[{"data":1,"prerenderedAt":11117},["ShallowReactive",2],{"blog-category-permissions-security-auditability":3},{"category":4,"posts":25,"seo":16},{"_createdAt":5,"_id":6,"_rev":7,"_system":8,"_type":11,"_updatedAt":12,"selectedColor":13,"seo":16,"slug":21,"title":24},"2026-03-23T09:46:15Z","X5t46vdoqNP2mdy9omYjVI","7ua5MtdqXdPDXzyEZJIlwF",{"base":9},{"id":6,"rev":10},"J5j1hv5WW9LqWb2ruucJ0V","category","2026-04-27T17:28:42Z",{"title":14,"value":15},"Blue","#9BD4FF",{"_type":17,"description":18,"shareImage":19,"title":20},"seo","Salesforce security, permissions, and audit guidance. How to lock down access, track changes, and prove compliance without slowing the business down.",null,"Salesforce Permissions, Security & Auditability",{"_type":22,"current":23},"slug","permissions-security-auditability","Security",[26,792,1324,1911,2433,3127,3513,4069,5084,5551,5961,6768,7499,8168,8767,9416,10052,10538],{"_createdAt":27,"_id":28,"_rev":29,"_system":30,"_type":33,"_updatedAt":34,"author":35,"category":92,"featuredImage":98,"modularContent":138,"postSubtitle":280,"postTitle":281,"publishDate":282,"richText":283,"seo":785,"slug":790},"2026-08-05T19:08:40Z","98157cbe-4901-42ac-ab9c-5e94c7883ce5","14hwWf6pHwd5baRRPrGFI3",{"base":31},{"id":28,"rev":32},"C4CeEnkfFkvlfFiLhbApHO","post","2026-08-06T18:40:28Z",{"authorImage":36,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":38,"image":39},"img","Nick Gaudio, Salesforce Expert of 8 Years",{"_type":40,"asset":41},"image",{"_createdAt":42,"_id":43,"_rev":44,"_type":45,"_updatedAt":46,"altText":19,"assetId":47,"description":19,"extension":48,"metadata":49,"mimeType":83,"opt":84,"originalFilename":86,"path":87,"sha1hash":47,"size":88,"title":19,"uploadId":89,"url":90},"2025-08-19T14:06:35Z","image-1642ac567769ad69575ba545e0bb55a9570810e1-491x491-heif","wJMBz141dB0bRw2KkFOfVC","sanity.imageAsset","2025-08-28T19:08:01Z","1642ac567769ad69575ba545e0bb55a9570810e1","heif",{"_type":50,"blurHash":51,"dimensions":52,"hasAlpha":56,"isOpaque":57,"lqip":58,"palette":59},"sanity.imageMetadata","eNJ??L}R1i4:r^-r$dElNFWX0gELnjbIS2o#$#kDS4xDE3Rj%2xtWo",{"_type":53,"aspectRatio":54,"height":55,"width":55},"sanity.imageDimensions",1,491,false,true,"data:image/jpeg;base64,/9j/2wBDAAYEBQYFBAYGBQYHBwYIChAKCgkJChQODwwQFxQYGBcUFhYaHSUfGhsjHBYWICwgIyYnKSopGR8tMC0oMCUoKSj/2wBDAQcHBwoIChMKChMoGhYaKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCj/wAARCAAUABQDASIAAhEBAxEB/8QAGQABAAMBAQAAAAAAAAAAAAAAAAQFBgcB/8QAJhAAAQMEAgEDBQAAAAAAAAAAAQIDBAAFESEGEhMHIlEUMkFCYf/EABUBAQEAAAAAAAAAAAAAAAAAAAUG/8QAHxEBAAIBAwUAAAAAAAAAAAAAAQACEQMFEhMhMUGh/9oADAMBAAIRAxEAPwC19PbPHW/PlXmOhRQcb3gVA5ZabAqS1cLWosuJcCR1OArexitdbZIXCT9HIZUqQgFLgAwayPN1uJvlotr0dt1CCXPKPbg/k0fS9uryz3jVqaZop6nrlrbKsoXo73SpMlYLg8TiOuB+wpVCbpxMNvkm3b8uSs4tAv8AcYyJEZmQoM9OyU5+0/I+Ku+GlzlDLJu77zi21lIWFkEj+mlKI1gGyROipUnR2eNwIrYbaDvU+7a80pSimznzESpif//Z",{"_type":60,"darkMuted":61,"darkVibrant":66,"dominant":69,"lightMuted":70,"lightVibrant":74,"muted":77,"vibrant":80},"sanity.imagePalette",{"_type":62,"background":63,"foreground":64,"population":65,"title":64},"sanity.imagePaletteSwatch","#342119","#fff",6.62,{"_type":62,"background":67,"foreground":64,"population":68,"title":64},"#593529",7.22,{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":71,"foreground":72,"population":73,"title":64},"#babfcb","#000",1.78,{"_type":62,"background":75,"foreground":72,"population":76,"title":72},"#fcb6a0",3.48,{"_type":62,"background":78,"foreground":64,"population":79,"title":64},"#ac6658",1.07,{"_type":62,"background":81,"foreground":64,"population":82,"title":64},"#448ccc",0,"image/heif",{"media":85},{"tags":19},"Nick Gaudio","images/9eu1m6zu/production/1642ac567769ad69575ba545e0bb55a9570810e1-491x491.heif",14480,"ovY23XQPwv0g34MVlgHS2wfeMJpfueBe","https://cdn.sanity.io/images/9eu1m6zu/production/1642ac567769ad69575ba545e0bb55a9570810e1-491x491.heif","Sweep Staff",{"_createdAt":5,"_id":6,"_rev":7,"_system":93,"_type":11,"_updatedAt":12,"selectedColor":95,"seo":96,"slug":97,"title":24},{"base":94},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":99,"image":100},"Finding Your Vulnerabilities Before AI Agents Do",{"_type":40,"asset":101},{"_createdAt":102,"_id":103,"_rev":104,"_type":45,"_updatedAt":102,"assetId":105,"extension":106,"metadata":107,"mimeType":132,"originalFilename":133,"path":134,"sha1hash":105,"size":135,"uploadId":136,"url":137},"2026-08-05T19:13:46Z","image-fb4439abe572d4bc7ab17fe2558c87b187d724f3-1200x630-png","DkG0n4g3BV5AE6ie0Zuemw","fb4439abe572d4bc7ab17fe2558c87b187d724f3","png",{"_type":50,"blurHash":108,"dimensions":109,"hasAlpha":57,"isOpaque":57,"lqip":113,"palette":114,"thumbHash":131},"MAQc;zITV@%g-p?ct7WBRjj[~q-=t7aKIU",{"_type":53,"aspectRatio":110,"height":111,"width":112},1.9047619047619047,630,1200,"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAAsTAAALEwEAmpwYAAABSElEQVR4nJ2SXVOCUBCG+f9/qaz0ptRGModERE2Cc4DDZ+gB7OJtWNSEMXO6eGeHPeyzn4pIv3AqP9mR2v5rpfwG+S9YaQYfAPX3qdqBPJSwxQZuXDSBlcP2M1huSpYFW3j00+4suBKPS6x4CsMOYAfbxptiexk04wOjiQl1YmL8tsJ87cHxszPgEjwqsBI5dLbBnH/CCSVEUh67U9Y8xUCd4a43RKc7wO1DH71HFaPXeQ2u2gq3cCMJL8rBwhyGK6ExiYWfUwJRJU5OgP3RlEC33QFBb+6f0OkNMVR1qn625LB4QkA3yvEucph+ASso6i6owv0MqwqmpkMtv2hLTPQ12eexQVYzLOgLBoun8OISfly3zeMdvMYi90CaSyjBxAYsqNqTtBhHZKTKx4+L2gdeOCflMPTDufwEtLNfd5N0h+1j/kuXgN/QqTwvQDOqjAAAAABJRU5ErkJggg==",{"_type":60,"darkMuted":115,"darkVibrant":118,"dominant":120,"lightMuted":123,"lightVibrant":126,"muted":127,"vibrant":129},{"_type":62,"background":116,"foreground":64,"population":117,"title":64},"#393b44",0.16,{"_type":62,"background":119,"foreground":64,"population":82,"title":64},"#124272",{"_type":62,"background":121,"foreground":72,"population":122,"title":72},"#ecf4fc",70.71,{"_type":62,"background":124,"foreground":72,"population":125,"title":64},"#a1b4cc",0.01,{"_type":62,"background":121,"foreground":72,"population":122,"title":72},{"_type":62,"background":128,"foreground":64,"population":82,"title":64},"#6c848c",{"_type":62,"background":130,"foreground":64,"population":82,"title":64},"#227fdc","uvcFBIByqZiZd3jPeFSfdvZpqA==","image/png","security-blog-header-1200x630.png","images/9eu1m6zu/production/fb4439abe572d4bc7ab17fe2558c87b187d724f3-1200x630.png",118886,"47784e1d1efaceeb004fea41835c0760ecd2a234","https://cdn.sanity.io/images/9eu1m6zu/production/fb4439abe572d4bc7ab17fe2558c87b187d724f3-1200x630.png",[139,273],{"_key":140,"_type":141,"expandToggle":57,"items":142,"removeMargins":56,"showModule":57,"useFullWidth":56},"275cb126ba9f","faqCollapsibleList",[143,190,220,250],{"_key":144,"_type":145,"ctaOne":146,"superSimpleRichTextWithLists":169,"title":189},"1a44c84f2987","item",{"_type":147,"buttonSize":148,"buttonStyle":149,"external":150,"linkType":152,"media":153,"openModal":159,"openModal2":163,"openModal3":166},"link","regular","primary",{"_type":151,"blank":57,"noOpener":57,"noReferrer":57},"externalLink","none",{"_type":154,"mediaType":155,"useCodeToEmbed":56,"vid":156},"media","video",{"_type":157,"addPlaceholderImage":56,"config":158,"transparent":56},"vid",{"autoplay":56,"controls":56,"loop":56,"muted":56},{"_type":160,"hubspotForm":161},"openModal",{"_type":162,"showModule":57},"hubspotForm",{"_type":164,"hubspotForm":165},"openModal2",{"_type":162,"showModule":57},{"_type":167,"hubspotForm":168},"openModal3",{"_type":162,"showModule":57},[170,181],{"_key":171,"_type":172,"children":173,"markDefs":179,"style":180},"cae1609876a7","block",[174],{"_key":175,"_type":176,"marks":177,"text":178},"1ebc535e1b0c","span",[],"Permission drift is the gradual accumulation of access that no longer maps to a current need… temporary elevations that were never revoked, inherited permission sets, and over-provisioned rights spread across profiles and users. It builds quietly until no one can confidently say who can do what.",[],"normal",{"_key":182,"_type":172,"children":183,"markDefs":188,"style":180},"3a1a07d34867",[184],{"_key":185,"_type":176,"marks":186,"text":187},"2eb171f4184d",[],"",[],"What is permission drift in Salesforce? ",{"_key":191,"_type":145,"ctaOne":192,"superSimpleRichTextWithLists":203,"title":219},"a5b2d41c984c",{"_type":147,"buttonSize":148,"buttonStyle":149,"external":193,"linkType":152,"media":194,"openModal":197,"openModal2":199,"openModal3":201},{"_type":151,"blank":57,"noOpener":57,"noReferrer":57},{"_type":154,"mediaType":155,"useCodeToEmbed":56,"vid":195},{"_type":157,"addPlaceholderImage":56,"config":196,"transparent":56},{"autoplay":56,"controls":56,"loop":56,"muted":56},{"_type":160,"hubspotForm":198},{"_type":162,"showModule":57},{"_type":164,"hubspotForm":200},{"_type":162,"showModule":57},{"_type":167,"hubspotForm":202},{"_type":162,"showModule":57},[204,212],{"_key":205,"_type":172,"children":206,"markDefs":211,"style":180},"810baf90887f",[207],{"_key":208,"_type":176,"marks":209,"text":210},"b8f5723efa3b",[],"It is indeed real, and it's important to know how it is distinct from shadow IT. Shadow IT was mostly about where data lived. Shadow AI adds three harder questions about every agent: what it can access, what permissions it actually holds, and what it can do… including creating, modifying, or deleting metadata, not just records.",[],{"_key":213,"_type":172,"children":214,"markDefs":218,"style":180},"4c26b2b5516e",[215],{"_key":216,"_type":176,"marks":217,"text":187},"9d90a53fe518",[],[],"Is shadow AI a real security risk or just a buzzword?",{"_key":221,"_type":145,"ctaOne":222,"superSimpleRichTextWithLists":233,"title":249},"8f3f39b38950",{"_type":147,"buttonSize":148,"buttonStyle":149,"external":223,"linkType":152,"media":224,"openModal":227,"openModal2":229,"openModal3":231},{"_type":151,"blank":57,"noOpener":57,"noReferrer":57},{"_type":154,"mediaType":155,"useCodeToEmbed":56,"vid":225},{"_type":157,"addPlaceholderImage":56,"config":226,"transparent":56},{"autoplay":56,"controls":56,"loop":56,"muted":56},{"_type":160,"hubspotForm":228},{"_type":162,"showModule":57},{"_type":164,"hubspotForm":230},{"_type":162,"showModule":57},{"_type":167,"hubspotForm":232},{"_type":162,"showModule":57},[234,242],{"_key":235,"_type":172,"children":236,"markDefs":241,"style":180},"6db05f1c50e3",[237],{"_key":238,"_type":176,"marks":239,"text":240},"e4627faa1f0e",[],"Agents operate through the access model of the org and the identities they're granted. Where drift has left over-provisioned or orphaned permissions in place, an agent inherits those very same rights and can act on them automatically, without the human judgment that once kept unused access dormant.",[],{"_key":243,"_type":172,"children":244,"markDefs":248,"style":180},"7c45002c8070",[245],{"_key":246,"_type":176,"marks":247,"text":187},"e48c9b042e82",[],[],"How do AI agents inherit permissions? ",{"_key":251,"_type":145,"ctaOne":252,"superSimpleRichTextWithLists":263,"title":272},"e76e0e14376c",{"_type":147,"buttonSize":148,"buttonStyle":149,"external":253,"linkType":152,"media":254,"openModal":257,"openModal2":259,"openModal3":261},{"_type":151,"blank":57,"noOpener":57,"noReferrer":57},{"_type":154,"mediaType":155,"useCodeToEmbed":56,"vid":255},{"_type":157,"addPlaceholderImage":56,"config":256,"transparent":56},{"autoplay":56,"controls":56,"loop":56,"muted":56},{"_type":160,"hubspotForm":258},{"_type":162,"showModule":57},{"_type":164,"hubspotForm":260},{"_type":162,"showModule":57},{"_type":167,"hubspotForm":262},{"_type":162,"showModule":57},[264],{"_key":265,"_type":172,"children":266,"markDefs":271,"style":180},"15a8dccf0ae8",[267],{"_key":268,"_type":176,"marks":269,"text":270},"e68894374c80",[],"Start from live metadata rather than a static export, surface over-provisioned and sensitive access (Modify All Data, View All Data, Delete rights), tie each finding to a remediation, and re-run the check continuously so new drift is caught early — rather than treating the audit as a one-time event.",[],"How do you audit Salesforce permissions before deploying agents? ",{"_key":274,"_type":275,"cols":276,"filterByCategory":277,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":279},"efbe44dad62a50a7c8d44a47fd7d44b4","listedPosts",2,{"_ref":6,"_type":278},"reference","Read more","Permission drift used to be housekeeping debt. Agentforce just turned it into a live security exposure.","Find Your Vulnerabilities Before AI Agents Do","2026-08-05",[284,293,313,331,339,346,354,377,384,407,414,426,432,440,447,455,469,476,488,496,504,512,537,545,553,558,582,590,598,606,614,622,630,638,650,670,682,694,745,753,777],{"_key":285,"_type":172,"children":286,"markDefs":291,"style":292},"7b628d5b0158",[287],{"_key":288,"_type":176,"marks":289,"text":290},"34e07581ddc3",[],"TL;DR",[],"h2",{"_key":294,"_type":172,"children":295,"level":54,"listItem":309,"markDefs":310,"style":180},"fd3a37b1a8c1",[296,300,305],{"_key":297,"_type":176,"marks":298,"text":299},"948447d3204c",[],"Security teams can see only about a third of their real AI footprint (",{"_key":301,"_type":176,"marks":302,"text":304},"d6ae437ef3f0",[303],"a3bc4af62155","Snyk",{"_key":306,"_type":176,"marks":307,"text":308},"f175bc5ab077",[],")  but in the field it's often closer to 10–15%. Agents operate inside that blind spot.","bullet",[311],{"_key":303,"_type":151,"blank":57,"href":312,"noOpener":57,"noReferrer":57,"url":312},"https://snyk.io/news/snyk-2026-state-of-agentic-ai-adoption-volume-ii/",{"_key":314,"_type":172,"children":315,"level":54,"listItem":309,"markDefs":325,"style":180},"7ed72b96d0ac",[316,321],{"_key":317,"_type":176,"marks":318,"text":320},"1f82c30f7849",[319],"fd6a37745723","Permission drift",{"_key":322,"_type":176,"marks":323,"text":324},"cd50e4665951",[]," (access that outlives its utility or reason) was tolerable when humans held the access. Autonomous agents inherit it and act on it at machine speed, including changing metadata, not just data.",[326],{"_key":319,"_ref":327,"_type":328,"linkType":33,"slug":329},"027213c8-53da-4cbc-b8da-5809a6255362","internalLink",{"_type":22,"current":330},"permission-drift-the-access-map-your-agent-is-working-from-doesn-t-exist",{"_key":332,"_type":172,"children":333,"level":54,"listItem":309,"markDefs":338,"style":180},"3cda7ce5ccd2",[334],{"_key":335,"_type":176,"marks":336,"text":337},"3908555c1306",[],"The fix requires continuous visibility into who (and what) can do what… so you find the exposure before your agents exercise it.",[],{"_key":340,"_type":172,"children":341,"markDefs":345,"style":180},"eb17f571b10a",[342],{"_key":343,"_type":176,"marks":344,"text":187},"bf5df13a10f7",[],[],{"_key":347,"_type":172,"children":348,"markDefs":353,"style":180},"bc19f76aabbd",[349],{"_key":350,"_type":176,"marks":351,"text":352},"c9b26109ad29",[],"*****",[],{"_key":355,"_type":172,"children":356,"markDefs":375,"style":180},"1c89bdad87e2",[357,362,366,371],{"_key":358,"_type":176,"marks":359,"text":361},"edb3eca31ef0",[360],"15d32af5cb9e","New research from Snyk",{"_key":363,"_type":176,"marks":364,"text":365},"c94f1f9e3ad8",[]," this month put a number on something security teams have felt for a while: they have visibility into roughly ",{"_key":367,"_type":176,"marks":368,"text":370},"7c2f62295b18",[369],"strong","33% of their organization's actual AI footprint",{"_key":372,"_type":176,"marks":373,"text":374},"d5469097400e",[],". ",[376],{"_key":360,"_type":151,"blank":57,"href":312,"noOpener":57,"noReferrer":57,"url":312},{"_key":378,"_type":172,"children":379,"markDefs":383,"style":180},"b9b09b7ff00b",[380],{"_key":372,"_type":176,"marks":381,"text":382},[],"Over the same six months, agentic architecture adoption bounced from 28% to 33%. ",[],{"_key":385,"_type":172,"children":386,"markDefs":406,"style":180},"1d2388458137",[387,390,395,399,403],{"_key":372,"_type":176,"marks":388,"text":389},[],"Smash those two lines together and the problem states itself: adoption is ",{"_key":391,"_type":176,"marks":392,"text":394},"69b2673385c9",[393],"em","accelerating",{"_key":396,"_type":176,"marks":397,"text":398},"8b899c3464f0",[]," and visibility ",{"_key":400,"_type":176,"marks":401,"text":402},"48cde0150508",[393],"isn't",{"_key":404,"_type":176,"marks":405,"text":374},"0205d0bfe165",[],[],{"_key":408,"_type":172,"children":409,"markDefs":413,"style":180},"4a013a7cf69b",[410],{"_key":404,"_type":176,"marks":411,"text":412},[],"Teams are, in a very real way, outrunning their headlights.",[],{"_key":415,"_type":172,"children":416,"markDefs":425,"style":180},"29fa72172da7",[417,421],{"_key":418,"_type":176,"marks":419,"text":420},"1736211e4fad",[],"And, in fact,",{"_key":422,"_type":176,"marks":423,"text":424},"eade20feeae8",[393]," 33% may be the generous version.",[],{"_key":427,"_type":428,"markDefs":19,"name":429,"position":430,"text":431},"35978ce34f2a","blockQuote","Daniel Barckley","Sweep (Former architect at Salesforce)","\"Even that number is optimistic. In the field it was closer to 10–15%… and only at public companies with reporting standards forcing the question. When security teams finally started asking, most were so new to it they couldn't separate metadata and structure from data and records. That distinction is the whole ballgame.\" ",{"_key":433,"_type":172,"children":434,"markDefs":439,"style":180},"213c321942f2",[435],{"_key":436,"_type":176,"marks":437,"text":438},"f81becd43da4",[],"It's the whole ballgame, indeed…. because agents don't just read. ",[],{"_key":441,"_type":172,"children":442,"markDefs":446,"style":180},"13c6565b9c27",[443],{"_key":436,"_type":176,"marks":444,"text":445},[],"They act.",[],{"_key":448,"_type":172,"children":449,"markDefs":454,"style":292},"41a68f495c43",[450],{"_key":451,"_type":176,"marks":452,"text":453},"cb8c50d2a84f",[],"What is permission drift?",[],{"_key":456,"_type":172,"children":457,"markDefs":466,"style":180},"37c665121010",[458,462],{"_key":459,"_type":176,"marks":460,"text":320},"87010ca4e752",[461],"19c8103617ba",{"_key":463,"_type":176,"marks":464,"text":465},"78d0715d5ca9",[]," is what happens when access outlives its reason. A temporary elevation granted \"just for this sprint\" never gets pulled back. A role built for one job eventually morphs into a template for five others. A departed employee's permission set lingers, then gets inherited by the next hire. ",[467],{"_key":461,"_ref":327,"_type":328,"linkType":33,"slug":468},{"_type":22,"current":330},{"_key":470,"_type":172,"children":471,"markDefs":475,"style":180},"fca086326566",[472],{"_key":463,"_type":176,"marks":473,"text":474},[],"Over-provisioned access (Modify All Data, View All Data, Delete rights) spreads because revoking it is riskier than leaving it alone.",[],{"_key":477,"_type":172,"children":478,"markDefs":487,"style":180},"1c5f8bbdd28b",[479,483],{"_key":480,"_type":176,"marks":481,"text":482},"1ed13a2eeecd",[],"In a vacuum, each of these is ordinary org housekeeping: the kind of debt every decent Salesforce admin on earth knows and most access reviews miss. Permission drift is a slow, invisible, gradual building-up of that debt across profiles, permission sets, and users until nobody can answer ",{"_key":484,"_type":176,"marks":485,"text":486},"2291aa27b0fe",[393],"who can do what, and why.",[],{"_key":489,"_type":172,"children":490,"markDefs":495,"style":292},"79cd7d5f457a",[491],{"_key":492,"_type":176,"marks":493,"text":494},"eba01798a49b",[],"How AI agents inherit permissions they were never scoped for",[],{"_key":497,"_type":172,"children":498,"markDefs":503,"style":180},"6964c36ec0d3",[499],{"_key":500,"_type":176,"marks":501,"text":502},"36d5e22f05ef",[],"For years, drift was a governance annoyance. The reason it's now a security headline is simple: you can point an autonomous agent at the same org.",[],{"_key":505,"_type":172,"children":506,"markDefs":511,"style":180},"b8d970a4b63d",[507],{"_key":508,"_type":176,"marks":509,"text":510},"90c33cc64202",[],"When you do, the agent inherits every permission humans never scoped — and it exercises them at machine speed, without the hesitation a person brings to \"wait, should I actually be able to do this?\" An agent doesn't know that the Delete right it inherited was a workaround from 2023. It just has it, and it will use it if a task calls for it.",[],{"_key":513,"_type":172,"children":514,"markDefs":532,"style":180},"8e56cc95845f",[515,519,523,528],{"_key":516,"_type":176,"marks":517,"text":518},"2309fd5036cf",[393],"\"An agent just inherited a departed user's permissions — what happens next?\"",{"_key":520,"_type":176,"marks":521,"text":522},"65817c45cf2f",[]," is no longer a thought experiment. In a ",{"_key":524,"_type":176,"marks":525,"text":527},"eedc4e0dce47",[526],"a2549fd092fe","production Agentforce org",{"_key":529,"_type":176,"marks":530,"text":531},"c3341a8f563f",[],", it's a Tuesday.",[533],{"_key":526,"_ref":534,"_type":328,"linkType":33,"slug":535},"44baa147-b9c0-4f0b-84ce-7e0cb3b22973",{"_type":22,"current":536},"the-5-salesforce-errors-that-break-agentforce",{"_key":538,"_type":172,"children":539,"markDefs":544,"style":292},"af5cbdd953dd",[540],{"_key":541,"_type":176,"marks":542,"text":543},"b78ea8a71f32",[],"Why shadow AI is worse than shadow IT",[],{"_key":546,"_type":172,"children":547,"markDefs":552,"style":180},"9015b9d25e59",[548],{"_key":549,"_type":176,"marks":550,"text":551},"b7bc8620bfe0",[],"The reflex is to file this under shadow IT and reach for the familiar playbook. That underestimates it.",[],{"_key":554,"_type":428,"markDefs":19,"name":555,"position":556,"text":557},"e4839fe32f2a","Eli Kaufman,","RevOps at Sweep","\"Shadow AI is worse. With shadow IT, the risk was mostly about location... where is our data being stored, shared, accessed? Contain the data, contain the problem. Shadow AI breaks that model. Now you have to understand three things about every agent: what it can access, what permissions it actually holds, and what it can do... create, modify, delete. And not just records. Metadata too.\" ",{"_key":559,"_type":172,"children":560,"markDefs":581,"style":180},"a2190c994073",[561,565,569,573,577],{"_key":562,"_type":176,"marks":563,"text":564},"e71618721865",[],"That last point is the escalation. The risk isn't only what an agent can ",{"_key":566,"_type":176,"marks":567,"text":568},"0468b5b51c62",[393],"read",{"_key":570,"_type":176,"marks":571,"text":572},"8c6babaa4359",[]," — it's what it can ",{"_key":574,"_type":176,"marks":575,"text":576},"91953b18f395",[393],"change",{"_key":578,"_type":176,"marks":579,"text":580},"495ca53915e5",[],": fields, flows, permission sets, the scaffolding of the org itself. A misplaced file is a data problem you can contain. An agent quietly rewriting the structure of your org is a different category of threat, and it's the one the shadow-IT playbook has no page for.",[],{"_key":583,"_type":172,"children":584,"markDefs":589,"style":292},"93431b72304d",[585],{"_key":586,"_type":176,"marks":587,"text":588},"b1505e3f6edf",[],"Permission drift and Agentforce: why this is a now problem",[],{"_key":591,"_type":172,"children":592,"markDefs":597,"style":180},"c0f8fe2559ec",[593],{"_key":594,"_type":176,"marks":595,"text":596},"eab6d067d172",[],"Agentforce is live in production orgs today. That's what moves permission inheritance from an abstract \"AI risk\" slide into a concrete exposure you already have. The agents are already operating inside the access you've accumulated over years — you just haven't had a way to see the shape of it.",[],{"_key":599,"_type":172,"children":600,"markDefs":605,"style":180},"9b0dbdeed017",[601],{"_key":602,"_type":176,"marks":603,"text":604},"0a97ac9d89a6",[],"It also lands at exactly the moment security and compliance functions are being asked about agents in earnest. SOX and SOC 2 reviewers who never touched Salesforce internals are suddenly asking what an agent can reach and what it can change. \"We ran a cleanup last year\" is not an answer to a control that has to hold continuously.",[],{"_key":607,"_type":172,"children":608,"markDefs":613,"style":180},"d6bacaaf26aa",[609],{"_key":610,"_type":176,"marks":611,"text":612},"d9b84df69334",[],"You can't govern what you can't see. And by the numbers, most teams can't see the two-thirds that actually breaks things.",[],{"_key":615,"_type":172,"children":616,"markDefs":621,"style":292},"e9ec9ee87e98",[617],{"_key":618,"_type":176,"marks":619,"text":620},"b1f82300ef95",[],"How to find and fix permission drift",[],{"_key":623,"_type":172,"children":624,"markDefs":629,"style":180},"6a89fe7aa532",[625],{"_key":626,"_type":176,"marks":627,"text":628},"55ed3d4ad00f",[],"Here's the trap: treat this as a one-time audit, sweep the org, declare victory. Drift doesn't work that way. Access keeps accumulating the moment the audit ends, so a point-in-time cleanup is stale before the quarter closes. The durable posture is continuous visibility and remediation — seeing access as it changes, not photographing it once.",[],{"_key":631,"_type":172,"children":632,"markDefs":637,"style":180},"e36c41ca64c9",[633],{"_key":634,"_type":176,"marks":635,"text":636},"8d759c13e256",[],"A practical version of that motion looks like this:",[],{"_key":639,"_type":172,"children":640,"level":54,"listItem":309,"markDefs":649,"style":180},"8627c90654f9",[641,645],{"_key":642,"_type":176,"marks":643,"text":644},"70aa67aa1fa7",[369],"Inventory the real access, not the intended access.",{"_key":646,"_type":176,"marks":647,"text":648},"91f4193a8779",[]," Start from live metadata — actual profiles, permission sets, and assignments — not last quarter's export or the org chart.",[],{"_key":651,"_type":172,"children":652,"level":54,"listItem":309,"markDefs":669,"style":180},"b427e071c2b2",[653,657,661,665],{"_key":654,"_type":176,"marks":655,"text":656},"9df6a1bea107",[369],"Surface the over-provisioning that matters.",{"_key":658,"_type":176,"marks":659,"text":660},"71947e02f510",[]," Flag who holds Modify All Data, View All Data, Delete rights, and sensitive-object access, and trace ",{"_key":662,"_type":176,"marks":663,"text":664},"10f1483645b8",[393],"why",{"_key":666,"_type":176,"marks":667,"text":668},"b05debfd4925",[]," each path exists.",[],{"_key":671,"_type":172,"children":672,"level":54,"listItem":309,"markDefs":681,"style":180},"edaf04569272",[673,677],{"_key":674,"_type":176,"marks":675,"text":676},"6de3cda95205",[369],"Tie every finding to a fix.",{"_key":678,"_type":176,"marks":679,"text":680},"87e97e245bf5",[]," A finding without a remediation path is just anxiety. Each exposure should come with the change that closes it.",[],{"_key":683,"_type":172,"children":684,"level":54,"listItem":309,"markDefs":693,"style":180},"a616978e4a59",[685,689],{"_key":686,"_type":176,"marks":687,"text":688},"a8c441f5f911",[369],"Make it continuous.",{"_key":690,"_type":176,"marks":691,"text":692},"ad24eff232d3",[]," Re-run it on a cadence — or on change — so drift is caught while it's small.",[],{"_key":695,"_type":172,"children":696,"markDefs":735,"style":180},"d062395eb981",[697,701,705,709,714,718,722,726,731],{"_key":698,"_type":176,"marks":699,"text":700},"830365d244ad",[],"This is where Sweep fits, and it's worth being precise about how: Sweep isn't a security product. It's the live context layer that makes these questions answerable in the first place. The ",{"_key":702,"_type":176,"marks":703,"text":704},"a64b769a737f",[369],"Permissions Agent",{"_key":706,"_type":176,"marks":707,"text":708},"11a67ccedfc3",[]," ",{"_key":710,"_type":176,"marks":711,"text":713},"899609d8a0db",[712],"de58ae30a7a2","gives admins, security, and compliance teams a conversational way to interrogate Salesforce access ",{"_key":715,"_type":176,"marks":716,"text":717},"6842e07be87b",[],"— profiles, permission sets, user access, licenses, and sensitive permissions — and surfaces where over-provisioning creates risk, why an access path exists, and where it no longer should. It reads from live metadata rather than a point-in-time export, and it returns audit-ready answers instead of another spreadsheet to reconcile. With ",{"_key":719,"_type":176,"marks":720,"text":721},"d7bcafc18c48",[369],"Playbooks",{"_key":723,"_type":176,"marks":724,"text":725},"97a2deeafd2e",[],", that whole investigation collapses into ",{"_key":727,"_type":176,"marks":728,"text":730},"e824547b4563",[729],"15672bbe5340","a single prompted motion",{"_key":732,"_type":176,"marks":733,"text":734},"d11f7391e30f",[]," you can run continuously, not only once a quarter.",[736,741],{"_key":712,"_ref":737,"_type":328,"linkType":738,"slug":739},"54e5317b-8d6a-4a9f-943e-d2538eeea973","page",{"_type":22,"current":740},"permissions-agent",{"_key":729,"_ref":742,"_type":328,"linkType":738,"slug":743},"d85e39d0-f984-464f-a8ce-c6ab51635da4",{"_type":22,"current":744},"playbooks",{"_key":746,"_type":172,"children":747,"markDefs":752,"style":292},"6a8f682305e2",[748],{"_key":749,"_type":176,"marks":750,"text":751},"57450e3f90c8",[],"From one-time cleanup to continuous visibility",[],{"_key":754,"_type":172,"children":755,"markDefs":776,"style":180},"28b5681979ff",[756,760,764,768,772],{"_key":757,"_type":176,"marks":758,"text":759},"c52269b0e973",[],"The shift is simple to say and hard to do without the right layer: stop trying to clean the org up ",{"_key":761,"_type":176,"marks":762,"text":763},"b5ed5489cdba",[393],"before",{"_key":765,"_type":176,"marks":766,"text":767},"90caea50ae43",[]," the agents arrive, and start keeping it visible ",{"_key":769,"_type":176,"marks":770,"text":771},"127e1184bf4c",[393],"while",{"_key":773,"_type":176,"marks":774,"text":775},"d3277aeddb09",[]," they work.",[],{"_key":778,"_type":172,"children":779,"markDefs":784,"style":180},"aec7a53131b6",[780],{"_key":781,"_type":176,"marks":782,"text":783},"b46adf0c9f04",[],"Permission drift is measurable. The teams who come out ahead over the next twelve months are the ones who make measuring it continuous… and who find their vulnerabilities before their agents do.",[],{"_type":17,"description":786,"shareImage":787,"title":789},"Permission drift lets AI agents inherit Salesforce access no one scoped. Here's why shadow AI is worse than shadow IT, and how to fix it before your agents behave unexpectedly.",{"_type":40,"asset":788},{"_ref":103,"_type":278},"Permission Drift: The Hidden Agentforce Security Risk",{"_type":22,"current":791},"find-your-vulnerabilities-before-ai-agents-do",{"_createdAt":793,"_id":794,"_rev":795,"_system":796,"_type":33,"_updatedAt":799,"author":800,"category":816,"featuredImage":822,"modularContent":858,"postTitle":861,"publishDate":862,"richText":863,"seo":1317,"slug":1322},"2026-07-20T16:47:21Z","52a45032-2b44-46d1-b93f-bd28624daf8d","C6EIdMWSvxTrb2zI1LU2Fl",{"base":797},{"id":794,"rev":798},"95PjqnUfTyT675cI59na0Q","2026-07-31T10:31:27Z",{"authorImage":801,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":38,"image":802},{"_type":40,"asset":803},{"_createdAt":42,"_id":43,"_rev":44,"_type":45,"_updatedAt":46,"altText":19,"assetId":47,"description":19,"extension":48,"metadata":804,"mimeType":83,"opt":814,"originalFilename":86,"path":87,"sha1hash":47,"size":88,"title":19,"uploadId":89,"url":90},{"_type":50,"blurHash":51,"dimensions":805,"hasAlpha":56,"isOpaque":57,"lqip":58,"palette":806},{"_type":53,"aspectRatio":54,"height":55,"width":55},{"_type":60,"darkMuted":807,"darkVibrant":808,"dominant":809,"lightMuted":810,"lightVibrant":811,"muted":812,"vibrant":813},{"_type":62,"background":63,"foreground":64,"population":65,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":71,"foreground":72,"population":73,"title":64},{"_type":62,"background":75,"foreground":72,"population":76,"title":72},{"_type":62,"background":78,"foreground":64,"population":79,"title":64},{"_type":62,"background":81,"foreground":64,"population":82,"title":64},{"media":815},{"tags":19},{"_createdAt":5,"_id":6,"_rev":7,"_system":817,"_type":11,"_updatedAt":12,"selectedColor":819,"seo":820,"slug":821,"title":24},{"base":818},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":823,"image":824},"salesforce admin security",{"_type":40,"asset":825},{"_createdAt":826,"_id":827,"_rev":828,"_type":45,"_updatedAt":826,"assetId":829,"extension":106,"metadata":830,"mimeType":132,"originalFilename":853,"path":854,"sha1hash":829,"size":855,"uploadId":856,"url":857},"2026-07-20T16:49:57Z","image-b58bb7a02342be04cf42e65283a2560db9669aef-1200x630-png","gFmkCs3yKzVLOIaRVRXonc","b58bb7a02342be04cf42e65283a2560db9669aef",{"_type":50,"blurHash":831,"dimensions":832,"hasAlpha":57,"isOpaque":57,"lqip":833,"palette":834,"thumbHash":852},"M6A2Q|-:R=NkaxkcWYjqj=fR9SIcs$xSj[",{"_type":53,"aspectRatio":110,"height":111,"width":112},"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAAsTAAALEwEAmpwYAAAA3ElEQVR4nM2ST2vCQBBH8xE1pGIT1JPtqdVlT0k1atNSbE1J9COKiAcPGv+A6D7ZqlBQNIIHD4/f7DA8ZmGMjAu3xLh/YdYF09uR1bh79u9DP7XQegOnBcVgRyFQFN7VXxYDRelD15BvpBMbOR+ev0F0QfR0rpBxgownyGiKjGeIaEb5a4FV21wWPtSh3IZqDK+R4uV3iQhHyLCP6AyodIZUfoY8fY7J1VaXhaYHeku7BY9N/bU1tj/H8ROcxhRbp5+Qry8wvRQbZs4OqH/c5Gyukx0J9bmcqq8RbgFirGepDGsjLgAAAABJRU5ErkJggg==",{"_type":60,"darkMuted":835,"darkVibrant":837,"dominant":839,"lightMuted":842,"lightVibrant":845,"muted":848,"vibrant":851},{"_type":62,"background":836,"foreground":64,"population":82,"title":64},"#548c6c",{"_type":62,"background":838,"foreground":64,"population":82,"title":64},"#022082",{"_type":62,"background":840,"foreground":64,"population":841,"title":64},"#547cfc",78.14,{"_type":62,"background":843,"foreground":72,"population":844,"title":64},"#b9a5c7",0.06,{"_type":62,"background":846,"foreground":64,"population":847,"title":64},"#5474fb",3.04,{"_type":62,"background":849,"foreground":64,"population":850,"title":64},"#6178af",0.41,{"_type":62,"background":840,"foreground":64,"population":841,"title":64},"ZrMBDIB9dmd3d4gwmJlcdsBlBw==","salesforce-blog-header-1200x630.png","images/9eu1m6zu/production/b58bb7a02342be04cf42e65283a2560db9669aef-1200x630.png",66764,"5162f9a339b87920c21705a07f4a055033a99b55","https://cdn.sanity.io/images/9eu1m6zu/production/b58bb7a02342be04cf42e65283a2560db9669aef-1200x630.png",[859],{"_key":860,"_type":275,"cols":276,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":279},"9e3f78102f5bd8349c919ef0e525f9ee","The Security-Minded Admin's Missing Layer","2026-07-20",[864,871,890,898,905,912,921,929,951,967,988,995,1002,1017,1025,1033,1041,1061,1080,1088,1096,1103,1124,1132,1140,1164,1172,1180,1188,1209,1217,1224,1245,1253,1261,1282,1290,1298,1310],{"_key":865,"_type":172,"children":866,"markDefs":870,"style":292},"66c43f13ec69",[867],{"_key":868,"_type":176,"marks":869,"text":861},"77ccc4db62da",[],[],{"_key":872,"_type":172,"children":873,"markDefs":887,"style":180},"1080223d8844",[874,878,883],{"_key":875,"_type":176,"marks":876,"text":877},"8e57d6655325",[],"Salesforce's new ",{"_key":879,"_type":176,"marks":880,"text":882},"a2686200453b",[393,881],"a90f4bfe014d","Next-Gen Admin Security Guide",{"_key":884,"_type":176,"marks":885,"text":886},"a4e430751203",[]," makes an admission most vendor content avoids, that is admins typically don't report to the CISO, most never came up through security, and the org's security belongs to them anyway.",[888],{"_key":881,"_type":151,"blank":57,"href":889,"noOpener":57,"noReferrer":57,"url":889},"https://www.salesforce.com/platform/resources/next-gen-admin-security-guide/",{"_key":891,"_type":172,"children":892,"markDefs":897,"style":180},"ed9b1c9d6f06",[893],{"_key":894,"_type":176,"marks":895,"text":896},"c8221babe52c",[],"The guide treats this as the reason admins need more support, which is more than fair. It's also the best argument in the doc for reading the rest of it closely.",[],{"_key":899,"_type":172,"children":900,"markDefs":904,"style":180},"3e2a811d5e29",[901],{"_key":894,"_type":176,"marks":902,"text":903},[],"A person holding that kind of responsibility without the reporting line deserves to know exactly what the recommended tools will and won't see. The four pillars the guide proposes are the right four. ",[],{"_key":906,"_type":172,"children":907,"markDefs":911,"style":180},"32def842b7db",[908],{"_key":894,"_type":176,"marks":909,"text":910},[],"The practices under them are sound. Each one of them stops in the same place.",[],{"_key":913,"_type":172,"children":914,"markDefs":919,"style":920},"e267b6027c09",[915],{"_key":916,"_type":176,"marks":917,"text":918},"e0004347dc5d",[],"The pillars are right",[],"h3",{"_key":922,"_type":172,"children":923,"markDefs":928,"style":180},"5e19885ead76",[924],{"_key":925,"_type":176,"marks":926,"text":927},"c82ba15d601c",[],"The guide organizes the job into four commitments: ",[],{"_key":930,"_type":172,"children":931,"level":54,"listItem":945,"markDefs":946,"style":180},"b3538cd6b068",[932,936,941],{"_key":933,"_type":176,"marks":934,"text":935},"aad8385eca24",[],"V",{"_key":937,"_type":176,"marks":938,"text":940},"6c627eeea268",[939],"4c0e6a55ee50","isibility",{"_key":942,"_type":176,"marks":943,"text":944},"3b8ce4cebcaf",[]," and awareness","number",[947],{"_key":939,"_ref":948,"_type":328,"linkType":738,"slug":949},"1c4b3b71-7528-4fc6-a221-16c014d38604",{"_type":22,"current":950},"salesforce-documentation",{"_key":952,"_type":172,"children":953,"level":54,"listItem":945,"markDefs":962,"style":180},"a4734c750161",[954,957],{"_key":942,"_type":176,"marks":955,"text":956},[],"Proactive ",{"_key":958,"_type":176,"marks":959,"text":961},"f8aa9a38ff23",[960],"4f04e190d8a6","monitoring",[963],{"_key":960,"_ref":964,"_type":328,"linkType":738,"slug":965},"b020c314-ced7-447a-a936-6fca530cc867",{"_type":22,"current":966},"monitoring-agent",{"_key":968,"_type":172,"children":969,"level":54,"listItem":945,"markDefs":983,"style":180},"686b4403022d",[970,974,979],{"_key":971,"_type":176,"marks":972,"text":973},"a2e969c43cb6",[],"S",{"_key":975,"_type":176,"marks":976,"text":978},"6cf778d1272d",[977],"5a448e804820","ecurity",{"_key":980,"_type":176,"marks":981,"text":982},"6728f30a05d9",[]," and resilience",[984],{"_key":977,"_ref":985,"_type":328,"linkType":33,"slug":986},"ab7410bc-e2d9-43e8-919b-9f22c15dc36d",{"_type":22,"current":987},"security-benchmark-for-salesforce",{"_key":989,"_type":172,"children":990,"level":54,"listItem":945,"markDefs":994,"style":180},"ec0912097f9e",[991],{"_key":980,"_type":176,"marks":992,"text":993},[],"User education",[],{"_key":996,"_type":172,"children":997,"level":54,"listItem":945,"markDefs":1001,"style":180},"9fef4dc29c56",[998],{"_key":980,"_type":176,"marks":999,"text":1000},[],"Advocacy",[],{"_key":1003,"_type":172,"children":1004,"markDefs":1016,"style":180},"ac961a670f0d",[1005,1008,1012],{"_key":980,"_type":176,"marks":1006,"text":1007},[],"Nobody can really argue with that list. It also maps Salesforce security as ",{"_key":1009,"_type":176,"marks":1010,"text":1011},"fcb0d8b03ff8",[369],"shared responsibility across three layers",{"_key":1013,"_type":176,"marks":1014,"text":1015},"3de6dee2fbce",[]," (foundationals Salesforce manages, configurables admins control, enhanceables you can buy) and is pretty explicit that the middle layer, the one admins own, is where security-mindedness lives.",[],{"_key":1018,"_type":172,"children":1019,"markDefs":1024,"style":180},"aaa56310d2bd",[1020],{"_key":1021,"_type":176,"marks":1022,"text":1023},"0dcbe0980aee",[],"A close reading starts with what the guide thinks an org is.",[],{"_key":1026,"_type":172,"children":1027,"markDefs":1032,"style":920},"f7589c7d9410",[1028],{"_key":1029,"_type":176,"marks":1030,"text":1031},"1fe6c674ea79",[],"Pillar 1: Visibility stops at the record",[],{"_key":1034,"_type":172,"children":1035,"markDefs":1040,"style":180},"abb27e4ffa03",[1036],{"_key":1037,"_type":176,"marks":1038,"text":1039},"d506f9220c39",[],"Pillar 1 opens with, in my opinion, is the best line in the document: \"you can't protect what you don't understand.” It then, unfortunately, defines understanding narrowly. ",[],{"_key":1042,"_type":172,"children":1043,"markDefs":1056,"style":180},"d2d31635f6e3",[1044,1047,1052],{"_key":1037,"_type":176,"marks":1045,"text":1046},[],"The recommended practice is a data ",{"_key":1048,"_type":176,"marks":1049,"text":1051},"a87cad8245d1",[1050],"1bebae47a894","audit",{"_key":1053,"_type":176,"marks":1054,"text":1055},"1f7061b10f14",[]," followed by a classification pass. Find the sensitive fields, tag them by compliance category, set field-level security. The org, in this telling, is a container of records.",[1057],{"_key":1050,"_ref":1058,"_type":328,"linkType":33,"slug":1059},"13b74dba-c9c4-4b73-9812-5456cdfd7f63",{"_type":22,"current":1060},"how-to-establish-audit-ready-change-governance-in-salesforce",{"_key":1062,"_type":172,"children":1063,"markDefs":1077,"style":180},"24ae8a9e0cad",[1064,1068,1073],{"_key":1065,"_type":176,"marks":1066,"text":1067},"b48ea36dc811",[],"An org is also a configuration. Fields sit inside objects that automations write to, flows branch on, integrations sync, and ",{"_key":1069,"_type":176,"marks":1070,"text":1072},"94477eb38093",[1071],"40cc5de07365","permission",{"_key":1074,"_type":176,"marks":1075,"text":1076},"5b5a0c3f2e70",[]," structures expose. When something leaks, the path runs through that graph: a flow nobody documented, touching a field somebody just reclassified. The guide's version of visibility can tell you a field is PII. It cannot tell you what else touches it.",[1078],{"_key":1071,"_ref":327,"_type":328,"linkType":33,"slug":1079},{"_type":22,"current":330},{"_key":1081,"_type":172,"children":1082,"markDefs":1087,"style":920},"a408bbff2039",[1083],{"_key":1084,"_type":176,"marks":1085,"text":1086},"1697d157e52f",[],"Pillar 