who can see and edit what, surfaced over-privileged access patterns, and ranked them by risk.

Findings are review candidates. The team worked the Remediation Tracker sheet finding by finding, validating each before making changes.

Run it on your org
Salesforce access governance

Permission sprawl and FLS risk review

A full access map of profiles, permission sets, and FLS, run read-only from the browser with no install.

67
Over-privileged patterns
18 / 100
Permission health baseline
23
Unassigned permission sets
0
Writes to the org
How it works

Run it in 60 seconds.

1

Connect

Open your Salesforce org in the browser. No install, no Connected App.

2

Run the free summary

Read-only checks run in your active session. Findings appear on screen.

3

Review findings

Counts, risks, and flagged items, before any payment.

4

Export the workbook

Pay $249 once and keep the full 19-sheet XLSX workbook.

Common questions

Before you run it.

Can I see a sample report before I buy?+

Yes. A sample workbook with fictitious, anonymized demo data is available for download on this page before you connect an org or purchase.

How long does an audit take?+

Most audits complete in under two minutes. Collection time depends on the size of your org and the number of objects or fields selected.

What if I am not a System Administrator?+

System Administrator profile is recommended for complete results. Lower-permission users may receive partial results, since only objects and fields your profile can read are included in the audit.

Does the audit show access per user?+

Yes. The Effective User Access sheet maps combined access per user across profiles and permission sets. No individual Salesforce record values are exported.

Does it cover Permission Set Groups?+

Yes. Permission Set Group membership and source attribution are included within the permission analysis — reflected in Effective User Access and the underlying access matrices — rather than as a separate worksheet.

Does purchasing the workbook change anything in Salesforce?+

No. The workbook is review-only. KeelCadence diagnostics do not write records, modify metadata, install a package, or create a Connected App.

See who can touch what.

Run the free summary now. No install, no account, no writes to the org. Pay only if the findings earn the workbook.

KeelCadence uses session cookies and Google Analytics 4 for site usage insights. GA4 does not receive Salesforce credentials, Org IDs, Report IDs, or payment data. You can opt out for this browser.