2: Monitoring looks backward",[],{"_key":1089,"_type":172,"children":1090,"markDefs":1095,"style":180},"bea9c1fd7231",[1091],{"_key":1092,"_type":176,"marks":1093,"text":1094},"5e6c4c04ea9a",[],"Pillar 2 is where the guide's own evidence undercuts its tooling. ",[],{"_key":1097,"_type":172,"children":1098,"markDefs":1102,"style":180},"95f2b7041e2b",[1099],{"_key":1092,"_type":176,"marks":1100,"text":1101},[],"It notes that human error (for example accidental deletion, or misconfiguration) has historically driven most data loss in Salesforce environments. Then the recommended tools are almost entirely behavioral and retrospective. Setup Audit Trail tells you who changed a setting and when, after they've changed it. Event Monitoring watches logins, exports, API calls.",[],{"_key":1104,"_type":172,"children":1105,"markDefs":1119,"style":180},"8eb88a00bbac",[1106,1110,1115],{"_key":1107,"_type":176,"marks":1108,"text":1109},"4b84ca9095c7",[],"Those are good tools for catching a compromised credential. Misconfiguration is a different kind of problem. It's structural  (a report type exposing fields it shouldn't, a permission set granting more than anyone remembers deciding) and it doesn't announce itself in an event log. It sits  until something finds it: an audit, an ",{"_key":1111,"_type":176,"marks":1112,"text":1114},"fd8cb963f26b",[1113],"b95da655632a","agent with broad permissions",{"_key":1116,"_type":176,"marks":1117,"text":1118},"eaccd9407aaa",[],", an attacker.",[1120],{"_key":1113,"_ref":1121,"_type":328,"linkType":33,"slug":1122},"944d255a-74a7-442a-b3b3-cbacee598e4f",{"_type":22,"current":1123},"salesforce-permission-sets-explained-a-complete-guide",{"_key":1125,"_type":172,"children":1126,"markDefs":1131,"style":180},"8a23361bf5b7",[1127],{"_key":1128,"_type":176,"marks":1129,"text":1130},"833ebb8358d3",[],"The gap in this pillar is the moment before the change. Nothing in the guide shows an admin what a modification will touch before they save it. Proactive monitoring, as described here, is reactive monitoring with good response times.",[],{"_key":1133,"_type":172,"children":1134,"markDefs":1139,"style":920},"f072ebe589ed",[1135],{"_key":1136,"_type":176,"marks":1137,"text":1138},"f86095b7ca96",[],"Pillar 3: Least privilege drifts",[],{"_key":1141,"_type":172,"children":1142,"markDefs":1163,"style":180},"95152a83f4d8",[1143,1147,1151,1155,1159],{"_key":1144,"_type":176,"marks":1145,"text":1146},"374c453d8eff",[],"Pillar 3 gets the principle right, and the warning against blanket profile permissions is advice every org should already follow. The hard part though is that least privilege is a ",{"_key":1148,"_type":176,"marks":1149,"text":1150},"2d2e1214c702",[393],"state",{"_key":1152,"_type":176,"marks":1153,"text":1154},"15c2468ef394",[],", and orgs are ",{"_key":1156,"_type":176,"marks":1157,"text":1158},"4bf4ffecb8e2",[393],"processes",{"_key":1160,"_type":176,"marks":1161,"text":1162},"1f58f4b54e61",[],". Permission sets accrete. Groups get cloned for a project and outlive it. A permission granted for a 2023 migration is still there, and nobody currently at the company knows why.",[],{"_key":1165,"_type":172,"children":1166,"markDefs":1171,"style":180},"b229894d4ca0",[1167],{"_key":1168,"_type":176,"marks":1169,"text":1170},"7329f304925d",[],"The guide's answer is monitoring permissions from a single view, which surfaces totals without the history or dependency context that would let an admin safely subtract. Its own illustrative dashboard shows an org with 240 users holding View All Data and 229 holding Modify All Data, presented as metrics to watch. A benchmark would call that a finding.",[],{"_key":1173,"_type":172,"children":1174,"markDefs":1179,"style":180},"88a8583027e4",[1175],{"_key":1176,"_type":176,"marks":1177,"text":1178},"13c5787baf13",[],"Backup, the other half of the pillar, has the same shape. Backup & Recover restores records after corruption. Restoring the org's structure to a known-good state is a different operation, and the guide doesn't have a word for it.",[],{"_key":1181,"_type":172,"children":1182,"markDefs":1187,"style":920},"936de8117752",[1183],{"_key":1184,"_type":176,"marks":1185,"text":1186},"949c0dbf3f0f",[],"Agents get watched, never readied",[],{"_key":1189,"_type":172,"children":1190,"markDefs":1204,"style":180},"15adc818f613",[1191,1196,1200],{"_key":1192,"_type":176,"marks":1193,"text":1195},"0d70b3f4f40b",[1194,369],"aa9c296ed510","Agentforce",{"_key":1197,"_type":176,"marks":1198,"text":1199},"b48693101b51",[369]," appears twice in the guide,",{"_key":1201,"_type":176,"marks":1202,"text":1203},"30177c7e18b0",[]," both times in the same role — anomaly detection inside Security Center, triaging suspicious behavior into investigations. Agents as security cameras.",[1205],{"_key":1194,"_ref":1206,"_type":328,"linkType":33,"slug":1207},"d5921d0e-86fe-4b7c-a213-d9cacc9f15de",{"_type":22,"current":1208},"the-agentforce-metadata-readiness-checklist",{"_key":1210,"_type":172,"children":1211,"markDefs":1216,"style":180},"124fbd5a73f1",[1212],{"_key":1213,"_type":176,"marks":1214,"text":1215},"e3650121e508",[],"The harder subject never comes up: the condition of the org those agents will operate in. ",[],{"_key":1218,"_type":172,"children":1219,"markDefs":1223,"style":180},"b094444e8207",[1220],{"_key":1213,"_type":176,"marks":1221,"text":1222},[369],"An agent acts through metadata. ",[],{"_key":1225,"_type":172,"children":1226,"markDefs":1240,"style":180},"7dd688df6906",[1227,1231,1236],{"_key":1228,"_type":176,"marks":1229,"text":1230},"3c45dc01cbb2",[],"Its ",{"_key":1232,"_type":176,"marks":1233,"text":1235},"de43e99c365b",[1234],"9b5a928b328a","context",{"_key":1237,"_type":176,"marks":1238,"text":1239},"da4eca30a55a",[]," is the schema and permission model it inherits, and its blast radius is whatever the automation layer allows. This is where the security conversation and the AI conversation turn out to be the same conversation. The complexity the guide treats as a management burden… the layered automation, the years of accumulated configuration… is exactly what gives agents their context. An org that understands its own structure can hand agents that context deliberately. An org that doesn't is letting agents loose in a structure nobody has read.",[1241],{"_key":1234,"_ref":1242,"_type":328,"linkType":33,"slug":1243},"035dd89f-52bc-49f4-a9a9-dfcd8cf37e8d",{"_type":22,"current":1244},"south-park-ai-and-sickofancy-why-ai-without-context-turns-into-chaos",{"_key":1246,"_type":172,"children":1247,"markDefs":1252,"style":920},"dd063e5e3e05",[1248],{"_key":1249,"_type":176,"marks":1250,"text":1251},"512338e827ba",[],"The benchmark the guide almost asks for",[],{"_key":1254,"_type":172,"children":1255,"markDefs":1260,"style":180},"f99379e48603",[1256],{"_key":1257,"_type":176,"marks":1258,"text":1259},"b1cd207b77cf",[],"Security Health Check is the most honest tool in the holw lineup, and the guide returns to it in three of the four pillars. It scores your settings against a baseline and tells you where you deviate. That's a benchmark… for settings. Session timeouts, password policies, login ranges. It doesn't read metadata, so the configuration layer every earlier pillar kept bumping into sits outside its scope.",[],{"_key":1262,"_type":172,"children":1263,"markDefs":1277,"style":180},"1ae79e92991a",[1264,1268,1273],{"_key":1265,"_type":176,"marks":1266,"text":1267},"22e3f617eab3",[],"That's the extension the Security Benchmark for Salesforce makes. It applies the logic Health Check already taught admins to trust… measure the org against a standard, get prioritized gaps back… one layer down, to how the org is actually built and how access actually resolves. Run Health Check weekly, as the guide says. Then take the ",{"_key":1269,"_type":176,"marks":1270,"text":1272},"2f405e59d53c",[1271],"960de326980c","structural",{"_key":1274,"_type":176,"marks":1275,"text":1276},"7d7bac319f0d",[]," questions somewhere that can read them.",[1278],{"_key":1271,"_ref":1279,"_type":328,"linkType":33,"slug":1280},"8ea0bb03-2f1d-4c55-bfaf-e4eba534635a",{"_type":22,"current":1281},"structural-context-the-next-ai-moat",{"_key":1283,"_type":172,"children":1284,"markDefs":1289,"style":920},"13d61f7be96b",[1285],{"_key":1286,"_type":176,"marks":1287,"text":1288},"719ed87bd76e",[],"Pillar 4: The advocacy problem is an evidence problem",[],{"_key":1291,"_type":172,"children":1292,"markDefs":1297,"style":180},"087e5f616b13",[1293],{"_key":1294,"_type":176,"marks":1295,"text":1296},"0e1333ebf004",[],"Pillar 4 asks admins to become advocates and build the business case, meet stakeholders, frame security in the language of corporate risk. The guide is probably right in that this is part of the whole job now. It just doesn't arm anyone for it. An admin who doesn't report to the CISO needs an artifact a CISO already respects, and a benchmark score with prioritized findings is that artifact. It converts \"I'm worried about our permission sprawl\" into a score and a remediation order.",[],{"_key":1299,"_type":172,"children":1300,"markDefs":1309,"style":180},"ad148edf91bc",[1301,1305],{"_key":1302,"_type":176,"marks":1303,"text":1304},"d2bfef64f693",[],"The security-minded admin this guide describes is real, and worth becoming. ",{"_key":1306,"_type":176,"marks":1307,"text":1308},"382429439705",[369],"The four pillars hold. ",[],{"_key":1311,"_type":172,"children":1312,"markDefs":1316,"style":180},"80f77f43e4b4",[1313],{"_key":1302,"_type":176,"marks":1314,"text":1315},[],"They just stop at the record layer, and the job doesn't.",[],{"_type":17,"description":1318,"shareImage":1319,"title":1321},"Salesforce security guides cover visibility, monitoring, and least privilege but stop at the record. The missing layer is the configuration your agents inherit.",{"_type":40,"asset":1320},{"_ref":827,"_type":278},"Salesforce Admin Security: The Missing Configuration Layer",{"_type":22,"current":1323},"the-security-minded-admin-s-missing-layer",{"_createdAt":1325,"_id":1326,"_rev":1327,"_system":1328,"_type":33,"_updatedAt":1331,"author":1332,"category":1349,"featuredImage":1355,"modularContent":1387,"postTitle":1391,"publishDate":1392,"richText":1393,"seo":1904,"slug":1909},"2026-07-15T16:28:58Z","981a1ef4-146c-4ee9-88d7-b4c6728e4d4a","ijuJ7N1wW29sfBYN29nqnL",{"base":1329},{"id":1326,"rev":1330},"0uL4pHBl0d25jRyoAmP1cp","2026-07-27T14:46:16Z",{"authorImage":1333,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":1334,"image":1335},"The Security Sync Survival Kit for Salesforce Admins",{"_type":40,"asset":1336},{"_createdAt":42,"_id":43,"_rev":44,"_type":45,"_updatedAt":46,"altText":19,"assetId":47,"description":19,"extension":48,"metadata":1337,"mimeType":83,"opt":1347,"originalFilename":86,"path":87,"sha1hash":47,"size":88,"title":19,"uploadId":89,"url":90},{"_type":50,"blurHash":51,"dimensions":1338,"hasAlpha":56,"isOpaque":57,"lqip":58,"palette":1339},{"_type":53,"aspectRatio":54,"height":55,"width":55},{"_type":60,"darkMuted":1340,"darkVibrant":1341,"dominant":1342,"lightMuted":1343,"lightVibrant":1344,"muted":1345,"vibrant":1346},{"_type":62,"background":63,"foreground":64,"population":65,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":71,"foreground":72,"population":73,"title":64},{"_type":62,"background":75,"foreground":72,"population":76,"title":72},{"_type":62,"background":78,"foreground":64,"population":79,"title":64},{"_type":62,"background":81,"foreground":64,"population":82,"title":64},{"media":1348},{"tags":19},{"_createdAt":5,"_id":6,"_rev":7,"_system":1350,"_type":11,"_updatedAt":12,"selectedColor":1352,"seo":1353,"slug":1354,"title":24},{"base":1351},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":1334,"image":1356},{"_type":40,"asset":1357},{"_createdAt":1358,"_id":1359,"_rev":1360,"_type":45,"_updatedAt":1358,"assetId":1361,"extension":106,"metadata":1362,"mimeType":132,"originalFilename":853,"path":1383,"sha1hash":1361,"size":1384,"uploadId":1385,"url":1386},"2026-07-17T16:40:32Z","image-7f472427f3266dd94b0b699848895832dfd48edf-1200x630-png","gciGOBqA3OpEJg4kabMJHW","7f472427f3266dd94b0b699848895832dfd48edf",{"_type":50,"blurHash":1363,"dimensions":1364,"hasAlpha":57,"isOpaque":57,"lqip":1365,"palette":1366},"M14xb@_29bIrofNLR*oIoJa|004o?F%0WB",{"_type":53,"aspectRatio":110,"height":111,"width":112},"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAAsTAAALEwEAmpwYAAABAUlEQVR4nJ1SWW6DMBT0KVKWgHGJDYSlUZo2CMwaSO9/oqkwjaCtiEg+RuPxs0fPz0O0jYU59Bdb4e/+WpClwrOmZBK/DfQnjclwwdAoDM1RfHuycWNVG9cTrEWQrcHg8RBhcMDef0PgxfBFrDjwEvgiUnpgT0Tgrg/LZMsdMipw/sxxab/QtVd0dYW+kbg2Bbq6QC0ztEWGrsrRFBk+ju9glC+Ogjg2x+mYopQtKlmiyU/oiwS9TNDmCcpzhDqNcckTVGmMQ+jD3t7p0NQpBlOXeXCZwI69QjCqwB0Kl1LsHArORqbmzwwfjY32L0arf3n94YeDPY/EGJV5JCZ9z/AbSfIpuKzXV2oAAAAASUVORK5CYII=",{"_type":60,"darkMuted":1367,"darkVibrant":1369,"dominant":1372,"lightMuted":1375,"lightVibrant":1376,"muted":1379,"vibrant":1381},{"_type":62,"background":1368,"foreground":64,"population":82,"title":64},"#542c4c",{"_type":62,"background":1370,"foreground":64,"population":1371,"title":64},"#1c105e",0.02,{"_type":62,"background":1373,"foreground":72,"population":1374,"title":72},"#d0c9b2",0.1,{"_type":62,"background":1373,"foreground":72,"population":1374,"title":72},{"_type":62,"background":1377,"foreground":72,"population":1378,"title":72},"#e6e06f",0.04,{"_type":62,"background":1380,"foreground":64,"population":125,"title":64},"#786e9a",{"_type":62,"background":1382,"foreground":72,"population":1371,"title":64},"#d8d247","images/9eu1m6zu/production/7f472427f3266dd94b0b699848895832dfd48edf-1200x630.png",75523,"c6a1b01020b99384339b6c621c1da2ee015ae5c7","https://cdn.sanity.io/images/9eu1m6zu/production/7f472427f3266dd94b0b699848895832dfd48edf-1200x630.png",[1388],{"_key":1389,"_type":275,"cols":276,"filterByCategory":1390,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":279},"30d6a9c6beac163e2e5da975063c90e9",{"_ref":6,"_type":278},"Salesforce Security Review Checklist for Admins (Free Template)","2026-07-17",[1394,1401,1408,1416,1424,1431,1439,1446,1467,1475,1505,1513,1521,1528,1535,1542,1549,1556,1564,1572,1580,1588,1595,1611,1626,1641,1663,1677,1692,1700,1708,1749,1757,1765,1773,1781,1789,1797,1805,1813,1821,1829,1850,1871,1890],{"_key":1395,"_type":172,"children":1396,"markDefs":1400,"style":180},"3e5e6d15c9ca",[1397],{"_key":1398,"_type":176,"marks":1399,"text":290},"b807a52c7a2d",[],[],{"_key":1402,"_type":172,"children":1403,"level":54,"listItem":309,"markDefs":1407,"style":180},"d8f81e77cda3",[1404],{"_key":1398,"_type":176,"marks":1405,"text":1406},[],"Salesforce security reviews go poorly when infosec lacks platform context and admins spend every meeting translating the org from scratch.",[],{"_key":1409,"_type":172,"children":1410,"level":54,"listItem":309,"markDefs":1415,"style":180},"fb55ffdb9a50",[1411],{"_key":1412,"_type":176,"marks":1413,"text":1414},"c3b16895761f",[],"A single, honest security baseline (including connected apps, permissions, integrations, AI agents, and known issues) turns the meeting from interrogation into review.",[],{"_key":1417,"_type":172,"children":1418,"level":54,"listItem":309,"markDefs":1423,"style":180},"493feba4c1c1",[1419],{"_key":1420,"_type":176,"marks":1421,"text":1422},"eddbc0a1deab",[],"The problem is keeping that map current: static documents go stale fast, while continuous metadata visibility keeps security aligned with what is actually happening in the org.",[],{"_key":1425,"_type":172,"children":1426,"markDefs":1430,"style":180},"5d90bf268875",[1427],{"_key":1428,"_type":176,"marks":1429,"text":352},"cd1268af3edc",[],[],{"_key":1432,"_type":172,"children":1433,"markDefs":1438,"style":180},"1aad46c80873",[1434],{"_key":1435,"_type":176,"marks":1436,"text":1437},"aada7f345342",[],"There's a meeting invite sitting in your inbox right now, or at least… there will be soon. ",[],{"_key":1440,"_type":172,"children":1441,"markDefs":1445,"style":180},"6c185f9090c8",[1442],{"_key":1435,"_type":176,"marks":1443,"text":1444},[],"It's from someone on the security team you've spoken to maybe four times in three years. The subject line says something like \"Salesforce Security Review — Weekly\" the word \"Weekly\" looking you dead in the eyes. Grief.",[],{"_key":1447,"_type":172,"children":1448,"markDefs":1462,"style":180},"8607b171120b",[1449,1453,1458],{"_key":1450,"_type":176,"marks":1451,"text":1452},"1e715b079326",[],"Something triggered the email. An incident review, an audit finding, a vendor report full of red boxes, or the general drumbeat of ",{"_key":1454,"_type":176,"marks":1455,"text":1457},"c9cd9997a8b6",[1456],"8147f6f9ba57","Salesforce security coverage",{"_key":1459,"_type":176,"marks":1460,"text":1461},"4056a8f73256",[]," over the past eighteen months. Salesforce itself spent this spring converting security recommendations into enforced requirements with hard deadlines, and every enforcement email that landed in your CISO's inbox made your org more interesting to people who had never once asked about it. The agent era finished the job. The moment AI started reading and writing inside your CRM, your org stopped being a sales tool in security's eyes and became an attack surface.",[1463],{"_key":1456,"_ref":1464,"_type":328,"linkType":738,"slug":1465},"2a1df450-8934-4857-bfc2-06681f2fb181",{"_type":22,"current":1466},"security-compliance-governance",{"_key":1468,"_type":172,"children":1469,"markDefs":1474,"style":180},"4996c95ba7e1",[1470],{"_key":1471,"_type":176,"marks":1472,"text":1473},"d3785c454684",[],"So the sync is happening. The question is whether you walk in as the subject of the meeting or the person running it.",[],{"_key":1476,"_type":172,"children":1477,"markDefs":1500,"style":180},"a1ca37c49b7d",[1478,1482,1487,1491,1496],{"_key":1479,"_type":176,"marks":1480,"text":1481},"c579f1ddc93c",[],"We built a template for exactly this situation, a one-document org baseline that becomes the standing agenda. ",{"_key":1483,"_type":176,"marks":1484,"text":1486},"c482618c41b3",[369,1485],"63da15110138","Download the Security Sync Survival Kit in Google Doc form here.",{"_key":1488,"_type":176,"marks":1489,"text":1490},"380766fcd85b",[]," Or, use our new ",{"_key":1492,"_type":176,"marks":1493,"text":1495},"786d5b087136",[1494],"c1786576ae7d","handy local app.",{"_key":1497,"_type":176,"marks":1498,"text":1499},"9d9bdb14ac32",[]," The rest of this piece is about why it works and how to use it.",[1501,1503],{"_key":1485,"_type":151,"blank":57,"href":1502,"noOpener":57,"noReferrer":57,"url":1502},"https://docs.google.com/document/d/1nVs3R6cS90ZpDGO1bSSE-15kI7QcO3FidQdRb8ZHcl0/edit?tab=t.0",{"_key":1494,"_type":151,"blank":57,"href":1504,"noOpener":57,"noReferrer":57,"url":1504},"https://sf-security-prep-kit.lovable.app/",{"_key":1506,"_type":172,"children":1507,"markDefs":1512,"style":920},"12617ba12d24",[1508],{"_key":1509,"_type":176,"marks":1510,"text":1511},"2b7df0de73fe",[],"Why these meetings go badly",[],{"_key":1514,"_type":172,"children":1515,"markDefs":1520,"style":180},"20db141b5b94",[1516],{"_key":1517,"_type":176,"marks":1518,"text":1519},"6583e078bb3a",[],"Ask admins who've lived through a standing infosec sync and you’ll hear the same tales. ",[],{"_key":1522,"_type":172,"children":1523,"level":54,"listItem":309,"markDefs":1527,"style":180},"b94d0dd704a3",[1524],{"_key":1517,"_type":176,"marks":1525,"text":1526},[],"The security team doesn't know the platform. ",[],{"_key":1529,"_type":172,"children":1530,"level":54,"listItem":309,"markDefs":1534,"style":180},"c1afa2a0f761",[1531],{"_key":1517,"_type":176,"marks":1532,"text":1533},[],"They don't know a profile from a role or a permission set from a sharing rule.",[],{"_key":1536,"_type":172,"children":1537,"level":54,"listItem":309,"markDefs":1541,"style":180},"9f288a36e2ef",[1538],{"_key":1517,"_type":176,"marks":1539,"text":1540},[],"They ask about a field they saw in a screenshot. ",[],{"_key":1543,"_type":172,"children":1544,"level":54,"listItem":309,"markDefs":1548,"style":180},"f02a758dc0bc",[1545],{"_key":1517,"_type":176,"marks":1546,"text":1547},[],"They flag a standard object as a critical finding. ",[],{"_key":1550,"_type":172,"children":1551,"markDefs":1555,"style":180},"adba72f8d563",[1552],{"_key":1517,"_type":176,"marks":1553,"text":1554},[],"Half of every session gets burned explaining Salesforce's access model from scratch, and the other half gets burned on one-off questions that generate action items nobody scoped.",[],{"_key":1557,"_type":172,"children":1558,"markDefs":1563,"style":180},"2c5741c7b6c8",[1559],{"_key":1560,"_type":176,"marks":1561,"text":1562},"1ebf051d3dec",[],"To their credit, Salesforce is a strange place from the outside, and the people responsible for securing it at most companies have never administered it. They secure networks, endpoints, and identity providers. Then someone hands them a CRM with fifteen years of accumulated customization, a few hundred integration touchpoints, and now agents acting inside it, and asks them to assess the risk.",[],{"_key":1565,"_type":172,"children":1566,"markDefs":1571,"style":180},"7f2b8a71dbe9",[1567],{"_key":1568,"_type":176,"marks":1569,"text":1570},"70b9e44fde02",[],"They can't. Not alone. Which is the part most admins miss: the knowledge gap that makes these meetings miserable is also what makes you the most important person in the room. You are the only one who can translate the org into risk language. The survival kit is how you do it once, in writing, instead of forty times out loud.",[],{"_key":1573,"_type":172,"children":1574,"markDefs":1579,"style":920},"82321c7ea356",[1575],{"_key":1576,"_type":176,"marks":1577,"text":1578},"549427a3020a",[],"One checklist seven sections, zero surprises",[],{"_key":1581,"_type":172,"children":1582,"markDefs":1587,"style":180},"82a38054f5c3",[1583],{"_key":1584,"_type":176,"marks":1585,"text":1586},"f085378d2b78",[],"Admins who've made these syncs work, we’ve found, all converge on the same move. Before the first meeting, they build a single point of reference: a map of everything in the org that security actually cares about, and they bring it unprompted. ",[],{"_key":1589,"_type":172,"children":1590,"markDefs":1594,"style":180},"355b399bbaa3",[1591],{"_key":1584,"_type":176,"marks":1592,"text":1593},[],"Done right, that doc stops being a handout and becomes your standing agenda. The random screenshot questions dry up because there's a baseline to point to. The meeting shifts from discovery to review.",[],{"_key":1596,"_type":172,"children":1597,"markDefs":1610,"style":180},"c1f735bca695",[1598,1602,1606],{"_key":1599,"_type":176,"marks":1600,"text":1601},"f21ab93f745a",[],"Our checklist walks through ",{"_key":1603,"_type":176,"marks":1604,"text":1605},"075d67a99844",[369],"seven sections",{"_key":1607,"_type":176,"marks":1608,"text":1609},"efdacaa58de5",[],", and the sequence matters because it mirrors how security thinks about your org:",[],{"_key":1612,"_type":172,"children":1613,"level":54,"listItem":945,"markDefs":1625,"style":180},"e395be677894",[1614,1617,1621],{"_key":1607,"_type":176,"marks":1615,"text":1616},[],"It opens with ",{"_key":1618,"_type":176,"marks":1619,"text":1620},"553cc12186be",[369],"connected apps and OAuth grants",{"_key":1622,"_type":176,"marks":1623,"text":1624},"260e78d5bdcd",[],", since malicious and dormant connected apps have been the front door in most recent Salesforce attacks and a dormant grant with broad scopes is the exact finding your security team is hunting for. ",[],{"_key":1627,"_type":172,"children":1628,"level":54,"listItem":945,"markDefs":1640,"style":180},"fd7d254c33c9",[1629,1632,1636],{"_key":1607,"_type":176,"marks":1630,"text":1631},[],"It moves to",{"_key":1633,"_type":176,"marks":1634,"text":1635},"401250d105ba",[369]," integration and API-only users",{"_key":1637,"_type":176,"marks":1638,"text":1639},"427f81d8ab0f",[],"… the non-human identities that are the least visible access in any org and the standard skeleton in the closet. ",[],{"_key":1642,"_type":172,"children":1643,"level":54,"listItem":945,"markDefs":1660,"style":180},"6f7f27b40c4e",[1644,1647,1652,1656],{"_key":1607,"_type":176,"marks":1645,"text":1646},[],"Then ",{"_key":1648,"_type":176,"marks":1649,"text":1651},"ac53c7fb06e7",[1650,369],"fc0507fcf15c","permission architecture",{"_key":1653,"_type":176,"marks":1654,"text":1655},"ee2b5e50391c",[369],",",{"_key":1657,"_type":176,"marks":1658,"text":1659},"7efe2ac1e18f",[]," stated honestly rather than screenshotted.",[1661],{"_key":1650,"_ref":327,"_type":328,"linkType":33,"slug":1662},{"_type":22,"current":330},{"_key":1664,"_type":172,"children":1665,"level":54,"listItem":945,"markDefs":1676,"style":180},"80962acf379a",[1666,1668,1672],{"_key":1653,"_type":176,"marks":1667,"text":1646},[],{"_key":1669,"_type":176,"marks":1670,"text":1671},"39d9631ad855",[369],"data exports and outbound flows",{"_key":1673,"_type":176,"marks":1674,"text":1675},"20ca760123cd",[],", because exfiltration is the outcome security is paid to prevent, and showing you know every exit ramp is worth more than any attestation.",[],{"_key":1678,"_type":172,"children":1679,"level":54,"listItem":945,"markDefs":1691,"style":180},"f319f040b068",[1680,1683,1687],{"_key":1653,"_type":176,"marks":1681,"text":1682},[],"Section five is the one that barely existed a year ago: ",{"_key":1684,"_type":176,"marks":1685,"text":1686},"89e1ddc3e0b8",[369],"AI and agent touchpoints",{"_key":1688,"_type":176,"marks":1689,"text":1690},"85dd49b84d0c",[],". What agents can read, what they can write, where prompt logs live, what happens to the data. Security's questions have moved past sharing rules to data residency and prompt handling, and this section is increasingly why the meeting exists at all.",[],{"_key":1693,"_type":172,"children":1694,"level":54,"listItem":945,"markDefs":1699,"style":180},"89cc63507948",[1695],{"_key":1696,"_type":176,"marks":1697,"text":1698},"9fa97d4d8ddb",[],"and 7. are where the document earns its keep, and they deserve their own discussion.",[],{"_key":1701,"_type":172,"children":1702,"markDefs":1707,"style":180},"1cc552901db1",[1703],{"_key":1704,"_type":176,"marks":1705,"text":1706},"ac39689dab1c",[],"Each section in the template carries a short note explaining why security asks.. that's the translation layer. Fill it in and you've mapped your org to their framework once, instead of relitigating vocabulary every Thursday.",[],{"_key":1709,"_type":1710,"img":1711,"markDefs":19},"1d6873196ae1","blockImage",{"_type":37,"altText":1712,"image":1713},"salesforce security review checklist",{"_type":40,"asset":1714},{"_createdAt":1715,"_id":1716,"_rev":1717,"_type":45,"_updatedAt":1715,"assetId":1718,"extension":106,"metadata":1719,"mimeType":132,"originalFilename":1744,"path":1745,"sha1hash":1718,"size":1746,"uploadId":1747,"url":1748},"2026-07-27T14:42:46Z","image-6bb972b269a662daa4b76abaddd2eeccba3f6dba-632x361-png","N2ICxYvj58ulASEVTvFicn","6bb972b269a662daa4b76abaddd2eeccba3f6dba",{"_type":50,"blurHash":1720,"dimensions":1721,"hasAlpha":57,"isOpaque":57,"lqip":1725,"palette":1726,"thumbHash":1743},"MUJ[02xtx]flxv00oft7ayt7~pWXWBj[WB",{"_type":53,"aspectRatio":1722,"height":1723,"width":1724},1.7506925207756232,361,632,"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAAsTAAALEwEAmpwYAAACmElEQVR4nI3QyU9TURTA4fcfAC1QStX20RKwgwE7WClQkBmiGKuB2IJgZBIjOIW9S8PgQlloWbQmunJlTIwJIRENYYEtshJXKhFFaMFWoAz5mfdKqksXX+7NOfeee+4RhobuUF9XxUmnA6fTidVqxWKxYDab/4vFYsFkMuFyuejv70cYGLhGbXU5ZaUluN1uuaDBkI8o5qHTiWi1WnQ6nUyj0aBSqcjOzk5RqVRkZWVRUFCA1+tFGBy8TlNDLTXVFTQ11lNbU0VZmYvSUhcOh43i4iIcDofMYDCgVCpJT09PycjIIC0tTX6wpaUF4fata3jOlNLcUMSFZjvnz9hpbrRxusFOlfsY1uNmuWubzYZeryczMxOFQpGiVCrloqIo0trainBzsIvTdSbqynNoOpVLQ6Wa6jI1FSW5OI+ryder0WhyZTk50vcyZVLh5D4LhSJZUO5QmmGl24nDWojTbsRhK+SE7Sh2qxFrsQmT8Sh6Qz46US8T8yQGRF0eWp0oz/rQ4SMYjWZ8vjaE8Yej3BjoprfrIn09Pnq7vVzt8cn6etro7fJy5XILly956DzQ0e6ho+0cl9rO0dnuod13Vr43fO8uwuLCC8Iz44TejRJ+N5YyN32f2SnJGHNvRnk/PcL7tyPMTY8wOzXKzKS0jiTj08PMzzxgceE5wsbya2Lfgmx9f8TOymN2f/plm8sTRD5PEP08wdb3x+ytSvzsrPiJLUk5P7+++kn88Mu53dUAibWXCOvLk0SXnrGxFGD7R5D9tSB7kSBbK0/YWJIE2V4JsB9J2lkNEv8WJPoleJCT7gTYW3tKIvIKIb7+iXjkA7+jYRKxMHu/kxKxEJvREJvrYXb+ie/GQ2xthOTzf3MhduPzbMc+8gdfJvsJMntIxgAAAABJRU5ErkJggg==",{"_type":60,"darkMuted":1727,"darkVibrant":1729,"dominant":1732,"lightMuted":1735,"lightVibrant":1738,"muted":1740,"vibrant":1742},{"_type":62,"background":1728,"foreground":64,"population":125,"title":64},"#444161",{"_type":62,"background":1730,"foreground":64,"population":1731,"title":64},"#6f5b08",0.67,{"_type":62,"background":1733,"foreground":72,"population":1734,"title":64},"#f7d308",7,{"_type":62,"background":1736,"foreground":72,"population":1737,"title":64},"#bca0a6",0.03,{"_type":62,"background":1739,"foreground":72,"population":844,"title":72},"#f3d85a",{"_type":62,"background":1741,"foreground":64,"population":1737,"title":64},"#9e9b62",{"_type":62,"background":1733,"foreground":72,"population":1734,"title":64},"3AgaJIKIh4eAeHh7h3l4gIkHmA==","Screenshot 2026-07-27 at 16.42.15.png","images/9eu1m6zu/production/6bb972b269a662daa4b76abaddd2eeccba3f6dba-632x361.png",35380,"86cae44ea45a487572369dad488a9e00a3bccde1","https://cdn.sanity.io/images/9eu1m6zu/production/6bb972b269a662daa4b76abaddd2eeccba3f6dba-632x361.png",{"_key":1750,"_type":172,"children":1751,"markDefs":1756,"style":920},"642e2e7bd802",[1752],{"_key":1753,"_type":176,"marks":1754,"text":1755},"07c2585eb9f1",[],"Bring the ugly map",[],{"_key":1758,"_type":172,"children":1759,"markDefs":1764,"style":180},"d1d6c652d902",[1760],{"_key":1761,"_type":176,"marks":1762,"text":1763},"ee3d4602b759",[],"Section six is a known-issues ledger, and it's the part admins resist.",[],{"_key":1766,"_type":172,"children":1767,"markDefs":1772,"style":180},"0be4234179ee",[1768],{"_key":1769,"_type":176,"marks":1770,"text":1771},"a785fd047ccc",[],"The instinct before a security review is to sanitize. Present the architecture diagram from the implementation deck, the one with clean boxes and orderly arrows, and hope nobody asks what's underneath. Every admin knows that diagram is fiction. The real org has flows nobody remembers building, integration users named after employees who left in 2021, and a permission structure that reflects a decade of exceptions.",[],{"_key":1774,"_type":172,"children":1775,"markDefs":1780,"style":180},"96af73c5133c",[1776],{"_key":1777,"_type":176,"marks":1778,"text":1779},"149cfc1c417e",[],"Bring that one. The real one.",[],{"_key":1782,"_type":172,"children":1783,"markDefs":1788,"style":180},"8b511cf1295a",[1784],{"_key":1785,"_type":176,"marks":1786,"text":1787},"db186d84bb7c",[],"Security teams deal in known and unknown risk, and the entire discipline is built on preferring the first kind. \"Here are five problems we've already found and here's the cleanup plan\" reads as competence. A pristine diagram that falls apart when someone discovers a random connected app live in the meeting reads as either negligence or concealment, and both cost you the room permanently. The mess was never the thing that gets you flagged. The surprise is.",[],{"_key":1790,"_type":172,"children":1791,"markDefs":1796,"style":180},"1e22570d6110",[1792],{"_key":1793,"_type":176,"marks":1794,"text":1795},"45fbebe4d6d1",[],"The template bakes this in as a house rule: nothing on the ledger page should be news to you. If security finds it before you list it, it moves to the top.",[],{"_key":1798,"_type":172,"children":1799,"markDefs":1804,"style":180},"3c2a5b934ded",[1800],{"_key":1801,"_type":176,"marks":1802,"text":1803},"0fc59fec026f",[],"There's a deeper reason this works, beyond meeting tactics. Every strange flow and legacy field encodes a decision your business made, and an accurate map of that tangle is the only real answer to the only real question security is asking: what can happen here, and would we know? A false clean picture answers neither. The ugly map answers both.",[],{"_key":1806,"_type":172,"children":1807,"markDefs":1812,"style":180},"f6eb95ef8fb1",[1808],{"_key":1809,"_type":176,"marks":1810,"text":1811},"ebc75bfc89bb",[],"Section seven, \"since last sync,” is what turns the whole thing from a one-time audit into a standing agenda. It's four lines: what changed, what's new, what closed, what security asked that you couldn't answer on the spot. It's the first thing anyone reads in week two, and it's the reason the meeting eventually gets shorter instead of longer.",[],{"_key":1814,"_type":172,"children":1815,"markDefs":1820,"style":920},"a41c69aa068b",[1816],{"_key":1817,"_type":176,"marks":1818,"text":1819},"da3dbbb2bea8",[],"The catch",[],{"_key":1822,"_type":172,"children":1823,"markDefs":1828,"style":180},"dbf0e1f7c3da",[1824],{"_key":1825,"_type":176,"marks":1826,"text":1827},"6186d5de18c7",[],"The Salesforce security review checklist works. It also goes stale the week after you build it.",[],{"_key":1830,"_type":172,"children":1831,"markDefs":1845,"style":180},"8498245083bd",[1832,1836,1841],{"_key":1833,"_type":176,"marks":1834,"text":1835},"6c3c5ca691d0",[],"Every admin who's assembled one by hand says a version of the same thing: the document was accurate for exactly oh…. one meeting. Then someone installed an app, a consultant added a flow, an agent got new permissions, and ",{"_key":1837,"_type":176,"marks":1838,"text":1840},"95e8544e1947",[1839],"a698dd27ce77","the map sneakily diverged from the territory",{"_key":1842,"_type":176,"marks":1843,"text":1844},"a224580b703d",[],". Now you're maintaining a second job, SF archaeologist, on top of your first one, and the standing sync has a standing prep tax.",[1846],{"_key":1839,"_ref":1847,"_type":328,"linkType":33,"slug":1848},"9cd0370d-f0dc-4c6a-abca-65638bd8662d",{"_type":22,"current":1849},"context-rot",{"_key":1851,"_type":172,"children":1852,"markDefs":1866,"style":180},"7b3e92a62eb5",[1853,1857,1862],{"_key":1854,"_type":176,"marks":1855,"text":1856},"09192e484cc7",[],"This is the  problem underneath the meeting. Not that security is asking questions, but that answering them requires ",{"_key":1858,"_type":176,"marks":1859,"text":1861},"7f6712abe399",[1860],"4ca51a845b42","visibility into your metadata",{"_key":1863,"_type":176,"marks":1864,"text":1865},"47556b1adb36",[]," that Salesforce doesn't give you natively and that no human can keep current by hand. The survival kit is a snapshot. What the sync actually needs is a live feed.",[1867],{"_key":1860,"_ref":1868,"_type":328,"linkType":33,"slug":1869},"4e422e65-9598-4bdc-86e2-bf4da4435754",{"_type":22,"current":1870},"schema-blindness-why-ai-agents-guess-wrong-in-your-salesforce-org",{"_key":1872,"_type":172,"children":1873,"markDefs":1887,"style":180},"fa2d649f2667",[1874,1878,1883],{"_key":1875,"_type":176,"marks":1876,"text":1877},"5fef59bb031d",[],"That's the layer ",{"_key":1879,"_type":176,"marks":1880,"text":1882},"f5d881d22a39",[1881],"1807070a902c","Sweep operates in.",{"_key":1884,"_type":176,"marks":1885,"text":1886},"7a0967e5fbd6",[]," It reads your org's metadata continuously: the connected apps, the integration users, the permission architecture, the automations, the agent touchpoints… and keeps the map current without anyone maintaining it. Bring the ugly map. Just don't draw it by hand every week.",[1888],{"_key":1881,"_type":151,"blank":57,"href":1889,"noOpener":57,"noReferrer":57,"url":1889},"https://www.sweep.io/why-sweep",{"_key":1891,"_type":172,"children":1892,"markDefs":1902,"style":180},"7d875bf675ab",[1893,1898],{"_key":1894,"_type":176,"marks":1895,"text":1897},"01741e9d748c",[369,1896],"ca67ecfd8b77","Steal the Google Doc here",{"_key":1899,"_type":176,"marks":1900,"text":1901},"0a411c400a5a",[]," and walk into your first sync with the agenda already written.",[1903],{"_key":1896,"_type":151,"blank":57,"href":1502,"noOpener":57,"noReferrer":57,"url":1502},{"_type":17,"description":1905,"shareImage":1906,"title":1908},"Run your next Salesforce security review with confidence. A free admin checklist template covering connected apps, permissions, data exports & AI agents.",{"_type":40,"asset":1907},{"_ref":1359,"_type":278},"Salesforce Security Review Checklist + Free Template",{"_type":22,"current":1910},"the-security-sync-survival-kit-for-salesforce-admins",{"_createdAt":1912,"_id":1913,"_rev":1914,"_system":1915,"_type":33,"_updatedAt":1918,"author":1919,"category":1935,"featuredImage":1941,"modularContent":1974,"postTitle":1978,"publishDate":1979,"richText":1980,"seo":2426,"slug":2431},"2026-07-13T17:46:23Z","49389fe7-330d-4cfe-9677-24ab4d5fe2e8","v7D8ElYpFNzwbZA17CMrcF",{"base":1916},{"id":1913,"rev":1917},"8cfuqYUy20MyX6iqQ1aWVo","2026-07-29T18:23:52Z",{"authorImage":1920,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":38,"image":1921},{"_type":40,"asset":1922},{"_createdAt":42,"_id":43,"_rev":44,"_type":45,"_updatedAt":46,"altText":19,"assetId":47,"description":19,"extension":48,"metadata":1923,"mimeType":83,"opt":1933,"originalFilename":86,"path":87,"sha1hash":47,"size":88,"title":19,"uploadId":89,"url":90},{"_type":50,"blurHash":51,"dimensions":1924,"hasAlpha":56,"isOpaque":57,"lqip":58,"palette":1925},{"_type":53,"aspectRatio":54,"height":55,"width":55},{"_type":60,"darkMuted":1926,"darkVibrant":1927,"dominant":1928,"lightMuted":1929,"lightVibrant":1930,"muted":1931,"vibrant":1932},{"_type":62,"background":63,"foreground":64,"population":65,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":71,"foreground":72,"population":73,"title":64},{"_type":62,"background":75,"foreground":72,"population":76,"title":72},{"_type":62,"background":78,"foreground":64,"population":79,"title":64},{"_type":62,"background":81,"foreground":64,"population":82,"title":64},{"media":1934},{"tags":19},{"_createdAt":5,"_id":6,"_rev":7,"_system":1936,"_type":11,"_updatedAt":12,"selectedColor":1938,"seo":1939,"slug":1940,"title":24},{"base":1937},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":1942,"image":1943},"sbs_salesforce",{"_type":40,"asset":1944},{"_createdAt":1945,"_id":1946,"_rev":1947,"_type":45,"_updatedAt":1945,"assetId":1948,"extension":106,"metadata":1949,"mimeType":132,"originalFilename":853,"path":1970,"sha1hash":1948,"size":1971,"uploadId":1972,"url":1973},"2026-07-15T15:59:13Z","image-3271b372f966afe76ea36b7102aa0b33f6c6987d-1200x630-png","1LauHAirdOo8wrIfk3nwWN","3271b372f966afe76ea36b7102aa0b33f6c6987d",{"_type":50,"blurHash":1950,"dimensions":1951,"hasAlpha":57,"isOpaque":57,"lqip":1952,"palette":1953,"thumbHash":1969},"M7ALWI%0N4kaaxkcWZj=j?fR9TNOxmjXj]",{"_type":53,"aspectRatio":110,"height":111,"width":112},"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAAsTAAALEwEAmpwYAAABAElEQVR4nM2STU/CQBRF+YkCihQosjHBhbY1uqC0JbR2IQVr+I1i1IWafgSTpnNMh2pi04UmLliczLv3TW4mb17jYAL/SWP/A5sTaJkFgqYJhf5G+sVZ9irUBran0J8Lhl6O6uaonkB1hfQGrmDkF+QMb4TsDVxQvR3dGbSmlcCOnTO+TbkM3zDCd/QwxggjtFWEdhdxtY65XkcS4z7hbJkxXiI58eHQqgQeWRmn/it68CC5WDxJ9MUGLdiU+hlj9ch58MLI28rX9+bQcXYj+TlDM+fY+kCxY3pOjGKndO1U1v1ZhGInpU5QnJS2mf32l0XNhcL7Yh/2sFiVuvovgZ/JOWhnHaYhxQAAAABJRU5ErkJggg==",{"_type":60,"darkMuted":1954,"darkVibrant":1956,"dominant":1958,"lightMuted":1960,"lightVibrant":1963,"muted":1965,"vibrant":1968},{"_type":62,"background":1955,"foreground":64,"population":82,"title":64},"#305468",{"_type":62,"background":1957,"foreground":64,"population":125,"title":64},"#40708a",{"_type":62,"background":840,"foreground":64,"population":1959,"title":64},72.63,{"_type":62,"background":1961,"foreground":72,"population":1962,"title":64},"#b2a6ca",0.09,{"_type":62,"background":1964,"foreground":72,"population":82,"title":64},"#ac8cfc",{"_type":62,"background":1966,"foreground":64,"population":1967,"title":64},"#637bab",0.61,{"_type":62,"background":840,"foreground":64,"population":1959,"title":64},"ZrMBFIBZeHd3iIhgeodadqBlBw==","images/9eu1m6zu/production/3271b372f966afe76ea36b7102aa0b33f6c6987d-1200x630.png",78139,"7a805a10ffb713c63ce8842440f6ee421a0bcfc6","https://cdn.sanity.io/images/9eu1m6zu/production/3271b372f966afe76ea36b7102aa0b33f6c6987d-1200x630.png",[1975],{"_key":1976,"_type":275,"cols":276,"filterByCategory":1977,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":279},"ca31690223ccd44cb2033c5b0bf785f8",{"_ref":6,"_type":278},"How to Run an SBS Gap Analysis (Without Doing It Twice)","2026-07-13",[1981,1989,2007,2014,2021,2028,2035,2043,2050,2057,2064,2072,2080,2096,2104,2111,2119,2126,2140,2147,2155,2163,2189,2197,2204,2212,2220,2228,2235,2242,2249,2278,2286,2294,2310,2318,2326,2334,2342,2350,2358,2377,2418],{"_key":1982,"_type":172,"children":1983,"markDefs":1988,"style":180},"5511b5a1b235",[1984],{"_key":1985,"_type":176,"marks":1986,"text":1987},"06451eafbbf0",[],"Here's how the first attempt at this usually goes: ",[],{"_key":1990,"_type":172,"children":1991,"level":54,"listItem":945,"markDefs":2004,"style":180},"879601d6fd87",[1992,1995,2000],{"_key":1985,"_type":176,"marks":1993,"text":1994},[],"A security lead reads about the ",{"_key":1996,"_type":176,"marks":1997,"text":1999},"4eab7f8769a4",[1998],"c56342e86037","Security Benchmark for Salesforce",{"_key":2001,"_type":176,"marks":2002,"text":2003},"cdf190d39599",[],", opens the docs, and starts with whatever domain scares them most (usually authentication). ",[2005],{"_key":1998,"_ref":985,"_type":328,"linkType":33,"slug":2006},{"_type":22,"current":987},{"_key":2008,"_type":172,"children":2009,"level":54,"listItem":945,"markDefs":2013,"style":180},"4ed1b09042d5",[2010],{"_key":1985,"_type":176,"marks":2011,"text":2012},[],"They assess it. They feel good. Then they hit the access controls domain and discover it wants a documented justification for every API-enabled permission, deposited into a system of record. ",[],{"_key":2015,"_type":172,"children":2016,"level":54,"listItem":945,"markDefs":2020,"style":180},"358c7c777a55",[2017],{"_key":1985,"_type":176,"marks":2018,"text":2019},[],"Then the OAuth domain wants the same for every connected app. ",[],{"_key":2022,"_type":172,"children":2023,"level":54,"listItem":945,"markDefs":2027,"style":180},"d4d145db09eb",[2024],{"_key":1985,"_type":176,"marks":2025,"text":2026},[],"Then integrations, same again. ",[],{"_key":2029,"_type":172,"children":2030,"level":54,"listItem":945,"markDefs":2034,"style":180},"3ef0dc83beb1",[2031],{"_key":1985,"_type":176,"marks":2032,"text":2033},[],"And there is no system of record, because nobody built one, because that looked like paperwork instead of actual infrastructure.",[],{"_key":2036,"_type":172,"children":2037,"level":54,"listItem":945,"markDefs":2042,"style":180},"20bd45d9682b",[2038],{"_key":2039,"_type":176,"marks":2040,"text":2041},"52d55db1b6dd",[],"So they build it mid-assessment. They backfill everything already reviewed, and absorb the fact that they've now done a third of the benchmark twice.",[],{"_key":2044,"_type":172,"children":2045,"level":54,"listItem":945,"markDefs":2049,"style":180},"eac37692f40f",[2046],{"_key":2039,"_type":176,"marks":2047,"text":2048},[],"The controls do have an order. ",[],{"_key":2051,"_type":172,"children":2052,"level":54,"listItem":945,"markDefs":2056,"style":180},"cf95c5e9e4f2",[2053],{"_key":2039,"_type":176,"marks":2054,"text":2055},[],"Follow it and the assessment compounds. ",[],{"_key":2058,"_type":172,"children":2059,"level":54,"listItem":945,"markDefs":2063,"style":180},"aebd7aab7c36",[2060],{"_key":2039,"_type":176,"marks":2061,"text":2062},[],"Ignore it and the assessment repeats. ",[],{"_key":2065,"_type":172,"children":2066,"markDefs":2071,"style":180},"3a72ccc7b894",[2067],{"_key":2068,"_type":176,"marks":2069,"text":2070},"7fcc0e632bc3",[],"This is the sequence to use at your best discretion. ",[],{"_key":2073,"_type":172,"children":2074,"markDefs":2079,"style":292},"8fd9dfcfa8d3",[2075],{"_key":2076,"_type":176,"marks":2077,"text":2078},"9d10c5895e35",[],"Step 0: Pin your version",[],{"_key":2081,"_type":172,"children":2082,"markDefs":2095,"style":180},"b149ced72307",[2083,2087,2091],{"_key":2084,"_type":176,"marks":2085,"text":2086},"a08ff9a87fa7",[],"Published SBS versions are ",{"_key":2088,"_type":176,"marks":2089,"text":2090},"9756a36326e5",[393],"immutable",{"_key":2092,"_type":176,"marks":2093,"text":2094},"8ca598a566c6",[],". Major releases are a different story. They can add, remove, renumber, or recategorize controls, and the benchmark has already grown substantially across its early releases (from 24 a few weeks ago to over 50 as of us writing this). ",[],{"_key":2097,"_type":172,"children":2098,"markDefs":2103,"style":180},"76f41dc2a820",[2099],{"_key":2100,"_type":176,"marks":2101,"text":2102},"88830bb75cf2",[],"Before touching a single control, record the version. ",[],{"_key":2105,"_type":172,"children":2106,"markDefs":2110,"style":180},"faf59a511176",[2107],{"_key":2100,"_type":176,"marks":2108,"text":2109},[],"Put it at the top of the assessment artifact. Importantly, when the next major release lands, you'll be able to then diff against a fixed point in time, instead of reconstructing what you meant a year ago.",[],{"_key":2112,"_type":172,"children":2113,"markDefs":2118,"style":180},"2f58c6f4564a",[2114],{"_key":2115,"_type":176,"marks":2116,"text":2117},"305c03edb8cb",[],"One paragraph of effort. It protects everything else downstream.",[],{"_key":2120,"_type":172,"children":2121,"markDefs":2125,"style":180},"86634feac4e8",[2122],{"_key":2123,"_type":176,"marks":2124,"text":352},"22eb572ae009",[],[],{"_key":2127,"_type":172,"children":2128,"markDefs":2138,"style":180},"adc44db8d769",[2129,2133],{"_key":2130,"_type":176,"marks":2131,"text":2132},"d94234656f56",[],"Wanna skip even that effort? We built an app for you to ",{"_key":2134,"_type":176,"marks":2135,"text":2137},"e28586f786c6",[2136],"101588005e30","track your own Salesforce security here.",[2139],{"_key":2136,"_type":151,"blank":57,"href":1504,"noOpener":57,"noReferrer":57,"url":1504},{"_key":2141,"_type":172,"children":2142,"markDefs":2146,"style":180},"335a8bac911e",[2143],{"_key":2144,"_type":176,"marks":2145,"text":352},"faee9ca7a57d",[],[],{"_key":2148,"_type":172,"children":2149,"markDefs":2154,"style":292},"7aae752e8ac1",[2150],{"_key":2151,"_type":176,"marks":2152,"text":2153},"6145e0fef1f3",[],"Step 1: Stand up the system of record",[],{"_key":2156,"_type":172,"children":2157,"markDefs":2162,"style":180},"888ce6a69826",[2158],{"_key":2159,"_type":176,"marks":2160,"text":2161},"a42477afc690",[],"The foundations domain sits first in the benchmark, and its opening requirement… a centralized system of record for security configurations, exceptions, justifications, and inventories… sits first in that domain.",[],{"_key":2164,"_type":172,"children":2165,"markDefs":2186,"style":180},"d785a3e3da39",[2166,2169,2173,2177,2182],{"_key":2159,"_type":176,"marks":2167,"text":2168},[],"That placement is structural. A large share of the remaining controls don't just ask you to check something, no rather they ask you to ",{"_key":2170,"_type":176,"marks":2171,"text":2172},"04049731d07f",[393],"record",{"_key":2174,"_type":176,"marks":2175,"text":2176},"c223a92aee75",[]," something: ",{"_key":2178,"_type":176,"marks":2179,"text":2181},"67a90ded790c",[2180],"1d9a87ab6500","which users hold super-admin-equivalent access",{"_key":2183,"_type":176,"marks":2184,"text":2185},"3e8441a74a19",[]," and why, which connected apps were formally approved, which SSO exceptions exist and who accepted them. All of that evidence needs a home, and the benchmark expects the home to exist before the evidence arrives.",[2187],{"_key":2180,"_ref":1121,"_type":328,"linkType":33,"slug":2188},{"_type":22,"current":1123},{"_key":2190,"_type":172,"children":2191,"markDefs":2196,"style":180},"269a7cf979a4",[2192],{"_key":2193,"_type":176,"marks":2194,"text":2195},"15551af10c81",[369],"Be honest about what qualifies. ",[],{"_key":2198,"_type":172,"children":2199,"markDefs":2203,"style":180},"e44bc968208e",[2200],{"_key":2193,"_type":176,"marks":2201,"text":2202},[],"A spreadsheet owned by someone who left in 2024 is a memorial, and a wiki page nobody has touched since the last audit is basically a fossil of a bygone era. The standard's bar is a maintained record with named ownership and a review cadence. That makes it something a new hire could open and trust.",[],{"_key":2205,"_type":172,"children":2206,"markDefs":2211,"style":180},"4d9fee7f1737",[2207],{"_key":2208,"_type":176,"marks":2209,"text":2210},"c1eca084f877",[],"Teams that skip this step don't skip the work. They defer it, then perform it twice under worse conditions. So it’s vital to build that container first.",[],{"_key":2213,"_type":172,"children":2214,"markDefs":2219,"style":292},"0fc1a55e37c8",[2215],{"_key":2216,"_type":176,"marks":2217,"text":2218},"6914141146b1",[],"Step 2: List the cheap domains",[],{"_key":2221,"_type":172,"children":2222,"markDefs":2227,"style":180},"4097c60732d6",[2223],{"_key":2224,"_type":176,"marks":2225,"text":2226},"9e3624aaea32",[],"With the system of record standing, go where the answers are cheapest. Access controls, OAuth security, and integrations are mostly metadata questions….",[],{"_key":2229,"_type":172,"children":2230,"level":54,"listItem":309,"markDefs":2234,"style":180},"dcfb9aa87a2f",[2231],{"_key":2224,"_type":176,"marks":2232,"text":2233},[],"Which profiles and permission sets grant API Enabled. ",[],{"_key":2236,"_type":172,"children":2237,"level":54,"listItem":309,"markDefs":2241,"style":180},"bff6b6c99342",[2238],{"_key":2224,"_type":176,"marks":2239,"text":2240},[],"Which connected apps exist that nobody formally installed. ",[],{"_key":2243,"_type":172,"children":2244,"level":54,"listItem":309,"markDefs":2248,"style":180},"cf2b5af47dfd",[2245],{"_key":2224,"_type":176,"marks":2246,"text":2247},[],"Which remote site settings are live, and whether anyone can produce a reason for them.",[],{"_key":2250,"_type":172,"children":2251,"markDefs":2273,"style":180},"3e32946f6727",[2252,2256,2260,2264,2269],{"_key":2253,"_type":176,"marks":2254,"text":2255},"bbf32593c1b3",[],"None of this requires new tooling to ",{"_key":2257,"_type":176,"marks":2258,"text":2259},"3dcca8a6174d",[393],"understand. ",{"_key":2261,"_type":176,"marks":2262,"text":2263},"4703e92e3151",[],"It requires ",{"_key":2265,"_type":176,"marks":2266,"text":2268},"e0b4d4075d1c",[2267],"d5d1d1592064","visibility into configuration",{"_key":2270,"_type":176,"marks":2271,"text":2272},"3ea89ab9df5e",[]," your org already contains. With real org visibility, this enumeration is an afternoon. Without it, it's a quarter-long archaeological dig conducted through exported CSVs and the memories of whoever's been around longest.",[2274],{"_key":2267,"_ref":2275,"_type":328,"linkType":33,"slug":2276},"13d41b03-37fd-4d5d-9b58-7629dcfa805e",{"_type":22,"current":2277},"5-reasons-sweep-beats-hubbl-for-salesforce-ops",{"_key":2279,"_type":172,"children":2280,"markDefs":2285,"style":180},"0cf40be74b66",[2281],{"_key":2282,"_type":176,"marks":2283,"text":2284},"e36e516d9940",[],"Either way, the output is the same. Inventories and justifications, deposited into the system of record you built in Step 1. This is where the sequence starts paying compound interest. Every enumerated domain makes the next one faster, because the container and the habit already exist.",[],{"_key":2287,"_type":172,"children":2288,"markDefs":2293,"style":292},"060c40bbcb1f",[2289],{"_key":2290,"_type":176,"marks":2291,"text":2292},"fac2ddd26215",[],"Step 3: Budget real time for the mechanism controls",[],{"_key":2295,"_type":172,"children":2296,"markDefs":2309,"style":180},"1315b0a862e9",[2297,2301,2305],{"_key":2298,"_type":176,"marks":2299,"text":2300},"8b496ea5da33",[],"Some controls can indeed be satisfied with a point-in-time check. Others simply can't. Requirements like continuous detection of regulated data in long text fields, or ongoing monitoring for unauthorized metadata changes, describe a ",{"_key":2302,"_type":176,"marks":2303,"text":2304},"ee3cba5397c3",[393],"capability…",{"_key":2306,"_type":176,"marks":2307,"text":2308},"decae4c344c8",[]," something that has to run tomorrow, and next month, and after the admin who set it up changes jobs.",[],{"_key":2311,"_type":172,"children":2312,"markDefs":2317,"style":180},"38509600ea15",[2313],{"_key":2314,"_type":176,"marks":2315,"text":2316},"6d1b324edf8b",[],"This is the step where \"we'll just handle it manually\" goes to die a slow painful death. A manual process is just a fancy point-in-time check. It satisfies the control on the day of the assessment and drifts out of compliance the day (maybe an hour) after. Budget for these controls the way you'd budget for standing infrastructure, because that's what they are. If the real answer is that your team can't sustain the mechanism, write that down as a gap  (a real one, with an owner and a date) instead of a process that exists only on the org chart.",[],{"_key":2319,"_type":172,"children":2320,"markDefs":2325,"style":292},"aa6314fa700c",[2321],{"_key":2322,"_type":176,"marks":2323,"text":2324},"fa73d47b7fd2",[],"Step 4: Fail honestly",[],{"_key":2327,"_type":172,"children":2328,"markDefs":2333,"style":180},"709bd458c56c",[2329],{"_key":2330,"_type":176,"marks":2331,"text":2332},"63b7d9c747fe",[],"SBS compliance is binary for a reason. Partial compliance isn't recognized, and compensating controls don't count unless your internal security authority formally documents and accepts them. An inventory that's 90% complete is a noncompliant inventory. There’s no way around it.",[],{"_key":2335,"_type":172,"children":2336,"markDefs":2341,"style":180},"43523f0f634f",[2337],{"_key":2338,"_type":176,"marks":2339,"text":2340},"e71124d82be6",[],"This might feel punishing until you appreciate why it's there. Mostly because a standard you can partially meet is a standard nobody meets. Every org becomes \"mostly compliant,\" the term stops carrying information, and the auditor's eyes glaze over. The binary is what makes an SBS assessment worth showing.",[],{"_key":2343,"_type":172,"children":2344,"markDefs":2349,"style":180},"d66ed99211ff",[2345],{"_key":2346,"_type":176,"marks":2347,"text":2348},"96cb07d1a6db",[],"So fail where you fail. Document the exception in the system of record, assign the remediation, set the reassessment date, and let the standard do what standards are for. The org that reports twelve honest gaps is in materially better shape than the org that reports zero but can't explain how.",[],{"_key":2351,"_type":172,"children":2352,"markDefs":2357,"style":292},"601f412715f4",[2353],{"_key":2354,"_type":176,"marks":2355,"text":2356},"9f72e084b0aa",[],"What the sequence actually buys you",[],{"_key":2359,"_type":172,"children":2360,"markDefs":2374,"style":180},"b24e614a189e",[2361,2365,2370],{"_key":2362,"_type":176,"marks":2363,"text":2364},"8de7a6264a96",[],"Run this once, in order, and you end up with more than a compliance posture. You end up with a legible org. ",{"_key":2366,"_type":176,"marks":2367,"text":2369},"c60470ebb5e5",[2368],"29f87f70c735","Every permission explainable",{"_key":2371,"_type":176,"marks":2372,"text":2373},"a6e4c2446142",[],", every integration justified, every exception owned by a person instead of a shrug. This is really the deeper trade SBS is offering, and we've written before about why it matters beyond audit season: the benchmark never asks you to simplify your org. It asks you to make it answerable.",[2375],{"_key":2368,"_ref":327,"_type":328,"linkType":33,"slug":2376},{"_type":22,"current":330},{"_key":2378,"_type":172,"children":2379,"markDefs":2411,"style":180},"ed5212d6b977",[2380,2384,2389,2393,2398,2402,2407],{"_key":2381,"_type":176,"marks":2382,"text":2383},"d10325057b1f",[],"If you're new to the standard itself (where it came from, how the controls are structured, what it deliberately isn't) start with ",{"_key":2385,"_type":176,"marks":2386,"text":2388},"757a2c0b8062",[2387],"4801e610f6f7","our full explainer on the Security Benchmark for Salesforce",{"_key":2390,"_type":176,"marks":2391,"text":2392},"8eeaee5fc2fc",[]," and ",{"_key":2394,"_type":176,"marks":2395,"text":2397},"2e15406db884",[2396],"e97ae4585d94","the official SBS documentation",{"_key":2399,"_type":176,"marks":2400,"text":2401},"1c2947572892",[],". And if Step 2 read less like an afternoon and more like a quarter, that's the gap worth closing first. (",{"_key":2403,"_type":176,"marks":2404,"text":2406},"7f53f1e7cb21",[2405],"0d5f13b64a80","See how Sweep gives you that visibility →",{"_key":2408,"_type":176,"marks":2409,"text":2410},"44e4faaabbec",[],")",[2412,2414,2416],{"_key":2387,"_ref":985,"_type":328,"linkType":33,"slug":2413},{"_type":22,"current":987},{"_key":2396,"_type":151,"blank":57,"href":2415,"noOpener":57,"noReferrer":57,"url":2415},"https://docs.securitybenchmark.org/introduction.html)",{"_key":2405,"_ref":948,"_type":328,"linkType":738,"slug":2417},{"_type":22,"current":950},{"_key":2419,"_type":172,"children":2420,"markDefs":2425,"style":180},"abff69ba5888",[2421],{"_key":2422,"_type":176,"marks":2423,"text":2424},"fcac2a704e3e",[393],"Note: SBS is an independent, community-maintained initiative. It is not a Salesforce product and is not endorsed by Salesforce, Inc.",[],{"_type":17,"description":2427,"shareImage":2428,"title":2430},"Get a practical sequence for assessing your Salesforce org against the Security Benchmark for Salesforce (SBS), including what to build first, where the easy wins are, and how to avoid doing it all twice.",{"_type":40,"asset":2429},{"_ref":1946,"_type":278},"Salesforce SBS Gap Analysis",{"_type":22,"current":2432},"how-to-run-an-sbs-gap-analysis",{"_createdAt":2434,"_id":985,"_rev":2435,"_system":2436,"_type":33,"_updatedAt":2439,"author":2440,"category":2483,"featuredImage":2489,"modularContent":2520,"postTitle":2490,"publishDate":2524,"richText":2525,"seo":3121,"slug":3126},"2026-07-10T19:02:46Z","fB1zqXIO2KOGAEcZYW0rzA",{"base":2437},{"id":985,"rev":2438},"Y1CGxGfXOTPJaN8tmA2BgK","2026-07-29T18:20:01Z",{"authorImage":2441,"authorJobTitle":2481,"authorName":2482},{"_type":37,"altText":2442,"image":2443},"Eran Kirshenboim, CTO at Sweep.io",{"_type":40,"asset":2444},{"_createdAt":2445,"_id":2446,"_rev":2447,"_type":45,"_updatedAt":2445,"assetId":2448,"extension":2449,"metadata":2450,"mimeType":2475,"originalFilename":2476,"path":2477,"sha1hash":2448,"size":2478,"uploadId":2479,"url":2480},"2026-07-10T19:18:16Z","image-4bce4e75c4ffada0efd37c5c03c0cdb18c156046-512x512-jpg","khhsqOtE7Pk10cRji75GxI","4bce4e75c4ffada0efd37c5c03c0cdb18c156046","jpg",{"_type":50,"blurHash":2451,"dimensions":2452,"hasAlpha":56,"isOpaque":57,"lqip":2454,"palette":2455},"eFKT0r~B0057K6-pIp9Zxax]0Ms.$hIp?GxtR*E2NHaeVss:?HR+IU",{"_type":53,"aspectRatio":54,"height":2453,"width":2453},512,"data:image/jpeg;base64,/9j/2wBDAAYEBQYFBAYGBQYHBwYIChAKCgkJChQODwwQFxQYGBcUFhYaHSUfGhsjHBYWICwgIyYnKSopGR8tMC0oMCUoKSj/2wBDAQcHBwoIChMKChMoGhYaKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCj/wAARCAAUABQDASIAAhEBAxEB/8QAGAABAQEBAQAAAAAAAAAAAAAAAAYHBAj/xAAmEAABBAECBgIDAAAAAAAAAAABAgMEBQAGEQcSEyFBUTFxCBQi/8QAFQEBAQAAAAAAAAAAAAAAAAAABQT/xAAeEQACAwABBQAAAAAAAAAAAAAAAQIDIRESMkFhgf/aAAwDAQACEQMRAD8AkuANA5CmptLCP1WSkFrYb/PnNm4o0um7WpccdjD9xTJKXEDuDt5yL/Hi4ErSTkVwNiSyrpgEdwn3l5qqZAp6CxfnlHI0ndK/Z9DDLJS62MVQg60/B4uuEIanLQlKgB7GM7tVWQuLt+Ww30mTsltO238jGIp5oTJLnDfdIITXadjWEJIakJAJKfhX2MmeIdlKuIXUnOlYLhHIOyQPrGMhr7/ojblfHozxqGyU90ecYxlbJEj/2Q==",{"_type":60,"darkMuted":2456,"darkVibrant":2459,"dominant":2462,"lightMuted":2463,"lightVibrant":2466,"muted":2469,"vibrant":2472},{"_type":62,"background":2457,"foreground":64,"population":2458,"title":64},"#624334",3.73,{"_type":62,"background":2460,"foreground":64,"population":2461,"title":64},"#3a1c0b",0.07,{"_type":62,"background":2457,"foreground":64,"population":2458,"title":64},{"_type":62,"background":2464,"foreground":72,"population":2465,"title":64},"#c99c83",2.01,{"_type":62,"background":2467,"foreground":72,"population":2468,"title":72},"#fcbc99",2.6,{"_type":62,"background":2470,"foreground":64,"population":2471,"title":64},"#a17159",2.09,{"_type":62,"background":2473,"foreground":64,"population":2474,"title":64},"#b07e5a",0.92,"image/jpeg","eran.jpg","images/9eu1m6zu/production/4bce4e75c4ffada0efd37c5c03c0cdb18c156046-512x512.jpg",46829,"0befd8f9a4e4add012063b65f0e3fb86557ebc59","https://cdn.sanity.io/images/9eu1m6zu/production/4bce4e75c4ffada0efd37c5c03c0cdb18c156046-512x512.jpg","Sweep CTO","Eran Kirshenboim",{"_createdAt":5,"_id":6,"_rev":7,"_system":2484,"_type":11,"_updatedAt":12,"selectedColor":2486,"seo":2487,"slug":2488,"title":24},{"base":2485},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":2490,"image":2491},"The New Security Benchmark for Salesforce, Explained",{"_type":40,"asset":2492},{"_createdAt":2493,"_id":2494,"_rev":2495,"_type":45,"_updatedAt":2493,"assetId":2496,"extension":106,"metadata":2497,"mimeType":132,"originalFilename":853,"path":2516,"sha1hash":2496,"size":2517,"uploadId":2518,"url":2519},"2026-07-10T19:19:43Z","image-bdea30ac9ce2b663eb727ccf9111baae4b5a9365-1200x630-png","khhsqOtE7Pk10cRji75NBM","bdea30ac9ce2b663eb727ccf9111baae4b5a9365",{"_type":50,"blurHash":2498,"dimensions":2499,"hasAlpha":57,"isOpaque":57,"lqip":2500,"palette":2501},"M7Axj:?aNPN5V=S.WDoGa~bJ4#D.t0xsoh",{"_type":53,"aspectRatio":110,"height":111,"width":112},"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAAsTAAALEwEAmpwYAAABM0lEQVR4nK2SXUsCQRSG/Ye5Su6HFEWkRGtpJbajOyoiaZL5EVL628KL6CKjC8sIXN0nll27iKwELw7vYc7Mczhz3lDYgnVGaO1AxYKIgEg+UAGK8IsLXQkYzYNegu2KH1sViJfBCMKreaoV/aZ/AjdtSFxCpgMnXTi7gXQH0m3/7KjlYjZd9usuMekSttzfgXrJfyz6kO+DPfBV3Hk6I9ebYjYddqsOqnSICAdFzJcDjTJkulAYQCGAWreQ683JdidkW8+kGk8kqiP2KiN2yi9o9sdSaEiVkGz4455647Yhde1yeDXjoDbGrD1wXL8nVRtiXgxJVh8x5ATFWgJUBMRsMILP14v+AlTpotpTNHtCXI4x5Cu6fEOz34kKZwUfnn+/tFiEy8ZX/k9je578KV/Fh5+OzW0GrS/lTAAAAABJRU5ErkJggg==",{"_type":60,"darkMuted":2502,"darkVibrant":2504,"dominant":2505,"lightMuted":2507,"lightVibrant":2510,"muted":2513,"vibrant":2515},{"_type":62,"background":2503,"foreground":64,"population":125,"title":64},"#447689",{"_type":62,"background":838,"foreground":64,"population":82,"title":64},{"_type":62,"background":840,"foreground":64,"population":2506,"title":64},74.11,{"_type":62,"background":2508,"foreground":72,"population":2509,"title":64},"#d0c9a6",0.25,{"_type":62,"background":2511,"foreground":64,"population":2512,"title":64},"#5c7bf9",1.55,{"_type":62,"background":2514,"foreground":64,"population":125,"title":64},"#ae8461",{"_type":62,"background":840,"foreground":64,"population":2506,"title":64},"images/9eu1m6zu/production/bdea30ac9ce2b663eb727ccf9111baae4b5a9365-1200x630.png",84357,"eb205860ea56d6aaebfdf1dc2d209f117ba8d131","https://cdn.sanity.io/images/9eu1m6zu/production/bdea30ac9ce2b663eb727ccf9111baae4b5a9365-1200x630.png",[2521],{"_key":2522,"_type":275,"cols":276,"filterByCategory":2523,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":279},"2beb2645ee5fee374bd06c85ef14f0a4",{"_ref":6,"_type":278},"2026-07-10",[2526,2549,2564,2571,2589,2596,2611,2627,2645,2660,2667,2674,2695,2703,2715,2723,2730,2751,2771,2778,2785,2792,2813,2821,2837,2852,2859,2867,2882,2893,2901,2909,2917,2929,2941,2953,2978,2998,3006,3013,3031,3038,3046,3067,3075,3083,3090],{"_key":2527,"_type":172,"children":2528,"markDefs":2548,"style":180},"f338de5f4e5a",[2529,2533,2537,2541,2545],{"_key":2530,"_type":176,"marks":2531,"text":2532},"77981ea2f0cd",[],"In truth, nobody fully ",{"_key":2534,"_type":176,"marks":2535,"text":2536},"42bae2902749",[393],"designs",{"_key":2538,"_type":176,"marks":2539,"text":2540},"30f412714e40",[]," a Salesforce org.  Orgs ",{"_key":2542,"_type":176,"marks":2543,"text":2544},"aa9de26a7f7c",[393],"happen",{"_key":2546,"_type":176,"marks":2547,"text":374},"c6739df0e14a",[],[],{"_key":2550,"_type":172,"children":2551,"markDefs":2563,"style":180},"c8e2165714cb",[2552,2555,2559],{"_key":2538,"_type":176,"marks":2553,"text":2554},[],"A permission set gets cloned for one project and outlives it by four years. An integration user picks up ",{"_key":2556,"_type":176,"marks":2557,"text":2558},"67569a1306fb",[369],"Modify All Data ",{"_key":2560,"_type":176,"marks":2561,"text":2562},"9b2978f9da01",[],"during a migration weekend and keeps it. A connected app gets authorized by whoever clicked \"allow\" first. ",[],{"_key":2565,"_type":172,"children":2566,"markDefs":2570,"style":180},"e435ddea6bab",[2567],{"_key":2538,"_type":176,"marks":2568,"text":2569},[],"Ask a mature enterprise three questions: who has access to what, why, and is that still appropriate… and the honest answer is usually a shrug, if not backed by institutional knowledge.",[],{"_key":2572,"_type":172,"children":2573,"markDefs":2586,"style":180},"866fa3267afc",[2574,2578,2582],{"_key":2575,"_type":176,"marks":2576,"text":2577},"b01aa7b293cb",[],"The ",{"_key":2579,"_type":176,"marks":2580,"text":1999},"9019eb68e863",[2581],"9aeee3982d9d",{"_key":2583,"_type":176,"marks":2584,"text":2585},"a450dbc4bd5e",[]," (SBS) exists to replace that very shrug. ",[2587],{"_key":2581,"_type":151,"blank":57,"href":2588,"noOpener":57,"noReferrer":57,"url":2588},"https://docs.securitybenchmark.org/introduction.html",{"_key":2590,"_type":172,"children":2591,"markDefs":2595,"style":180},"29830218550e",[2592],{"_key":2583,"_type":176,"marks":2593,"text":2594},[],"It's a new, formal, independent compliance standard that defines mandatory, auditable requirements for securing Salesforce environments, the same role CIS Benchmarks play for operating systems and cloud platforms. ",[],{"_key":2597,"_type":172,"children":2598,"markDefs":2610,"style":180},"10db933bd243",[2599,2602,2606],{"_key":2583,"_type":176,"marks":2600,"text":2601},[],"Where NIST and ISO define program-level principles, SBS helpfully translates them into ",{"_key":2603,"_type":176,"marks":2604,"text":2605},"d78bae6e19a8",[393],"Salesforce-specific language",{"_key":2607,"_type":176,"marks":2608,"text":2609},"2a3cfec5ef98",[],": concrete requirements, written against  platform behavior, that an org either meets with a yes or doesn't with a no.",[],{"_key":2612,"_type":172,"children":2613,"markDefs":2626,"style":180},"2706a914a08a",[2614,2618,2622],{"_key":2615,"_type":176,"marks":2616,"text":2617},"49313da3fa53",[],"As of this writing, the SBS benchmark spans a full",{"_key":2619,"_type":176,"marks":2620,"text":2621},"d8ada94d1f42",[369]," 54 controls across 12 domains",{"_key":2623,"_type":176,"marks":2624,"text":2625},"499a7f5e0acf",[],": access controls, authentication, OAuth security, integrations, deployments, code security, customer portals, data security, file security, event monitoring, security configuration, and a foundations domain that anchors the rest. ",[],{"_key":2628,"_type":172,"children":2629,"markDefs":2642,"style":180},"3a2cb37125eb",[2630,2633,2638],{"_key":2615,"_type":176,"marks":2631,"text":2632},[],"It's practitioner-developed and community-maintained ",{"_key":2634,"_type":176,"marks":2635,"text":2637},"3580bebf42b4",[2636],"abd34fcaf105","on GitHub",{"_key":2639,"_type":176,"marks":2640,"text":2641},"0e789540c036",[],", with a chief editor overseeing structure and releases.",[2643],{"_key":2636,"_type":151,"blank":57,"href":2644,"noOpener":57,"noReferrer":57,"url":2644},"https://github.com/Salesforce-Security-Benchmark/docs-site/",{"_key":2646,"_type":172,"children":2647,"markDefs":2659,"style":180},"1f20a81fd841",[2648,2652,2656],{"_key":2649,"_type":176,"marks":2650,"text":2651},"388fc619b278",[],"Two things SBS is ",{"_key":2653,"_type":176,"marks":2654,"text":2655},"605b048154c9",[393],"not",{"_key":2657,"_type":176,"marks":2658,"text":374},"3feffd04ba29",[],[],{"_key":2661,"_type":172,"children":2662,"level":54,"listItem":309,"markDefs":2666,"style":180},"c7a1fd604e41",[2663],{"_key":2657,"_type":176,"marks":2664,"text":2665},[],"It's not a cert program, ",[],{"_key":2668,"_type":172,"children":2669,"level":54,"listItem":309,"markDefs":2673,"style":180},"cdc158339e83",[2670],{"_key":2657,"_type":176,"marks":2671,"text":2672},[],"and it doesn't replace regulatory obligations.",[],{"_key":2675,"_type":172,"children":2676,"markDefs":2693,"style":180},"b0435ced151b",[2677,2680,2685,2689],{"_key":2657,"_type":176,"marks":2678,"text":2679},[],"And it's not a Salesforce product, ",{"_key":2681,"_type":176,"marks":2682,"text":2684},"bac03d6a2450",[2683],"e1d24bdcd1ee","in their own words",{"_key":2686,"_type":176,"marks":2687,"text":2688},"b6eef0f467c4",[],": “",{"_key":2690,"_type":176,"marks":2691,"text":2692},"afa959b89349",[393],"SBS is not a certification program and does not replace regulatory or compliance obligations. It is an independent initiative, not a Salesforce product, and is not endorsed or supported by Salesforce, Inc.”",[2694],{"_key":2683,"_type":151,"blank":57,"href":2588,"noOpener":57,"noReferrer":57,"url":2588},{"_key":2696,"_type":172,"children":2697,"markDefs":2702,"style":920},"31af3a9a42d5",[2698],{"_key":2699,"_type":176,"marks":2700,"text":2701},"e284981ffa21",[],"How the controls work",[],{"_key":2704,"_type":172,"children":2705,"markDefs":2714,"style":180},"498be914d2e7",[2706,2710],{"_key":2707,"_type":176,"marks":2708,"text":2709},"bb836f1f4299",[369],"Every SBS control",{"_key":2711,"_type":176,"marks":2712,"text":2713},"c4319280b2f3",[]," follows the same anatomy: a unique ID, a single-sentence requirement, an audit procedure that describes exactly how to check compliance, remediation steps, and usefully Salesforce's default behavior for that setting (which is often the root of the problem).",[],{"_key":2716,"_type":172,"children":2717,"markDefs":2722,"style":180},"53260792b2a6",[2718],{"_key":2719,"_type":176,"marks":2720,"text":2721},"b65676a186ae",[],"As stated before, compliance is black-and-white binary. ",[],{"_key":2724,"_type":172,"children":2725,"markDefs":2729,"style":180},"820727e3e661",[2726],{"_key":2719,"_type":176,"marks":2727,"text":2728},[],"If a requirement isn't satisfied, the environment is noncompliant. Partial compliance is not recognized. Compensating controls don't count unless your internal security authority formally documents and accepts them. That rigidity is deliberate and important… a standard you can partially meet is a standard nobody meets.",[],{"_key":2731,"_type":172,"children":2732,"markDefs":2746,"style":180},"a75536b3ebb0",[2733,2737,2742],{"_key":2734,"_type":176,"marks":2735,"text":2736},"f0abebd0c041",[],"Each control also carries ",{"_key":2738,"_type":176,"marks":2739,"text":2741},"756a61804c2e",[2740],"286c75f58d9d","a risk tier",{"_key":2743,"_type":176,"marks":2744,"text":2745},"1d46f290df71",[],", assigned through three questions applied in order: ",[2747],{"_key":2740,"_ref":2748,"_type":328,"linkType":33,"slug":2749},"0504af25-bd53-4845-9afb-7446e90ebd33",{"_type":22,"current":2750},"2026s-most-dangerous-salesforce-trend",{"_key":2752,"_type":172,"children":2753,"level":54,"listItem":309,"markDefs":2766,"style":180},"79bf063eedb2",[2754,2757,2762],{"_key":2743,"_type":176,"marks":2755,"text":2756},[],"Does the control establish a ",{"_key":2758,"_type":176,"marks":2759,"text":2761},"7bfc4bd32522",[2760],"b5214a73f5fa","security boundary,",{"_key":2763,"_type":176,"marks":2764,"text":2765},"111c6163c9d5",[]," meaning its failure alone lets someone gain access or exceed their permissions? Critical. ",[2767],{"_key":2760,"_ref":2768,"_type":328,"linkType":33,"slug":2769},"d78370ef-b861-4d98-87c1-4cbab41d63a2",{"_type":22,"current":2770},"the-new-perimeter-the-agentic-layer",{"_key":2772,"_type":172,"children":2773,"level":54,"listItem":309,"markDefs":2777,"style":180},"cb32c09ef379",[2774],{"_key":2743,"_type":176,"marks":2775,"text":2776},[],"Does it provide visibility, meaning its failure lets incidents go undetected or uninvestigated? High. ",[],{"_key":2779,"_type":172,"children":2780,"level":54,"listItem":309,"markDefs":2784,"style":180},"24f322733632",[2781],{"_key":2743,"_type":176,"marks":2782,"text":2783},[],"Does it add assurance while other controls still provide coverage? Moderate. ",[],{"_key":2786,"_type":172,"children":2787,"markDefs":2791,"style":180},"69650d303998",[2788],{"_key":2743,"_type":176,"marks":2789,"text":2790},[],"SSO enforcement is Critical. Persistent application logging is High. Peer code review is Moderate, as static analysis and testing catch the same issues.  ",[],{"_key":2793,"_type":172,"children":2794,"markDefs":2808,"style":180},"9be821b09535",[2795,2799,2804],{"_key":2796,"_type":176,"marks":2797,"text":2798},"bb3e9c4f5ab3",[],"Controls are also tagged against ",{"_key":2800,"_type":176,"marks":2801,"text":2803},"666db3c0c4d8",[2802],"8860511f0ccf","HIPAA",{"_key":2805,"_type":176,"marks":2806,"text":2807},"f1c3660451c4",[],", GDPR, NIST, CCPA/CPRA, SOC 2, and ISO 27001… and the tagging philosophy is refreshingly strict. A control gets tagged only when an auditor for that framework would expect to see it as evidence. Most controls map to one to three frameworks, and the maintainers state directly that under-tagging is preferable to over-tagging. In a world of compliance-mapping matrices where every row checks every column, restraint is a credibility signal in our book. ",[2809],{"_key":2802,"_ref":2810,"_type":328,"linkType":33,"slug":2811},"d1fb9635-3286-4666-a673-5e6751ad2182",{"_type":22,"current":2812},"salesforce-documentation-the-complete-living-source-of-truth-with-ai",{"_key":2814,"_type":172,"children":2815,"markDefs":2820,"style":920},"474b10a30092",[2816],{"_key":2817,"_type":176,"marks":2818,"text":2819},"460e7b3b7024",[],"The pattern hiding in the control list",[],{"_key":2822,"_type":172,"children":2823,"markDefs":2836,"style":180},"d6cdf9518a82",[2824,2828,2832],{"_key":2825,"_type":176,"marks":2826,"text":2827},"2fdc7dfff3e3",[],"We read ",{"_key":2829,"_type":176,"marks":2830,"text":2831},"970b94d16959",[369],"all 54 controls in one sitting",{"_key":2833,"_type":176,"marks":2834,"text":2835},"9b78113ea9be",[]," and a pattern emerged that the domain structure obscures. ",[],{"_key":2838,"_type":172,"children":2839,"markDefs":2851,"style":180},"c7db35e54f84",[2840,2843,2847],{"_key":2825,"_type":176,"marks":2841,"text":2842},[],"Count the recurring phrases: ",{"_key":2844,"_type":176,"marks":2845,"text":2846},"702de9f98022",[393],"documented justification. Authoritative inventory. System of record.",{"_key":2848,"_type":176,"marks":2849,"text":2850},"c76f9098501c",[]," They appear in the access controls domain, the OAuth domain, the integrations domain, the data security domain. ",[],{"_key":2853,"_type":172,"children":2854,"markDefs":2858,"style":180},"ee31c0c08944",[2855],{"_key":2848,"_type":176,"marks":2856,"text":2857},[],"The very first control in the benchmark (SBS-FDNS-001) requires a centralized system of record documenting all security configurations, exceptions, justifications, and required inventories before anything else. SBS is a security benchmark on the front cover and a documentation mandate in Chapter 1. ",[],{"_key":2860,"_type":172,"children":2861,"markDefs":2866,"style":180},"a31fa5277af2",[2862],{"_key":2863,"_type":176,"marks":2864,"text":2865},"234593db3223",[],"Comparatively, few controls order you to change a setting. ",[],{"_key":2868,"_type":172,"children":2869,"markDefs":2881,"style":180},"507719769546",[2870,2873,2877],{"_key":2863,"_type":176,"marks":2871,"text":2872},[],"Most order you to be able to ",{"_key":2874,"_type":176,"marks":2875,"text":2876},"b853ddf3ec4f",[393],"explain",{"_key":2878,"_type":176,"marks":2879,"text":2880},"05371ea8c428",[]," your settings (every API-enabled permission, every super-admin-equivalent user, every connected app, every remote site, every SSO bypass) with a written reason, in a maintained record, reviewed on a cadence. ",[],{"_key":2883,"_type":172,"children":2884,"markDefs":2892,"style":180},"0310dade0a5a",[2885,2888],{"_key":2878,"_type":176,"marks":2886,"text":2887},[],"The benchmark's authors say it themselves: SBS doesn't demand perfection. ",{"_key":2889,"_type":176,"marks":2890,"text":2891},"09c11a8ab655",[369],"\"It requires knowing where you stand.\" ",[],{"_key":2894,"_type":172,"children":2895,"markDefs":2900,"style":180},"e521274cdd0a",[2896],{"_key":2897,"_type":176,"marks":2898,"text":2899},"5562ab64ed3b",[],"That framing is helpful because it inverts the usual security posture… The threat model here isn't the usual sophisticated attacker wearing a black hoodie, but rather org-wide amnesia. The org where nobody remembers why the setting is the way it is, so nobody dares touch it, so it stays wrong forever.",[],{"_key":2902,"_type":172,"children":2903,"markDefs":2908,"style":920},"95b363b7e28f",[2904],{"_key":2905,"_type":176,"marks":2906,"text":2907},"f9e4b0e413aa",[],"Running a gap analysis",[],{"_key":2910,"_type":172,"children":2911,"markDefs":2916,"style":180},"f04910d3d03c",[2912],{"_key":2913,"_type":176,"marks":2914,"text":2915},"fa1b9d10b29f",[],"A practical sequence, based on how the controls cluster:",[],{"_key":2918,"_type":172,"children":2919,"level":54,"listItem":945,"markDefs":2928,"style":180},"44ef0da87e51",[2920,2924],{"_key":2921,"_type":176,"marks":2922,"text":2923},"4fbc13b21f84",[369],"Pin your version.",{"_key":2925,"_type":176,"marks":2926,"text":2927},"3cd94be09dfe",[]," Published SBS versions are immutable, but major releases can add, remove, or renumber controls… the benchmark grew from roughly two dozen controls to 54 in its early releases, fairly quickly it seems. Record which version you assessed against, or your audit trail will mean nothing in a year.",[],{"_key":2930,"_type":172,"children":2931,"level":54,"listItem":945,"markDefs":2940,"style":180},"2ffac7d5b7b2",[2932,2936],{"_key":2933,"_type":176,"marks":2934,"text":2935},"82e3cdcf6c3e",[369],"Stand up the system of record first.",{"_key":2937,"_type":176,"marks":2938,"text":2939},"93172f6cb319",[]," FDNS-001 isn't numbered first by accident. Roughly a third of the remaining controls deposit their evidence ( inventories, justifications, exceptions) into it. Do this without it and you'll end up doing it twice.",[],{"_key":2942,"_type":172,"children":2943,"level":54,"listItem":945,"markDefs":2952,"style":180},"11e2dbffb65f",[2944,2948],{"_key":2945,"_type":176,"marks":2946,"text":2947},"1f0c9ffd826b",[369],"Enumerate the cheap domains next.",{"_key":2949,"_type":176,"marks":2950,"text":2951},"2b838a00a6ed",[]," Access controls, OAuth, and integrations are mostly metadata questions: which profiles grant API Enabled, which connected apps were never formally installed, which remote site settings exist and why. This is queryable in hours if you have org visibility, and a quarter-long archaeology project if you don't.",[],{"_key":2954,"_type":172,"children":2955,"level":54,"listItem":945,"markDefs":2973,"style":180},"709cc31eff4f",[2956,2960,2964,2969],{"_key":2957,"_type":176,"marks":2958,"text":2959},"2adfb90f22a2",[369],"Budget real time for the mechanism controls.",{"_key":2961,"_type":176,"marks":2962,"text":2963},"e33d86910063",[]," Some requirements, like ",{"_key":2965,"_type":176,"marks":2966,"text":2968},"71c039c46211",[2967],"4554993b4f61","continuous detection",{"_key":2970,"_type":176,"marks":2971,"text":2972},"f8c9fcecab96",[]," of regulated data in long text fields, monitoring for unauthorized metadata changes, demand ongoing capability, not a one-time check. These are where \"we'll just do it manually\" quietly dies.",[2974],{"_key":2967,"_ref":2975,"_type":328,"linkType":33,"slug":2976},"2a8020a3-daed-4754-8c1c-e6d315aa6363",{"_type":22,"current":2977},"how-to-detect-cross-org-drift-before-it-becomes-a-revenue-problem",{"_key":2979,"_type":172,"children":2980,"level":54,"listItem":945,"markDefs":2997,"style":180},"bbb4341e48e5",[2981,2985,2989,2993],{"_key":2982,"_type":176,"marks":2983,"text":2984},"5f21c4fe9f03",[369],"Fail honestly.",{"_key":2986,"_type":176,"marks":2987,"text":2988},"6ebb96ab2873",[]," Binary means ",{"_key":2990,"_type":176,"marks":2991,"text":2992},"044a2b9661e5",[369],"binary",{"_key":2994,"_type":176,"marks":2995,"text":2996},"21a83a2d0d98",[],". An inventory that's 90% complete is a noncompliant inventory. Document the exception, assign the remediation, and let the standard do what standards are for.",[],{"_key":2999,"_type":172,"children":3000,"markDefs":3005,"style":180},"0c018c83f70f",[3001],{"_key":3002,"_type":176,"marks":3003,"text":3004},"3ea9a9fe7352",[],"On tooling: SBS published its full control set as machine-readable XML specifically so vendors can automate assessment, and the maintainers are explicit that the benchmark defines what to check while vendors supply the scanning logic. I think we can expect a gap-analysis tooling ecosystem to form around this quickly. ",[],{"_key":3007,"_type":172,"children":3008,"markDefs":3012,"style":180},"a2d734956843",[3009],{"_key":3002,"_type":176,"marks":3010,"text":3011},[],"\n*****",[],{"_key":3014,"_type":172,"children":3015,"markDefs":3028,"style":180},"2c9f4bb23c8c",[3016,3020,3025],{"_key":3017,"_type":176,"marks":3018,"text":3019},"18ce6fe5f7cf",[393],"🪄 For more, check out our our latest, more detailed guide here: ",{"_key":3021,"_type":176,"marks":3022,"text":3024},"07573507052f",[3023,393],"bde5ccc521d6","How to Run an SBS Gap Analysis",{"_key":3026,"_type":176,"marks":3027,"text":3011},"37f782a62889",[],[3029],{"_key":3023,"_ref":1913,"_type":328,"linkType":33,"slug":3030},{"_type":22,"current":2432},{"_key":3032,"_type":172,"children":3033,"markDefs":3037,"style":180},"5b200c916d28",[3034],{"_key":3035,"_type":176,"marks":3036,"text":187},"4d25cd47bf47",[],[],{"_key":3039,"_type":172,"children":3040,"markDefs":3045,"style":920},"b5b41547e1fd",[3041],{"_key":3042,"_type":176,"marks":3043,"text":3044},"460ebe3b3d63",[],"The chapter that hasn't been written",[],{"_key":3047,"_type":172,"children":3048,"markDefs":3062,"style":180},"0a2ce71e0b02",[3049,3053,3058],{"_key":3050,"_type":176,"marks":3051,"text":3052},"e77045c9a74f",[],"For all its coverage, the benchmark has a conspicuous blank space: ",{"_key":3054,"_type":176,"marks":3055,"text":3057},"c584dc93448d",[3056],"ad88da5cbfd7","agents",{"_key":3059,"_type":176,"marks":3060,"text":3061},"f75e5a3c9af1",[],". The closest it gets is a strong set of controls on non-human identities… inventory them, restrict their broad privileges, add compensating controls when they're privileged. Necessary, and written for a world of static integration users. ",[3063],{"_key":3056,"_ref":3064,"_type":328,"linkType":738,"slug":3065},"22717211-f1f7-44d7-9327-93e9d63c7cdb",{"_type":22,"current":3066},"metadata-agents",{"_key":3068,"_type":172,"children":3069,"markDefs":3074,"style":180},"ea980a9ceaf6",[3070],{"_key":3071,"_type":176,"marks":3072,"text":3073},"61a31299f197",[],"AI agents are non-human identities with another big difference: their action surface changes at runtime. An agent operating inside a Salesforce org authenticates like an integration user but behaves like an employee, one that works at machine speed and never files a ticket. Which permissions it exercises, which records it touches, and which metadata it modifies are questions the current control set doesn't yet ask. It's an open, community-maintained standard, so those controls will get written. The interesting question is by whom.",[],{"_key":3076,"_type":172,"children":3077,"markDefs":3082,"style":180},"6739dad18c78",[3078],{"_key":3079,"_type":176,"marks":3080,"text":3081},"83f01960b7ee",[],"The deeper idea in SBS holds either way. ",[],{"_key":3084,"_type":172,"children":3085,"markDefs":3089,"style":180},"07dc03d7a449",[3086],{"_key":3079,"_type":176,"marks":3087,"text":3088},[],"The benchmark never asks you to simplify your org. It asks you to make your org legible… every permission explainable, every integration justified, every change attributable. ",[],{"_key":3091,"_type":172,"children":3092,"markDefs":3114,"style":180},"ee59ba66b48c",[3093,3096,3100,3105,3109],{"_key":3079,"_type":176,"marks":3094,"text":3095},[],"As we’ve said time and time again here, complexity is never the disqualifying condition. Illegibility is. And an org that can answer the benchmark's questions for an auditor is, not coincidentally, an org that can answer them for anything else you invite inside.\n——\n\n",{"_key":3097,"_type":176,"marks":3098,"text":3099},"463bfd8503bb",[393],"For more helpful security in Salesforce news and information, check out our ",{"_key":3101,"_type":176,"marks":3102,"text":3104},"a44d952022e7",[3103,393],"86db0c8b13c3","Resources Hub",{"_key":3106,"_type":176,"marks":3107,"text":3108},"37c0eaa50b31",[393],", as well as ",{"_key":3110,"_type":176,"marks":3111,"text":3113},"f4da5fd48a5e",[3112,393],"f96d011ed1e7","Security-focused content.",[3115,3117],{"_key":3112,"_ref":1464,"_type":328,"linkType":738,"slug":3116},{"_type":22,"current":1466},{"_key":3103,"_ref":3118,"_type":328,"linkType":738,"slug":3119},"cf41ff2a-ac3c-4f9a-a47f-453b2d727f6e",{"_type":22,"current":3120},"resources",{"_type":17,"description":3122,"shareImage":3123,"title":3125},"SBS defines dozens of auditable, pass/fail controls for Salesforce security. Here's what the benchmark requires, how the risk tiers work, and how to run a gap analysis.",{"_type":40,"asset":3124},{"_ref":2494,"_type":278},"Salesforce Security Benchmark",{"_type":22,"current":987},{"_createdAt":3128,"_id":3129,"_rev":3130,"_system":3131,"_type":33,"_updatedAt":3134,"author":3135,"category":3151,"featuredImage":3157,"modularContent":3190,"postTitle":3193,"publishDate":3194,"richText":3195,"seo":3506,"slug":3511},"2026-07-09T14:16:00Z","f32deb4c-7902-4237-bf07-982b1e5ead2e","glaCZpWrgFDvTLVjGQUN1g",{"base":3132},{"id":3129,"rev":3133},"xWUapYXK662od3tII9dyct","2026-07-09T16:44:40Z",{"authorImage":3136,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":38,"image":3137},{"_type":40,"asset":3138},{"_createdAt":42,"_id":43,"_rev":44,"_type":45,"_updatedAt":46,"altText":19,"assetId":47,"description":19,"extension":48,"metadata":3139,"mimeType":83,"opt":3149,"originalFilename":86,"path":87,"sha1hash":47,"size":88,"title":19,"uploadId":89,"url":90},{"_type":50,"blurHash":51,"dimensions":3140,"hasAlpha":56,"isOpaque":57,"lqip":58,"palette":3141},{"_type":53,"aspectRatio":54,"height":55,"width":55},{"_type":60,"darkMuted":3142,"darkVibrant":3143,"dominant":3144,"lightMuted":3145,"lightVibrant":3146,"muted":3147,"vibrant":3148},{"_type":62,"background":63,"foreground":64,"population":65,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":71,"foreground":72,"population":73,"title":64},{"_type":62,"background":75,"foreground":72,"population":76,"title":72},{"_type":62,"background":78,"foreground":64,"population":79,"title":64},{"_type":62,"background":81,"foreground":64,"population":82,"title":64},{"media":3150},{"tags":19},{"_createdAt":5,"_id":6,"_rev":7,"_system":3152,"_type":11,"_updatedAt":12,"selectedColor":3154,"seo":3155,"slug":3156,"title":24},{"base":3153},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":3158,"image":3159},"78% of Enterprises Have Already Had an AI Incident... Here's Why",{"_type":40,"asset":3160},{"_createdAt":3161,"_id":3162,"_rev":3163,"_type":45,"_updatedAt":3161,"assetId":3164,"extension":106,"metadata":3165,"mimeType":132,"originalFilename":853,"path":3186,"sha1hash":3164,"size":3187,"uploadId":3188,"url":3189},"2026-07-09T16:43:11Z","image-78afbb2f83676eaf98cb38c90839aeaba0d825e9-1200x630-png","xWUapYXK662od3tII9dy0h","78afbb2f83676eaf98cb38c90839aeaba0d825e9",{"_type":50,"blurHash":3166,"dimensions":3167,"hasAlpha":57,"isOpaque":57,"lqip":3168,"palette":3169},"MDSqU2I?$~-SWW-la|fQj@fQ~7-lNIRloK",{"_type":53,"aspectRatio":110,"height":111,"width":112},"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAAsTAAALEwEAmpwYAAABB0lEQVR4nK2SwW6CQBCG972Ku+juy7a2NxQxkTvuRmy8GbHag/ZeBarVv9lFoqWAmvTwZZJN9p/JN0OOY4FLDmFG8f1WiAk58R/BpOpz3qSsWW3gdygQS4FNkNVYccSSI1G/SRXHbnRunA9xKEASybEaNBG5DEvPxluPYe5SUzWLHsOyz/DeZ1j7TWyCVq0Ksh1yRF2G8MnCuN0wdfT4YGrO67OFsG1h8tLAamDjS/LqwFQJrP0Wpg7D1KGYdSkil2Lunib0bCw8ZprOOhQfvo1U8kqvRDtMpMBnwA1bmaE9ap+JEsaheR9mPvcXLo+VZ6Ollmz33k2TP5uqOaOb77B4zNeoC/wBzqKXk3TJxRkAAAAASUVORK5CYII=",{"_type":60,"darkMuted":3170,"darkVibrant":3172,"dominant":3174,"lightMuted":3177,"lightVibrant":3179,"muted":3182,"vibrant":3185},{"_type":62,"background":3171,"foreground":64,"population":1737,"title":64},"#643d45",{"_type":62,"background":3173,"foreground":64,"population":1378,"title":64},"#796c14",{"_type":62,"background":3175,"foreground":72,"population":3176,"title":72},"#fcd444",74.92,{"_type":62,"background":3178,"foreground":72,"population":125,"title":64},"#c09490",{"_type":62,"background":3180,"foreground":72,"population":3181,"title":72},"#fbd04c",1.73,{"_type":62,"background":3183,"foreground":64,"population":3184,"title":64},"#a58468",0.17,{"_type":62,"background":3175,"foreground":72,"population":3176,"title":72},"images/9eu1m6zu/production/78afbb2f83676eaf98cb38c90839aeaba0d825e9-1200x630.png",76957,"b55ffd3a5a3ff4e45e4fc37a383deecb5f578bbf","https://cdn.sanity.io/images/9eu1m6zu/production/78afbb2f83676eaf98cb38c90839aeaba0d825e9-1200x630.png",[3191],{"_key":3192,"_type":275,"cols":276,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":279},"a1d561778993fb4d4be9bff832ff58ed"," 78% of Enterprises Have Already Had an AI Incident... Here's Why","2026-07-09",[3196,3203,3230,3238,3246,3261,3272,3288,3295,3316,3324,3332,3348,3356,3373,3390,3407,3414,3422,3430,3451,3471,3490,3498],{"_key":3197,"_type":172,"children":3198,"markDefs":3202,"style":292},"3d720b534cc2",[3199],{"_key":3200,"_type":176,"marks":3201,"text":290},"4543e044d86d",[],[],{"_key":3204,"_type":172,"children":3205,"markDefs":3227,"style":180},"2bfcec89322c",[3206,3210,3215,3219,3223],{"_key":3207,"_type":176,"marks":3208,"text":3209},"65ab46988bd4",[393],"DigiCert's ",{"_key":3211,"_type":176,"marks":3212,"text":3214},"0508d3347fdf",[393,3213],"ceec90b8572e","new AI Trust Outlook",{"_key":3216,"_type":176,"marks":3217,"text":3218},"86b3db09868a",[393]," (1,001 IT and security leaders, May 2026) found that 78% of organizations have already experienced an AI-related incident or identified an AI-related vulnerability. Nearly ",{"_key":3220,"_type":176,"marks":3221,"text":3222},"7b1f386cd61e",[393,369],"half",{"_key":3224,"_type":176,"marks":3225,"text":3226},"0c0e50a329ef",[393]," lack visibility into their AI systems, and 47% can't trace AI decisions back to the models and source data that produced them. The incidents are the predictable results of lacking live structural context.",[3228],{"_key":3213,"_type":151,"blank":57,"href":3229,"noOpener":57,"noReferrer":57,"url":3229},"https://www.digicert.com/content/dam/digicert/pdfs/report/ai-trust-pulse.pdf",{"_key":3231,"_type":172,"children":3232,"markDefs":3237,"style":292},"6b698b1b337a",[3233],{"_key":3234,"_type":176,"marks":3235,"text":3236},"2b854e638531",[],"78% of enterprises have already had an AI incident. Almost none know why.",[],{"_key":3239,"_type":172,"children":3240,"markDefs":3245,"style":180},"ffee2587231c",[3241],{"_key":3242,"_type":176,"marks":3243,"text":3244},"7037bc4a6e35",[],"DigiCert just published survey data that should stifle a certain kind of disagreement languishing inside enterprise IT as of late…",[],{"_key":3247,"_type":172,"children":3248,"markDefs":3260,"style":180},"5afc9427914d",[3249,3253,3257],{"_key":3250,"_type":176,"marks":3251,"text":3252},"be16fac86323",[],"The argument: AI risk is still ",{"_key":3254,"_type":176,"marks":3255,"text":3256},"fa8d36f873d6",[393],"theoretical",{"_key":3258,"_type":176,"marks":3259,"text":374},"e4551d440248",[],[],{"_key":3262,"_type":172,"children":3263,"markDefs":3271,"style":180},"bb67e52c28dd",[3264,3267],{"_key":3258,"_type":176,"marks":3265,"text":3266},[],"It lives in thinkpieces, they say, and analyst decks. ",{"_key":3268,"_type":176,"marks":3269,"text":3270},"f3df60bf4c1c",[393],"We'll deal with governance once the agents are actually doing real work.",[],{"_key":3273,"_type":172,"children":3274,"markDefs":3287,"style":180},"9465f2d120d9",[3275,3279,3283],{"_key":3276,"_type":176,"marks":3277,"text":3278},"7b058c1bb514",[],"Here’s the issue with all that: The agents ",{"_key":3280,"_type":176,"marks":3281,"text":3282},"4f749d086fb5",[393],"are",{"_key":3284,"_type":176,"marks":3285,"text":3286},"2079e08cb638",[]," doing real work. Now. Already. Like, as you read this sentence.",[],{"_key":3289,"_type":172,"children":3290,"markDefs":3294,"style":180},"7bf16f833ec7",[3291],{"_key":3284,"_type":176,"marks":3292,"text":3293},[],"According to DigiCert's AI Trust Outlook, 75% of organizations deployed four or more AI-powered systems in the last six months alone. And 78% have already experienced an AI-related incident or found an AI-related vulnerability in their environment.",[],{"_key":3296,"_type":172,"children":3297,"markDefs":3311,"style":180},"10d0c56364c1",[3298,3302,3307],{"_key":3299,"_type":176,"marks":3300,"text":3301},"e2fafd7642cb",[],"So, more than three in four enterprises have already been burned (or nearly burned) by AI systems they chose to deploy, all while 90% of organizations are talking about ",{"_key":3303,"_type":176,"marks":3304,"text":3306},"6226537fc2c1",[3305],"a43f61ff62af","AI governance",{"_key":3308,"_type":176,"marks":3309,"text":3310},"42a0509b318e",[]," at the board level, but only half have a formal program in place.",[3312],{"_key":3305,"_ref":3313,"_type":328,"linkType":33,"slug":3314},"30ffa7ad-5fba-41f9-8f02-55ebc1b1120f",{"_type":22,"current":3315},"salesforce-just-made-ai-a-governance-problem",{"_key":3317,"_type":172,"children":3318,"markDefs":3323,"style":920},"47df48949413",[3319],{"_key":3320,"_type":176,"marks":3321,"text":3322},"4807312395a6",[],"The gap is visibility, and it always was",[],{"_key":3325,"_type":172,"children":3326,"markDefs":3331,"style":180},"b6205ff2e538",[3327],{"_key":3328,"_type":176,"marks":3329,"text":3330},"06f98166bae4",[],"The most telling stat in the report sits further down: 47% of organizations cannot fully trace AI decisions back to the models and source data that produced them.",[],{"_key":3333,"_type":172,"children":3334,"markDefs":3347,"style":180},"762b55219d5c",[3335,3339,3343],{"_key":3336,"_type":176,"marks":3337,"text":3338},"29ac14de4757",[],"When read alongside the incident number, the story crystalizes. Nearly half of enterprises are running agents whose decisions they ",{"_key":3340,"_type":176,"marks":3341,"text":3342},"6c19206151a9",[393],"cannot reconstruct. ",{"_key":3344,"_type":176,"marks":3345,"text":3346},"6a5d2452e074",[],"When one of those agents does something wrong (pulls the wrong record, updates the wrong field, acts on stale permissions) the postmortem hits a wall. No lineage. No map from output back to the data and structure that shaped it.",[],{"_key":3349,"_type":172,"children":3350,"markDefs":3355,"style":180},"ec4ea639d4fb",[3351],{"_key":3352,"_type":176,"marks":3353,"text":3354},"c16154b8292f",[],"We've written about what this looks like in practice inside Salesforce environments…",[],{"_key":3357,"_type":172,"children":3358,"level":54,"listItem":309,"markDefs":3370,"style":180},"5bc653a02a7e",[3359,3362,3367],{"_key":3352,"_type":176,"marks":3360,"text":3361},[],"An agent that can't see how objects relate develops ",{"_key":3363,"_type":176,"marks":3364,"text":3366},"ede54a6bd45b",[3365],"8676e12da1b2","schema blindness",{"_key":3368,"_type":176,"marks":3369,"text":374},"c8e16b68280c",[],[3371],{"_key":3365,"_ref":1868,"_type":328,"linkType":33,"slug":3372},{"_type":22,"current":1870},{"_key":3374,"_type":172,"children":3375,"level":54,"listItem":309,"markDefs":3387,"style":180},"8fba4905087f",[3376,3379,3384],{"_key":3352,"_type":176,"marks":3377,"text":3378},[],"An agent operating on access it should have lost develops ",{"_key":3380,"_type":176,"marks":3381,"text":3383},"d202f8842b51",[3382],"0a042fe8c3b5","permission drift",{"_key":3385,"_type":176,"marks":3386,"text":374},"bef96243246a",[],[3388],{"_key":3382,"_ref":327,"_type":328,"linkType":33,"slug":3389},{"_type":22,"current":330},{"_key":3391,"_type":172,"children":3392,"level":54,"listItem":309,"markDefs":3404,"style":180},"46d1c46828b3",[3393,3396,3401],{"_key":3352,"_type":176,"marks":3394,"text":3395},[],"An agent working from decayed or outdated inputs suffers ",{"_key":3397,"_type":176,"marks":3398,"text":3400},"2e4a7bbdae6e",[3399],"c820f44ed2e6","context rot",{"_key":3402,"_type":176,"marks":3403,"text":374},"a472454ee750",[],[3405],{"_key":3399,"_ref":1847,"_type":328,"linkType":33,"slug":3406},{"_type":22,"current":1849},{"_key":3408,"_type":172,"children":3409,"markDefs":3413,"style":180},"80fb2fe6896d",[3410],{"_key":3352,"_type":176,"marks":3411,"text":3412},[],"These failure modes all share a root cause: the agent was deployed on top of a system nobody fully mapped.",[],{"_key":3415,"_type":172,"children":3416,"markDefs":3421,"style":180},"c24359048fca",[3417],{"_key":3418,"_type":176,"marks":3419,"text":3420},"aa8b0d98817d",[],"DigiCert's SVP Brian Trzupek put it squarely… the question has shifted from whether to adopt AI to whether organizations can explain, govern, and trust what they've already deployed.",[],{"_key":3423,"_type":172,"children":3424,"markDefs":3429,"style":920},"04bed320d741",[3425],{"_key":3426,"_type":176,"marks":3427,"text":3428},"7803a2fefff0",[],"Governance is catching up. Context has to come first.",[],{"_key":3431,"_type":172,"children":3432,"markDefs":3446,"style":180},"2fe1f9a6aa0e",[3433,3437,3442],{"_key":3434,"_type":176,"marks":3435,"text":3436},"dbfdfcf94956",[],"To be fair to the enterprises in this survey, the response is still underway. 57% have dedicated budgets for ",{"_key":3438,"_type":176,"marks":3439,"text":3441},"71ea953dbed1",[3440],"82f23a04242f","securing AI systems",{"_key":3443,"_type":176,"marks":3444,"text":3445},"a3f06e656bfc",[],". 86% have some process for revoking trust when an AI system is compromised. Roughly half have assigned unique  identities to all their AI agents... treating non-human actors with the same accountability as human ones.",[3447],{"_key":3440,"_ref":3448,"_type":328,"linkType":33,"slug":3449},"7a7818f1-1442-4a15-8a25-e194aa25e3ed",{"_type":22,"current":3450},"the-ultimate-guide-to-ai-readiness-in-salesforce-from-metadata-to-agents",{"_key":3452,"_type":172,"children":3453,"markDefs":3470,"style":180},"5156b3ed9553",[3454,3458,3462,3466],{"_key":3455,"_type":176,"marks":3456,"text":3457},"9399efe765e1",[],"Useful controls. But identity and revocation are what you do ",{"_key":3459,"_type":176,"marks":3460,"text":3461},"7617576b56d1",[393],"after",{"_key":3463,"_type":176,"marks":3464,"text":3465},"56e128b39cd6",[]," something goes wrong. ",{"_key":3467,"_type":176,"marks":3468,"text":3469},"eaaf7be90089",[393],"Traceability is what prevents the wrongness in the first place.",[],{"_key":3472,"_type":172,"children":3473,"markDefs":3487,"style":180},"31a4719cc3c8",[3474,3478,3483],{"_key":3475,"_type":176,"marks":3476,"text":3477},"f9bc68794300",[],"In a Salesforce context, that model is your metadata (every object, field, flow, permission set, and dependency, and how they connect). An agent with access to that ",{"_key":3479,"_type":176,"marks":3480,"text":3482},"027b5723e694",[3481],"67323fa3d85b","structural context",{"_key":3484,"_type":176,"marks":3485,"text":3486},"e6ae67bacad4",[]," can ground its decisions in how your business actually works. An agent without it is guessing, and DigiCert's data shows what guessing costs at scale.",[3488],{"_key":3481,"_ref":1279,"_type":328,"linkType":33,"slug":3489},{"_type":22,"current":1281},{"_key":3491,"_type":172,"children":3492,"markDefs":3497,"style":180},"c883101568dd",[3493],{"_key":3494,"_type":176,"marks":3495,"text":3496},"db4bc36a728a",[],"Your CRM's complexity is not the obstacle. Fifteen years of custom objects and interlocking automations is a detailed record of how your company operates, exactly the context an agent needs to act correctly. ",[],{"_key":3499,"_type":172,"children":3500,"markDefs":3505,"style":180},"fbc9fdd53bf8",[3501],{"_key":3502,"_type":176,"marks":3503,"text":3504},"0172cddc7028",[],"The enterprises in that 78% learned that the expensive way. The window to learn it the cheap way is still open, but DigiCert's deployment numbers suggest it won't stay open long",[],{"_type":17,"description":3507,"shareImage":3508,"title":3510},"New DigiCert research shows AI security incidents are already becoming widespread. The cause: half of enterprises can't see or trace what their AI is actually doing.",{"_type":40,"asset":3509},{"_ref":3162,"_type":278}," 78% of Enterprises Have Already Had an AI Incident. Here's the Real Reason Why | Sweep",{"_type":22,"current":3512},"78-of-enterprises-have-already-hit-an-ai-incident-here-s-why",{"_createdAt":3514,"_id":3515,"_rev":3516,"_system":3517,"_type":33,"_updatedAt":3520,"author":3521,"category":3537,"featuredImage":3543,"modularContent":3577,"postSubtitle":3581,"postTitle":3544,"publishDate":3582,"richText":3583,"seo":4062,"slug":4067},"2026-07-02T18:02:05Z","587dc1d5-b6f7-4241-ade6-efdf639a41ef","tQwtu1wFg483FhC8CG6raA",{"base":3518},{"id":3515,"rev":3519},"fZHBywFlaOaa1oDlceSHEP","2026-07-13T18:10:22Z",{"authorImage":3522,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":38,"image":3523},{"_type":40,"asset":3524},{"_createdAt":42,"_id":43,"_rev":44,"_type":45,"_updatedAt":46,"altText":19,"assetId":47,"description":19,"extension":48,"metadata":3525,"mimeType":83,"opt":3535,"originalFilename":86,"path":87,"sha1hash":47,"size":88,"title":19,"uploadId":89,"url":90},{"_type":50,"blurHash":51,"dimensions":3526,"hasAlpha":56,"isOpaque":57,"lqip":58,"palette":3527},{"_type":53,"aspectRatio":54,"height":55,"width":55},{"_type":60,"darkMuted":3528,"darkVibrant":3529,"dominant":3530,"lightMuted":3531,"lightVibrant":3532,"muted":3533,"vibrant":3534},{"_type":62,"background":63,"foreground":64,"population":65,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":71,"foreground":72,"population":73,"title":64},{"_type":62,"background":75,"foreground":72,"population":76,"title":72},{"_type":62,"background":78,"foreground":64,"population":79,"title":64},{"_type":62,"background":81,"foreground":64,"population":82,"title":64},{"media":3536},{"tags":19},{"_createdAt":5,"_id":6,"_rev":7,"_system":3538,"_type":11,"_updatedAt":12,"selectedColor":3540,"seo":3541,"slug":3542,"title":24},{"base":3539},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":3544,"image":3545},"The 2026 Guide to Salesforce Event Monitoring",{"_type":40,"asset":3546},{"_createdAt":3547,"_id":3548,"_rev":3549,"_type":45,"_updatedAt":3547,"assetId":3550,"extension":106,"metadata":3551,"mimeType":132,"originalFilename":3572,"path":3573,"sha1hash":3550,"size":3574,"uploadId":3575,"url":3576},"2026-07-02T18:06:52Z","image-f899efd223adb7c40a1b2f7bb58ee4df2f732718-1200x630-png","nzZ4yidQWUBixWjztcLlKN","f899efd223adb7c40a1b2f7bb58ee4df2f732718",{"_type":50,"blurHash":3552,"dimensions":3553,"hasAlpha":57,"isOpaque":57,"lqip":3554,"palette":3555,"thumbHash":3571},"M9R{=Io#xWx]xX?bj[j?a#j@~RxtNKocNJ",{"_type":53,"aspectRatio":110,"height":111,"width":112},"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAAsTAAALEwEAmpwYAAABAElEQVR4nK2SYW+DIBCG/f8/cFm22q0OW9RiqwJ34Id3AWaHXWaWbR+eHHfIw8WjIOeRY9lF7us/pfhu47fiIi0crAuHk4BDbRFG6VrMW0LLDpNhDJowGoYmB0Mehhw0+Y/cQduUh/UKThcvFOFDqRivJ8LhxBCtx/HsIVWKdZdiQLRzzPNad/GYbNZh6KqShIeXxOOB8VQxSsHYCcbzW4gO+9pjJ+YbZe1R1jMqOeOqM+FkCI2aIJoRx05DnjVkp9GogIFUBm1voa6MfvRQg4+xH9L6MobfkgkNMUZtItrSCmMZYT/wOfGvQ6L7odz4j3e4HM5Ff5GuHvaq2w22hO8OclRVTFDErAAAAABJRU5ErkJggg==",{"_type":60,"darkMuted":3556,"darkVibrant":3558,"dominant":3560,"lightMuted":3563,"lightVibrant":3564,"muted":3566,"vibrant":3569},{"_type":62,"background":3557,"foreground":64,"population":82,"title":64},"#0e218a",{"_type":62,"background":3559,"foreground":64,"population":82,"title":64},"#0c1c77",{"_type":62,"background":3561,"foreground":72,"population":3562,"title":64},"#acb8d4",0.21,{"_type":62,"background":3561,"foreground":72,"population":3562,"title":64},{"_type":62,"background":3565,"foreground":72,"population":82,"title":64},"#94c4fc",{"_type":62,"background":3567,"foreground":64,"population":3568,"title":64},"#6574a6",0.15,{"_type":62,"background":3570,"foreground":64,"population":82,"title":64},"#4c64ec","/fcBDICVl4iHeIifhniXd3959w==","fast-blog-header-1200x630.png","images/9eu1m6zu/production/f899efd223adb7c40a1b2f7bb58ee4df2f732718-1200x630.png",77794,"b35eb665ab79b3e416fa7ff52a520e6c3a392ebb","https://cdn.sanity.io/images/9eu1m6zu/production/f899efd223adb7c40a1b2f7bb58ee4df2f732718-1200x630.png",[3578],{"_key":3579,"_type":275,"cols":276,"filterByCategory":3580,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":279},"cab963f7f411402fcb157a2ccdd2956e",{"_ref":6,"_type":278},"What It Tracks, What It Misses, and What to Do About the Gap","2026-07-02",[3584,3591,3599,3607,3615,3623,3631,3638,3645,3653,3671,3679,3687,3706,3714,3722,3746,3752,3760,3768,3787,3795,3803,3811,3845,3857,3869,3881,3893,3901,3908,3916,3924,3943,3962,3970,3978,3986,3993,4001,4009,4017,4025,4033,4054],{"_key":3585,"_type":172,"children":3586,"markDefs":3590,"style":180},"fb5d5b218750",[3587],{"_key":3588,"_type":176,"marks":3589,"text":290},"3c5e0f1c4eee",[369],[],{"_key":3592,"_type":172,"children":3593,"level":54,"listItem":309,"markDefs":3598,"style":180},"a70c1de534e0",[3594],{"_key":3595,"_type":176,"marks":3596,"text":3597},"b97e50ac227c",[],"Salesforce event monitoring records user actions and login events reliably, but it doesn’t include the metadata context that makes those events meaningful for either troubleshooting or governance.",[],{"_key":3600,"_type":172,"children":3601,"level":54,"listItem":309,"markDefs":3606,"style":180},"460bf663fa40",[3602],{"_key":3603,"_type":176,"marks":3604,"text":3605},"1110db429cf3",[],"The audit log tells you a field changed but it rarely tells you which Flow, permission set, or downstream integration depended on that field before the change.",[],{"_key":3608,"_type":172,"children":3609,"level":54,"listItem":309,"markDefs":3614,"style":180},"d91b1cf19e60",[3610],{"_key":3611,"_type":176,"marks":3612,"text":3613},"a6a2f0365816",[],"Closing the gap between raw event data and actionable context is the main pre-req now for faster incident resolution.",[],{"_key":3616,"_type":172,"children":3617,"markDefs":3622,"style":180},"691a2b9eee35",[3618],{"_key":3619,"_type":176,"marks":3620,"text":3621},"74cc4a825419",[],"---",[],{"_key":3624,"_type":172,"children":3625,"markDefs":3630,"style":180},"aedb2c3cbeea",[3626],{"_key":3627,"_type":176,"marks":3628,"text":3629},"433692c26f69",[],"Salesforce event monitoring is useful. Let’s get that out of the way first.",[],{"_key":3632,"_type":172,"children":3633,"markDefs":3637,"style":180},"3c0107158834",[3634],{"_key":3627,"_type":176,"marks":3635,"text":3636},[],"If you need to know that a specific user exported a report at 11:47 p.m. on Wednesday, or that a login came from an unexpected IP on Friday, it will tell you. ",[],{"_key":3639,"_type":172,"children":3640,"markDefs":3644,"style":180},"e5ee7476b905",[3641],{"_key":3627,"_type":176,"marks":3642,"text":3643},[],"The Event Monitoring API surfaces real data about real actions, and the Setup Audit Trail gives you a timestamped record of config changes going back 180 days. For a compliance checkbox, that’s often close enough for jazz.",[],{"_key":3646,"_type":172,"children":3647,"markDefs":3652,"style":180},"aca6a85529a1",[3648],{"_key":3649,"_type":176,"marks":3650,"text":3651},"bdb4939e446e",[],"For everything else, though, it begins to show its limits.",[],{"_key":3654,"_type":172,"children":3655,"markDefs":3668,"style":180},"f1d9178c9e8c",[3656,3660,3664],{"_key":3657,"_type":176,"marks":3658,"text":3659},"fe162a17fcbf",[],"The problem? Event monitoring answers a narrow question (\"what action occurred?\") while the questions that actually cost your team time are different ones entirely: what did this action touch, who will notice, and how quickly can we reverse it? Those questions live one layer above the event log, in the metadata that describes how your org is wired together. That layer is largely invisible to native ",{"_key":3661,"_type":176,"marks":3662,"text":961},"78cc785dcffb",[3663],"7787b44b55fa",{"_key":3665,"_type":176,"marks":3666,"text":3667},"31ed83f02cde",[],".",[3669],{"_key":3663,"_ref":964,"_type":328,"linkType":738,"slug":3670},{"_type":22,"current":966},{"_key":3672,"_type":172,"children":3673,"markDefs":3678,"style":292},"6931000568de",[3674],{"_key":3675,"_type":176,"marks":3676,"text":3677},"9a88ebcc5517",[],"What Salesforce event monitoring actually covers",[],{"_key":3680,"_type":172,"children":3681,"markDefs":3686,"style":180},"d10f12a65c5e",[3682],{"_key":3683,"_type":176,"marks":3684,"text":3685},"23574b0475f6",[],"The Salesforce audit log captures events in a few distinct buckets. User behavior events (logins, report exports, API calls, record views) come through Event Monitoring, which requires an add-on license at most tiers. Configuration changes, meaning edits to fields, page layouts, flows, permission sets, and profiles, appear in Setup Audit Trail. Field History Tracking records changes to specific field values on records, but it is limited to 20 tracked fields per object and rolls off after 18 months.",[],{"_key":3688,"_type":172,"children":3689,"markDefs":3703,"style":180},"811c4c0a6dc8",[3690,3694,3699],{"_key":3691,"_type":176,"marks":3692,"text":3693},"960c45e825ca",[],"Each of these is doing the job it was designed for. Event Monitoring was built ",{"_key":3695,"_type":176,"marks":3696,"text":3698},"22de6853bd69",[3697],"944b6f3c80d3","for security operations",{"_key":3700,"_type":176,"marks":3701,"text":3702},"5450bb26be5e",[],": detect anomalies, identify exfiltration risk, satisfy audit requests. Setup Audit Trail was built for change accountability: who touched what configuration and when. Field History Tracking was built for data lineage on a subset of fields.",[3704],{"_key":3697,"_ref":985,"_type":328,"linkType":33,"slug":3705},{"_type":22,"current":987},{"_key":3707,"_type":172,"children":3708,"markDefs":3713,"style":180},"a2cfc78672e8",[3709],{"_key":3710,"_type":176,"marks":3711,"text":3712},"3b8cee204491",[],"Where they were not designed to go is impact analysis. If a developer renames a custom field at 4 p.m. on a Friday, Setup Audit Trail will record the rename. It will not tell you that three Flows reference that field's API name, that a Snowflake pipeline pulls it nightly, or that the field label appears in a Visualforce email template sent to customers. You find those things out the hard way.",[],{"_key":3715,"_type":172,"children":3716,"markDefs":3721,"style":180},"91ab90542c2f",[3717],{"_key":3718,"_type":176,"marks":3719,"text":3720},"b9f67c195571",[],"———",[],{"_key":3723,"_type":172,"children":3724,"markDefs":3741,"style":180},"a23ab7dfbd7e",[3725,3729,3734,3737],{"_key":3726,"_type":176,"marks":3727,"text":3728},"3b1ef1129de4",[369,393],"🪄 Read more: ",{"_key":3730,"_type":176,"marks":3731,"text":3733},"a103ecf12784",[3732,393],"6b8d86e1ebcb","The security leaders using Sweep’s agentic AI to stay on top of their own security and audit readiness.",{"_key":3735,"_type":176,"marks":3736,"text":708},"b03abe9cd935",[],{"_key":3738,"_type":176,"marks":3739,"text":3740},"46235bc8f640",[369,393],"🪄",[3742],{"_key":3732,"_ref":3743,"_type":328,"linkType":33,"slug":3744},"3f192786-d855-4e25-8290-d4c968586d0f",{"_type":22,"current":3745},"cybersecurity-use-agentic-ai-to-govern-salesforce-at-scale",{"_key":3747,"_type":172,"children":3748,"markDefs":3751,"style":180},"04988a5ec3cf",[3749],{"_key":3718,"_type":176,"marks":3750,"text":3720},[],[],{"_key":3753,"_type":172,"children":3754,"markDefs":3759,"style":292},"cd062c854375",[3755],{"_key":3756,"_type":176,"marks":3757,"text":3758},"584b66590738",[],"The dependency problem that monitoring cannot solve",[],{"_key":3761,"_type":172,"children":3762,"markDefs":3767,"style":180},"4b6d80c2f756",[3763],{"_key":3764,"_type":176,"marks":3765,"text":3766},"23232ab7843b",[],"Consider for a moment what a Salesforce admin actually needs when an incident lands… A pipeline is showing wrong values. A flow stopped firing. An integration is throwing multiple errors. The first question is always some version of \"what changed?\" and the audit log helps with that. The second question is \"what is broken because of it?\" and then, most unfortunately, said audit log goes quiet.",[],{"_key":3769,"_type":172,"children":3770,"markDefs":3784,"style":180},"cbbe9f7217b7",[3771,3775,3780],{"_key":3772,"_type":176,"marks":3773,"text":3774},"6f06a4f51e75",[],"This is ",{"_key":3776,"_type":176,"marks":3777,"text":3779},"88864032e0f3",[3778],"3ee0b5e851dd","the Context Gap",{"_key":3781,"_type":176,"marks":3782,"text":3783},"837e64aab8de",[],". The distance between what your Salesforce org actually does and what anyone can readily see about it. In a young org with 50 fields and two flows, the gap is narrow and probably survivable. In an org that has been running for five or more years, with hundreds of custom objects, layered automation, and integrations built by people who have since left the company, the gap is where incidents live. And it compounds: every undocumented change widens it slightly, until investigation time stops being measured in minutes and starts being measured in days.",[3785],{"_key":3778,"_ref":1279,"_type":328,"linkType":33,"slug":3786},{"_type":22,"current":1281},{"_key":3788,"_type":172,"children":3789,"markDefs":3794,"style":180},"c2c7f2d165c8",[3790],{"_key":3791,"_type":176,"marks":3792,"text":3793},"082d445dfa2b",[],"The audit log records what happened at the surface. The Metadata Graph describes what the surface is built on. You need both.",[],{"_key":3796,"_type":172,"children":3797,"markDefs":3802,"style":292},"a5c9d1d2f87b",[3798],{"_key":3799,"_type":176,"marks":3800,"text":3801},"daa2036317ce",[],"What the Salesforce change tracking picture is missing",[],{"_key":3804,"_type":172,"children":3805,"markDefs":3810,"style":180},"81efdea94257",[3806],{"_key":3807,"_type":176,"marks":3808,"text":3809},"9de3ebdd4d0a",[],"Here is a practical inventory of what native Salesforce event monitoring and audit logging do not cover, and where teams typically feel it:",[],{"_key":3812,"_type":172,"children":3813,"markDefs":3840,"style":180},"de0ca0ef0933",[3814,3818,3822,3827,3831,3836],{"_key":3815,"_type":176,"marks":3816,"text":3817},"ba89a6a5c1ce",[369],"Dependency chains.",{"_key":3819,"_type":176,"marks":3820,"text":3821},"d3175d2d9e47",[]," A ",{"_key":3823,"_type":176,"marks":3824,"text":3826},"35377b54c59f",[3825],"c56918a04353","permission set ",{"_key":3828,"_type":176,"marks":3829,"text":3830},"04997785cfb4",[],"change that removes field-level ",{"_key":3832,"_type":176,"marks":3833,"text":3835},"bea2ae41f758",[3834],"64e6de7d39ed","security",{"_key":3837,"_type":176,"marks":3838,"text":3839},"68299a20c6d6",[]," on a field used in a critical validation rule will not generate an alert that connects those two facts. You see the permission change; you do not see the validation rule. You find the broken validation rule when a rep complains.",[3841,3843],{"_key":3825,"_ref":1121,"_type":328,"linkType":33,"slug":3842},{"_type":22,"current":1123},{"_key":3834,"_ref":1913,"_type":328,"linkType":33,"slug":3844},{"_type":22,"current":2432},{"_key":3846,"_type":172,"children":3847,"markDefs":3856,"style":180},"893167801330",[3848,3852],{"_key":3849,"_type":176,"marks":3850,"text":3851},"b4243397e267",[369],"Automation logic drift.",{"_key":3853,"_type":176,"marks":3854,"text":3855},"22839b95d77a",[]," When a Flow is updated, Setup Audit Trail records that it was updated. The diff of what changed inside the Flow, which condition was added, which action was removed, what the prior state was, requires you to maintain your own version history or use a third-party tool. Most teams do not do this consistently.",[],{"_key":3858,"_type":172,"children":3859,"markDefs":3868,"style":180},"b03d2bf101ce",[3860,3864],{"_key":3861,"_type":176,"marks":3862,"text":3863},"6956145517c8",[369],"Cross-object impact.",{"_key":3865,"_type":176,"marks":3866,"text":3867},"3b025c934a1e",[]," A change to a lookup relationship or a shared picklist value ripples across every object that uses it. The audit log does not surface the ripple; it surfaces only the source event.",[],{"_key":3870,"_type":172,"children":3871,"markDefs":3880,"style":180},"f75fbf2d481f",[3872,3876],{"_key":3873,"_type":176,"marks":3874,"text":3875},"03ab747acbcd",[369],"Integration surface area.",{"_key":3877,"_type":176,"marks":3878,"text":3879},"2d549e0aa271",[]," Fields that external systems read or write to are not flagged in native monitoring. There is no built-in mechanism that says \"this field is part of an active integration and any change to it deserves extra scrutiny.\"",[],{"_key":3882,"_type":172,"children":3883,"markDefs":3892,"style":180},"ce31bc81769b",[3884,3888],{"_key":3885,"_type":176,"marks":3886,"text":3887},"e8985c93d785",[369],"Permission set group complexity.",{"_key":3889,"_type":176,"marks":3890,"text":3891},"db4f4e56e03b",[]," As orgs adopt permission set groups (which Salesforce strongly encourages as a replacement for profiles), the layered inheritance makes it increasingly hard to reason about what any user can actually do. The audit log records individual permission changes; it does not render the effective access picture.",[],{"_key":3894,"_type":172,"children":3895,"markDefs":3900,"style":180},"07f477105aa2",[3896],{"_key":3897,"_type":176,"marks":3898,"text":3899},"513a3c73b619",[],"This is not a criticism of Salesforce. These are governance and observability features that sit outside the core product's scope. Filling them in is the job of a monitoring layer that understands metadata, not just events.",[],{"_key":3902,"_type":172,"children":3903,"markDefs":3907,"style":180},"63a1defae2f0",[3904],{"_key":3905,"_type":176,"marks":3906,"text":187},"9ff560ae03e6",[],[],{"_key":3909,"_type":172,"children":3910,"markDefs":3915,"style":292},"e0a9f6e27640",[3911],{"_key":3912,"_type":176,"marks":3913,"text":3914},"81c17164e1ba",[],"How metadata-aware monitoring changes the calculus",[],{"_key":3917,"_type":172,"children":3918,"markDefs":3923,"style":180},"fff1c49eb4cb",[3919],{"_key":3920,"_type":176,"marks":3921,"text":3922},"60fac1ccc0b8",[],"The practical improvement is straightforward to describe. Instead of answering \"a field was changed,\" a metadata-aware system can answer \"a field was changed, and here are the 14 places it is referenced, here is who has write access to it, and here is what it feeds downstream.\" Investigation time compresses because context travels with the alert.",[],{"_key":3925,"_type":172,"children":3926,"markDefs":3940,"style":180},"68a2d9038360",[3927,3931,3936],{"_key":3928,"_type":176,"marks":3929,"text":3930},"6d565e19e49e",[],"Sweep's Monitoring Agent sits on top of the Metadata Graph, Sweep's indexed representation of your org's schema, logic, permissions, and dependencies. When a configuration change occurs, the agent can ",{"_key":3932,"_type":176,"marks":3933,"text":3935},"1a5fb3a9f05b",[3934],"4e4717a906c7","surface its dependencies in context",{"_key":3937,"_type":176,"marks":3938,"text":3939},"0dc7edacdf20",[]," rather than as a separate lookup task. A field rename triggers not just a log entry but a view of the flows, reports, validation rules, and integrations that reference that field's API name. The Alerts capability can notify the right people before the downstream consequences surface as user complaints.",[3941],{"_key":3934,"_ref":1847,"_type":328,"linkType":33,"slug":3942},{"_type":22,"current":1849},{"_key":3944,"_type":172,"children":3945,"markDefs":3959,"style":180},"677e55c81e11",[3946,3950,3955],{"_key":3947,"_type":176,"marks":3948,"text":3949},"dfda7a35b374",[],"That shift from reactive to anticipatory is where delivery timelines actually compress. ClearGov cut org audit time from two weeks to 20 minutes using the ",{"_key":3951,"_type":176,"marks":3952,"text":3954},"25757047e96f",[3953],"3aa665cff338","Documentation Agent",{"_key":3956,"_type":176,"marks":3957,"text":3958},"5421f7dba780",[],". The investigation did not get easier because the org got simpler; it got easier because the context became legible.",[3960],{"_key":3953,"_ref":3064,"_type":328,"linkType":738,"slug":3961},{"_type":22,"current":3066},{"_key":3963,"_type":172,"children":3964,"markDefs":3969,"style":292},"c7775d111dbb",[3965],{"_key":3966,"_type":176,"marks":3967,"text":3968},"ad78e7e9a863",[],"Making your existing Salesforce alerts more useful right now",[],{"_key":3971,"_type":172,"children":3972,"markDefs":3977,"style":180},"7c6a874daa06",[3973],{"_key":3974,"_type":176,"marks":3975,"text":3976},"792cd1c43fc9",[],"If you are not ready to add a metadata layer yet, there are improvements you can make within native tools.",[],{"_key":3979,"_type":172,"children":3980,"markDefs":3985,"style":180},"faccd620f8c8",[3981],{"_key":3982,"_type":176,"marks":3983,"text":3984},"cc449a826417",[],"First, be specific about what you track. ",[],{"_key":3987,"_type":172,"children":3988,"markDefs":3992,"style":180},"270245057614",[3989],{"_key":3982,"_type":176,"marks":3990,"text":3991},[],"The Setup Audit Trail captures everything, which means it is also noise when you need signal. Decide in advance which object types, permission changes, and automation edits are high-enough-risk to warrant proactive review, and build that review into a recurring process rather than a post-incident scramble.",[],{"_key":3994,"_type":172,"children":3995,"markDefs":4000,"style":180},"516c233139f3",[3996],{"_key":3997,"_type":176,"marks":3998,"text":3999},"9800408ab5ae",[],"Second, cross-reference Field History Tracking selections with your integration surface. If a field is read by an external system, it probably belongs in your 20 tracked fields per object. Most teams choose tracked fields based on what business stakeholders care about, not on what integrations depend on. Both criteria belong in the conversation.",[],{"_key":4002,"_type":172,"children":4003,"markDefs":4008,"style":180},"1f1a5d026b32",[4004],{"_key":4005,"_type":176,"marks":4006,"text":4007},"53c42a53d7ab",[],"Third, document change intentions alongside the audit log. The audit log records what changed; it does not record why. A lightweight change-management practice, even a Slack thread with a link to the affected metadata, creates the connective tissue that lets future you reconstruct decisions that past you made on a deadline.",[],{"_key":4010,"_type":172,"children":4011,"markDefs":4016,"style":180},"4707d7fc75a2",[4012],{"_key":4013,"_type":176,"marks":4014,"text":4015},"38c6930ab384",[],"These are good practices that help. They do not close the Context Gap. They manage it.",[],{"_key":4018,"_type":172,"children":4019,"markDefs":4024,"style":292},"fb2c53e362c3",[4020],{"_key":4021,"_type":176,"marks":4022,"text":4023},"2a584c160c98",[],"Complexity is the record, not the obstacle",[],{"_key":4026,"_type":172,"children":4027,"markDefs":4032,"style":180},"f15181a22045",[4028],{"_key":4029,"_type":176,"marks":4030,"text":4031},"351e8d623256",[],"There is an old instinct in Salesforce work: clean up the org before you do anything significant. Simplify the schema, reduce the flows, consolidate permissions. The instinct comes from a reasonable place: complex systems are hard to reason about.",[],{"_key":4034,"_type":172,"children":4035,"markDefs":4049,"style":180},"e7839c92781b",[4036,4040,4045],{"_key":4037,"_type":176,"marks":4038,"text":4039},"d8265039cabf",[],"The better frame is that years of fields, flows, and integrations are not a mess to apologize for. They are the record of how your business actually works, and that record is valuable. The goal is not to reduce it; the goal is to make it legible. When complexity is legible, the audit log becomes genuinely useful because you can trace events into their actual consequences. ",{"_key":4041,"_type":176,"marks":4042,"text":4044},"233c6d585d46",[4043],"462e55519e1d","Salesforce",{"_key":4046,"_type":176,"marks":4047,"text":4048},"d3f5d618e33e",[]," event monitoring stops being a compliance artifact and starts being an operational instrument.",[4050],{"_key":4043,"_ref":4051,"_type":328,"linkType":738,"slug":4052},"550bebfb-868b-4f34-bbf1-786a87134a5c",{"_type":22,"current":4053},"salesforce",{"_key":4055,"_type":172,"children":4056,"markDefs":4061,"style":180},"9da2c457e3c7",[4057],{"_key":4058,"_type":176,"marks":4059,"text":4060},"4e1b551f6560",[],"That is the difference between knowing something changed and knowing what to do about it.",[],{"_type":17,"description":4063,"shareImage":4064,"title":4066},"Event Monitoring catches the login. It rarely catches the config change. How to layer audit logs, alerts, and change tracking to see what's really happening in your org.",{"_type":40,"asset":4065},{"_ref":3548,"_type":278},"Salesforce Event Monitoring: What It Tracks and What It Misses",{"_type":22,"current":4068},"2026-guide-to-salesforce-event-monitoring",{"_createdAt":4070,"_id":4071,"_rev":4072,"_type":33,"_updatedAt":4073,"author":4074,"category":4090,"featuredImage":4096,"modularContent":4131,"postTitle":4097,"publishDate":4135,"richText":4136,"seo":5078,"slug":5082},"2026-07-01T17:03:11Z","0699c1ea-60e6-4d45-842b-b84cceb1b85f","1j2P1LzCZw1VBHySYII3m3","2026-07-01T19:56:42Z",{"authorImage":4075,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":38,"image":4076},{"_type":40,"asset":4077},{"_createdAt":42,"_id":43,"_rev":44,"_type":45,"_updatedAt":46,"altText":19,"assetId":47,"description":19,"extension":48,"metadata":4078,"mimeType":83,"opt":4088,"originalFilename":86,"path":87,"sha1hash":47,"size":88,"title":19,"uploadId":89,"url":90},{"_type":50,"blurHash":51,"dimensions":4079,"hasAlpha":56,"isOpaque":57,"lqip":58,"palette":4080},{"_type":53,"aspectRatio":54,"height":55,"width":55},{"_type":60,"darkMuted":4081,"darkVibrant":4082,"dominant":4083,"lightMuted":4084,"lightVibrant":4085,"muted":4086,"vibrant":4087},{"_type":62,"background":63,"foreground":64,"population":65,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":71,"foreground":72,"population":73,"title":64},{"_type":62,"background":75,"foreground":72,"population":76,"title":72},{"_type":62,"background":78,"foreground":64,"population":79,"title":64},{"_type":62,"background":81,"foreground":64,"population":82,"title":64},{"media":4089},{"tags":19},{"_createdAt":5,"_id":6,"_rev":7,"_system":4091,"_type":11,"_updatedAt":12,"selectedColor":4093,"seo":4094,"slug":4095,"title":24},{"base":4092},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":4097,"image":4098},"The New Economics of Salesforce Exposure",{"_type":40,"asset":4099},{"_createdAt":4100,"_id":4101,"_rev":4102,"_type":45,"_updatedAt":4100,"assetId":4103,"extension":106,"metadata":4104,"mimeType":132,"originalFilename":4126,"path":4127,"sha1hash":4103,"size":4128,"uploadId":4129,"url":4130},"2026-07-01T17:46:46Z","image-fe6f539206160c9eb47edc753c3bbaae82100cda-1200x630-png","1j2P1LzCZw1VBHySYHune9","fe6f539206160c9eb47edc753c3bbaae82100cda",{"_type":50,"blurHash":4105,"dimensions":4106,"hasAlpha":57,"isOpaque":57,"lqip":4107,"palette":4108,"thumbHash":4125},"M7Aebe-$N5SAjYp3b0axj?fR52Ifxms*a~",{"_type":53,"aspectRatio":110,"height":111,"width":112},"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAAsTAAALEwEAmpwYAAABH0lEQVR4nMWSW0sCURRG/Yc6ppmhXYgCbyUp5NxsFCl1xpKsv2dSWVFSD6OQjp0VM44PEfMgFD0svn02h7VhnxOKyPCbhP5GqPiNCoQrPy+FVxFGFUicQtIQJKqCdR+39s66IO734voSiKoBwpgm2Dt3KFxMKVwuyHVmZDuOlzlrRtZya4eM6XDQmrN75g4IFDpkmm/IvSHq9SPazRMnVy+UuiMv5d6zly7l7oi8OWa7MSemBQnVGfuNV0pWn3KnT8m6pWjeUWgNOWrfc2wOKLYHHLYG5JsP7NTfiakOEVkE7fCTZPWDrbq9oGaTro1JGRPStQkpw2azarOh2yS0MWvKNFAWWb6ypLhLFt9RFikpAskTLPmXf+gjBdSrCL8AeuNpBlQ2K0MAAAAASUVORK5CYII=",{"_type":60,"darkMuted":4109,"darkVibrant":4111,"dominant":4113,"lightMuted":4115,"lightVibrant":4118,"muted":4121,"vibrant":4124},{"_type":62,"background":4110,"foreground":64,"population":82,"title":64},"#4c6c74",{"_type":62,"background":4112,"foreground":64,"population":1737,"title":64},"#9a9434",{"_type":62,"background":840,"foreground":64,"population":4114,"title":64},76.38,{"_type":62,"background":4116,"foreground":72,"population":4117,"title":64},"#d2ca9a",0.57,{"_type":62,"background":4119,"foreground":64,"population":4120,"title":64},"#5c7af9",1.4,{"_type":62,"background":4122,"foreground":64,"population":4123,"title":64},"#647aaa",0.73,{"_type":62,"background":840,"foreground":64,"population":4114,"title":64},"prMBFIJbd3aIh3hQinVbd7B1Bw==","clean-data-blog-header-1200x630.png","images/9eu1m6zu/production/fe6f539206160c9eb47edc753c3bbaae82100cda-1200x630.png",83004,"3f7fed8f768fa8f176b757cb8fa4cf673eaa76bd","https://cdn.sanity.io/images/9eu1m6zu/production/fe6f539206160c9eb47edc753c3bbaae82100cda-1200x630.png",[4132],{"_key":4133,"_type":275,"cols":276,"filterByCategory":4134,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":279},"428d3313e21671f24a3db6177c9c0a4b",{"_ref":6,"_type":278},"2026-07-01",[4137,4144,4152,4160,4168,4176,4183,4199,4207,4215,4223,4238,4245,4252,4260,4268,4289,4297,4304,4324,4332,4340,4348,4367,4374,4393,4401,4409,4417,4425,4433,4445,4465,4484,4503,4511,4519,4527,4535,4543,4558,4579,4598,4606,4614,4622,4630,4653,4661,4669,4677,4697,4705,4713,4720,4727,4734,4741,4748,4756,4775,4783,4791,4799,4807,4815,4823,4831,4839,4847,4855,4863,4871,4879,4887,4902,4910,4918,4926,4934,4942,4950,4958,4966,4974,4982,4990,4998,5006,5014,5030,5038,5046,5054,5062,5070],{"_key":4138,"_type":172,"children":4139,"markDefs":4143,"style":292},"d2b451d06a5e",[4140],{"_key":4141,"_type":176,"marks":4142,"text":290},"3cb8283b44c4",[],[],{"_key":4145,"_type":172,"children":4146,"level":54,"listItem":309,"markDefs":4151,"style":180},"e014bb9b1398",[4147],{"_key":4148,"_type":176,"marks":4149,"text":4150},"ce868bfa98af",[],"AI has changed the cost of finding security exposure in Salesforce, particularly.",[],{"_key":4153,"_type":172,"children":4154,"level":54,"listItem":309,"markDefs":4159,"style":180},"aadbd3ce450d",[4155],{"_key":4156,"_type":176,"marks":4157,"text":4158},"a01cf9d2d2ec",[],"Public sites, guest users, Apex, files, permissions, connected apps, and service accounts make this challenge a particularly unique one.",[],{"_key":4161,"_type":172,"children":4162,"level":54,"listItem":309,"markDefs":4167,"style":180},"0c007a407da1",[4163],{"_key":4164,"_type":176,"marks":4165,"text":4166},"132d30dead24",[],"Salesforce security now requires continuous exposure management: discover what is exposed, understand why it matters, remediate safely, and monitor what changes.",[],{"_key":4169,"_type":172,"children":4170,"markDefs":4175,"style":180},"3b2a519bdc42",[4171],{"_key":4172,"_type":176,"marks":4173,"text":4174},"aa1b2b98b724",[],"————-",[],{"_key":4177,"_type":172,"children":4178,"markDefs":4182,"style":180},"41dd9a01fe5e",[4179],{"_key":4180,"_type":176,"marks":4181,"text":187},"5cfc35df2777",[],[],{"_key":4184,"_type":172,"children":4185,"markDefs":4198,"style":180},"d23f9d74ada7",[4186,4190,4194],{"_key":4187,"_type":176,"marks":4188,"text":4189},"51de434bf5f7",[],"Salesforce exposure used to have an awkward kind of protection: it was hard to find. Not ",{"_key":4191,"_type":176,"marks":4192,"text":4193},"152b86e4100e",[393],"impossible",{"_key":4195,"_type":176,"marks":4196,"text":4197},"f63ae1b11fbf",[],". Just… relatively difficult.",[],{"_key":4200,"_type":172,"children":4201,"markDefs":4206,"style":180},"8fd81c1c1271",[4202],{"_key":4203,"_type":176,"marks":4204,"text":4205},"d2c68cab20ed",[],"A risky guest user permission might sit inside an Experience Cloud site. A forgotten Apex method might be callable from a public surface. ",[],{"_key":4208,"_type":172,"children":4209,"markDefs":4214,"style":180},"5d62d8b2281d",[4210],{"_key":4211,"_type":176,"marks":4212,"text":4213},"7cf34c7eddfd",[],"These kind of issues were of course present, but finding the dangerous combination required an unusual combination of talents that included a great deal of patience, a great deal of context, and a great deal of Salesforce-specific expertise.",[],{"_key":4216,"_type":172,"children":4217,"markDefs":4222,"style":180},"011759ee230c",[4218],{"_key":4219,"_type":176,"marks":4220,"text":4221},"e9a2da384a99",[],"That’s all changed now.",[],{"_key":4224,"_type":172,"children":4225,"markDefs":4235,"style":180},"30f146bbc2ec",[4226,4231],{"_key":4227,"_type":176,"marks":4228,"text":4230},"7504c5d51c08",[4229],"36f33cc6b047","Recent research from Reco",{"_key":4232,"_type":176,"marks":4233,"text":4234},"e712112b2e11",[]," has shown an AI-powered agent performing end-to-end security assessments of Salesforce Experience Cloud sites. ",[4236],{"_key":4229,"_type":151,"blank":57,"href":4237,"noOpener":57,"noReferrer":57,"url":4237},"https://thehackernews.com/expert-insights/2026/06/hacking-salesforce-sites-with-llm-agent.html",{"_key":4239,"_type":172,"children":4240,"markDefs":4244,"style":180},"33fbb899613b",[4241],{"_key":4232,"_type":176,"marks":4242,"text":4243},[],"Starting with a URL, the agent mapped exposed Salesforce objects, Apex methods, routes, files; then it analyzed accessible data; then it probed for vulnerabilities; and finally it validated impact. ",[],{"_key":4246,"_type":172,"children":4247,"markDefs":4251,"style":180},"3a0df3220df6",[4248],{"_key":4232,"_type":176,"marks":4249,"text":4250},[],"In one case, it found sensitive files among ordinary assets. In another, it found a path in through an exposed Apex method.",[],{"_key":4253,"_type":172,"children":4254,"markDefs":4259,"style":180},"ca8ef2b1cd2d",[4255],{"_key":4256,"_type":176,"marks":4257,"text":4258},"a84cd1d7ff59",[],"The lesson, which is pretty uncomfortable, is that AI did not create the exposure.. it just changed the economics of finding it. And that should change how every security, IT, and Salesforce team thinks about risk.",[],{"_key":4261,"_type":172,"children":4262,"markDefs":4267,"style":292},"c844c63e2b17",[4263],{"_key":4264,"_type":176,"marks":4265,"text":4266},"8a91fab8aaf5",[],"Exposure used to be expensive to find",[],{"_key":4269,"_type":172,"children":4270,"markDefs":4284,"style":180},"194d7f903c40",[4271,4275,4280],{"_key":4272,"_type":176,"marks":4273,"text":4274},"8f877fc8725f",[],"Most Salesforce environments ",{"_key":4276,"_type":176,"marks":4277,"text":4279},"ec45059f32c5",[4278],"b57725b02f8d","are not simple systems",{"_key":4281,"_type":176,"marks":4282,"text":4283},"d483ae2e644e",[],". They are highly complex, living maps of how the business actually works in reality.",[4285],{"_key":4278,"_ref":4286,"_type":328,"linkType":33,"slug":4287},"56d3d976-f938-4a89-99e9-4d7245f3d7e2",{"_type":22,"current":4288},"the-myth-of-the-clean-salesforce-org",{"_key":4290,"_type":172,"children":4291,"markDefs":4296,"style":180},"300c8b96e565",[4292],{"_key":4293,"_type":176,"marks":4294,"text":4295},"efb5bdd8d873",[],"There are public sites, partner portals, customer communities, integrations, managed packages, flows, validation rules, permission sets, permission set groups (deep breath) profiles, connected apps, files, Apex classes, and service accounts. ",[],{"_key":4298,"_type":172,"children":4299,"markDefs":4303,"style":180},"cea806e0c0e2",[4300],{"_key":4293,"_type":176,"marks":4301,"text":4302},[],"There are also years of exceptions: the emergency change that became permanent times what might as well be infinity.",[],{"_key":4305,"_type":172,"children":4306,"markDefs":4319,"style":180},"fc01aee2a219",[4307,4311,4316],{"_key":4308,"_type":176,"marks":4309,"text":4310},"329e5d5cbf12",[],"As it is often the record of a business adapting, ",{"_key":4312,"_type":176,"marks":4313,"text":4315},"0a22292134b5",[4314],"a8771cdfe565","complexity itself is not inherently bad",{"_key":4317,"_type":176,"marks":4318,"text":3667},"207110c92213",[],[4320],{"_key":4314,"_ref":4321,"_type":328,"linkType":33,"slug":4322},"91bbe0ee-91ed-45f3-91f2-1b671414c44e",{"_type":22,"current":4323},"why-salesforce-complexity-is-your-ai-advantage",{"_key":4325,"_type":172,"children":4326,"markDefs":4331,"style":180},"cb083d8132c4",[4327],{"_key":4328,"_type":176,"marks":4329,"text":4330},"43c249066576",[],"Complexity is how Salesforce runs, but unmanaged complexity is where exposure hides. That exposure can span permissions, public surfaces, connected apps, service accounts, files, automations, integrations, data platforms, and business processes.",[],{"_key":4333,"_type":172,"children":4334,"markDefs":4339,"style":180},"f332cbf453f4",[4335],{"_key":4336,"_type":176,"marks":4337,"text":4338},"b53e676e95c2",[],"Historically, defenders could tell themselves a story about that exposure. Sure, it existed. Yes, it should probably be cleaned up. But exploiting it required a human attacker to do a lot of tedious work: list surfaces, understand object access, test endpoints, inspect files, infer business meaning, and connect a lot of those weak signals across the org.",[],{"_key":4341,"_type":172,"children":4342,"markDefs":4347,"style":180},"9621d6c5a1b6",[4343],{"_key":4344,"_type":176,"marks":4345,"text":4346},"c11cfda015ae",[],"This fable is now totally outmoded.",[],{"_key":4349,"_type":172,"children":4350,"markDefs":4364,"style":180},"5f891a203d1c",[4351,4355,4360],{"_key":4352,"_type":176,"marks":4353,"text":4354},"03f53ea754e3",[],"Google Threat Intelligence Group ",{"_key":4356,"_type":176,"marks":4357,"text":4359},"33fb4d972bbb",[4358],"1d76b06a5c82","reported in 2025",{"_key":4361,"_type":176,"marks":4362,"text":4363},"60ad05469faa",[]," that threat actors tracked as UNC6040 had repeatedly used voice phishing to compromise Salesforce orgs. Mostly, by tricking employees into authorizing a malicious connected app resembling Salesforce Data Loader. ",[4365],{"_key":4358,"_type":151,"blank":57,"href":4366,"noOpener":57,"noReferrer":57,"url":4366},"https://cloud.google.com/blog/topics/threat-intelligence/voice-phishing-data-extortion",{"_key":4368,"_type":172,"children":4369,"markDefs":4373,"style":180},"7d5e485e51d6",[4370],{"_key":4361,"_type":176,"marks":4371,"text":4372},[],"Once authorized, that app could access, query, and exfiltrate sensitive information from customer environments.",[],{"_key":4375,"_type":172,"children":4376,"markDefs":4390,"style":180},"b1e667d19e77",[4377,4381,4386],{"_key":4378,"_type":176,"marks":4379,"text":4380},"75ae0841eceb",[],"A ",{"_key":4382,"_type":176,"marks":4383,"text":4385},"be46293df842",[4384],"89436c779575","joint FBI advisory",{"_key":4387,"_type":176,"marks":4388,"text":4389},"4ad7231e2d93",[]," made the same point from another angle: once victims authorized malicious connected apps, attackers could use API queries to exfiltrate large volumes of data, and the OAuth-token-based activity could appear to come from a trusted integration.",[4391],{"_key":4384,"_type":151,"blank":57,"href":4392,"noOpener":57,"noReferrer":57,"url":4392},"https://www.ic3.gov/CSA/2025/250912.pdf",{"_key":4394,"_type":172,"children":4395,"markDefs":4400,"style":180},"7f0fbd710911",[4396],{"_key":4397,"_type":176,"marks":4398,"text":4399},"3e7c2edf94ac",[],"Notice that this isn’t the same attack path as an exposed Experience Cloud guest user or vulnerable Apex method. But it points to the same deeper issue: Salesforce risk increasingly lives in the connection-spaces between identity, configuration, data access, public surfaces, integrations, and business process.",[],{"_key":4402,"_type":172,"children":4403,"markDefs":4408,"style":292},"0c630a2325c1",[4404],{"_key":4405,"_type":176,"marks":4406,"text":4407},"e1d27361e0da",[],"AI lowers the cost of patience",[],{"_key":4410,"_type":172,"children":4411,"markDefs":4416,"style":180},"371264b18f44",[4412],{"_key":4413,"_type":176,"marks":4414,"text":4415},"cfda1d46b091",[],"A human security team has constraints. A backlog. Meetings. It has other systems to protect. ",[],{"_key":4418,"_type":172,"children":4419,"markDefs":4424,"style":180},"df9f304e05e1",[4420],{"_key":4421,"_type":176,"marks":4422,"text":4423},"0db1803fe852",[],"An AI agent does not have the same limitations.",[],{"_key":4426,"_type":172,"children":4427,"markDefs":4432,"style":180},"d6bb30d22f64",[4428],{"_key":4429,"_type":176,"marks":4430,"text":4431},"58d37c4c0118",[],"It can enumerate. It can compare. It can read. It can retry. It can inspect a hundred boring files to find the one that should not be public. It can test many exposed methods to find the one that behaves differently. It can connect a public record, a parameter name, an error message, and a likely data path without getting bored.",[],{"_key":4434,"_type":172,"children":4435,"markDefs":4444,"style":180},"b1f035084d5a",[4436,4440],{"_key":4437,"_type":176,"marks":4438,"text":4439},"21a8081467ef",[393],"That",{"_key":4441,"_type":176,"marks":4442,"text":4443},"b9d05c1b657d",[]," is the new economics of exposure.",[],{"_key":4446,"_type":172,"children":4447,"markDefs":4460,"style":180},"f6c6dfedf64a",[4448,4451,4456],{"_key":4449,"_type":176,"marks":4450,"text":2577},"86bb7e6a9ff3",[],{"_key":4452,"_type":176,"marks":4453,"text":4455},"886da56f475e",[4454],"b7302695c5ee","cost of discovery",{"_key":4457,"_type":176,"marks":4458,"text":4459},"4812bbdb0166",[]," is falling. The cost of patience is falling. The cost of connecting seemingly minor weaknesses is falling.",[4461],{"_key":4454,"_ref":4462,"_type":328,"linkType":33,"slug":4463},"967e0489-33de-4a93-be45-07816d9db666",{"_type":22,"current":4464},"how-to-run-salesforce-org-discovery-in-hours-not-days",{"_key":4466,"_type":172,"children":4467,"markDefs":4481,"style":180},"a7e211a47650",[4468,4472,4477],{"_key":4469,"_type":176,"marks":4470,"text":4471},"ec300c0dfa69",[],"Microsoft’s ",{"_key":4473,"_type":176,"marks":4474,"text":4476},"03f23d8f2b31",[4475],"4b281dc6dc3f","Digital Defense Report",{"_key":4478,"_type":176,"marks":4479,"text":4480},"d55898c5584b",[]," framed the broader risk clearly: AI agents could allow threat actors to automate the attack lifecycle through reconnaissance, vulnerability scanning, and exploitation at scale. The same report noted that defenders are also using AI to scan threat intelligence, identify protection gaps, and respond faster.",[4482],{"_key":4475,"_type":151,"blank":57,"href":4483,"noOpener":57,"noReferrer":57,"url":4483},"https://microsoft.com/en-us/corporate-responsibility/topics/cybersecurity/reports/microsoft-digital-defense-report-2025/",{"_key":4485,"_type":172,"children":4486,"markDefs":4500,"style":180},"02397ec81c9c",[4487,4491,4496],{"_key":4488,"_type":176,"marks":4489,"text":4490},"795ad8898311",[],"Verizon’s ",{"_key":4492,"_type":176,"marks":4493,"text":4495},"da1049872fc7",[4494],"230f0552ad25","2026 DBIR",{"_key":4497,"_type":176,"marks":4498,"text":4499},"4089f625d03e",[]," likewise describes a threat landscape where vulnerabilities have become a leading breach entry point, and where different  techniques of attack are being bolstered by gen AI, helping threat actors work faster across all the stages of attack.",[4501],{"_key":4494,"_type":151,"blank":57,"href":4502,"noOpener":57,"noReferrer":57,"url":4502},"https://www.verizon.com/business/resources/reports/dbir/",{"_key":4504,"_type":172,"children":4505,"markDefs":4510,"style":180},"142259543a99",[4506],{"_key":4507,"_type":176,"marks":4508,"text":4509},"5fc3c11f43bd",[],"The Salesforce implication is direct: risks that were previously dismissed as “low exploitability” deserve a real-good-hard second pass.",[],{"_key":4512,"_type":172,"children":4513,"markDefs":4518,"style":292},"10097f59ed99",[4514],{"_key":4515,"_type":176,"marks":4516,"text":4517},"66c21be6d02b",[],"The problem is not one setting",[],{"_key":4520,"_type":172,"children":4521,"markDefs":4526,"style":180},"2422efb5685c",[4522],{"_key":4523,"_type":176,"marks":4524,"text":4525},"7eecde957985",[],"The instinct after reading about Salesforce exposure is probably to jump straight to a checklist… and sure.",[],{"_key":4528,"_type":172,"children":4529,"markDefs":4534,"style":180},"80ab41c73b3c",[4530],{"_key":4531,"_type":176,"marks":4532,"text":4533},"d30a01cf9bd6",[],"Audit those guest users. Disable those unnecessary public APIs. Review that Apex. Review those connected apps.",[],{"_key":4536,"_type":172,"children":4537,"markDefs":4542,"style":180},"ad1fdb40cab6",[4538],{"_key":4539,"_type":176,"marks":4540,"text":4541},"d462bdbbc7d4",[],"All good. All helpful.",[],{"_key":4544,"_type":172,"children":4545,"markDefs":4555,"style":180},"1e7af61e0106",[4546,4551],{"_key":4547,"_type":176,"marks":4548,"text":4550},"f3e87f14c78a",[4549],"63c225cefd3d","Salesforce itself recommends",{"_key":4552,"_type":176,"marks":4553,"text":4554},"d52033ae0f46",[]," tightly controlling Experience Cloud guest user access. Its guidance says unauthenticated guest users should only access the data intended for them, and it recommends reviewing guest object, record, and field access. Salesforce also recommends disabling guest access to public APIs where it is not needed and restricting portal and site user visibility to prevent enumeration of internal users.",[4556],{"_key":4549,"_type":151,"blank":57,"href":4557,"noOpener":57,"noReferrer":57,"url":4557},"https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/",{"_key":4559,"_type":172,"children":4560,"markDefs":4574,"style":180},"a4500ff3d1da",[4561,4565,4570],{"_key":4562,"_type":176,"marks":4563,"text":4564},"78e44b6d56c5",[],"Salesforce’s guest-user ",{"_key":4566,"_type":176,"marks":4567,"text":4569},"85740b2cf0f7",[4568],"cb5bf13ee3f0","documentation",{"_key":4571,"_type":176,"marks":4572,"text":4573},"ac9ccab3edea",[]," is similarly clear that sharing data with guest users should be deliberate and carefully controlled, because Experience Cloud sites can support many different use cases and only the business knows which records and fields should be accessible.",[4575],{"_key":4568,"_ref":4576,"_type":328,"linkType":33,"slug":4577},"2d92f2e2-a912-40cf-8c1b-2dbf31fa1be5",{"_type":22,"current":4578},"best-tools-for-salesforce-process-mapping-documentation",{"_key":4580,"_type":172,"children":4581,"markDefs":4595,"style":180},"ac7bc80fac87",[4582,4586,4591],{"_key":4583,"_type":176,"marks":4584,"text":4585},"5d7d40fde95c",[],"For code-level risk, Salesforce’s ",{"_key":4587,"_type":176,"marks":4588,"text":4590},"6293c7247a89",[4589],"024715a9c7ce","Trailhead guidance says",{"_key":4592,"_type":176,"marks":4593,"text":4594},"32851761d990",[]," the first and most recommended way to prevent SOQL injection is to use static queries with bind variables, rather than inserting user input directly into dynamic queries.",[4596],{"_key":4589,"_type":151,"blank":57,"href":4597,"noOpener":57,"noReferrer":57,"url":4597},"https://trailhead.salesforce.com/content/learn/modules/secure-serverside-development/mitigate-soql-injection",{"_key":4599,"_type":172,"children":4600,"markDefs":4605,"style":180},"40e3a80a7ff5",[4601],{"_key":4602,"_type":176,"marks":4603,"text":4604},"c5d9cf187a6a",[],"But the deeper problem is the system around the setting.",[],{"_key":4607,"_type":172,"children":4608,"markDefs":4613,"style":180},"889437fa021b",[4609],{"_key":4610,"_type":176,"marks":4611,"text":4612},"8f633dfd2015",[],"A guest user profile can connect to a site, a sharing model, objects, fields, files, pages, forms, and business processes.",[],{"_key":4615,"_type":172,"children":4616,"markDefs":4621,"style":180},"d553fd311f8e",[4617],{"_key":4618,"_type":176,"marks":4619,"text":4620},"5bc55c1f727b",[],"An Apex method can connect to a controller, a user mode, a sharing assumption, a data model, a page, an integration, and a workflow someone may still depend on.",[],{"_key":4623,"_type":172,"children":4624,"markDefs":4629,"style":180},"a608ed1847a8",[4625],{"_key":4626,"_type":176,"marks":4627,"text":4628},"e70d6a9ce3f6",[],"The risk does not live in the component alone.",[],{"_key":4631,"_type":172,"children":4632,"markDefs":4650,"style":180},"7d87415b7063",[4633,4637,4641,4646],{"_key":4634,"_type":176,"marks":4635,"text":4636},"cec2b0520bbe",[],"It lives in the ",{"_key":4638,"_type":176,"marks":4639,"text":4640},"ec635ff1f436",[393],"relationship between components. ",{"_key":4642,"_type":176,"marks":4643,"text":4645},"9b76334d09ea",[4644],"50acd068bbf4","The structural context",{"_key":4647,"_type":176,"marks":4648,"text":4649},"85bcb361e52b",[],", as it wre.",[4651],{"_key":4644,"_ref":1279,"_type":328,"linkType":33,"slug":4652},{"_type":22,"current":1281},{"_key":4654,"_type":172,"children":4655,"markDefs":4660,"style":292},"65a1d02fbaa1",[4656],{"_key":4657,"_type":176,"marks":4658,"text":4659},"3bfcc2485904",[],"Technical debt = security debt",[],{"_key":4662,"_type":172,"children":4663,"markDefs":4668,"style":180},"42e8dfdcb7f2",[4664],{"_key":4665,"_type":176,"marks":4666,"text":4667},"b29650967d9d",[],"Salesforce teams have chatted for years about technical debt as a delivery problem.",[],{"_key":4670,"_type":172,"children":4671,"markDefs":4676,"style":180},"124409066b48",[4672],{"_key":4673,"_type":176,"marks":4674,"text":4675},"3238a339d5f9",[],"Too many fields. Too many flows. Too many permission sets. ",[],{"_key":4678,"_type":172,"children":4679,"markDefs":4692,"style":180},"d15bd5e68bde",[4680,4684,4689],{"_key":4681,"_type":176,"marks":4682,"text":4683},"06c0d32d207e",[],"That is still true. ",{"_key":4685,"_type":176,"marks":4686,"text":4688},"ab515d3727bf",[4687],"a39ea4b72865","Technical debt slows change",{"_key":4690,"_type":176,"marks":4691,"text":3667},"26a7347e8985",[],[4693],{"_key":4687,"_ref":4694,"_type":328,"linkType":33,"slug":4695},"aa7444e0-f466-4469-8d2b-56bdbec7ff71",{"_type":22,"current":4696},"the-drag-point-when-systems-complexity-outpaces-your-capacity",{"_key":4698,"_type":172,"children":4699,"markDefs":4704,"style":180},"c70933d01910",[4700],{"_key":4701,"_type":176,"marks":4702,"text":4703},"a9ba375a3066",[],"But in the AI era, Salesforce technical debt is also security debt. Let’s think of a few examples…",[],{"_key":4706,"_type":172,"children":4707,"level":54,"listItem":309,"markDefs":4712,"style":180},"89a019751826",[4708],{"_key":4709,"_type":176,"marks":4710,"text":4711},"6811924f90d7",[],"A stale permission",[],{"_key":4714,"_type":172,"children":4715,"level":54,"listItem":309,"markDefs":4719,"style":180},"327980b43303",[4716],{"_key":4709,"_type":176,"marks":4717,"text":4718},[],"A forgotten public site",[],{"_key":4721,"_type":172,"children":4722,"level":54,"listItem":309,"markDefs":4726,"style":180},"927c8e93d8ed",[4723],{"_key":4709,"_type":176,"marks":4724,"text":4725},[],"A broad service account",[],{"_key":4728,"_type":172,"children":4729,"level":54,"listItem":309,"markDefs":4733,"style":180},"2e77971a2a47",[4730],{"_key":4709,"_type":176,"marks":4731,"text":4732},[],"A downloadable file in the wrong place ",[],{"_key":4735,"_type":172,"children":4736,"level":54,"listItem":309,"markDefs":4740,"style":180},"4d4cf9fe5827",[4737],{"_key":4709,"_type":176,"marks":4738,"text":4739},[],"A without sharing class.",[],{"_key":4742,"_type":172,"children":4743,"level":54,"listItem":309,"markDefs":4747,"style":180},"8a29bb7e8002",[4744],{"_key":4709,"_type":176,"marks":4745,"text":4746},[],"A connected app nobody owns",[],{"_key":4749,"_type":172,"children":4750,"markDefs":4755,"style":180},"8d6dc0bb8b31",[4751],{"_key":4752,"_type":176,"marks":4753,"text":4754},"9a0807ed9439",[],"They are all possible paths.",[],{"_key":4757,"_type":172,"children":4758,"markDefs":4772,"style":180},"3f71b9c4a4a7",[4759,4763,4768],{"_key":4760,"_type":176,"marks":4761,"text":4762},"3970a54fed1e",[],"Interestingly enough, ",{"_key":4764,"_type":176,"marks":4765,"text":4767},"56c37f5d7107",[4766],"1d69042ce9c1","IBM’s Cost of a Data Breach report",{"_key":4769,"_type":176,"marks":4770,"text":4771},"d35c6bcc51d7",[]," puts real-money numbers behind the urgency: the global average cost of a data breach was $4.4 million, while organizations making extensive use of AI in security saw $1.9 million in cost savings compared to those that did not. (For what it’s worth, IBM also emphasized faster identification and containment as drivers of reduced breach cost.)",[4773],{"_key":4766,"_type":151,"blank":57,"href":4774,"noOpener":57,"noReferrer":57,"url":4774},"https://www.ibm.com/reports/data-breach",{"_key":4776,"_type":172,"children":4777,"markDefs":4782,"style":180},"3456ccfb3af0",[4778],{"_key":4779,"_type":176,"marks":4780,"text":4781},"1c32b6949881",[],"Salesforce often contains customer data, partner data, pipeline data, support data, identity-adjacent data, contractual information, and operational workflows. The cost of exposure extends beyond the breach to the response, the investigation, the remediation, the customer trust problem, and the operational risk of even fixing the wrong thing too quickly.",[],{"_key":4784,"_type":172,"children":4785,"markDefs":4790,"style":292},"83d0c4609617",[4786],{"_key":4787,"_type":176,"marks":4788,"text":4789},"b97b4fe3f0bf",[],"The remediation paradox",[],{"_key":4792,"_type":172,"children":4793,"markDefs":4798,"style":180},"7b880aea30b2",[4794],{"_key":4795,"_type":176,"marks":4796,"text":4797},"c017d44a7239",[],"Most security advice gets too confident on this one.",[],{"_key":4800,"_type":172,"children":4801,"markDefs":4806,"style":180},"e917f9d65397",[4802],{"_key":4803,"_type":176,"marks":4804,"text":4805},"49105b287aaa",[],"“Review guest permissions” sounds straightforward.",[],{"_key":4808,"_type":172,"children":4809,"markDefs":4814,"style":180},"5358d9b1696d",[4810],{"_key":4811,"_type":176,"marks":4812,"text":4813},"eec677682d92",[],"In a real Salesforce org, that is rarely as utopian as it sounds.",[],{"_key":4816,"_type":172,"children":4817,"markDefs":4822,"style":180},"f39da0459663",[4818],{"_key":4819,"_type":176,"marks":4820,"text":4821},"39344830253d",[],"The moment a finding appears, teams have to answer much harder questions:",[],{"_key":4824,"_type":172,"children":4825,"level":54,"listItem":309,"markDefs":4830,"style":180},"c6baf5041967",[4826],{"_key":4827,"_type":176,"marks":4828,"text":4829},"c05e8eebb0db",[],"What data is actually exposed?",[],{"_key":4832,"_type":172,"children":4833,"level":54,"listItem":309,"markDefs":4838,"style":180},"2a13ef99e2a1",[4834],{"_key":4835,"_type":176,"marks":4836,"text":4837},"a614fa3c3633",[],"Which business process depends on this access?",[],{"_key":4840,"_type":172,"children":4841,"level":54,"listItem":309,"markDefs":4846,"style":180},"c31e9228c309",[4842],{"_key":4843,"_type":176,"marks":4844,"text":4845},"04c431604b3b",[],"Who owns the site, object, app, service account, or file?",[],{"_key":4848,"_type":172,"children":4849,"level":54,"listItem":309,"markDefs":4854,"style":180},"cf3c853c9182",[4850],{"_key":4851,"_type":176,"marks":4852,"text":4853},"a4dd2e6b41c9",[],"Is this permission inherited through a profile, permission set, permission set group, sharing rule, or code path?",[],{"_key":4856,"_type":172,"children":4857,"level":54,"listItem":309,"markDefs":4862,"style":180},"35b58cebb6ce",[4858],{"_key":4859,"_type":176,"marks":4860,"text":4861},"37491987d081",[],"What breaks if we remove it?",[],{"_key":4864,"_type":172,"children":4865,"level":54,"listItem":309,"markDefs":4870,"style":180},"eab386fb0f3c",[4866],{"_key":4867,"_type":176,"marks":4868,"text":4869},"52ebcad2f28f",[],"What should be remediated first?",[],{"_key":4872,"_type":172,"children":4873,"level":54,"listItem":309,"markDefs":4878,"style":180},"0e16a238232f",[4874],{"_key":4875,"_type":176,"marks":4876,"text":4877},"c4604383ed32",[],"How do we validate the fix?",[],{"_key":4880,"_type":172,"children":4881,"level":54,"listItem":309,"markDefs":4886,"style":180},"a1366f2b612e",[4882],{"_key":4883,"_type":176,"marks":4884,"text":4885},"e2aaabee4f60",[],"How do we know the same exposure will not return next month?",[],{"_key":4888,"_type":172,"children":4889,"markDefs":4899,"style":180},"643d92b3281a",[4890,4894],{"_key":4891,"_type":176,"marks":4892,"text":4893},"fc9f1c355b39",[],"A scan can identify a problem. A report can describe a problem. But remediation ",{"_key":4895,"_type":176,"marks":4896,"text":4898},"095a1b7bd51a",[4897],"8075b17d2a66","requires context.",[4900],{"_key":4897,"_ref":4321,"_type":328,"linkType":33,"slug":4901},{"_type":22,"current":4323},{"_key":4903,"_type":172,"children":4904,"markDefs":4909,"style":180},"c18f07e3c469",[4905],{"_key":4906,"_type":176,"marks":4907,"text":4908},"a34ddeeb57dd",[],"That is why Salesforce exposure management has to move beyond point-in-time assessment. The org keeps changing. A new site goes live. A permission set gets edited. A flow changes. A file is uploaded. A connected app is approved. A service account is reused. A “temporary” access grant becomes invisible.",[],{"_key":4911,"_type":172,"children":4912,"markDefs":4917,"style":292},"8bf9650c236f",[4913],{"_key":4914,"_type":176,"marks":4915,"text":4916},"cc38fcc29f23",[],"What Salesforce exposure management now requires",[],{"_key":4919,"_type":172,"children":4920,"markDefs":4925,"style":180},"3cb8840fb666",[4921],{"_key":4922,"_type":176,"marks":4923,"text":4924},"af2939510261",[],"The new economics of exposure demand a new operating model. A modern Salesforce exposure program needs to continuously answer four questions.",[],{"_key":4927,"_type":172,"children":4928,"markDefs":4933,"style":920},"4b0d1c8e8a05",[4929],{"_key":4930,"_type":176,"marks":4931,"text":4932},"ebfd3e1e80c6",[],"1. What exactly is exposed?",[],{"_key":4935,"_type":172,"children":4936,"markDefs":4941,"style":180},"541e7fa01e22",[4937],{"_key":4938,"_type":176,"marks":4939,"text":4940},"ff4e8984e32a",[],"Teams need visibility across public sites, guest users, files, Apex, permissions, connected apps, service accounts, integrations, automations, and data platforms.",[],{"_key":4943,"_type":172,"children":4944,"markDefs":4949,"style":920},"64817345ca6d",[4945],{"_key":4946,"_type":176,"marks":4947,"text":4948},"8e9c58145ae9",[],"2. Why does that matter?",[],{"_key":4951,"_type":172,"children":4952,"markDefs":4957,"style":180},"fda1c9460f43",[4953],{"_key":4954,"_type":176,"marks":4955,"text":4956},"3cb8e6841a40",[],"Exposure only becomes meaningful when it is connected to business context: sensitive data, customer workflows, revenue processes, partner operations, support processes, or regulated information.",[],{"_key":4959,"_type":172,"children":4960,"markDefs":4965,"style":920},"d1550fef8c7c",[4961],{"_key":4962,"_type":176,"marks":4963,"text":4964},"316ad072e92e",[],"3. What should we fix first?",[],{"_key":4967,"_type":172,"children":4968,"markDefs":4973,"style":180},"ea77e31dd1b8",[4969],{"_key":4970,"_type":176,"marks":4971,"text":4972},"50768f8be3e4",[],"Not every issue carries the same risk. Prioritization should consider exploitability, blast radius, ownership, dependencies, and business impact.",[],{"_key":4975,"_type":172,"children":4976,"markDefs":4981,"style":920},"043ca247ced1",[4977],{"_key":4978,"_type":176,"marks":4979,"text":4980},"9e73cc0cf88c",[],"4. How do we keep it fixed?",[],{"_key":4983,"_type":172,"children":4984,"markDefs":4989,"style":180},"e079245c4b83",[4985],{"_key":4986,"_type":176,"marks":4987,"text":4988},"6050e4d85ede",[],"Salesforce changes constantly. Monitoring has to track metadata and configuration changes that could reintroduce exposure after remediation.",[],{"_key":4991,"_type":172,"children":4992,"markDefs":4997,"style":180},"aea781e3ec04",[4993],{"_key":4994,"_type":176,"marks":4995,"text":4996},"7d25a0548aa2",[],"This is the shift from security assessment to continuous exposure management.",[],{"_key":4999,"_type":172,"children":5000,"markDefs":5005,"style":292},"06f3f83013f4",[5001],{"_key":5002,"_type":176,"marks":5003,"text":5004},"2521a0eb995f",[],"Complexity is not the enemy",[],{"_key":5007,"_type":172,"children":5008,"markDefs":5013,"style":180},"64468834708c",[5009],{"_key":5010,"_type":176,"marks":5011,"text":5012},"b7e76b66f1b9",[],"The answer is not to pretend your Salesforce org can be made simple.",[],{"_key":5015,"_type":172,"children":5016,"markDefs":5029,"style":180},"a09c8d8f5141",[5017,5021,5025],{"_key":5018,"_type":176,"marks":5019,"text":5020},"b99c06e5c0f8",[],"It cannot. And honestly, it probably ",{"_key":5022,"_type":176,"marks":5023,"text":5024},"df23a9a10277",[393],"should",{"_key":5026,"_type":176,"marks":5027,"text":5028},"d4864970974d",[]," not.",[],{"_key":5031,"_type":172,"children":5032,"markDefs":5037,"style":180},"95af52b3c5a4",[5033],{"_key":5034,"_type":176,"marks":5035,"text":5036},"3d4363e1ab3b",[],"A simple Salesforce org is often a whiteboard fantasy. Real Salesforce environments are complex because real businesses operating in real… reality… are complex. They have exceptions, channels, products, regions, partners, legacy processes, compliance needs, and customer promises embedded into the system.",[],{"_key":5039,"_type":172,"children":5040,"markDefs":5045,"style":180},"19469ae133b0",[5041],{"_key":5042,"_type":176,"marks":5043,"text":5044},"33064effdedc",[],"The goal cannot be to erase complexity but to make it visible, understandable, governable, and safe to change.",[],{"_key":5047,"_type":172,"children":5048,"markDefs":5053,"style":180},"076608338cf1",[5049],{"_key":5050,"_type":176,"marks":5051,"text":5052},"ac698f1de16e",[],"AI has changed the risk calculation. What used to be buried can now be found. What used to require patient manual work can now be automated. What used to look like scattered hygiene issues can now become a connected path to sensitive data.",[],{"_key":5055,"_type":172,"children":5056,"markDefs":5061,"style":180},"971539b57211",[5057],{"_key":5058,"_type":176,"marks":5059,"text":5060},"bb1d4c6f2fa0",[],"The exposure was already there.",[],{"_key":5063,"_type":172,"children":5064,"markDefs":5069,"style":180},"8a26ecbdc5f8",[5065],{"_key":5066,"_type":176,"marks":5067,"text":5068},"f3581b25c636",[],"AI changed the economics.",[],{"_key":5071,"_type":172,"children":5072,"markDefs":5077,"style":180},"0255d09432c7",[5073],{"_key":5074,"_type":176,"marks":5075,"text":5076},"30ea2817ed07",[],"Now, Salesforce teams must change the operating model to survive.",[],{"_type":17,"description":5079,"shareImage":5080,"title":4097},"AI has changed the Salesforce security equation. Exposure that was once too buried to find can now be discovered, connected, and acted on at machine speed.",{"_type":40,"asset":5081},{"_ref":4101,"_type":278},{"_type":22,"current":5083},"new-economics-of-salesforce-exposure",{"_createdAt":5085,"_id":5086,"_rev":5087,"_type":33,"_updatedAt":5088,"author":5089,"category":5105,"featuredImage":5111,"modularContent":5144,"postTitle":5112,"publishDate":5148,"richText":5149,"seo":5544,"slug":5549},"2026-05-30T20:17:24Z","2e959d9d-b823-4636-8f8c-d830e74c9fe3","lObXj35dtY4hvwCgWVnJuH","2026-06-12T17:48:09Z",{"authorImage":5090,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":38,"image":5091},{"_type":40,"asset":5092},{"_createdAt":42,"_id":43,"_rev":44,"_type":45,"_updatedAt":46,"altText":19,"assetId":47,"description":19,"extension":48,"metadata":5093,"mimeType":83,"opt":5103,"originalFilename":86,"path":87,"sha1hash":47,"size":88,"title":19,"uploadId":89,"url":90},{"_type":50,"blurHash":51,"dimensions":5094,"hasAlpha":56,"isOpaque":57,"lqip":58,"palette":5095},{"_type":53,"aspectRatio":54,"height":55,"width":55},{"_type":60,"darkMuted":5096,"darkVibrant":5097,"dominant":5098,"lightMuted":5099,"lightVibrant":5100,"muted":5101,"vibrant":5102},{"_type":62,"background":63,"foreground":64,"population":65,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":71,"foreground":72,"population":73,"title":64},{"_type":62,"background":75,"foreground":72,"population":76,"title":72},{"_type":62,"background":78,"foreground":64,"population":79,"title":64},{"_type":62,"background":81,"foreground":64,"population":82,"title":64},{"media":5104},{"tags":19},{"_createdAt":5,"_id":6,"_rev":7,"_system":5106,"_type":11,"_updatedAt":12,"selectedColor":5108,"seo":5109,"slug":5110,"title":24},{"base":5107},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":5112,"image":5113},"Salesforce-Snowflake Integration: Cross-System Governance Patterns",{"_type":40,"asset":5114},{"_createdAt":5115,"_id":5116,"_rev":5117,"_type":45,"_updatedAt":5115,"assetId":5118,"extension":106,"metadata":5119,"mimeType":132,"originalFilename":5139,"path":5140,"sha1hash":5118,"size":5141,"uploadId":5142,"url":5143},"2026-05-30T20:18:43Z","image-84fe33bb9dd3d361e38711e0e747fefdaa09d73e-1200x630-png","7C11lhdHH1sdLwfCVMswbe","84fe33bb9dd3d361e38711e0e747fefdaa09d73e",{"_type":50,"blurHash":5120,"dimensions":5121,"hasAlpha":57,"isOpaque":57,"lqip":5122,"palette":5123,"thumbHash":5138},"M59[,Wx_RmtUWDtWa#azfRj@9MRmt4WEod",{"_type":53,"aspectRatio":110,"height":111,"width":112},"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAAsTAAALEwEAmpwYAAAArklEQVR4nM2S6wqCUBCEfUQ1otLKgiC7vEDaxUsWpdUjf3E4R7JDEViEP4bZHdhhdlnDXMEvYfzd0ApqGNrB50FL47eGrRCcGAYp9BNwIuhFUnMUC91VvRupOobOFuxQM2xvYHKC5Q0WV5gVMM0VzuDnUvNVL+r5BfwCRhmI+eeEa5lgfFQ4gJc9ErtJhWMYpuDtpdbdvUhY3lCsXoXQ9PuVtdWotzG/MdRXq2N4B4I+aFNGy9jcAAAAAElFTkSuQmCC",{"_type":60,"darkMuted":5124,"darkVibrant":5126,"dominant":5128,"lightMuted":5130,"lightVibrant":5132,"muted":5134,"vibrant":5137},{"_type":62,"background":5125,"foreground":64,"population":82,"title":64},"#213977",{"_type":62,"background":5127,"foreground":64,"population":125,"title":64},"#3154ae",{"_type":62,"background":840,"foreground":64,"population":5129,"title":64},80.23,{"_type":62,"background":5131,"foreground":72,"population":82,"title":64},"#a4b4cc",{"_type":62,"background":5133,"foreground":72,"population":125,"title":64},"#74a4fc",{"_type":62,"background":5135,"foreground":64,"population":5136,"title":64},"#5770b0",0.23,{"_type":62,"background":840,"foreground":64,"population":5129,"title":64},"ZrMBDIBpaHd3eIhgeYhpd5B2Bw==","process-blog-header-1200x630.png","images/9eu1m6zu/production/84fe33bb9dd3d361e38711e0e747fefdaa09d73e-1200x630.png",63387,"iaCsWDCMhAtGn1CgznI3cKcXlLHZzGCb","https://cdn.sanity.io/images/9eu1m6zu/production/84fe33bb9dd3d361e38711e0e747fefdaa09d73e-1200x630.png",[5145],{"_key":5146,"_type":275,"cols":276,"filterByCategory":5147,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":279},"65dd78798ff66f90107495b4d1ffb594",{"_ref":6,"_type":278},"2026-05-30",[5150,5157,5165,5173,5181,5189,5197,5205,5212,5220,5227,5234,5242,5250,5266,5274,5285,5292,5303,5318,5329,5336,5344,5352,5372,5380,5399,5407,5415,5427,5439,5451,5470,5478,5498,5519,5527],{"_key":5151,"_type":172,"children":5152,"markDefs":5156,"style":292},"96290d4935bb",[5153],{"_key":5154,"_type":176,"marks":5155,"text":290},"a3f942ae9b66",[],[],{"_key":5158,"_type":172,"children":5159,"level":54,"listItem":309,"markDefs":5164,"style":180},"7e2b0adfcc1a",[5160],{"_key":5161,"_type":176,"marks":5162,"text":5163},"bcc907fa1320",[],"Salesforce and Snowflake each have their own governance model, and neither one can see across the boundary — that’s where the risk lives.",[],{"_key":5166,"_type":172,"children":5167,"level":54,"listItem":309,"markDefs":5172,"style":180},"4e5cb2fdc053",[5168],{"_key":5169,"_type":176,"marks":5170,"text":5171},"3c4e8bac5c52",[],"The integration breaks governance in three predictable places: definitions drift apart (e.g., \"Account\" means different things), access gets over-provisioned because no one sees the full path, and PII flows downstream into tables no policy is watching.",[],{"_key":5174,"_type":172,"children":5175,"level":54,"listItem":309,"markDefs":5180,"style":180},"e9b2afdb255f",[5176],{"_key":5177,"_type":176,"marks":5178,"text":5179},"08537eca0140",[],"Native lineage doesn't span the two systems, so most teams stitch together connectors, ETL jobs, and catalogs and still can't answer \"what breaks if this field changes.\"",[],{"_key":5182,"_type":172,"children":5183,"level":54,"listItem":309,"markDefs":5188,"style":180},"7847af217495",[5184],{"_key":5185,"_type":176,"marks":5186,"text":5187},"300f804b9410",[],"The durable pattern is governing the metadata layer that connects both systems — one map of how CRM changes propagate into the warehouse, with definitions, access, and lineage visible across the seam.",[],{"_key":5190,"_type":172,"children":5191,"markDefs":5196,"style":292},"be110f3ff530",[5192],{"_key":5193,"_type":176,"marks":5194,"text":5195},"1773fc0d9044",[],"Salesforce Snowflake Integration: Cross-System Governance Patterns",[],{"_key":5198,"_type":172,"children":5199,"markDefs":5204,"style":180},"e92a1b2b1612",[5200],{"_key":5201,"_type":176,"marks":5202,"text":5203},"aab51988be22",[],"Connecting Salesforce to Snowflake is deceptively easy.",[],{"_key":5206,"_type":172,"children":5207,"markDefs":5211,"style":180},"334f5b16d8b3",[5208],{"_key":5201,"_type":176,"marks":5209,"text":5210},[],"A reverse-ETL job here, a connector there, and within a quarter your CRM objects are feeding raw tables, your tables are powering executive dashboards, and your revenue numbers are flowing in both directions. The pipes! They work!",[],{"_key":5213,"_type":172,"children":5214,"markDefs":5219,"style":180},"8b5f45d6cd21",[5215],{"_key":5216,"_type":176,"marks":5217,"text":5218},"2bbd8984593a",[],"The governance… on the other hand… that’s where it things snag. And usually, the reason is structural. ",[],{"_key":5221,"_type":172,"children":5222,"markDefs":5226,"style":180},"f85902d5a551",[5223],{"_key":5216,"_type":176,"marks":5224,"text":5225},[],"Salesforce governs its world. Snowflake governs its world. ",[],{"_key":5228,"_type":172,"children":5229,"markDefs":5233,"style":180},"4ce6a5e39354",[5230],{"_key":5216,"_type":176,"marks":5231,"text":5232},[],"Neither one governs the seam betwixt them, and the seam is precisely where  expensive failures explode: the metric that means one thing in the CRM and something else in the warehouse, the PII that left its policy behind when it crossed the boundary, the field someone changed in Salesforce that silently broke a dashboard three systems downstream.",[],{"_key":5235,"_type":172,"children":5236,"markDefs":5241,"style":180},"a341bfb59c33",[5237],{"_key":5238,"_type":176,"marks":5239,"text":5240},"b569f3997d5f",[],"Let’s dish on where cross-system governance actually breaks, and the patterns that hold.",[],{"_key":5243,"_type":172,"children":5244,"markDefs":5249,"style":292},"327104ac6517",[5245],{"_key":5246,"_type":176,"marks":5247,"text":5248},"18155013a7ff",[],"Why the Salesforce Snowflake integration breaks governance",[],{"_key":5251,"_type":172,"children":5252,"markDefs":5265,"style":180},"4defd49048cf",[5253,5257,5261],{"_key":5254,"_type":176,"marks":5255,"text":5256},"f34a3bccf087",[],"Each system has a competent governance model on its own turf. The problem is that neither model extends past its own edge, and an integration is nothing ",{"_key":5258,"_type":176,"marks":5259,"text":5260},"eee1c03fdaa0",[393],"but",{"_key":5262,"_type":176,"marks":5263,"text":5264},"c7c2a3b3c784",[]," edges.",[],{"_key":5267,"_type":172,"children":5268,"markDefs":5273,"style":180},"cd558ef8a6a9",[5269],{"_key":5270,"_type":176,"marks":5271,"text":5272},"f978a21a7714",[],"Three failure modes show up in almost every org running this integration:",[],{"_key":5275,"_type":172,"children":5276,"markDefs":5284,"style":180},"9f0cd99e9179",[5277,5281],{"_key":5278,"_type":176,"marks":5279,"text":5280},"5bbcbede5799",[369],"Definitions drift apart.",{"_key":5282,"_type":176,"marks":5283,"text":708},"0af3d7b478f2",[],[],{"_key":5286,"_type":172,"children":5287,"markDefs":5291,"style":180},"ac27bf722863",[5288],{"_key":5282,"_type":176,"marks":5289,"text":5290},[],"\"Account,\" \"Opportunity,\" \"qualified\" — these get defined once in Salesforce and redefined, often subtly differently, when they land in Snowflake. Conflicting definitions of core entities like \"Account\" or \"Opportunity\" are exactly the kind of issue that's almost impossible to catch manually, alongside orphaned tables, zombie pipelines, and risky PII flows that don't align with policy. Nobody decided to have two definitions. They just accumulated, one well-intentioned transformation at a time. ",[],{"_key":5293,"_type":172,"children":5294,"markDefs":5302,"style":180},"602cbbad103e",[5295,5299],{"_key":5296,"_type":176,"marks":5297,"text":5298},"f3237fccc2d4",[369],"Access gets over-provisioned because no one sees the whole path.",{"_key":5300,"_type":176,"marks":5301,"text":708},"109e98a1dda0",[],[],{"_key":5304,"_type":172,"children":5305,"markDefs":5317,"style":180},"aa11d0a20aac",[5306,5309,5313],{"_key":5300,"_type":176,"marks":5307,"text":5308},[],"A user's effective access to a piece of data is the ",{"_key":5310,"_type":176,"marks":5311,"text":5312},"052d9fd0c08b",[393],"product",{"_key":5314,"_type":176,"marks":5315,"text":5316},"50d7f1f8dbe2",[]," of Salesforce permissions and Snowflake grants, but no single tool computes that product. So teams grant generously on each side to avoid breaking things, and the combined surface area quietly widens.",[],{"_key":5319,"_type":172,"children":5320,"markDefs":5328,"style":180},"338993911ee6",[5321,5325],{"_key":5322,"_type":176,"marks":5323,"text":5324},"9cb868a98224",[369],"PII outruns its policy.",{"_key":5326,"_type":176,"marks":5327,"text":708},"11abee7a7c3e",[],[],{"_key":5330,"_type":172,"children":5331,"markDefs":5335,"style":180},"3abfacc5b5d8",[5332],{"_key":5326,"_type":176,"marks":5333,"text":5334},[],"A field that's governed and masked in Salesforce gets replicated into a Snowflake table where the masking policy doesn't follow. The data is the same; the controls aren't. Salesforce objects feed raw tables, stored procedures calculate metrics, views power dashboards, and downstream systems activate insights — and that chain is where governance constraints get lost if nothing is tracking them across systems.  ",[],{"_key":5337,"_type":172,"children":5338,"markDefs":5343,"style":292},"f228d03fd501",[5339],{"_key":5340,"_type":176,"marks":5341,"text":5342},"15bcda2c78c6",[],"The cross-system lineage gap",[],{"_key":5345,"_type":172,"children":5346,"markDefs":5351,"style":180},"2ff81c63f7f5",[5347],{"_key":5348,"_type":176,"marks":5349,"text":5350},"3cc33d8cb447",[],"Underneath all three failures is one missing capability: lineage that crosses the boundary.",[],{"_key":5353,"_type":172,"children":5354,"markDefs":5367,"style":180},"14def1400a8c",[5355,5359,5364],{"_key":5356,"_type":176,"marks":5357,"text":5358},"c51dac15e5e3",[],"Within Snowflake, you have queryable metadata and reasonable native lineage. Within Salesforce, you don't even get that. There's no equivalent out-of-the-box lineage view across Salesforce objects, flows, and integrations, so the burden falls on pipelines and catalogs. Stitch the two together and the gap compounds — you can trace data inside each system, but not the handoff between them, ",{"_key":5360,"_type":176,"marks":5361,"text":5363},"84ed410d3c90",[5362],"229a6dc31d17","which is the part that matters most",{"_key":5365,"_type":176,"marks":5366,"text":3667},"4d7237a43785",[],[5368],{"_key":5362,"_ref":5369,"_type":328,"linkType":33,"slug":5370},"af91a929-cfba-4d9a-a30c-60fc5f947b52",{"_type":22,"current":5371},"metadata-lineage-in-cross-cloud-pipelines-salesforce-to-snowflake",{"_key":5373,"_type":172,"children":5374,"markDefs":5379,"style":180},"47369c11592d",[5375],{"_key":5376,"_type":176,"marks":5377,"text":5378},"0f782b219978",[],"The emerging best practice on the engineering side is to stop reconstructing lineage after the fact and have the pipeline declare it as it runs. ",[],{"_key":5381,"_type":172,"children":5382,"markDefs":5398,"style":180},"8a5a1bfe5613",[5383,5386,5390,5394],{"_key":5376,"_type":176,"marks":5384,"text":5385},[],"The OpenLineage standard is built for this: it defines a generic API for jobs and datasets, so a reverse-ETL job can emit an event whose inputs include a Snowflake table and whose outputs include a Salesforce object, feeding an end-to-end graph. It's a worth adopting. But on its own, it produces a lineage ",{"_key":5387,"_type":176,"marks":5388,"text":5389},"0fde173cd52e",[393],"log. ",{"_key":5391,"_type":176,"marks":5392,"text":5393},"8cf0039ec1ed",[369,393],"And a log does not governance make ",{"_key":5395,"_type":176,"marks":5396,"text":5397},"bda44ddb2b08",[],"— you still need something that reasons over the graph to tell you which definitions conflict, which access paths are over-broad, and what breaks when a field changes. In practice, most organizations end up stitching together SaaS connectors, ETL jobs, and open-source agents and still don't have a single answer.",[],{"_key":5400,"_type":172,"children":5401,"markDefs":5406,"style":920},"a92c186aa517",[5402],{"_key":5403,"_type":176,"marks":5404,"text":5405},"621a67c6d333",[],"Cross-system governance patterns that hold",[],{"_key":5408,"_type":172,"children":5409,"markDefs":5414,"style":180},"2a5f72c7e0f8",[5410],{"_key":5411,"_type":176,"marks":5412,"text":5413},"a3e5ddc976ce",[],"So what actually works here? There are options, in rough priority order:",[],{"_key":5416,"_type":172,"children":5417,"level":54,"listItem":309,"markDefs":5426,"style":180},"685f55756ff8",[5418,5422],{"_key":5419,"_type":176,"marks":5420,"text":5421},"e9d61dc9eea2",[369],"Govern the metadata layer, not each system separately.",{"_key":5423,"_type":176,"marks":5424,"text":5425},"655afd03c2b4",[]," The seam is the unit of governance. Any pattern that treats Salesforce and Snowflake as two independent governance projects will leave the boundary uncovered. Wasn’t that the place were were trying to cover?",[],{"_key":5428,"_type":172,"children":5429,"level":54,"listItem":309,"markDefs":5438,"style":180},"84f6c5630453",[5430,5434],{"_key":5431,"_type":176,"marks":5432,"text":5433},"3ab46163eea8",[369],"Make definitions canonical and visible across both systems.",{"_key":5435,"_type":176,"marks":5436,"text":5437},"db38791c8c73",[]," One source of truth for what \"Account\" means, with deviations surfaced rather than discovered during a board-deck discrepancy.",[],{"_key":5440,"_type":172,"children":5441,"level":54,"listItem":309,"markDefs":5450,"style":180},"f4b1dcf741c0",[5442,5446],{"_key":5443,"_type":176,"marks":5444,"text":5445},"45dd498c10ba",[369],"Compute access across the full path.",{"_key":5447,"_type":176,"marks":5448,"text":5449},"64a23c9db640",[]," Governance has to see the Salesforce-to-Snowflake access chain as one thing, so over-provisioning shows up instead of hiding in the gap between two grant models.",[],{"_key":5452,"_type":172,"children":5453,"level":54,"listItem":309,"markDefs":5469,"style":180},"16b5e34154bb",[5454,5458,5462,5465],{"_key":5455,"_type":176,"marks":5456,"text":5457},"a32b539a71f6",[369],"Track changes before they propagate.",{"_key":5459,"_type":176,"marks":5460,"text":5461},"61b501e98405",[]," The goal is to know what a CRM change will do to the warehouse ",{"_key":5463,"_type":176,"marks":5464,"text":763},"744f671413b2",[393],{"_key":5466,"_type":176,"marks":5467,"text":5468},"68ddb1105ae0",[]," it ships, not to debug the broken dashboard after.",[],{"_key":5471,"_type":172,"children":5472,"markDefs":5477,"style":180},"282eb52705e0",[5473],{"_key":5474,"_type":176,"marks":5475,"text":5476},"7dc5cf327d8d",[],"This is the layer Sweep is built to govern. ",[],{"_key":5479,"_type":172,"children":5480,"markDefs":5493,"style":180},"4d469b1c5c5b",[5481,5484,5489],{"_key":5474,"_type":176,"marks":5482,"text":5483},[],"Sweep's metadata agents continuously read Snowflake's metadata — objects, usage, tags, access history — and stitch it together with the rest of the operational graph, including Salesforce, building a real-time view of how the systems actually connect rather than how the architecture diagram says they should. Crucially, it does this without touching the sensitive part: Sweep connects to Snowflake using read-only, metadata-only access by default and does not ingest customer data values, operating exclusively ",{"_key":5485,"_type":176,"marks":5486,"text":5488},"f6fb88ec0111",[5487],"7cdbbeee7026","on metadata",{"_key":5490,"_type":176,"marks":5491,"text":5492},"6b2e72ba3405",[]," while remaining SOC 2 Type II compliant for regulated environments. ",[5494],{"_key":5487,"_ref":5495,"_type":328,"linkType":33,"slug":5496},"307dd935-bc85-46db-9aba-dfd3e2ba0085",{"_type":22,"current":5497},"snowflake-metadata-a-beginner-s-guide",{"_key":5499,"_type":172,"children":5500,"markDefs":5514,"style":180},"6282778e0adb",[5501,5505,5510],{"_key":5502,"_type":176,"marks":5503,"text":5504},"3c144a2d269a",[],"On top of that map, the cross-system failures become both visible and actionable. Sweep maps how CRM changes propagate into warehouse transformations and analytics in a shared workspace, so cross-system lineage becomes visible, explainable, and actionable, and it maps structural access paths and object ownership so teams can enforce governance and reduce over-privileged access. Rather than catching schema drift after a pipeline breaks, it analyzes changes before they happen, maps dependencies across Salesforce and Snowflake, identifies which assets will break and who owns them, and wraps schema changes in ",{"_key":5506,"_type":176,"marks":5507,"text":5509},"a108539240dd",[5508],"27cb42d47e8d","governed workflows",{"_key":5511,"_type":176,"marks":5512,"text":5513},"a6a4712d02ad",[]," instead of best-effort communication. ",[5515],{"_key":5508,"_ref":5516,"_type":328,"linkType":33,"slug":5517},"198bff75-2986-4077-bb4e-fc90c12c2bf8",{"_type":22,"current":5518},"detect-data-drift-between-salesforce-and-snowflake",{"_key":5520,"_type":172,"children":5521,"markDefs":5526,"style":180},"1608949c0b18",[5522],{"_key":5523,"_type":176,"marks":5524,"text":5525},"8542c4d9172e",[],"The integration was never the hard part. Governing what flows across it is — and that's a job neither system can do alone, because neither one can see the other side.",[],{"_key":5528,"_type":172,"children":5529,"markDefs":5539,"style":180},"1ec61eb3c043",[5530,5535],{"_key":5531,"_type":176,"marks":5532,"text":5534},"6a641cb5f3f0",[5533],"66055219c2e0","Book a demo.",{"_key":5536,"_type":176,"marks":5537,"text":5538},"4626f6bf5640",[]," We’d love to show you how cross-system governance gets done.",[5540],{"_key":5533,"_ref":5541,"_type":328,"linkType":738,"slug":5542},"2bad9bbb-b388-4ab3-861e-5dd3c1159a6e",{"_type":22,"current":5543},"lp-demo-request",{"_type":17,"description":5545,"shareImage":5546,"title":5548},"Connecting Salesforce to Snowflake is easy. Governing the seam isn't. The cross-system patterns for definitions, access, and lineage that hold across both.",{"_type":40,"asset":5547},{"_ref":5116,"_type":278},"Salesforce-Snowflake Integration: Cross-System Governance",{"_type":22,"current":5550},"salesforce-snowflake-governance",{"_createdAt":5552,"_id":5553,"_rev":5554,"_system":5555,"_type":33,"_updatedAt":5558,"author":5559,"category":5576,"featuredImage":5582,"modularContent":5619,"postTitle":5623,"publishDate":5624,"richText":5625,"seo":5954,"slug":5959},"2026-05-14T18:56:33Z","1f220821-1389-43b0-8945-cfac9adda91e","LR2JmGsXZsTFhbg10L0fce",{"base":5556},{"id":5553,"rev":5557},"27JYKTS1NaJJUiEMtKAriX","2026-05-14T19:25:34Z",{"authorImage":5560,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":5561,"image":5562},"Nick Gaudio, Salesforce Expert of 8 years",{"_type":40,"asset":5563},{"_createdAt":42,"_id":43,"_rev":44,"_type":45,"_updatedAt":46,"altText":19,"assetId":47,"description":19,"extension":48,"metadata":5564,"mimeType":83,"opt":5574,"originalFilename":86,"path":87,"sha1hash":47,"size":88,"title":19,"uploadId":89,"url":90},{"_type":50,"blurHash":51,"dimensions":5565,"hasAlpha":56,"isOpaque":57,"lqip":58,"palette":5566},{"_type":53,"aspectRatio":54,"height":55,"width":55},{"_type":60,"darkMuted":5567,"darkVibrant":5568,"dominant":5569,"lightMuted":5570,"lightVibrant":5571,"muted":5572,"vibrant":5573},{"_type":62,"background":63,"foreground":64,"population":65,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":71,"foreground":72,"population":73,"title":64},{"_type":62,"background":75,"foreground":72,"population":76,"title":72},{"_type":62,"background":78,"foreground":64,"population":79,"title":64},{"_type":62,"background":81,"foreground":64,"population":82,"title":64},{"media":5575},{"tags":19},{"_createdAt":5,"_id":6,"_rev":7,"_system":5577,"_type":11,"_updatedAt":12,"selectedColor":5579,"seo":5580,"slug":5581,"title":24},{"base":5578},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":5583,"image":5584},"The hidden audit that's coming to your Salesforce",{"_type":40,"asset":5585},{"_createdAt":5586,"_id":5587,"_rev":5588,"_type":45,"_updatedAt":5586,"assetId":5589,"extension":106,"metadata":5590,"mimeType":132,"originalFilename":5614,"path":5615,"sha1hash":5589,"size":5616,"uploadId":5617,"url":5618},"2026-05-14T19:10:08Z","image-f125eae3b256ecc6bf94a302d057a2621ce8f097-1200x628-png","h2nYnUJu2loxbdwMxUlHrm","f125eae3b256ecc6bf94a302d057a2621ce8f097",{"_type":50,"blurHash":5591,"dimensions":5592,"hasAlpha":57,"isOpaque":57,"lqip":5595,"palette":5596,"thumbHash":5613},"MMQ5bjJ5oMsqoMS0sqoLjusq}dxIS0WUS0",{"_type":53,"aspectRatio":5593,"height":5594,"width":112},1.910828025477707,628,"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAAKCAYAAAC0VX7mAAAACXBIWXMAAAsTAAALEwEAmpwYAAABz0lEQVR4nI1SaVPaUBTNf3RGiVnAhT3S8J/6xdFWECEJW9iE4oaIQgiKFAhMR6da+AGn8260ZaadaT+cucvce859717uRR3jRZ3ghzrFUp1hGZ9hEXftUp27dhV/yX1XR5jvWXCifXCO0scw1MEkYmGmDDCO9PA10iWw3FwZEFjxTLEpN450f8VO1H6LLTzHRuAeQm00vAU0vEVcblVxKudhChkUhTRKooam18TVdg1nvhLVVSUDVdlAQy5QbVnSYYoa2jt1PMWG4OxACxUpi4KQRk3KEpHmOYLmSSDLJ11Sn0lkpphBXkiRLQoZqkuu7+Nk45BEn2OP4Do7TeQ2UzheP4DuScDgk9D5BAkw5Ypo0HTnvjJqco4mrMt51KQckRpvooPgNe2Ba22fIr3xCQdrH5FipHwCmuczibBC9nyGimTQl1iBK2q2g9foB1ro+S9xH2zj294DFnEH3O1uE2VRR37zhCaoywV6NotLok5+lj9GSdDQ81/Qx7+qE7oMhleGD1MsVIc2ToQXWxXYwRYcxcY0amEUvsMw3MFj+JbsfeiG/Pcp/jilFXBV2V0Ea3Bv0G1gt8h81/7O/wtc13+Om90vdGurhO/+Kv6H8CcJCWPBRzwUIAAAAABJRU5ErkJggg==",{"_type":60,"darkMuted":5597,"darkVibrant":5600,"dominant":5602,"lightMuted":5605,"lightVibrant":5607,"muted":5608,"vibrant":5611},{"_type":62,"background":5598,"foreground":64,"population":5599,"title":64},"#683974",1.25,{"_type":62,"background":5601,"foreground":64,"population":82,"title":64},"#242c6c",{"_type":62,"background":5603,"foreground":72,"population":5604,"title":64},"#f474e4",43.41,{"_type":62,"background":5606,"foreground":72,"population":844,"title":64},"#daabc6",{"_type":62,"background":5603,"foreground":72,"population":5604,"title":64},{"_type":62,"background":5609,"foreground":64,"population":5610,"title":64},"#965290",2.08,{"_type":62,"background":5612,"foreground":64,"population":82,"title":64},"#cc34c4","rOYGDISFh5eViIifdmt6alBY+Q==","ls-1200x628.png","images/9eu1m6zu/production/f125eae3b256ecc6bf94a302d057a2621ce8f097-1200x628.png",107298,"clqa4gHuNkvF76kYKQNpEz4nGgXVBQ38","https://cdn.sanity.io/images/9eu1m6zu/production/f125eae3b256ecc6bf94a302d057a2621ce8f097-1200x628.png",[5620],{"_key":5621,"_type":275,"cols":276,"filterByCategory":5622,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":279},"ef0b60452f044ba8ae732c19cdcd01e5",{"_ref":6,"_type":278},"The hidden audit inside Salesforce's June 2026 MFA mandate","2026-05-14",[5626,5633,5652,5660,5668,5675,5682,5690,5702,5710,5718,5726,5734,5742,5750,5758,5766,5774,5782,5801,5809,5817,5829,5837,5854,5862,5870,5878,5886,5894,5902,5923,5930,5938,5946],{"_key":5627,"_type":172,"children":5628,"markDefs":5632,"style":292},"275cfba91c46",[5629],{"_key":5630,"_type":176,"marks":5631,"text":290},"f1362ac8c41a",[],[],{"_key":5634,"_type":172,"children":5635,"level":54,"listItem":309,"markDefs":5649,"style":180},"37b26122ff60",[5636,5640,5645],{"_key":5637,"_type":176,"marks":5638,"text":5639},"5658b817eed6",[],"Salesforce's ",{"_key":5641,"_type":176,"marks":5642,"text":5644},"37ef8c4af4b0",[5643],"09ccb468f19c","June 2026 enforcement",{"_key":5646,"_type":176,"marks":5647,"text":5648},"b88eb30050e4",[]," of phishing-resistant MFA for privileged users isn't a settings change — it's a permission audit you have to run on a deadline.",[5650],{"_key":5643,"_type":151,"blank":57,"href":5651,"noOpener":57,"noReferrer":57,"url":5651},"https://help.salesforce.com/s/articleView?id=005321563&language=en_US&type=1",{"_key":5653,"_type":172,"children":5654,"level":54,"listItem":309,"markDefs":5659,"style":180},"44ef63d0db73",[5655],{"_key":5656,"_type":176,"marks":5657,"text":5658},"30e323f42b64",[],"\"Privileged users\" means anyone with System Admin, View All Data, Modify All Data, Customize Application, or Author Apex. In a mature org, finding them is multi-week work because those grants live across profiles, permission sets, and permission set groups.",[],{"_key":5661,"_type":172,"children":5662,"level":54,"listItem":309,"markDefs":5667,"style":180},"f65ebb3d678b",[5663],{"_key":5664,"_type":176,"marks":5665,"text":5666},"e151c528324f",[],"The enforcement cadence isn't a one-off. The audit muscle you build for June is the muscle you'll need every release.",[],{"_key":5669,"_type":172,"children":5670,"markDefs":5674,"style":180},"0be71e2bcdb3",[5671],{"_key":5672,"_type":176,"marks":5673,"text":187},"66f2b0859197",[],[],{"_key":5676,"_type":172,"children":5677,"markDefs":5681,"style":180},"192958d9f362",[5678],{"_key":5679,"_type":176,"marks":5680,"text":352},"ce3615d92756",[],[],{"_key":5683,"_type":172,"children":5684,"markDefs":5689,"style":180},"ff9d97754069",[5685],{"_key":5686,"_type":176,"marks":5687,"text":5688},"07d7bfc40e2f",[],"If you read Salesforce's June 2026 security announcement and your first thought was \"okay, we'll turn on phishing-resistant MFA,\" you were reading the wrong sentence.",[],{"_key":5691,"_type":172,"children":5692,"markDefs":5701,"style":180},"04652c8e609e",[5693,5697],{"_key":5694,"_type":176,"marks":5695,"text":5696},"17687407d9a9",[],"The harder sentence is the one before it. The one that says phishing-resistant MFA — physical security keys, biometric authenticators, none of the SMS or TOTP that worked last year — is",{"_key":5698,"_type":176,"marks":5699,"text":5700},"d97f54a602a9",[369]," mandatory for any user with System Administrator, View All Data, Modify All Data, Customize Application, or Author Apex.",[],{"_key":5703,"_type":172,"children":5704,"markDefs":5709,"style":180},"42fbd26ef457",[5705],{"_key":5706,"_type":176,"marks":5707,"text":5708},"3cd512c12d31",[],"Anyone. In your org. ",[],{"_key":5711,"_type":172,"children":5712,"markDefs":5717,"style":180},"7e5f5d4192d8",[5713],{"_key":5714,"_type":176,"marks":5715,"text":5716},"ffef3d010c1d",[],"That’s an audit you have to run. And in most Salesforce orgs, nobody can run it cleanly.",[],{"_key":5719,"_type":172,"children":5720,"markDefs":5725,"style":292},"e62a37dc1455",[5721],{"_key":5722,"_type":176,"marks":5723,"text":5724},"27cffede7e4a",[],"The deadline",[],{"_key":5727,"_type":172,"children":5728,"markDefs":5733,"style":180},"7aa06ac2fe83",[5729],{"_key":5730,"_type":176,"marks":5731,"text":5732},"24d16c447849",[],"Sandbox enforcement starts June 22, 2026. Production rolls July 1 for the privileged-user subset, with the broader employee MFA mandate hitting July 20. Sandbox enforcement starts June 22, 2026. Production rolls July 1 for the privileged-user subset, with the broader employee MFA mandate hitting July 20. Step-up authentication for report actions begins rolling into production June 10. Shield and Event Monitoring customers also get Transaction Security Policy changes around large report exports, including a default ReportEvent policy for UI exports over 10,000 records if they haven’t configured their own. Login IP restrictions, meanwhile, remain strongly recommended — especially for orgs without phishing-resistant MFA fully in place — but Salesforce appears to have pulled back from mandatory enforcement.",[],{"_key":5735,"_type":172,"children":5736,"markDefs":5741,"style":180},"241773515ee5",[5737],{"_key":5738,"_type":176,"marks":5739,"text":5740},"29f7a2a10756",[],"This is one of the most aggressive security enforcement waves Salesforce has run, and it is clearly responding to the same threat pattern behind recent Salesforce-adjacent breaches: identity compromise, social engineering, data exfiltration, and AI-powered phishing that regular MFA was never built to withstand.",[],{"_key":5743,"_type":172,"children":5744,"markDefs":5749,"style":180},"3b299044f1c0",[5745],{"_key":5746,"_type":176,"marks":5747,"text":5748},"fabb68bd8c10",[],"But the cadence is the part Salesforce told you about. The need for an audit is the part the press release left out.",[],{"_key":5751,"_type":172,"children":5752,"markDefs":5757,"style":292},"685661e130bd",[5753],{"_key":5754,"_type":176,"marks":5755,"text":5756},"6f96a663f283",[],"What the audit actually looks like",[],{"_key":5759,"_type":172,"children":5760,"markDefs":5765,"style":180},"f78bc225c31e",[5761],{"_key":5762,"_type":176,"marks":5763,"text":5764},"686a4028e58f",[],"To enforce phishing-resistant MFA, you have to know who's covered. That means producing a list of every active user with at least one of: the System Administrator profile, View All Data, Modify All Data, Customize Application, or Author Apex.",[],{"_key":5767,"_type":172,"children":5768,"markDefs":5773,"style":180},"9fac0d874ecf",[5769],{"_key":5770,"_type":176,"marks":5771,"text":5772},"baa9ad5f3c62",[],"A reasonable person reads that list and says: thirty admins, fine.",[],{"_key":5775,"_type":172,"children":5776,"markDefs":5781,"style":180},"7284e5a29a24",[5777],{"_key":5778,"_type":176,"marks":5779,"text":5780},"265774371724",[],"A reasonable person who has actually done this work knows the number is wrong by an order of magnitude.",[],{"_key":5783,"_type":172,"children":5784,"markDefs":5798,"style":180},"3b15158c3a18",[5785,5789,5794],{"_key":5786,"_type":176,"marks":5787,"text":5788},"5a4a70a89e75",[],"In a mature org, those ",{"_key":5790,"_type":176,"marks":5791,"text":5793},"1ae933f3f26a",[5792],"c2b0c2d9d313","permissions",{"_key":5795,"_type":176,"marks":5796,"text":5797},"89b43bb14f2f",[]," are granted through profiles, permission sets, permission set groups, and muted permission sets. They're inherited. They're attached to \"temporary\" perm sets created during a 2022 implementation and never cleaned up. They're hiding inside permission set groups labeled \"Sales Ops Power User\" that nobody on the security team can interpret without forensics.",[5799],{"_key":5792,"_ref":1121,"_type":328,"linkType":33,"slug":5800},{"_type":22,"current":1123},{"_key":5802,"_type":172,"children":5803,"markDefs":5808,"style":180},"d563c90b73e7",[5804],{"_key":5805,"_type":176,"marks":5806,"text":5807},"984a051bc872",[],"To produce the real list, you have to walk every grant path. Profile → user. Permission set → assignment → user. Permission set group → component permission sets → assignments → user. Muted exclusions on top of that. Cross-reference for active users. Filter out integration users — which is a whole other phishing-resistant MFA conversation, because you can't biometric-auth a service account. Then validate each remaining user against actual business need.",[],{"_key":5810,"_type":172,"children":5811,"markDefs":5816,"style":180},"d1b236165318",[5812],{"_key":5813,"_type":176,"marks":5814,"text":5815},"51c148742e80",[],"For a 500-seat org that's a couple of weeks of dedicated work. For a 5,000-seat org with a decade of accumulated metadata, it's a full quarter.",[],{"_key":5818,"_type":172,"children":5819,"markDefs":5828,"style":180},"f65644576381",[5820,5824],{"_key":5821,"_type":176,"marks":5822,"text":5823},"cc992554c93d",[],"And that's just to produce the list. ",{"_key":5825,"_type":176,"marks":5826,"text":5827},"8d389ebd46d1",[369],"You haven't deployed anything yet.",[],{"_key":5830,"_type":172,"children":5831,"markDefs":5836,"style":292},"199e7d96d22e",[5832],{"_key":5833,"_type":176,"marks":5834,"text":5835},"431a4298a66c",[],"The work nobody scoped",[],{"_key":5838,"_type":172,"children":5839,"markDefs":5849,"style":180},"bfe077952b36",[5840,5844],{"_key":5841,"_type":176,"marks":5842,"text":5843},"0cb16c838a9d",[],"The reason this audit hurts is that it's exposing something every Salesforce team already knew but didn't have a deadline for: permission sprawl is real, ",{"_key":5845,"_type":176,"marks":5846,"text":5848},"6a8f5397d0d7",[5847],"8eca3853cdc3","and it compounds.",[5850],{"_key":5847,"_ref":5851,"_type":328,"linkType":33,"slug":5852},"31e1f234-4da4-4c70-a56e-007e301dd0ce",{"_type":22,"current":5853},"permissions-agent-launch",{"_key":5855,"_type":172,"children":5856,"markDefs":5861,"style":180},"1ea1877f20fc",[5857],{"_key":5858,"_type":176,"marks":5859,"text":5860},"2153e842df90",[],"Every \"just for this project\" permission set group, every cloned profile with one tweak, every Customize Application grant given to a developer who left in 2023 — all of it sits in your org earning interest. The June enforcement is the first time it's been priced.",[],{"_key":5863,"_type":172,"children":5864,"markDefs":5869,"style":180},"8b2076dc7b45",[5865],{"_key":5866,"_type":176,"marks":5867,"text":5868},"62b39bca6350",[],"The cost shows up two ways. First, the audit itself. Second, the rollout — YubiKeys to procure, biometric enrollment to walk users through, exception handling for the contractor who has Modify All Data and is on PTO until August.",[],{"_key":5871,"_type":172,"children":5872,"markDefs":5877,"style":180},"3f1683ab7ba5",[5873],{"_key":5874,"_type":176,"marks":5875,"text":5876},"0847127188e8",[],"If you have Shield or Event Monitoring and haven't built your own Transaction Security Policy by June, Salesforce installs a default one. It may or may not match your operational needs. They're not asking.",[],{"_key":5879,"_type":172,"children":5880,"markDefs":5885,"style":292},"2f60169c6800",[5881],{"_key":5882,"_type":176,"marks":5883,"text":5884},"45d6f46fe6b9",[],"Why this isn't a one-off",[],{"_key":5887,"_type":172,"children":5888,"markDefs":5893,"style":180},"a77846df5215",[5889],{"_key":5890,"_type":176,"marks":5891,"text":5892},"10cc3de2a142",[],"Salesforce has been clear that more enforcement is coming. They're publishing a roadmap. The pattern — security recommendations becoming enforced requirements with hard deadlines — is the new normal, driven by the same threat environment that made phishing-resistant MFA mandatory in the first place.",[],{"_key":5895,"_type":172,"children":5896,"markDefs":5901,"style":180},"1631ccfee0d1",[5897],{"_key":5898,"_type":176,"marks":5899,"text":5900},"41699855d717",[],"Which means the muscle you build for June is the muscle you'll need every release.",[],{"_key":5903,"_type":172,"children":5904,"markDefs":5918,"style":180},"319477d49bed",[5905,5909,5914],{"_key":5906,"_type":176,"marks":5907,"text":5908},"5d4dcf5a3703",[],"The orgs that handle this well will use a ",{"_key":5910,"_type":176,"marks":5911,"text":5913},"b3ad6b4c6b2d",[5912],"8b782a9920be","metadata layer",{"_key":5915,"_type":176,"marks":5916,"text":5917},"d7fbaebeb2db",[]," that can answer \"who has Modify All Data, and exactly which grant gives it to them\" in seconds. Whether you build that visibility, buy it, or pull it out of a half-dozen SOQL queries every quarter — that's the call to make. ",[5919],{"_key":5912,"_ref":5920,"_type":328,"linkType":33,"slug":5921},"8067e019-ac5e-4715-b258-5ecb023926dd",{"_type":22,"current":5922},"the-context-layer-had-its-day",{"_key":5924,"_type":172,"children":5925,"markDefs":5929,"style":180},"fe96edda7d15",[5926],{"_key":5906,"_type":176,"marks":5927,"text":5928},[],"Just don't make it on July 19.",[],{"_key":5931,"_type":172,"children":5932,"markDefs":5937,"style":292},"58034b0536c9",[5933],{"_key":5934,"_type":176,"marks":5935,"text":5936},"f512852a67ea",[],"The shorter version, wrapped up",[],{"_key":5939,"_type":172,"children":5940,"markDefs":5945,"style":180},"a495fda298eb",[5941],{"_key":5942,"_type":176,"marks":5943,"text":5944},"584f92bcc225",[],"Salesforce told you to turn on phishing-resistant MFA for privileged users. They didn't tell you that \"privileged users\" is a metadata question your org can't answer without a multi-week audit. The compliance work is the audit. The MFA part is the easy part. And the audit isn't going away after June, because the enforcement cadence isn't going away.",[],{"_key":5947,"_type":172,"children":5948,"markDefs":5953,"style":180},"75790ba2956d",[5949],{"_key":5950,"_type":176,"marks":5951,"text":5952},"6db6077bda11",[],"If you don't know who has Modify All Data,  Salesforce just made the deadline to find out July 1. Get digging. Or just get Sweep.",[],{"_type":17,"description":5955,"shareImage":5956,"title":5958},"Salesforce's June 2026 phishing-resistant MFA enforcement looks like a settings change. It's actually a multi-week permission audit. Here's what's hiding inside. ",{"_type":40,"asset":5957},{"_ref":5587,"_type":278},"The Hidden Audit Inside Salesforce's June 2026 MFA Mandate",{"_type":22,"current":5960},"the-hidden-audit-inside-salesforce-s-june-2026-mfa-mandate",{"_createdAt":5962,"_id":5963,"_rev":5964,"_system":5965,"_type":33,"_updatedAt":5968,"author":5969,"category":6006,"featuredImage":6012,"modularContent":6025,"postTitle":5971,"publishDate":6029,"richText":6030,"seo":6761,"slug":6766},"2026-04-14T17:15:38Z","afa64dae-44f8-4819-8194-48ee2e67c035","9qGNavu5Tnrr4SJYTBVWY4",{"base":5966},{"id":5963,"rev":5967},"ICUqLtleLxMYRZjp6lSPib","2026-04-14T17:55:02Z",{"authorImage":5970,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":5971,"image":5972},"The Best AI Summarization Tools for Audit Compliance in 2026",{"_type":40,"asset":5973},{"_createdAt":5974,"_id":5975,"_rev":5976,"_type":45,"_updatedAt":5974,"assetId":5977,"extension":106,"metadata":5978,"mimeType":132,"originalFilename":6001,"path":6002,"sha1hash":5977,"size":6003,"uploadId":6004,"url":6005},"2026-04-14T17:16:21Z","image-908191aa323d9e49adc60b770aecf931f73fad74-1600x900-png","9qGNavu5Tnrr4SJYTAr8v2","908191aa323d9e49adc60b770aecf931f73fad74",{"_type":50,"blurHash":5979,"dimensions":5980,"hasAlpha":57,"isOpaque":56,"lqip":5984,"palette":5985,"thumbHash":6000},"M14n_Qs;00Rj?G$~j[IqWC-n00WB_4ogRj",{"_type":53,"aspectRatio":5981,"height":5982,"width":5983},1.7777777777777777,900,1600,"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7EAAAOxAGVKw4bAAABlElEQVR4nHVSy1LbQBD0T2h3RmhHTyPJL3B4xDbGxiny/4dUPiAVCkKOudgX1NRObCEoc+gazWN7u2fVo8D9scbtyLiGjANbgY/HcOj5+GGusYHbkokeezZwf+kDYXf4hAVFkigi9nU5TmiU42lPGLWEXSU2cMiTDPfLETbzCqmI1roX8//ZLqG8U+gRUowTThBSgrKocL+6wHo2Qh6n2vNgelPJVhqysmPrnnpsDpZFCf1wlpSoyzGG9TnOJ5e4+nKF6WSKQT3BoDrDaX8IF2VdN81e1BshW9f4ZiwFRsMpZtdLrJbfsFl/1zifrbCYr9vvqhwjCtNjO4xahSHHKLJaVV1fLnCzuMPtzQaL2Qrzr7eae0JPfDa+QOyKwx5VoVruvrJvSpSr5Tyt0M8H6Oc18rREnlVq9bQYol8MdKZVaF1D1u1ov8NnNrJlKy9epb+ti5Bijf5Qt77fm4Kte2HrtmTdY4+M/GYj/8j4H1Ote7Ut2L7Pj4GtCvIcv7zln2TcAwXu2YONKD7Lj0H7Rh4okB+vY0Ak+KDyVMMAAAAASUVORK5CYII=",{"_type":60,"darkMuted":5986,"darkVibrant":5988,"dominant":5990,"lightMuted":5992,"lightVibrant":5994,"muted":5996,"vibrant":5999},{"_type":62,"background":5987,"foreground":64,"population":125,"title":64},"#643c3c",{"_type":62,"background":5989,"foreground":64,"population":82,"title":64},"#542c04",{"_type":62,"background":5991,"foreground":72,"population":3562,"title":64},"#e8cc45",{"_type":62,"background":5993,"foreground":72,"population":3562,"title":64},"#bab8bf",{"_type":62,"background":5995,"foreground":72,"population":2461,"title":72},"#ead970",{"_type":62,"background":5997,"foreground":64,"population":5998,"title":64},"#7c7c84",0.05,{"_type":62,"background":5991,"foreground":72,"population":3562,"title":64},"yAeCA4APGKd3h3AHfIbQmAgIj4dw+Ag=","Blog Header Templates (1).png","images/9eu1m6zu/production/908191aa323d9e49adc60b770aecf931f73fad74-1600x900.png",117176,"Ait57sXWTzUu9bMNiUgMrJ8SYlY1h4Y1","https://cdn.sanity.io/images/9eu1m6zu/production/908191aa323d9e49adc60b770aecf931f73fad74-1600x900.png",{"_createdAt":5,"_id":6,"_rev":7,"_system":6007,"_type":11,"_updatedAt":12,"selectedColor":6009,"seo":6010,"slug":6011,"title":24},{"base":6008},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":5971,"image":6013},{"_type":40,"asset":6014},{"_createdAt":5974,"_id":5975,"_rev":5976,"_type":45,"_updatedAt":5974,"assetId":5977,"extension":106,"metadata":6015,"mimeType":132,"originalFilename":6001,"path":6002,"sha1hash":5977,"size":6003,"uploadId":6004,"url":6005},{"_type":50,"blurHash":5979,"dimensions":6016,"hasAlpha":57,"isOpaque":56,"lqip":5984,"palette":6017,"thumbHash":6000},{"_type":53,"aspectRatio":5981,"height":5982,"width":5983},{"_type":60,"darkMuted":6018,"darkVibrant":6019,"dominant":6020,"lightMuted":6021,"lightVibrant":6022,"muted":6023,"vibrant":6024},{"_type":62,"background":5987,"foreground":64,"population":125,"title":64},{"_type":62,"background":5989,"foreground":64,"population":82,"title":64},{"_type":62,"background":5991,"foreground":72,"population":3562,"title":64},{"_type":62,"background":5993,"foreground":72,"population":3562,"title":64},{"_type":62,"background":5995,"foreground":72,"population":2461,"title":72},{"_type":62,"background":5997,"foreground":64,"population":5998,"title":64},{"_type":62,"background":5991,"foreground":72,"population":3562,"title":64},[6026],{"_key":6027,"_type":275,"cols":276,"filterByCategory":6028,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":279},"06089ab800c5b0ad7521861be1e692f9",{"_ref":6,"_type":278},"2026-04-14",[6031,6038,6053,6065,6072,6079,6094,6110,6131,6143,6151,6159,6178,6186,6194,6202,6210,6218,6226,6241,6249,6257,6265,6273,6281,6289,6297,6305,6313,6328,6336,6344,6352,6360,6368,6376,6384,6392,6400,6408,6416,6424,6432,6440,6448,6456,6464,6472,6480,6494,6502,6517,6532,6552,6560,6568,6576,6584,6592,6600,6615,6623,6631,6639,6647,6655,6674,6682,6690,6698,6706,6714,6722,6730,6738,6746],{"_key":6032,"_type":172,"children":6033,"markDefs":6037,"style":920},"00436726ffef",[6034],{"_key":6035,"_type":176,"marks":6036,"text":290},"55384c9f9ea3",[],[],{"_key":6039,"_type":172,"children":6040,"markDefs":6050,"style":180},"b24859b72b03",[6041,6046],{"_key":6042,"_type":176,"marks":6043,"text":6045},"4d15ae372f62",[6044],"30826c015038","AI compliance",{"_key":6047,"_type":176,"marks":6048,"text":6049},"60511d56b2ec",[]," is shifting from manual audits to always-on systems. A new ecosystem has formed: infrastructure layers (like Microsoft, Google, Salesforce) capture activity, GRC platforms turn it into reports, and newer “agentic” tools (like Vanta and Drata) automate the work itself. Meanwhile, meeting and documentation tools are becoming audit trails in their own right.",[6051],{"_key":6044,"_ref":1464,"_type":328,"linkType":738,"slug":6052},{"_type":22,"current":1466},{"_key":6054,"_type":172,"children":6055,"markDefs":6064,"style":180},"b547005a1243",[6056,6060],{"_key":6057,"_type":176,"marks":6058,"text":6059},"20a81fc37376",[],"Everything is converging on one goal: ",{"_key":6061,"_type":176,"marks":6062,"text":6063},"7b07b98bb6c3",[369],"making it possible to explain — and prove — what happened across both human and AI-driven systems.",[],{"_key":6066,"_type":172,"children":6067,"markDefs":6071,"style":180},"73d48f99fe13",[6068],{"_key":6069,"_type":176,"marks":6070,"text":187},"29e06612b9d6",[],[],{"_key":6073,"_type":172,"children":6074,"markDefs":6078,"style":180},"a225370c46fe",[6075],{"_key":6076,"_type":176,"marks":6077,"text":352},"7bbb0756b8db",[],[],{"_key":6080,"_type":172,"children":6081,"markDefs":6093,"style":180},"cb23837988a8",[6082,6086,6090],{"_key":6083,"_type":176,"marks":6084,"text":6085},"3217ba751271",[],"At some point in the last two years, audit work stopped being about sampling and started becoming about ",{"_key":6087,"_type":176,"marks":6088,"text":6089},"fd4a4d54a211",[369],"understanding everything",{"_key":6091,"_type":176,"marks":6092,"text":3667},"8aad85b5e3f9",[],[],{"_key":6095,"_type":172,"children":6096,"markDefs":6109,"style":180},"4dd20fb864e8",[6097,6101,6105],{"_key":6098,"_type":176,"marks":6099,"text":6100},"222e06a0da0d",[],"Not a subset of transactions. Not a handful of meetings. Not a curated set of policies. ",{"_key":6102,"_type":176,"marks":6103,"text":6104},"8f7f284fac21",[369],"Everything",{"_key":6106,"_type":176,"marks":6107,"text":6108},"b9d835ea6831",[],". Literally. Every system change. Every AI-generated output. Every compliance conversation. Every dependency.",[],{"_key":6111,"_type":172,"children":6112,"markDefs":6126,"style":180},"470475929405",[6113,6117,6122],{"_key":6114,"_type":176,"marks":6115,"text":6116},"2d6deaf6b04a",[],"That shift is now what’s driving the explosion of ",{"_key":6118,"_type":176,"marks":6119,"text":6121},"774524568280",[6120],"6210e0b27ce9","AI-powered audit and compliance tools ",{"_key":6123,"_type":176,"marks":6124,"text":6125},"46e07e4a9773",[],"in 2026.",[6127],{"_key":6120,"_ref":6128,"_type":328,"linkType":738,"slug":6129},"112e13a1-a07c-48f8-9e9e-a477d74ae86a",{"_type":22,"current":6130},"ai-powered-salesforce-documentation",{"_key":6132,"_type":172,"children":6133,"markDefs":6142,"style":180},"bb0db05521d3",[6134,6138],{"_key":6135,"_type":176,"marks":6136,"text":6137},"6addb55efebf",[],"And it’s why “AI summarization” is no longer a convenience feature. It’s becoming the backbone of how organizations ",{"_key":6139,"_type":176,"marks":6140,"text":6141},"1829b4e058db",[369],"prove compliance in a world where humans are no longer the only actors inside their systems.",[],{"_key":6144,"_type":172,"children":6145,"markDefs":6150,"style":292},"bcad7a7150e0",[6146],{"_key":6147,"_type":176,"marks":6148,"text":6149},"da4abace416d",[],"The Market Is Moving Faster Than Governance Can Keep Up",[],{"_key":6152,"_type":172,"children":6153,"markDefs":6158,"style":180},"a41179aa0b26",[6154],{"_key":6155,"_type":176,"marks":6156,"text":6157},"3b50d4722b90",[],"The numbers tell a pretty blunt story.",[],{"_key":6160,"_type":172,"children":6161,"markDefs":6175,"style":180},"e11f08337839",[6162,6166,6171],{"_key":6163,"_type":176,"marks":6164,"text":6165},"965580cdd0f9",[],"The compliance automation AI market now sits at ",{"_key":6167,"_type":176,"marks":6168,"text":6170},"c935f17c8b6b",[6169],"04c930b46fff","$6.8 billion and is projected to hit $28.4 billion by 2034",{"_key":6172,"_type":176,"marks":6173,"text":6174},"23dfaaa5365b",[],". AI governance spending alone reached nearly half a billion dollars in 2026 and is expected to double by the end of the decade. Meanwhile, 66% of audit professionals already use AI day-to-day, and 60% of Fortune 500 companies adopted AI auditing solutions as early as 2024.",[6176],{"_key":6169,"_type":151,"blank":57,"href":6177,"noOpener":57,"noReferrer":57,"url":6177},"https://dataintelo.com/report/compliance-automation-ai-market",{"_key":6179,"_type":172,"children":6180,"markDefs":6185,"style":180},"f6854bacc838",[6181],{"_key":6182,"_type":176,"marks":6183,"text":6184},"0b6db9d15038",[],"But adoption is outpacing control. Only one in five companies has mature governance for autonomous AI systems. That gap — between what AI is doing and what organizations can explain — is where compliance risk now lives. And regulators are paying attention.",[],{"_key":6187,"_type":172,"children":6188,"markDefs":6193,"style":180},"3bfc79858de2",[6189],{"_key":6190,"_type":176,"marks":6191,"text":6192},"00d463c4b292",[],"The EU AI Act hits its high-risk system compliance deadline on August 2, 2026. The SEC has shifted its examination priorities toward AI usage and “AI washing,” with explicit requirements to retain prompts and outputs. Existing frameworks like SOX, GDPR, and HIPAA now implicitly apply to AI systems, whether companies like it or not.",[],{"_key":6195,"_type":172,"children":6196,"markDefs":6201,"style":180},"49beba5ace15",[6197],{"_key":6198,"_type":176,"marks":6199,"text":6200},"a0892a5e305d",[],"There’s no carve-out for “welp, the model did it.”",[],{"_key":6203,"_type":172,"children":6204,"markDefs":6209,"style":292},"237454080c36",[6205],{"_key":6206,"_type":176,"marks":6207,"text":6208},"62a5976e9a3e",[],"Why Summarization Became a Compliance Problem",[],{"_key":6211,"_type":172,"children":6212,"markDefs":6217,"style":180},"7414d70bc397",[6213],{"_key":6214,"_type":176,"marks":6215,"text":6216},"87781881dce4",[],"For years, summarization tools were positioned as productivity enhancers. They saved time in meetings, helped teams take notes, and made documentation easier.",[],{"_key":6219,"_type":172,"children":6220,"markDefs":6225,"style":180},"716bc1c72afb",[6221],{"_key":6222,"_type":176,"marks":6223,"text":6224},"e66ead2aae90",[],"But something changed.",[],{"_key":6227,"_type":172,"children":6228,"markDefs":6240,"style":180},"fe5873d402e6",[6229,6233,6237],{"_key":6230,"_type":176,"marks":6231,"text":6232},"414f6d0870b0",[],"When AI started making decisions—or influencing decisions—summaries stopped being optional artifacts and became ",{"_key":6234,"_type":176,"marks":6235,"text":6236},"aa9678c44837",[369],"evidence",{"_key":6238,"_type":176,"marks":6239,"text":3667},"064965490a94",[],[],{"_key":6242,"_type":172,"children":6243,"markDefs":6248,"style":180},"3bec8b42700d",[6244],{"_key":6245,"_type":176,"marks":6246,"text":6247},"b4a145f8fb22",[],"If an AI summarizes a compliance meeting incorrectly, that’s not just a bad note. That’s a flawed audit trail.",[],{"_key":6250,"_type":172,"children":6251,"markDefs":6256,"style":180},"ae7bb1315098",[6252],{"_key":6253,"_type":176,"marks":6254,"text":6255},"17750c21d094",[],"If a system generates documentation automatically, that documentation needs to be traceable, verifiable, and defensible.",[],{"_key":6258,"_type":172,"children":6259,"markDefs":6264,"style":180},"2969d66ed65f",[6260],{"_key":6261,"_type":176,"marks":6262,"text":6263},"7b766f42ba75",[],"That’s why the modern compliance stack increasingly revolves around three questions:",[],{"_key":6266,"_type":172,"children":6267,"level":54,"listItem":309,"markDefs":6272,"style":180},"e5b9ac3220e0",[6268],{"_key":6269,"_type":176,"marks":6270,"text":6271},"504b6fe06a5a",[],"What happened?",[],{"_key":6274,"_type":172,"children":6275,"level":54,"listItem":309,"markDefs":6280,"style":180},"524a0530bee2",[6276],{"_key":6277,"_type":176,"marks":6278,"text":6279},"7326f903bff3",[],"Why did it happen?",[],{"_key":6282,"_type":172,"children":6283,"level":54,"listItem":309,"markDefs":6288,"style":180},"4154ace506d7",[6284],{"_key":6285,"_type":176,"marks":6286,"text":6287},"724513a01d0a",[],"Can we prove it?",[],{"_key":6290,"_type":172,"children":6291,"markDefs":6296,"style":180},"4e9027c99398",[6292],{"_key":6293,"_type":176,"marks":6294,"text":6295},"0a95feb01c92",[],"And increasingly, those answers are being generated, tracked, and validated by AI itself.",[],{"_key":6298,"_type":172,"children":6299,"markDefs":6304,"style":292},"c4dab3de57eb",[6300],{"_key":6301,"_type":176,"marks":6302,"text":6303},"2aa660313db9",[],"A New Category: Agentic Trust Management",[],{"_key":6306,"_type":172,"children":6307,"markDefs":6312,"style":180},"9dd8b985573a",[6308],{"_key":6309,"_type":176,"marks":6310,"text":6311},"1aa955eb66de",[],"The most interesting shift in the market isn’t just better tools—it’s a new category.",[],{"_key":6314,"_type":172,"children":6315,"markDefs":6327,"style":180},"0ba11ffdf828",[6316,6320,6324],{"_key":6317,"_type":176,"marks":6318,"text":6319},"62f66597f7c0",[],"Call it ",{"_key":6321,"_type":176,"marks":6322,"text":6323},"aaaf504b7a08",[393],"agentic trust management",{"_key":6325,"_type":176,"marks":6326,"text":3667},"3dd01bfbc135",[],[],{"_key":6329,"_type":172,"children":6330,"markDefs":6335,"style":180},"c7bc9438f110",[6331],{"_key":6332,"_type":176,"marks":6333,"text":6334},"6d781966a9fa",[],"Platforms like Vanta, Drata, and Certa are no longer just automating compliance workflows. They’re deploying AI agents that act like full-time compliance operators — generating policies, collecting evidence, running vendor assessments, and maintaining audit readiness continuously.",[],{"_key":6337,"_type":172,"children":6338,"markDefs":6343,"style":180},"16760eec86bd",[6339],{"_key":6340,"_type":176,"marks":6341,"text":6342},"54a00f3a1700",[],"Vanta’s “Agentic Trust Platform” positions AI as a 24/7 GRC engineer. Drata automates compliance testing and vendor reviews. Certa handles third-party risk with AI-driven adjudication and real-time verification.",[],{"_key":6345,"_type":172,"children":6346,"markDefs":6351,"style":180},"ed9bc1612bc0",[6347],{"_key":6348,"_type":176,"marks":6349,"text":6350},"e5f12deb4f14",[],"The pitch is simple: compliance should not be a periodic event. It should be a continuous system.",[],{"_key":6353,"_type":172,"children":6354,"markDefs":6359,"style":180},"43a8ac822e90",[6355],{"_key":6356,"_type":176,"marks":6357,"text":6358},"51a22d602d6c",[393],"But there’s a catch.",[],{"_key":6361,"_type":172,"children":6362,"markDefs":6367,"style":180},"0f728ac29961",[6363],{"_key":6364,"_type":176,"marks":6365,"text":6366},"2d21aa38bed9",[],"Once AI agents start doing compliance work, you need another layer to audit the agents themselves.",[],{"_key":6369,"_type":172,"children":6370,"markDefs":6375,"style":292},"8986d4472c99",[6371],{"_key":6372,"_type":176,"marks":6373,"text":6374},"c701168d62bb",[],"When Meeting Intelligence Becomes Audit Infrastructure",[],{"_key":6377,"_type":172,"children":6378,"markDefs":6383,"style":180},"e16ff143e04b",[6379],{"_key":6380,"_type":176,"marks":6381,"text":6382},"014202fe139c",[],"At the same time, tools that once lived in the “note-taking” category have  evolved into compliance infrastructure.",[],{"_key":6385,"_type":172,"children":6386,"markDefs":6391,"style":180},"9abd770ff133",[6387],{"_key":6388,"_type":176,"marks":6389,"text":6390},"92f323865327",[],"Otter.ai now supports HIPAA compliance, tracks meeting data across entire organizations, and allows teams to query decisions across historical conversations. Fireflies.ai enforces policy rules, manages data retention, and supports a wide range of regulatory certifications. Even tools like Notion have evolved into full audit documentation hubs with enterprise-grade logging and SIEM integrations.",[],{"_key":6393,"_type":172,"children":6394,"markDefs":6399,"style":180},"664f14675215",[6395],{"_key":6396,"_type":176,"marks":6397,"text":6398},"ef7f1e8d77f1",[],"What these tools are really doing is turning conversations into structured, queryable data.",[],{"_key":6401,"_type":172,"children":6402,"markDefs":6407,"style":180},"cff54e6eedfd",[6403],{"_key":6404,"_type":176,"marks":6405,"text":6406},"f0f0e22120a7",[],"And in a compliance context, that’s incredibly powerful. Why? Because instead of asking “Who remembers what we decided about data retention?”, you can ask: “What decisions were made about data retention across all compliance meetings?” And get a defensible answer.",[],{"_key":6409,"_type":172,"children":6410,"markDefs":6415,"style":292},"caad1d3b1d4b",[6411],{"_key":6412,"_type":176,"marks":6413,"text":6414},"c76654a5c11d",[],"The Infrastructure Layer: Where Governance Actually Happens",[],{"_key":6417,"_type":172,"children":6418,"markDefs":6423,"style":180},"20bf943cfcd6",[6419],{"_key":6420,"_type":176,"marks":6421,"text":6422},"2d743a5e30cd",[],"Above all of this sits a more foundational layer: enterprise AI platforms that govern how data moves, how AI interacts with systems, and how everything gets audited.",[],{"_key":6425,"_type":172,"children":6426,"markDefs":6431,"style":180},"b66eda41bc7c",[6427],{"_key":6428,"_type":176,"marks":6429,"text":6430},"cd83ad1848eb",[],"Microsoft’s Copilot paired with Purview logs AI interactions, enforces data loss prevention policies, and enables eDiscovery across AI-generated content. Google’s Vertex AI provides the infrastructure to build custom compliance automation systems. Salesforce Shield captures audit data at the platform level, logging interactions and changes across the entire environment.",[],{"_key":6433,"_type":172,"children":6434,"markDefs":6439,"style":180},"9c9bbc3294c8",[6435],{"_key":6436,"_type":176,"marks":6437,"text":6438},"773732a368bc",[],"These systems don’t necessarily “solve” compliance on their own.",[],{"_key":6441,"_type":172,"children":6442,"markDefs":6447,"style":180},"2c78e2e49e1b",[6443],{"_key":6444,"_type":176,"marks":6445,"text":6446},"6ced99f9c13a",[],"They provide the raw material: logs, events, and data.",[],{"_key":6449,"_type":172,"children":6450,"markDefs":6455,"style":180},"73fc87b20a2e",[6451],{"_key":6452,"_type":176,"marks":6453,"text":6454},"5cb8b3fdb427",[],"But raw data isn’t enough.",[],{"_key":6457,"_type":172,"children":6458,"markDefs":6463,"style":180},"331b269bf7de",[6459],{"_key":6460,"_type":176,"marks":6461,"text":6462},"59ae0e35547a",[],"You still need to interpret it.",[],{"_key":6465,"_type":172,"children":6466,"markDefs":6471,"style":292},"7cd8cf3dc666",[6467],{"_key":6468,"_type":176,"marks":6469,"text":6470},"0131e215c87a",[],"The Missing Layer: Context",[],{"_key":6473,"_type":172,"children":6474,"markDefs":6479,"style":180},"e8af16980751",[6475],{"_key":6476,"_type":176,"marks":6477,"text":6478},"bbb9487cd539",[],"This is where most organizations hit a wall. They have logs. They have audit trails. They have meeting transcripts. They have compliance workflows.",[],{"_key":6481,"_type":172,"children":6482,"markDefs":6493,"style":180},"8b09575785db",[6483,6487,6490],{"_key":6484,"_type":176,"marks":6485,"text":6486},"15cb4974b118",[],"But they don’t have ",{"_key":6488,"_type":176,"marks":6489,"text":1235},"c583406e5173",[369],{"_key":6491,"_type":176,"marks":6492,"text":3667},"cb4ac590c5bb",[],[],{"_key":6495,"_type":172,"children":6496,"markDefs":6501,"style":180},"1ff59e3afa25",[6497],{"_key":6498,"_type":176,"marks":6499,"text":6500},"d7089e9a9eb3",[],"They can see that something changed, but not what depends on it.\nThey can see that an AI generated output, but not how it interacted with the system.\nThey can see that a policy exists, but not whether it aligns with actual behavior.",[],{"_key":6503,"_type":172,"children":6504,"markDefs":6514,"style":180},"b20064579bf0",[6505,6509],{"_key":6506,"_type":176,"marks":6507,"text":6508},"4e1220ac47d0",[],"And that’s why",{"_key":6510,"_type":176,"marks":6511,"text":6513},"fad3b5de6b62",[6512],"3ddf10468db3"," a new layer is emerging on top of the stack.",[6515],{"_key":6512,"_ref":5920,"_type":328,"linkType":33,"slug":6516},{"_type":22,"current":5922},{"_key":6518,"_type":172,"children":6519,"markDefs":6531,"style":180},"1e403c9e424c",[6520,6524,6528],{"_key":6521,"_type":176,"marks":6522,"text":6523},"6018598a92c6",[],"Not just automation. Not just summarization. But ",{"_key":6525,"_type":176,"marks":6526,"text":6527},"02fc67b45fdb",[369],"interpretation",{"_key":6529,"_type":176,"marks":6530,"text":3667},"ca1b1cf725a4",[],[],{"_key":6533,"_type":172,"children":6534,"markDefs":6547,"style":180},"2ca21e3d50ad",[6535,6539,6544],{"_key":6536,"_type":176,"marks":6537,"text":6538},"54f687fed7bd",[],"This is where tools like Sweep position themselves — mapping system behavior, understanding dependencies, and creating a ",{"_key":6540,"_type":176,"marks":6541,"text":6543},"3279c29864c4",[6542],"44fa925ebf9c","coherent, auditable narrative of how systems actually operate",{"_key":6545,"_type":176,"marks":6546,"text":3667},"c5452d66439d",[],[6548],{"_key":6542,"_ref":6549,"_type":328,"linkType":33,"slug":6550},"38915ee3-9c60-4a63-b672-b4b90f5bcd4a",{"_type":22,"current":6551},"a-practical-guide-to-context-graphs-in-the-enterprise",{"_key":6553,"_type":172,"children":6554,"markDefs":6559,"style":180},"6ccb7a8c2cfd",[6555],{"_key":6556,"_type":176,"marks":6557,"text":6558},"f841abf26e81",[],"In a world where AI agents are making changes, that narrative becomes the audit trail.",[],{"_key":6561,"_type":172,"children":6562,"markDefs":6567,"style":292},"d9f547855e0a",[6563],{"_key":6564,"_type":176,"marks":6565,"text":6566},"7353af26ec5d",[],"The SEO Reality: Everyone Is Writing the Wrong Content",[],{"_key":6569,"_type":172,"children":6570,"markDefs":6575,"style":180},"7629d15a74e5",[6571],{"_key":6572,"_type":176,"marks":6573,"text":6574},"4d0053f11492",[],"If you look at the current search landscape for “AI compliance tools,” it’s dominated by listicles.",[],{"_key":6577,"_type":172,"children":6578,"markDefs":6583,"style":180},"f92c5975375f",[6579],{"_key":6580,"_type":176,"marks":6581,"text":6582},"dd5e3b7389a5",[],"“Top 13 AI Compliance Tools.”\n“Best AI Auditing Platforms.”\n“Top GRC Solutions for 2026.”",[],{"_key":6585,"_type":172,"children":6586,"markDefs":6591,"style":180},"f6acfa4db8d5",[6587],{"_key":6588,"_type":176,"marks":6589,"text":6590},"2e162f26336e",[],"They rank because they’re broad, exhaustive, and optimized.",[],{"_key":6593,"_type":172,"children":6594,"markDefs":6599,"style":180},"1efaaadaffb8",[6595],{"_key":6596,"_type":176,"marks":6597,"text":6598},"51f4e03b6c7e",[],"But they miss something important.",[],{"_key":6601,"_type":172,"children":6602,"markDefs":6614,"style":180},"c9ee227f9399",[6603,6607,6611],{"_key":6604,"_type":176,"marks":6605,"text":6606},"6c164db4c9e4",[],"Very few focus specifically on ",{"_key":6608,"_type":176,"marks":6609,"text":6610},"1cfe520469b0",[369],"summarization as a compliance function",{"_key":6612,"_type":176,"marks":6613,"text":3667},"be81ec5690af",[],[],{"_key":6616,"_type":172,"children":6617,"markDefs":6622,"style":180},"46c3d0b956b5",[6618],{"_key":6619,"_type":176,"marks":6620,"text":6621},"643c3759603a",[],"Even fewer connect tools directly to regulatory frameworks like SOX, GDPR, or the EU AI Act.",[],{"_key":6624,"_type":172,"children":6625,"markDefs":6630,"style":180},"9a9992378ded",[6626],{"_key":6627,"_type":176,"marks":6628,"text":6629},"545957a3c037",[],"And almost none address the emerging challenge of auditing AI agents themselves.",[],{"_key":6632,"_type":172,"children":6633,"markDefs":6638,"style":180},"32626bc80344",[6634],{"_key":6635,"_type":176,"marks":6636,"text":6637},"43e1b105ceba",[],"That gap is where the real opportunity sits.",[],{"_key":6640,"_type":172,"children":6641,"markDefs":6646,"style":180},"7cceeae001ca",[6642],{"_key":6643,"_type":176,"marks":6644,"text":6645},"c2e042678f71",[],"Because the question buyers are actually asking right now is: “How do I prove what my systems — and my AI — are doing?”",[],{"_key":6648,"_type":172,"children":6649,"markDefs":6654,"style":292},"7b9a4a281531",[6650],{"_key":6651,"_type":176,"marks":6652,"text":6653},"c13893538282",[],"Where This Is All Going",[],{"_key":6656,"_type":172,"children":6657,"markDefs":6671,"style":180},"c0d9c687d56c",[6658,6662,6667],{"_key":6659,"_type":176,"marks":6660,"text":6661},"e2eedaef1238",[],"The direction is pretty clear. ",{"_key":6663,"_type":176,"marks":6664,"text":6666},"3add98e3efb6",[6665],"53b9f3d7a7b4","Compliance",{"_key":6668,"_type":176,"marks":6669,"text":6670},"269d06079fe8",[]," is shifting from periodic review to continuous verification. Audit trails are expanding from human activity to include AI behavior. Summarization is evolving into structured, queryable evidence. And governance is becoming a system-level problem, not a workflow problem.",[6672],{"_key":6665,"_ref":1464,"_type":328,"linkType":738,"slug":6673},{"_type":22,"current":1466},{"_key":6675,"_type":172,"children":6676,"markDefs":6681,"style":180},"7a8713171177",[6677],{"_key":6678,"_type":176,"marks":6679,"text":6680},"7c0c9737f80b",[],"By the end of 2026, Forrester expects half of enterprise ERP vendors to launch autonomous governance modules — systems that combine explainable AI, automated audit trails, and real-time compliance monitoring.",[],{"_key":6683,"_type":172,"children":6684,"markDefs":6689,"style":180},"bacde2169a3b",[6685],{"_key":6686,"_type":176,"marks":6687,"text":6688},"f12a9c794db9",[],"That’s not a feature roadmap.",[],{"_key":6691,"_type":172,"children":6692,"markDefs":6697,"style":180},"d36b8461ca91",[6693],{"_key":6694,"_type":176,"marks":6695,"text":6696},"11ced9c956a7",[],"That’s a fundamental change in how organizations operate.",[],{"_key":6699,"_type":172,"children":6700,"markDefs":6705,"style":292},"2d477a364d1b",[6701],{"_key":6702,"_type":176,"marks":6703,"text":6704},"eabe122f1bb7",[],"Sweeping It All Up ",[],{"_key":6707,"_type":172,"children":6708,"markDefs":6713,"style":180},"acba6278ac15",[6709],{"_key":6710,"_type":176,"marks":6711,"text":6712},"44f0ba5ade84",[],"For a long time, compliance asked a simple question: “Did you follow the rules?”",[],{"_key":6715,"_type":172,"children":6716,"markDefs":6721,"style":180},"1573febcca43",[6717],{"_key":6718,"_type":176,"marks":6719,"text":6720},"7df7c6b4b462",[],"Now it asks something much harder:",[],{"_key":6723,"_type":172,"children":6724,"markDefs":6729,"style":180},"9781efca80ad",[6725],{"_key":6726,"_type":176,"marks":6727,"text":6728},"117c7601b754",[],"“Can you explain everything that happened?”",[],{"_key":6731,"_type":172,"children":6732,"markDefs":6737,"style":180},"b66962fa83ca",[6733],{"_key":6734,"_type":176,"marks":6735,"text":6736},"ce9d588a3b48",[],"And increasingly, the only way to answer that question…",[],{"_key":6739,"_type":172,"children":6740,"markDefs":6745,"style":180},"c9c104e1e844",[6741],{"_key":6742,"_type":176,"marks":6743,"text":6744},"b645f436d81a",[],"…is with AI.",[],{"_key":6747,"_type":172,"children":6748,"markDefs":6758,"style":180},"6cce8bdbefd1",[6749,6753],{"_key":6750,"_type":176,"marks":6751,"text":6752},"6711c52f7ffe",[],"Want to see how Sweep does it? ",{"_key":6754,"_type":176,"marks":6755,"text":6757},"2b5db035e470",[6756],"ec7a75d5f36a","Book a demo here.",[6759],{"_key":6756,"_ref":5541,"_type":328,"linkType":738,"slug":6760},{"_type":22,"current":5543},{"_type":17,"description":6762,"shareImage":6763,"title":6765},"Manual audit documentation is a bottleneck. See which AI summarization tools are helping compliance teams move faster without sacrificing accuracy.",{"_type":40,"asset":6764},{"_ref":5975,"_type":278},"Best AI Summarization Tools for Audit Compliance",{"_type":22,"current":6767},"best-ai-summarization-tools-for-audit-compliance-2026",{"_createdAt":6769,"_id":1058,"_rev":6770,"_type":33,"_updatedAt":6771,"author":6772,"category":6788,"featuredImage":6794,"modularContent":6828,"postTitle":6832,"publishDate":6833,"richText":6834,"seo":7494,"slug":7498},"2026-04-08T18:40:03Z","q81r2sSlILGlwpvqM4O108","2026-04-08T18:54:14Z",{"authorImage":6773,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":38,"image":6774},{"_type":40,"asset":6775},{"_createdAt":42,"_id":43,"_rev":44,"_type":45,"_updatedAt":46,"altText":19,"assetId":47,"description":19,"extension":48,"metadata":6776,"mimeType":83,"opt":6786,"originalFilename":86,"path":87,"sha1hash":47,"size":88,"title":19,"uploadId":89,"url":90},{"_type":50,"blurHash":51,"dimensions":6777,"hasAlpha":56,"isOpaque":57,"lqip":58,"palette":6778},{"_type":53,"aspectRatio":54,"height":55,"width":55},{"_type":60,"darkMuted":6779,"darkVibrant":6780,"dominant":6781,"lightMuted":6782,"lightVibrant":6783,"muted":6784,"vibrant":6785},{"_type":62,"background":63,"foreground":64,"population":65,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":71,"foreground":72,"population":73,"title":64},{"_type":62,"background":75,"foreground":72,"population":76,"title":72},{"_type":62,"background":78,"foreground":64,"population":79,"title":64},{"_type":62,"background":81,"foreground":64,"population":82,"title":64},{"media":6787},{"tags":19},{"_createdAt":5,"_id":6,"_rev":7,"_system":6789,"_type":11,"_updatedAt":12,"selectedColor":6791,"seo":6792,"slug":6793,"title":24},{"base":6790},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":6795,"image":6796},"The Guide to Audit-Ready Change Governance in Salesforce",{"_type":40,"asset":6797},{"_createdAt":6798,"_id":6799,"_rev":6800,"_type":45,"_updatedAt":6798,"assetId":6801,"extension":106,"metadata":6802,"mimeType":132,"originalFilename":6823,"path":6824,"sha1hash":6801,"size":6825,"uploadId":6826,"url":6827},"2026-04-08T18:43:17Z","image-83d94d5efb6ea176bbd4d1ef2fda2e2b6bdc8b96-1600x900-png","q81r2sSlILGlwpvqM4JnvV","83d94d5efb6ea176bbd4d1ef2fda2e2b6bdc8b96",{"_type":50,"blurHash":6803,"dimensions":6804,"exif":6805,"hasAlpha":57,"isOpaque":56,"lqip":6808,"palette":6809},"MBR3m2V@?b?bxu-;ofRjt7og~q%gD$Mxa#",{"_type":53,"aspectRatio":5981,"height":5982,"width":5983},{"ColorSpace":6806,"PixelXDimension":5983,"PixelYDimension":5982,"_type":6807},65535,"sanity.imageExifMetadata","data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAB7ElEQVR4nGWR6ZbiIBSEff8Xm+lxWuMS9z1qQqIJkAUIgZoDHrvt8UedS7F8FNwek11SKiOZNJaKDk5MGq///XPO10YhoxzxvQApuM0rIajQ1x4VOuUOKLSltUJeChSVgBuzRr8AH3DvhUFeNTgnMeabHeabk43SQhaNjr+AtJb2RjnILQe558hyhpzXuFcSubuobkGF/kpaNK1PeE7viEhhU9ZIKru4R2WXcqUlKUp7uCTYRzEO5xi76IptdMXmFGMbJThnuQe7pO9f0FmuOsmUB+qUyVZG5GYniy2C2Qqj+RqDyRx/gik+hlP0gynC9Q6XLMetbMBekjJpwJXxQCr1N/CYZHYYrvxhB/o9GHk9/d9RiNFs6ZPfeOOf/9Iwy2UnqdBxrxA6paKVx9gBl+iPZ/iczNEfhR4ShCsMpwt8DCb49RkgmC2xjWJcbhT3Sn0D3ZPdHz6BEcltuD5gstxhut4/6mqPxe6E+faI8WKNIFxivNhgtjlgdyHIuHgHcmVI1RpR1MoQWllCS6+kcLWyGattymqbFNwmObeueW49442lorWuIaUyxjHK1lx7jUbUaMNrDVFpI58q24cqV59eOQ8/97qn1kbUrWOYY69qTchbc2aqI2+SHeHqoaf/IdERKtxYuz3nqjWTfwfVPE8I5oU+AAAAAElFTkSuQmCC",{"_type":60,"darkMuted":6810,"darkVibrant":6812,"dominant":6814,"lightMuted":6816,"lightVibrant":6818,"muted":6819,"vibrant":6821},{"_type":62,"background":6811,"foreground":64,"population":82,"title":64},"#343c4c",{"_type":62,"background":6813,"foreground":64,"population":82,"title":64},"#706213",{"_type":62,"background":6815,"foreground":72,"population":844,"title":72},"#eee19d",{"_type":62,"background":6817,"foreground":72,"population":125,"title":64},"#acb4bc",{"_type":62,"background":6815,"foreground":72,"population":844,"title":72},{"_type":62,"background":6820,"foreground":72,"population":1371,"title":64},"#a99a5c",{"_type":62,"background":6822,"foreground":72,"population":82,"title":64},"#d9bc25","Blog Header Templates.png","images/9eu1m6zu/production/83d94d5efb6ea176bbd4d1ef2fda2e2b6bdc8b96-1600x900.png",360191,"8LbjMu7RL4QeCsModrnB0EX6NIKsGToZ","https://cdn.sanity.io/images/9eu1m6zu/production/83d94d5efb6ea176bbd4d1ef2fda2e2b6bdc8b96-1600x900.png",[6829],{"_key":6830,"_type":275,"cols":276,"filterByCategory":6831,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":279},"75594b7f1e70049065648d343b79df70",{"_ref":6,"_type":278},"How to Establish Audit-Ready Change Governance in Salesforce","2026-04-08",[6835,6843,6851,6859,6867,6875,6894,6902,6910,6918,6926,6934,6954,6962,6970,6991,6999,7007,7015,7023,7031,7039,7047,7055,7063,7071,7079,7104,7112,7120,7128,7136,7144,7152,7160,7168,7176,7184,7192,7200,7208,7216,7232,7240,7248,7256,7264,7272,7280,7288,7296,7304,7312,7327,7335,7343,7355,7363,7371,7379,7387,7395,7403,7411,7430,7438,7446,7454,7462,7470,7478,7486],{"_key":6836,"_type":172,"children":6837,"markDefs":6842,"style":180},"376ba2e389c4",[6838],{"_key":6839,"_type":176,"marks":6840,"text":6841},"ee3f50c91d74",[],"The audit started with a single question: “Why did this field change?”",[],{"_key":6844,"_type":172,"children":6845,"markDefs":6850,"style":180},"181cbff8e5ce",[6846],{"_key":6847,"_type":176,"marks":6848,"text":6849},"051908fa33ba",[],"The admin pulled up Salesforce. The field history showed the update. A timestamp. A user. That part came easy.",[],{"_key":6852,"_type":172,"children":6853,"markDefs":6858,"style":180},"b145d5e3f947",[6854],{"_key":6855,"_type":176,"marks":6856,"text":6857},"2ab911250416",[],"The next question didn’t.",[],{"_key":6860,"_type":172,"children":6861,"markDefs":6866,"style":180},"8463da9ae5bb",[6862],{"_key":6863,"_type":176,"marks":6864,"text":6865},"c4e50cfbdbb3",[],"“What did it impact?”",[],{"_key":6868,"_type":172,"children":6869,"markDefs":6874,"style":180},"681d0e715b3e",[6870],{"_key":6871,"_type":176,"marks":6872,"text":6873},"8204de980e22",[],"Now the room slowed down. Time itself seemed to grind to a halt. Someone mentioned a Flow. Someone else flagged a validation rule. A third person thought a downstream integration might depend on it. Slack threads opened. Old tickets surfaced. Nobody could give a clean answer. Not without digging, anyway.",[],{"_key":6876,"_type":172,"children":6877,"markDefs":6891,"style":180},"63d92dd68900",[6878,6882,6887],{"_key":6879,"_type":176,"marks":6880,"text":6881},"75497d896a5c",[],"By the time the team reconstructed the change, the audit had already exposed the real issue: the system had ",{"_key":6883,"_type":176,"marks":6884,"text":6886},"20177ec2642b",[6885],"4fe0b903cb37","grown beyond anyone’s ability to explain it ",{"_key":6888,"_type":176,"marks":6889,"text":6890},"feaa2ee1c4bd",[],"in real time.",[6892],{"_key":6885,"_ref":1464,"_type":328,"linkType":738,"slug":6893},{"_type":22,"current":1466},{"_key":6895,"_type":172,"children":6896,"markDefs":6901,"style":180},"7bd9562818bd",[6897],{"_key":6898,"_type":176,"marks":6899,"text":6900},"53fd62ab3fc3",[],"That’s where governance breaks.",[],{"_key":6903,"_type":172,"children":6904,"markDefs":6909,"style":292},"26481443846d",[6905],{"_key":6906,"_type":176,"marks":6907,"text":6908},"1a55989d7de6",[],"Change moves faster than understanding",[],{"_key":6911,"_type":172,"children":6912,"markDefs":6917,"style":180},"cc5d65717351",[6913],{"_key":6914,"_type":176,"marks":6915,"text":6916},"f674249c3d06",[],"Salesforce risk builds through thousands of small, reasonable changes— each one made without full visibility into what already exists.",[],{"_key":6919,"_type":172,"children":6920,"markDefs":6925,"style":180},"1b204335fdc1",[6921],{"_key":6922,"_type":176,"marks":6923,"text":6924},"b53bf182713b",[],"An admin adds a field. A developer updates a Flow. Ops adjusts routing logic. Each change solves a local problem. Over time, those decisions layer into a system nobody can fully trace.",[],{"_key":6927,"_type":172,"children":6928,"markDefs":6933,"style":180},"dd0f041524a2",[6929],{"_key":6930,"_type":176,"marks":6931,"text":6932},"87d0c8faedab",[],"Teams still deploy, but every change carries hidden dependencies.",[],{"_key":6935,"_type":172,"children":6936,"markDefs":6949,"style":180},"f0c774ddf564",[6937,6941,6945],{"_key":6938,"_type":176,"marks":6939,"text":6940},"f92e47722904",[],"Governance processes try to keep up. Tickets, approvals, ",{"_key":6942,"_type":176,"marks":6943,"text":4569},"bd8b80a4a9d2",[6944],"941aeed90c87",{"_key":6946,"_type":176,"marks":6947,"text":6948},"335b09461f55",[],", CAB reviews. All of it assumes someone understands the system well enough to evaluate risk before deployment.",[6950],{"_key":6944,"_ref":6951,"_type":328,"linkType":33,"slug":6952},"0f96aa76-866b-4863-bd1b-54a4711e3c57",{"_type":22,"current":6953},"sweep-vs-elements-cloud",{"_key":6955,"_type":172,"children":6956,"markDefs":6961,"style":180},"6b24bd386b01",[6957],{"_key":6958,"_type":176,"marks":6959,"text":6960},"8e02cd235416",[],"That assumption fails quietly.",[],{"_key":6963,"_type":172,"children":6964,"markDefs":6969,"style":292},"135a64c4324b",[6965],{"_key":6966,"_type":176,"marks":6967,"text":6968},"db104554b393",[],"Audit pressure exposes the gaps",[],{"_key":6971,"_type":172,"children":6972,"markDefs":6986,"style":180},"7bf147e0c70f",[6973,6977,6982],{"_key":6974,"_type":176,"marks":6975,"text":6976},"6912e8968c20",[],"When ",{"_key":6978,"_type":176,"marks":6979,"text":6981},"3bb158b43f7d",[6980],"2a1b4bec813a","auditors ask for evidence",{"_key":6983,"_type":176,"marks":6984,"text":6985},"6a45ea144a5f",[],", they’re not looking for activity logs alone. They want to see intent, traceability, and control tied directly to how the system behaves.",[6987],{"_key":6980,"_ref":6988,"_type":328,"linkType":33,"slug":6989},"58bb094e-5e6b-4412-91b4-54d68512cadd",{"_type":22,"current":6990},"the-audit-trail-of-an-ai-agent",{"_key":6992,"_type":172,"children":6993,"markDefs":6998,"style":180},"820936c696b0",[6994],{"_key":6995,"_type":176,"marks":6996,"text":6997},"bd3b6a31ab5b",[],"They ask:",[],{"_key":7000,"_type":172,"children":7001,"level":54,"listItem":309,"markDefs":7006,"style":180},"db89e60a55b2",[7002],{"_key":7003,"_type":176,"marks":7004,"text":7005},"635f917d2547",[],"Who approved this change?",[],{"_key":7008,"_type":172,"children":7009,"level":54,"listItem":309,"markDefs":7014,"style":180},"f42cc3e807ec",[7010],{"_key":7011,"_type":176,"marks":7012,"text":7013},"0500ab9ddc3f",[],"What analysis supported that approval?",[],{"_key":7016,"_type":172,"children":7017,"level":54,"listItem":309,"markDefs":7022,"style":180},"6b51643fbd31",[7018],{"_key":7019,"_type":176,"marks":7020,"text":7021},"00e777d13042",[],"What downstream systems did it affect?",[],{"_key":7024,"_type":172,"children":7025,"markDefs":7030,"style":180},"86ba7231dff1",[7026],{"_key":7027,"_type":176,"marks":7028,"text":7029},"d597aa88c3c3",[],"Most teams can produce fragments of those answers. A Jira ticket here. A Slack approval there. A change log somewhere else.",[],{"_key":7032,"_type":172,"children":7033,"markDefs":7038,"style":180},"35779e7073cb",[7034],{"_key":7035,"_type":176,"marks":7036,"text":7037},"278de1c0c379",[],"None of it connects cleanly.",[],{"_key":7040,"_type":172,"children":7041,"markDefs":7046,"style":180},"ffff072de7dd",[7042],{"_key":7043,"_type":176,"marks":7044,"text":7045},"4537ab574894",[],"So teams reconstruct the story after the fact.",[],{"_key":7048,"_type":172,"children":7049,"markDefs":7054,"style":180},"921da1024f15",[7050],{"_key":7051,"_type":176,"marks":7052,"text":7053},"d96af2d2a865",[],"That reconstruction becomes the work.",[],{"_key":7056,"_type":172,"children":7057,"markDefs":7062,"style":292},"3164312d4613",[7058],{"_key":7059,"_type":176,"marks":7060,"text":7061},"bab7b7cbd02b",[],"Logs record events. They don’t explain systems.",[],{"_key":7064,"_type":172,"children":7065,"markDefs":7070,"style":180},"13db7f334751",[7066],{"_key":7067,"_type":176,"marks":7068,"text":7069},"918c8636b3d1",[],"Field history tracking. Setup audit trail. Deployment logs. Salesforce captures a lot.",[],{"_key":7072,"_type":172,"children":7073,"markDefs":7078,"style":180},"5b51b81ec110",[7074],{"_key":7075,"_type":176,"marks":7076,"text":7077},"049d6a0822bc",[],"But logs operate at the surface.",[],{"_key":7080,"_type":172,"children":7081,"markDefs":7099,"style":180},"ceb4bfa89ceb",[7082,7086,7091,7095],{"_key":7083,"_type":176,"marks":7084,"text":7085},"88d4177592b3",[],"They show that ",{"_key":7087,"_type":176,"marks":7088,"text":7090},"a40c72399a55",[7089],"dcfa4c6fa421","something ",{"_key":7092,"_type":176,"marks":7093,"text":7094},"9cca2f030c07",[393,7089],"changed",{"_key":7096,"_type":176,"marks":7097,"text":7098},"e384d628ecbd",[],". They don’t show how that change ripples through automations, permissions, and integrations. They don’t capture reasoning. They don’t model dependencies.",[7100],{"_key":7089,"_ref":7101,"_type":328,"linkType":33,"slug":7102},"05f126c5-baf0-434b-b166-d883f418d38e",{"_type":22,"current":7103},"from-incident-driven-to-evidence-driven-change-in-salesforce",{"_key":7105,"_type":172,"children":7106,"markDefs":7111,"style":180},"6f996638b232",[7107],{"_key":7108,"_type":176,"marks":7109,"text":7110},"676a40f406e0",[],"So every audit turns into a manual investigation.",[],{"_key":7113,"_type":172,"children":7114,"markDefs":7119,"style":180},"67372f3882c6",[7115],{"_key":7116,"_type":176,"marks":7117,"text":7118},"f0174bc467e2",[],"Someone traces a Flow. Someone checks Apex. Someone scans reports. The team pieces together impact step by step.",[],{"_key":7121,"_type":172,"children":7122,"markDefs":7127,"style":180},"0da2b2a32ca0",[7123],{"_key":7124,"_type":176,"marks":7125,"text":7126},"5168e1d010dc",[],"That process doesn’t scale.",[],{"_key":7129,"_type":172,"children":7130,"markDefs":7135,"style":292},"5eac1028f9e2",[7131],{"_key":7132,"_type":176,"marks":7133,"text":7134},"d4c7903c82b2",[],"Audit-ready governance starts before deployment",[],{"_key":7137,"_type":172,"children":7138,"markDefs":7143,"style":180},"b44da4d51593",[7139],{"_key":7140,"_type":176,"marks":7141,"text":7142},"c9131e7e695d",[],"Teams that handle audits cleanly don’t rely on better documentation habits. They change how they approach every change.",[],{"_key":7145,"_type":172,"children":7146,"markDefs":7151,"style":180},"627c361cbf78",[7147],{"_key":7148,"_type":176,"marks":7149,"text":7150},"2f14b06093f2",[],"They treat governance as part of execution, not a checkpoint after the fact.",[],{"_key":7153,"_type":172,"children":7154,"markDefs":7159,"style":180},"752e8e47fc6e",[7155],{"_key":7156,"_type":176,"marks":7157,"text":7158},"7a4e6b3b812f",[],"Before a change moves forward, they answer three questions with system-backed evidence:",[],{"_key":7161,"_type":172,"children":7162,"level":54,"listItem":309,"markDefs":7167,"style":180},"93ccd56e0784",[7163],{"_key":7164,"_type":176,"marks":7165,"text":7166},"038004771ad5",[],"What exactly will change?",[],{"_key":7169,"_type":172,"children":7170,"level":54,"listItem":309,"markDefs":7175,"style":180},"8b76bdece26b",[7171],{"_key":7172,"_type":176,"marks":7173,"text":7174},"1ddf1888850b",[],"Where does that change propagate?",[],{"_key":7177,"_type":172,"children":7178,"level":54,"listItem":309,"markDefs":7183,"style":180},"aa5ab34790b7",[7179],{"_key":7180,"_type":176,"marks":7181,"text":7182},"bb3614f6ca53",[],"Why does this change make sense in the context of the current system?",[],{"_key":7185,"_type":172,"children":7186,"markDefs":7191,"style":180},"915722e5883b",[7187],{"_key":7188,"_type":176,"marks":7189,"text":7190},"3a3bb98f4f17",[],"Those answers come from the system itself, not from memory or guesswork.",[],{"_key":7193,"_type":172,"children":7194,"markDefs":7199,"style":180},"7aacfb414d32",[7195],{"_key":7196,"_type":176,"marks":7197,"text":7198},"33ac9ad18fbb",[],"That requires a different foundation.",[],{"_key":7201,"_type":172,"children":7202,"markDefs":7207,"style":292},"818083d42f75",[7203],{"_key":7204,"_type":176,"marks":7205,"text":7206},"c6e85513b3dd",[],"Model the system as it actually runs",[],{"_key":7209,"_type":172,"children":7210,"markDefs":7215,"style":180},"537fa6ca700b",[7211],{"_key":7212,"_type":176,"marks":7213,"text":7214},"730ba39af504",[],"Salesforce stores metadata across objects, fields, Flows, permissions, and more. Out of the box, those components sit in separate layers.",[],{"_key":7217,"_type":172,"children":7218,"markDefs":7231,"style":180},"0155331ca9f5",[7219,7223,7227],{"_key":7220,"_type":176,"marks":7221,"text":7222},"41956f5eff1c",[],"Audit-ready governance requires ",{"_key":7224,"_type":176,"marks":7225,"text":7226},"971ac3b3589c",[393],"connecting",{"_key":7228,"_type":176,"marks":7229,"text":7230},"c7385bd79af6",[]," them.",[],{"_key":7233,"_type":172,"children":7234,"markDefs":7239,"style":180},"938d30238748",[7235],{"_key":7236,"_type":176,"marks":7237,"text":7238},"97ce898f1f67",[],"Teams need a unified view of how logic flows through the system—how a field update triggers a Flow, which updates another object, which feeds a report, which drives a downstream process.",[],{"_key":7241,"_type":172,"children":7242,"markDefs":7247,"style":180},"4dad1d702654",[7243],{"_key":7244,"_type":176,"marks":7245,"text":7246},"169127d5364d",[],"Once that model exists, impact stops being hypothetical.",[],{"_key":7249,"_type":172,"children":7250,"markDefs":7255,"style":180},"72b015647455",[7251],{"_key":7252,"_type":176,"marks":7253,"text":7254},"0b7dc3452271",[],"A proposed change can be evaluated against real dependencies. Not a checklist. Not tribal knowledge. A mapped system.",[],{"_key":7257,"_type":172,"children":7258,"markDefs":7263,"style":180},"92e6c8f25a18",[7259],{"_key":7260,"_type":176,"marks":7261,"text":7262},"24048c1e7956",[],"That changes the approval process completely.",[],{"_key":7265,"_type":172,"children":7266,"markDefs":7271,"style":180},"125529f72452",[7267],{"_key":7268,"_type":176,"marks":7269,"text":7270},"76c14f95bce4",[],"Approvals stop asking, “Did someone review this?”",[],{"_key":7273,"_type":172,"children":7274,"markDefs":7279,"style":180},"a48b035b6a91",[7275],{"_key":7276,"_type":176,"marks":7277,"text":7278},"a8a5019c7190",[],"They start asking, “Did the system confirm this change won’t create unintended consequences?”",[],{"_key":7281,"_type":172,"children":7282,"markDefs":7287,"style":292},"3ea99ecf705a",[7283],{"_key":7284,"_type":176,"marks":7285,"text":7286},"977bc9e7392f",[],"Capture reasoning alongside action",[],{"_key":7289,"_type":172,"children":7290,"markDefs":7295,"style":180},"6a120315ccb8",[7291],{"_key":7292,"_type":176,"marks":7293,"text":7294},"a1404e205c8c",[],"Auditors don’t just care about what changed. They care about why the change happened.",[],{"_key":7297,"_type":172,"children":7298,"markDefs":7303,"style":180},"4d563772645d",[7299],{"_key":7300,"_type":176,"marks":7301,"text":7302},"c75a1fd2fafa",[],"Most teams separate those two things.",[],{"_key":7305,"_type":172,"children":7306,"markDefs":7311,"style":180},"70397efe7dd7",[7307],{"_key":7308,"_type":176,"marks":7309,"text":7310},"20682eca5faf",[],"The reasoning lives in tickets or conversations. The action lives in Salesforce. The connection between them breaks over time.",[],{"_key":7313,"_type":172,"children":7314,"markDefs":7324,"style":180},"f406c7945ac6",[7315,7320],{"_key":7316,"_type":176,"marks":7317,"text":7319},"fcde3b917ded",[7318],"080b4d3b14cc","Audit-ready governance ",{"_key":7321,"_type":176,"marks":7322,"text":7323},"6c6594e4d8a0",[],"keeps them together.",[7325],{"_key":7318,"_ref":3743,"_type":328,"linkType":33,"slug":7326},{"_type":22,"current":3745},{"_key":7328,"_type":172,"children":7329,"markDefs":7334,"style":180},"1c8fee0d6303",[7330],{"_key":7331,"_type":176,"marks":7332,"text":7333},"afccf99131a9",[],"Every change carries its own context: the analysis, the dependencies, the decision, and the approval. That context stays attached to the change as it moves through environments and over time.",[],{"_key":7336,"_type":172,"children":7337,"markDefs":7342,"style":180},"6ed539521706",[7338],{"_key":7339,"_type":176,"marks":7340,"text":7341},"becd9a655739",[],"So when someone asks six months later, the answer doesn’t require reconstruction.",[],{"_key":7344,"_type":172,"children":7345,"markDefs":7354,"style":180},"c488ea2fee70",[7346,7350],{"_key":7347,"_type":176,"marks":7348,"text":7349},"a8aff8e71dd9",[],"It’s just… ",{"_key":7351,"_type":176,"marks":7352,"text":7353},"e244ad09ae82",[393],"already there.",[],{"_key":7356,"_type":172,"children":7357,"markDefs":7362,"style":292},"6d2a176c45dc",[7358],{"_key":7359,"_type":176,"marks":7360,"text":7361},"08c1e6715a9b",[],"Replace reactive debugging with continuous visibility",[],{"_key":7364,"_type":172,"children":7365,"markDefs":7370,"style":180},"6b20ee4c444f",[7366],{"_key":7367,"_type":176,"marks":7368,"text":7369},"3254b51fe5fb",[],"Even well-governed systems drift. New automations overlap with old ones. Permissions expand. Edge cases accumulate. What worked six months ago starts to behave differently under new conditions.",[],{"_key":7372,"_type":172,"children":7373,"markDefs":7378,"style":180},"28f028d242ea",[7374],{"_key":7375,"_type":176,"marks":7376,"text":7377},"0d9dcbe4e920",[],"Teams often catch this drift after something breaks.",[],{"_key":7380,"_type":172,"children":7381,"markDefs":7386,"style":180},"d5164eb8b169",[7382],{"_key":7383,"_type":176,"marks":7384,"text":7385},"83d1acea40b3",[],"Audit-ready organizations surface it earlier.",[],{"_key":7388,"_type":172,"children":7389,"markDefs":7394,"style":180},"495a9222cd3f",[7390],{"_key":7391,"_type":176,"marks":7392,"text":7393},"357c4d0062e5",[],"They monitor changes continuously. They track how new logic interacts with existing dependencies. They flag risk as it emerges, not after it triggers an incident.",[],{"_key":7396,"_type":172,"children":7397,"markDefs":7402,"style":180},"eb9c1209c881",[7398],{"_key":7399,"_type":176,"marks":7400,"text":7401},"3aba58bce0df",[],"That reduces both operational fire drills and audit exposure.",[],{"_key":7404,"_type":172,"children":7405,"markDefs":7410,"style":292},"dadda8009586",[7406],{"_key":7407,"_type":176,"marks":7408,"text":7409},"b79aaaa57f8b",[],"Governance becomes a property of the system",[],{"_key":7412,"_type":172,"children":7413,"markDefs":7427,"style":180},"a84d2ad8245e",[7414,7418,7423],{"_key":7415,"_type":176,"marks":7416,"text":7417},"c733d091c89e",[],"When teams connect metadata, model dependencies, and ",{"_key":7419,"_type":176,"marks":7420,"text":7422},"a88e0a0531ef",[7421],"28e45cb1c7f8","attach context to every change",{"_key":7424,"_type":176,"marks":7425,"text":7426},"092273b00108",[],", governance stops depending on process discipline alone.",[7428],{"_key":7421,"_ref":1242,"_type":328,"linkType":33,"slug":7429},{"_type":22,"current":1244},{"_key":7431,"_type":172,"children":7432,"markDefs":7437,"style":180},"305459412400",[7433],{"_key":7434,"_type":176,"marks":7435,"text":7436},"c4b0ee37b271",[],"It becomes a property of the system itself.",[],{"_key":7439,"_type":172,"children":7440,"markDefs":7445,"style":180},"e5329905a3bf",[7441],{"_key":7442,"_type":176,"marks":7443,"text":7444},"55b2f2ba9793",[],"Changes carry traceability by default. Impact analysis happens before deployment. Approvals reflect actual system behavior, not assumptions.",[],{"_key":7447,"_type":172,"children":7448,"markDefs":7453,"style":180},"8b5485ed8949",[7449],{"_key":7450,"_type":176,"marks":7451,"text":7452},"3ff5c8fed14d",[],"Audits stop feeling like interruptions.",[],{"_key":7455,"_type":172,"children":7456,"markDefs":7461,"style":180},"611f3dc4937f",[7457],{"_key":7458,"_type":176,"marks":7459,"text":7460},"245e259b9d01",[],"They become validations of how the system already operates.",[],{"_key":7463,"_type":172,"children":7464,"markDefs":7469,"style":292},"baa1b6c902aa",[7465],{"_key":7466,"_type":176,"marks":7467,"text":7468},"4b1d6084dfe2",[],"The outcome: fewer surprises",[],{"_key":7471,"_type":172,"children":7472,"markDefs":7477,"style":180},"86dea3f55626",[7473],{"_key":7474,"_type":176,"marks":7475,"text":7476},"04859112fc90",[],"Back in that audit room,audit-ready governance prevents time from telescoping down unto your face.",[],{"_key":7479,"_type":172,"children":7480,"markDefs":7485,"style":180},"77ac4a196c8d",[7481],{"_key":7482,"_type":176,"marks":7483,"text":7484},"e1d97e36db4e",[],"A field changes. The system shows what triggered it, what it affects, and why it was approved. No digging. No guessing. No reconstruction.",[],{"_key":7487,"_type":172,"children":7488,"markDefs":7493,"style":180},"3ed49620432b",[7489],{"_key":7490,"_type":176,"marks":7491,"text":7492},"883a8d2c7475",[],"Just real, trustworthy answers.",[],{"_type":17,"description":7495,"shareImage":7496,"title":6832},"Learn how to establish audit-ready change governance in Salesforce with full visibility, traceability, and impact analysis before issues arise.",{"_type":40,"asset":7497},{"_ref":6799,"_type":278},{"_type":22,"current":1060},{"_createdAt":7500,"_id":7501,"_rev":7502,"_system":7503,"_type":33,"_updatedAt":7506,"author":7507,"category":7523,"featuredImage":7529,"modularContent":7562,"postTitle":7530,"publishDate":7566,"richText":7567,"seo":8161,"slug":8166},"2026-03-26T16:52:13Z","f6782281-5271-43e7-a3bf-035851fedfbb","R0391oZCNphDuGuVrI9FNO",{"base":7504},{"id":7501,"rev":7505},"QYgiFmmkYC7bfHy8awlYGS","2026-03-30T16:41:49Z",{"authorImage":7508,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":38,"image":7509},{"_type":40,"asset":7510},{"_createdAt":42,"_id":43,"_rev":44,"_type":45,"_updatedAt":46,"altText":19,"assetId":47,"description":19,"extension":48,"metadata":7511,"mimeType":83,"opt":7521,"originalFilename":86,"path":87,"sha1hash":47,"size":88,"title":19,"uploadId":89,"url":90},{"_type":50,"blurHash":51,"dimensions":7512,"hasAlpha":56,"isOpaque":57,"lqip":58,"palette":7513},{"_type":53,"aspectRatio":54,"height":55,"width":55},{"_type":60,"darkMuted":7514,"darkVibrant":7515,"dominant":7516,"lightMuted":7517,"lightVibrant":7518,"muted":7519,"vibrant":7520},{"_type":62,"background":63,"foreground":64,"population":65,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":71,"foreground":72,"population":73,"title":64},{"_type":62,"background":75,"foreground":72,"population":76,"title":72},{"_type":62,"background":78,"foreground":64,"population":79,"title":64},{"_type":62,"background":81,"foreground":64,"population":82,"title":64},{"media":7522},{"tags":19},{"_createdAt":5,"_id":6,"_rev":7,"_system":7524,"_type":11,"_updatedAt":12,"selectedColor":7526,"seo":7527,"slug":7528,"title":24},{"base":7525},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":7530,"image":7531},"How to Run a Salesforce Permission Audit in Complex Environments",{"_type":40,"asset":7532},{"_createdAt":7533,"_id":7534,"_rev":7535,"_type":45,"_updatedAt":7533,"assetId":7536,"extension":106,"metadata":7537,"mimeType":132,"originalFilename":6823,"path":7558,"sha1hash":7536,"size":7559,"uploadId":7560,"url":7561},"2026-03-26T17:12:22Z","image-bb2b7bd0cda72ccdf234804219e1bce094458c1a-1600x900-png","QYgiFmmkYC7bfHy8avjt2q","bb2b7bd0cda72ccdf234804219e1bce094458c1a",{"_type":50,"blurHash":7538,"dimensions":7539,"hasAlpha":57,"isOpaque":56,"lqip":7540,"palette":7541,"thumbHash":7557},"M15hV]M|4nax9ZM{xuNGoft600M{~qWB-;",{"_type":53,"aspectRatio":5981,"height":5982,"width":5983},"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAB3ElEQVR4nHWS2XLaMBSGeQlrsSV5BZtsNosJYQsBwpqm02fv9AE6zSQ1l7nBN9HpSNgEaHvxzZH0S7/OOVKFGPw3RjwniEuCOFAsQMV/cayd7ZPY4DuC2GsFG3xLzgz/Z1pqx5DScO/xdjDEhrqFHQ5jYx8t6gC3PI0aaw197iOFITk2pFjkFnWkSRxQMNMFi7o6Bl4dLusJXEQx+G4I3FKao1E6M9XYlhTznGL+VqGIbznz8osolvF1GxTN5BYacQrJTQrdzhBGgwkMemPotHvQSDqaZtKBVrOrYxReS2a6ZYZsK5ifN+JUTsZzmM/WMH/cwHSygNl0CZvVV3h++gar5RdYPG4KfQ3LxROsV896X3zTltzyTksOvEimrTsYDh6gf3cPt2kfet0RjEczuB9O9Zqal1FlPOg/gDrje5FUHiePYhIhbR6A59TAEVWwRQCuXdN9K9fOce0qCOaDSWxJMM8JZqqHIiNY7CgWHxQLSZGCqyarWzXFK56gdJvZMvCqsupHH65T21nUea0QJH4RLN4J4juKRL5HfwFNUcpfmETkoeflrSTJ01Z3d3XZeBfM/6lK/kEQfyEGzxQqY2oIPT7MVRXF/HOdZ4LZWS0Is3p4lflu9GJR5/sfd1gvCSqATiEAAAAASUVORK5CYII=",{"_type":60,"darkMuted":7542,"darkVibrant":7545,"dominant":7547,"lightMuted":7548,"lightVibrant":7551,"muted":7553,"vibrant":7555},{"_type":62,"background":7543,"foreground":64,"population":7544,"title":64},"#3d3b42",1.02,{"_type":62,"background":7546,"foreground":64,"population":1737,"title":64},"#141024",{"_type":62,"background":7543,"foreground":64,"population":7544,"title":64},{"_type":62,"background":7549,"foreground":72,"population":7550,"title":64},"#bcbcc1",0.13,{"_type":62,"background":7552,"foreground":72,"population":82,"title":72},"#e4dd94",{"_type":62,"background":7554,"foreground":64,"population":82,"title":64},"#8c7464",{"_type":62,"background":7556,"foreground":72,"population":844,"title":64},"#bdb12f","yQeGA4APV2eHh3Bx0HRa+QgIj4dw+Ag=","images/9eu1m6zu/production/bb2b7bd0cda72ccdf234804219e1bce094458c1a-1600x900.png",139830,"Tv4rY6eei7OQ0HTLhzoVRFq1IFuyiyDx","https://cdn.sanity.io/images/9eu1m6zu/production/bb2b7bd0cda72ccdf234804219e1bce094458c1a-1600x900.png",[7563],{"_key":7564,"_type":275,"cols":276,"filterByCategory":7565,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":279},"ba4ea76d9fd7c64e26cacc5dd3049d47",{"_ref":6,"_type":278},"2026-03-27",[7568,7576,7591,7606,7614,7621,7633,7640,7660,7668,7676,7684,7692,7699,7716,7723,7731,7741,7751,7762,7769,7777,7784,7791,7809,7825,7833,7841,7849,7856,7864,7871,7879,7886,7894,7901,7909,7917,7925,7932,7940,7948,7956,7964,7972,7980,7988,7996,8004,8012,8020,8028,8036,8044,8052,8060,8067,8075,8083,8090,8098,8106,8114,8122,8129,8137,8145,8153],{"_key":7569,"_type":172,"children":7570,"markDefs":7575,"style":292},"7137e6e901bd",[7571],{"_key":7572,"_type":176,"marks":7573,"text":7574},"92fe9105d65d",[],"TL;DR:",[],{"_key":7577,"_type":172,"children":7578,"level":54,"listItem":309,"markDefs":7588,"style":180},"5152b3bb6691",[7579,7584],{"_key":7580,"_type":176,"marks":7581,"text":7583},"76c6a3965abb",[7582],"a0bad3828262","Salesforce permission models",{"_key":7585,"_type":176,"marks":7586,"text":7587},"8410507e9be1",[]," get messy fast — profile sprawl, permission creep, and layered access controls make it nearly impossible to answer \"who has access to what?\" without a structured audit.",[7589],{"_key":7582,"_ref":1121,"_type":328,"linkType":33,"slug":7590},{"_type":22,"current":1123},{"_key":7592,"_type":172,"children":7593,"level":54,"listItem":309,"markDefs":7603,"style":180},"7a8d02313618",[7594,7599],{"_key":7595,"_type":176,"marks":7596,"text":7598},"1b1b06db8f53",[7597],"bfa322e1e831","The audit",{"_key":7600,"_type":176,"marks":7601,"text":7602},"42f183c684d2",[]," should map every permission against a persona matrix, prioritize high-risk grants like \"Modify All Data\" and \"View All Data.”",[7604],{"_key":7597,"_ref":6988,"_type":328,"linkType":33,"slug":7605},{"_type":22,"current":6990},{"_key":7607,"_type":172,"children":7608,"level":54,"listItem":309,"markDefs":7613,"style":180},"beda13a3ee04",[7609],{"_key":7610,"_type":176,"marks":7611,"text":7612},"c102e43f8f1f",[],"With Agentforce introducing AI users that inherit permissions from your security model, a permission audit should be the start of an ongoing governance program.",[],{"_key":7615,"_type":172,"children":7616,"markDefs":7620,"style":180},"f3a0813d4a2d",[7617],{"_key":7618,"_type":176,"marks":7619,"text":352},"b77442e4163f",[],[],{"_key":7622,"_type":172,"children":7623,"markDefs":7632,"style":180},"ee3492d637b9",[7624,7628],{"_key":7625,"_type":176,"marks":7626,"text":7627},"a06d6e558d56",[369,393],"\"So who has access to what… and why?\"",{"_key":7629,"_type":176,"marks":7630,"text":7631},"bd11bda6ea1a",[],"\n\nThere's a moment in the life of every growing Salesforce org where someone asks these questions and then waits for a quick answer.",[],{"_key":7634,"_type":172,"children":7635,"markDefs":7639,"style":180},"3c5ff73c6e4e",[7636],{"_key":7629,"_type":176,"marks":7637,"text":7638},[],"And then, nobody can answer quickly.",[],{"_key":7641,"_type":172,"children":7642,"markDefs":7655,"style":180},"97d67249ad28",[7643,7646,7651],{"_key":7625,"_type":176,"marks":7644,"text":7645},[],"Maybe these questions come from a compliance officer preparing for ",{"_key":7647,"_type":176,"marks":7648,"text":7650},"730353d90677",[7649],"cdf7450cdc98","SOC 2",{"_key":7652,"_type":176,"marks":7653,"text":7654},"6b3d327602e8",[],". Maybe they surfacesduring a security review after a data incident. Or maybe there’s just a new admin staring at 47 custom profiles, 120 permission sets, and a role hierarchy that looks like it was designed by a committee of people who never spoke to each other.",[7656],{"_key":7649,"_ref":7657,"_type":328,"linkType":33,"slug":7658},"688a4669-f338-42d7-89d9-05a928951f48",{"_type":22,"current":7659},"soc-2-compliance-2025",{"_key":7661,"_type":172,"children":7662,"markDefs":7667,"style":180},"716393d19b76",[7663],{"_key":7664,"_type":176,"marks":7665,"text":7666},"158f7325f543",[],"In any case, the question is easy to ask and terrifically difficult  to answer — especially in complex environments where permissions have accumulated over years, across multiple business units, through acquisitions, org merges, and the quiet entropy of \"just give them access so they can do their job.\"",[],{"_key":7669,"_type":172,"children":7670,"markDefs":7675,"style":180},"db58bf247ecc",[7671],{"_key":7672,"_type":176,"marks":7673,"text":7674},"db8b6c844b35",[],"This guide walks through how to actually run a permission audit in that kind of environment: not a theoretical exercise in a clean demo org, but a practical methodology for orgs where the permission model is already tangled and the stakes are real.",[],{"_key":7677,"_type":172,"children":7678,"markDefs":7683,"style":292},"aa23583eae0c",[7679],{"_key":7680,"_type":176,"marks":7681,"text":7682},"42ec3b0ab632",[],"Why Salesforce Permission Audits Are Non-Negotiable Now",[],{"_key":7685,"_type":172,"children":7686,"markDefs":7691,"style":180},"2b9e8e71260f",[7687],{"_key":7688,"_type":176,"marks":7689,"text":7690},"d7c81a2fa498",[],"The operational case for permission audits has always been straightforward.",[],{"_key":7693,"_type":172,"children":7694,"markDefs":7698,"style":180},"d6304039829d",[7695],{"_key":7688,"_type":176,"marks":7696,"text":7697},[],"Over-permissioned users represent a security risk. Users with \"Modify All Data\" or \"View All Data\" who don't need it are one compromised credential away from a catastrophic data breach. ",[],{"_key":7700,"_type":172,"children":7701,"markDefs":7714,"style":180},"bc01d3a75ef0",[7702,7705,7710],{"_key":7688,"_type":176,"marks":7703,"text":7704},[],"An ",{"_key":7706,"_type":176,"marks":7707,"text":7709},"6dc0ae26ea98",[7708],"5979a61eba3e","2025 FBI advisory",{"_key":7711,"_type":176,"marks":7712,"text":7713},"7e8f5f9762fd",[]," (pdf) documenting threat actors compromising Salesforce orgs through stolen OAuth tokens made this viscerally real: when integration accounts have permissions far beyond their functional requirements, attackers don't need to be clever. ",[7715],{"_key":7708,"_type":151,"blank":57,"href":4392,"noOpener":57,"noReferrer":57,"url":4392},{"_key":7717,"_type":172,"children":7718,"markDefs":7722,"style":180},"ca1a354f3167",[7719],{"_key":7711,"_type":176,"marks":7720,"text":7721},[369],"They just need one token.",[],{"_key":7724,"_type":172,"children":7725,"markDefs":7730,"style":180},"a0cc00aebac5",[7726],{"_key":7727,"_type":176,"marks":7728,"text":7729},"152e2171ace0",[],"But the compliance case has sharpened considerably. ",[],{"_key":7732,"_type":172,"children":7733,"level":54,"listItem":309,"markDefs":7740,"style":180},"bf95d13e661d",[7734,7736],{"_key":7727,"_type":176,"marks":7735,"text":7650},[369],{"_key":7737,"_type":176,"marks":7738,"text":7739},"f90fd58ab41a",[]," commonly drives quarterly access reviews to validate permissions against current job responsibilities.",[],{"_key":7742,"_type":172,"children":7743,"level":54,"listItem":309,"markDefs":7750,"style":180},"7566750bb10f",[7744,7746],{"_key":7727,"_type":176,"marks":7745,"text":2803},[369],{"_key":7747,"_type":176,"marks":7748,"text":7749},"724ecea75bb8",[]," mandates that access be limited to the minimum necessary. GDPR requires access restrictions proportionate to data sensitivity…",[],{"_key":7752,"_type":172,"children":7753,"level":54,"listItem":309,"markDefs":7761,"style":180},"e45dcdebc5f4",[7754,7757],{"_key":7727,"_type":176,"marks":7755,"text":7756},[369],"ISO 27001 ",{"_key":7758,"_type":176,"marks":7759,"text":7760},"d79322dc339b",[],"demands formal, documented user access management procedures with regular reviews. ",[],{"_key":7763,"_type":172,"children":7764,"markDefs":7768,"style":180},"48a26428fe8c",[7765],{"_key":7727,"_type":176,"marks":7766,"text":7767},[],"If your organization operates under any of these frameworks, permission sprawl isn't just an operational headache — it's an audit finding waiting to happen.",[],{"_key":7770,"_type":172,"children":7771,"markDefs":7776,"style":292},"4312ae7ec200",[7772],{"_key":7773,"_type":176,"marks":7774,"text":7775},"a84624dd5ced",[],"And then there's Agentforce",[],{"_key":7778,"_type":172,"children":7779,"markDefs":7783,"style":180},"61990d1d75f9",[7780],{"_key":7773,"_type":176,"marks":7781,"text":7782},[],"AI agents in Salesforce are associated with a \"running user\" whose permissions determine what the agent can access and do. In Agentforce, actions can inherit permissions from referenced Apex, Flow, or Prompt Templates, so the running user’s scope matters a lot.",[],{"_key":7785,"_type":172,"children":7786,"markDefs":7790,"style":180},"ce60dcf28140",[7787],{"_key":7773,"_type":176,"marks":7788,"text":7789},[],"An over-permissioned agent user expands the attack surface for prompt injection, data exfiltration, and scope creep in ways that are harder to detect and contain than traditional human-user risks. ",[],{"_key":7792,"_type":172,"children":7793,"markDefs":7806,"style":180},"1705efc7a6a6",[7794,7797,7802],{"_key":7773,"_type":176,"marks":7795,"text":7796},[],"Salesforce's own ",{"_key":7798,"_type":176,"marks":7799,"text":7801},"b6196dd3d337",[7800],"40fc46a40b29","security guidance",{"_key":7803,"_type":176,"marks":7804,"text":7805},"7c292a56409c",[]," is explicit: each agent user should be unique, should never be reused across multiple agents, and must strictly adhere to the principle of least privilege. ",[7807],{"_key":7800,"_type":151,"blank":57,"href":7808,"noOpener":57,"noReferrer":57,"url":7808},"https://architect.salesforce.com/well-architected/trusted/secure",{"_key":7810,"_type":172,"children":7811,"markDefs":7820,"style":180},"6d016b589591",[7812,7815],{"_key":7773,"_type":176,"marks":7813,"text":7814},[],"You can't enforce any of that without first knowing ",{"_key":7816,"_type":176,"marks":7817,"text":7819},"13fa8058bce1",[7818],"e88eae16ac8f","what permissions exist and where they live.",[7821],{"_key":7818,"_ref":7822,"_type":328,"linkType":33,"slug":7823},"aa08201e-8009-4516-9157-9c3acdd0afa1",{"_type":22,"current":7824},"the-salesforce-entropy-index-2025",{"_key":7826,"_type":172,"children":7827,"markDefs":7832,"style":292},"8950f760ba05",[7828],{"_key":7829,"_type":176,"marks":7830,"text":7831},"db0ed6b41fe0",[],"The Anatomy of a Messy Permission Model",[],{"_key":7834,"_type":172,"children":7835,"markDefs":7840,"style":180},"ea9f34454ae6",[7836],{"_key":7837,"_type":176,"marks":7838,"text":7839},"8ff70382b02d",[],"Before you can audit permissions, you need to understand how they got messy in the first place. In most complex orgs, the story follows a familiar pattern.",[],{"_key":7842,"_type":172,"children":7843,"markDefs":7848,"style":180},"e725cc492dde",[7844],{"_key":7845,"_type":176,"marks":7846,"text":7847},"0133af9f7a5d",[],"It starts with profile sprawl. Someone clones \"Sales User\" to create \"Sales User – London.\" Then someone else clones that to create \"Sales User – London Events.\" Then someone creates \"Sales User – London New Starter\" as a temporary fix that becomes permanent. ",[],{"_key":7850,"_type":172,"children":7851,"markDefs":7855,"style":180},"5e9d9ea24e8a",[7852],{"_key":7845,"_type":176,"marks":7853,"text":7854},[],"Five years later, you have dozens of nearly identical profiles with minor, undocumented variations. Auditing who has what access becomes a guessing game because nobody remembers why the profiles diverged.",[],{"_key":7857,"_type":172,"children":7858,"markDefs":7863,"style":180},"54d5f15932e1",[7859],{"_key":7860,"_type":176,"marks":7861,"text":7862},"9bd8f9493bf1",[369],"On top of that, permission creep accumulates. ",[],{"_key":7865,"_type":172,"children":7866,"markDefs":7870,"style":180},"9dd241ec2871",[7867],{"_key":7860,"_type":176,"marks":7868,"text":7869},[],"A user needs access to a report, so an admin adds a permission to their profile instead of creating a permission set. A manager escalates a ticket about a blocked workflow, and someone grants \"Modify All Data\" to resolve it quickly. The temporary fix never gets reverted. Multiply this across hundreds of users and several years of turnover, and you end up with an org where most users have substantially more access than their role requires.",[],{"_key":7872,"_type":172,"children":7873,"markDefs":7878,"style":180},"c70cfe895dbb",[7874],{"_key":7875,"_type":176,"marks":7876,"text":7877},"b5e24e57f17c",[],"Then there's the layering problem. Salesforce's security model is inherently layered: organization-wide defaults set the baseline, the role hierarchy opens up record visibility, sharing rules add exceptions, profiles define broad access, and permission sets add granular capabilities on top. ",[],{"_key":7880,"_type":172,"children":7881,"markDefs":7885,"style":180},"9f52d58047f6",[7882],{"_key":7875,"_type":176,"marks":7883,"text":7884},[],"Understanding what a single user can actually do requires tracing through all of these layers simultaneously — a task that's difficult for humans and essentially impossible without tooling at scale.",[],{"_key":7887,"_type":172,"children":7888,"markDefs":7893,"style":180},"518aad943a28",[7889],{"_key":7890,"_type":176,"marks":7891,"text":7892},"ad17f225cfc2",[],"The profile-to-permission-set migration adds another dimension of complexity. Salesforce originally announced that permissions on profiles would reach end-of-life in the Spring '26 release, requiring all object access, field-level security, and system permissions to live exclusively in permission sets. ",[],{"_key":7895,"_type":172,"children":7896,"markDefs":7900,"style":180},"2df014e3dc6e",[7897],{"_key":7890,"_type":176,"marks":7898,"text":7899},[],"While Salesforce later walked back the hard enforcement date, the direction of travel hasn't changed: all investment is going into permission sets and permission set groups. Profiles will retain only baseline settings like login hours, IP ranges, default apps, record types, and page layout assignments. For teams that haven't started migrating, the audit becomes both an assessment of the current state and a planning exercise for the future state.",[],{"_key":7902,"_type":172,"children":7903,"markDefs":7908,"style":292},"682efa4361c4",[7904],{"_key":7905,"_type":176,"marks":7906,"text":7907},"88346c31bd76",[],"Step One: Inventory Everything",[],{"_key":7910,"_type":172,"children":7911,"markDefs":7916,"style":180},"e4c4fe9dc1e6",[7912],{"_key":7913,"_type":176,"marks":7914,"text":7915},"9eac373ba00d",[],"The first step in any permission audit is producing a complete inventory of the permission mechanisms in your org. This means cataloging every profile, every permission set, every permission set group, every role in the hierarchy, every sharing rule, and every public group. You need to know what exists before you can evaluate whether it's appropriate.",[],{"_key":7918,"_type":172,"children":7919,"markDefs":7924,"style":180},"1c2d346f3fb5",[7920],{"_key":7921,"_type":176,"marks":7922,"text":7923},"eb94d9fb0b7c",[],"Salesforce provides several native paths for this. ",[],{"_key":7926,"_type":172,"children":7927,"markDefs":7931,"style":180},"0138e4572760",[7928],{"_key":7921,"_type":176,"marks":7929,"text":7930},[],"The Setup Audit Trail captures changes to security configurations, including profile and permission modifications, though it only retains data for 180 days and the detail it provides on complex changes is often limited to \"Modified profile X\" without specifying what changed inside it.",[],{"_key":7933,"_type":172,"children":7934,"markDefs":7939,"style":180},"0dc76dd640ff",[7935],{"_key":7936,"_type":176,"marks":7937,"text":7938},"6ea67dd2049c",[],"For a more systematic extraction, SOQL queries against the Tooling API give you direct access to permission metadata. Querying the ObjectPermissions object surfaces every CRUD setting for every profile and permission set in the org. Querying FieldPermissions reveals field-level security grants. And querying PermissionSetAssignment shows you which permission sets are assigned to which users. These queries can be run through the Developer Console, Data Loader, or third-party tools that wrap SOQL in a more accessible interface.",[],{"_key":7941,"_type":172,"children":7942,"markDefs":7947,"style":180},"2f9ffa74f355",[7943],{"_key":7944,"_type":176,"marks":7945,"text":7946},"e817b6e06fe1",[],"The User Access and Permissions Assistant, a free app on the AppExchange from Salesforce, adds a significant capability here. It lets you report by user, permission set, or permission set group to understand who has what. It can surface which users hold dangerous permissions like \"Modify All Data\" or \"Customize Application,\" and it includes a permission dependency visualization that shows what's downstream of a specific permission. For teams that don't want to write raw SOQL, this is a meaningful starting point.",[],{"_key":7949,"_type":172,"children":7950,"markDefs":7955,"style":180},"4586ae45fdc8",[7951],{"_key":7952,"_type":176,"marks":7953,"text":7954},"ee475669326f",[],"But there's a catch. Even the Salesforce product management team has acknowledged that natively computing a user's effective permissions — the net result of their profile, all assigned permission sets, any permission set groups, and any muted permissions — is genuinely hard. The data model wasn't designed to make this calculation simple, and native reporting can't fully handle the complex joins required.",[],{"_key":7957,"_type":172,"children":7958,"markDefs":7963,"style":292},"523bb3a27ae7",[7959],{"_key":7960,"_type":176,"marks":7961,"text":7962},"17b1960f04e4",[],"Step Two: Map Permissions to Personas",[],{"_key":7965,"_type":172,"children":7966,"markDefs":7971,"style":180},"dba038a43acd",[7967],{"_key":7968,"_type":176,"marks":7969,"text":7970},"4303801de5ca",[],"A raw export of permissions is necessary but not sufficient. The audit only becomes meaningful when you map permissions against what users actually need.",[],{"_key":7973,"_type":172,"children":7974,"markDefs":7979,"style":180},"9ab091e2bd62",[7975],{"_key":7976,"_type":176,"marks":7977,"text":7978},"7d47b7232ae9",[],"This requires building (or validating) a persona matrix: a document that defines the distinct job functions in your org and the minimum permissions each function requires. \"Sales Rep,\" \"Sales Manager,\" \"Service Agent,\" \"Marketing Ops,\" \"Finance Analyst,\" \"System Admin\" — each of these personas has a specific set of objects they need to read, create, edit, or delete, a specific set of fields that should be visible to them, and a specific set of system permissions they require.",[],{"_key":7981,"_type":172,"children":7982,"markDefs":7987,"style":180},"0c62e4fde225",[7983],{"_key":7984,"_type":176,"marks":7985,"text":7986},"9215d48864ec",[],"The persona matrix is your baseline. Once you have it, you compare it against reality. Export every profile's permissions and every permission set's grants, then overlay the actual assignments against the expected assignments. The gaps — permissions that exist in the org but don't appear in any persona definition — are your audit findings.",[],{"_key":7989,"_type":172,"children":7990,"markDefs":7995,"style":180},"71a981036301",[7991],{"_key":7992,"_type":176,"marks":7993,"text":7994},"d698adbde4cc",[],"In practice, this comparison almost always reveals three things: users with far more access than their persona requires, permission sets that were created for a specific project and never cleaned up, and profiles that have drifted so far from their original intent that they're essentially ungovernable.",[],{"_key":7997,"_type":172,"children":7998,"markDefs":8003,"style":292},"988aaa551765",[7999],{"_key":8000,"_type":176,"marks":8001,"text":8002},"0600d1796044",[],"Step Three: Hunt for High-Risk Permissions",[],{"_key":8005,"_type":172,"children":8006,"markDefs":8011,"style":180},"c3e50e5a6ba1",[8007],{"_key":8008,"_type":176,"marks":8009,"text":8010},"7ec31adc1ae3",[],"Not all permission gaps are created equal. Some are minor annoyances. Others are genuine security exposures. The audit should prioritize identifying and remediating the highest-risk permissions first.",[],{"_key":8013,"_type":172,"children":8014,"markDefs":8019,"style":180},"40dfa42ac997",[8015],{"_key":8016,"_type":176,"marks":8017,"text":8018},"cfbf86b52a03",[],"The usual suspects include \"Modify All Data\" and \"View All Data\" (which bypass all sharing rules and field-level security), \"Export Reports\" (which enables bulk data exfiltration), \"Manage All Data\" on specific objects containing PII or financial records, \"Author Apex\" (which allows code execution), and \"Customize Application\" (which grants the ability to modify the org's configuration).",[],{"_key":8021,"_type":172,"children":8022,"markDefs":8027,"style":180},"af5e171d7958",[8023],{"_key":8024,"_type":176,"marks":8025,"text":8026},"5910c5d90aef",[],"These permissions should be held by the smallest possible number of users, and every assignment should be documented and justified. If your audit reveals 30 users with \"Modify All Data\" and only three of them are system administrators, that's a finding that needs immediate remediation.",[],{"_key":8029,"_type":172,"children":8030,"markDefs":8035,"style":180},"8bd284bb2732",[8031],{"_key":8032,"_type":176,"marks":8033,"text":8034},"89523d32195a",[],"For Agentforce-specific audits, the high-risk list extends further. Agent users that share permission sets with human users, agent users with access to objects or fields beyond their functional scope, and agents with CRUD access they don't need for their defined actions are all red flags. Salesforce's guidance is clear: avoid sharing the same permission sets between multiple agents, and avoid granting broad access \"just in case.\"",[],{"_key":8037,"_type":172,"children":8038,"markDefs":8043,"style":292},"26a1157935b0",[8039],{"_key":8040,"_type":176,"marks":8041,"text":8042},"eb8a59dd68ab",[],"Step Four: Evaluate Sharing Rules and Role Hierarchy",[],{"_key":8045,"_type":172,"children":8046,"markDefs":8051,"style":180},"2dc15de8cdfa",[8047],{"_key":8048,"_type":176,"marks":8049,"text":8050},"ba82653abfda",[],"Permissions audits often focus narrowly on profiles and permission sets while ignoring the role hierarchy and sharing rules — which is like auditing the locks on your doors while ignoring the open windows.",[],{"_key":8053,"_type":172,"children":8054,"markDefs":8059,"style":180},"6a51cc8d8151",[8055],{"_key":8056,"_type":176,"marks":8057,"text":8058},"e62e48c83681",[],"The role hierarchy determines record-level visibility. ",[],{"_key":8061,"_type":172,"children":8062,"markDefs":8066,"style":180},"4fcaaa05b81a",[8063],{"_key":8056,"_type":176,"marks":8064,"text":8065},[],"A user positioned high in the hierarchy automatically inherits visibility into records owned by users below them. If the hierarchy doesn't accurately reflect your organization's reporting structure, users may be seeing records they shouldn't.",[],{"_key":8068,"_type":172,"children":8069,"markDefs":8074,"style":180},"e46d8f23fd4a",[8070],{"_key":8071,"_type":176,"marks":8072,"text":8073},"878b5372d3df",[],"Sharing rules add lateral access: they open up record visibility between roles that aren't in a parent-child relationship. Criteria-based sharing rules, in particular, can create access paths that are hard to trace without careful review.",[],{"_key":8076,"_type":172,"children":8077,"markDefs":8082,"style":180},"7dfcc3279115",[8078],{"_key":8079,"_type":176,"marks":8080,"text":8081},"27bf31b124bc",[],"Organization-wide defaults (OWDs) set the foundation for all of this. If your OWDs for sensitive objects like Opportunities, Cases, or custom objects containing financial data are set to \"Public Read/Write\" instead of \"Private,\" then no amount of profile cleanup will prevent over-exposure. ",[],{"_key":8084,"_type":172,"children":8085,"markDefs":8089,"style":180},"246d13d0a25a",[8086],{"_key":8079,"_type":176,"marks":8087,"text":8088},[],"The audit should verify that OWDs for sensitive objects are appropriately restrictive, and that the role hierarchy and sharing rules only open up access where it's genuinely needed.",[],{"_key":8091,"_type":172,"children":8092,"markDefs":8097,"style":292},"ec00d0deed8f",[8093],{"_key":8094,"_type":176,"marks":8095,"text":8096},"6eb685bf6286",[],"Step Five: Establish Ongoing Governance",[],{"_key":8099,"_type":172,"children":8100,"markDefs":8105,"style":180},"db7d39d49095",[8101],{"_key":8102,"_type":176,"marks":8103,"text":8104},"a73befdd6f5a",[],"A permission audit is not a one-time project. It's the first iteration of an ongoing governance program. Without a recurring cadence, permission creep will reassert itself within months.",[],{"_key":8107,"_type":172,"children":8108,"markDefs":8113,"style":180},"3478d2d8fa07",[8109],{"_key":8110,"_type":176,"marks":8111,"text":8112},"70dce1d690cc",[],"The governance program should include quarterly access reviews (aligned with SOC 2 requirements if applicable), a formal change-control process for any permission modification, automated monitoring of high-risk permission changes (which Salesforce's Security Center can provide for organizations that have licensed it), and a clear ownership model where someone — an admin, a security team, or a dedicated governance role — is accountable for the permission model.",[],{"_key":8115,"_type":172,"children":8116,"markDefs":8121,"style":180},"78539193f744",[8117],{"_key":8118,"_type":176,"marks":8119,"text":8120},"1215e0a73cc2",[],"The profile-to-permission-set migration, even though it's no longer being enforced on a hard timeline, should be part of this governance program. Every new permission should be created as a permission set, not added to a profile.",[],{"_key":8123,"_type":172,"children":8124,"markDefs":8128,"style":180},"3b63b9f32b02",[8125],{"_key":8118,"_type":176,"marks":8126,"text":8127},[],"Over time, the goal is to consolidate down to a small number of minimum-access profiles with a library of composable, well-documented permission sets that map cleanly to your persona matrix.",[],{"_key":8130,"_type":172,"children":8131,"markDefs":8136,"style":180},"787a3b210837",[8132],{"_key":8133,"_type":176,"marks":8134,"text":8135},"7cd5373368da",[],"For organizations deploying Agentforce, governance extends to agent-specific concerns: regular reviews of agent user permissions, monitoring of agent access logs and conversation data, and periodic testing to verify that agents can't access data beyond their defined scope.",[],{"_key":8138,"_type":172,"children":8139,"markDefs":8144,"style":292},"2ee5d6439f74",[8140],{"_key":8141,"_type":176,"marks":8142,"text":8143},"90ee84d930db",[],"The Payoff",[],{"_key":8146,"_type":172,"children":8147,"markDefs":8152,"style":180},"18aab3be5488",[8148],{"_key":8149,"_type":176,"marks":8150,"text":8151},"c2c75f69f70f",[],"A clean permission model isn't just a compliance checkbox. It's the foundation for everything else: safe deployments, confident change management, Agentforce readiness, and the basic organizational trust that comes from knowing who can see what and why.",[],{"_key":8154,"_type":172,"children":8155,"markDefs":8160,"style":180},"3967f3ae0b66",[8156],{"_key":8157,"_type":176,"marks":8158,"text":8159},"77af6b3848c5",[],"In complex environments, getting there takes real work. But the alternative — an org where nobody can answer the question \"who has access to what?\" — in world of AI agents, regulatory scrutiny, and expanding attack surfaces, is totally untenable.",[],{"_type":17,"description":8162,"shareImage":8163,"title":8165},"A practical guide to auditing Salesforce permissions in complex orgs — covering profile sprawl, permission creep, SOQL-based exports, persona mapping, high-risk permission remediation, and building ongoing governance for Agentforce readiness.",{"_type":40,"asset":8164},{"_ref":7534,"_type":278},"How to Run a Salesforce Permission Audit in Complex Environments | Sweep",{"_type":22,"current":8167},"salesforce-permission-audits-complex-environments",{"_createdAt":8169,"_id":1121,"_rev":8170,"_system":8171,"_type":33,"_updatedAt":8174,"author":8175,"category":8191,"featuredImage":8197,"modularContent":8234,"postTitle":8238,"publishDate":8239,"richText":8240,"seo":8761,"slug":8766},"2026-03-17T18:50:36Z","R0391oZCNphDuGuVrI9nbP",{"base":8172},{"id":1121,"rev":8173},"aW1912VeQE9kmb7jB71iZy","2026-03-30T16:43:26Z",{"authorImage":8176,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":38,"image":8177},{"_type":40,"asset":8178},{"_createdAt":42,"_id":43,"_rev":44,"_type":45,"_updatedAt":46,"altText":19,"assetId":47,"description":19,"extension":48,"metadata":8179,"mimeType":83,"opt":8189,"originalFilename":86,"path":87,"sha1hash":47,"size":88,"title":19,"uploadId":89,"url":90},{"_type":50,"blurHash":51,"dimensions":8180,"hasAlpha":56,"isOpaque":57,"lqip":58,"palette":8181},{"_type":53,"aspectRatio":54,"height":55,"width":55},{"_type":60,"darkMuted":8182,"darkVibrant":8183,"dominant":8184,"lightMuted":8185,"lightVibrant":8186,"muted":8187,"vibrant":8188},{"_type":62,"background":63,"foreground":64,"population":65,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":71,"foreground":72,"population":73,"title":64},{"_type":62,"background":75,"foreground":72,"population":76,"title":72},{"_type":62,"background":78,"foreground":64,"population":79,"title":64},{"_type":62,"background":81,"foreground":64,"population":82,"title":64},{"media":8190},{"tags":19},{"_createdAt":5,"_id":6,"_rev":7,"_system":8192,"_type":11,"_updatedAt":12,"selectedColor":8194,"seo":8195,"slug":8196,"title":24},{"base":8193},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":8198,"image":8199},"Salesforce Permission Sets Explained",{"_type":40,"asset":8200},{"_createdAt":8201,"_id":8202,"_rev":8203,"_type":45,"_updatedAt":8201,"assetId":8204,"extension":106,"metadata":8205,"mimeType":132,"originalFilename":6823,"path":8230,"sha1hash":8204,"size":8231,"uploadId":8232,"url":8233},"2026-03-17T18:52:02Z","image-768dc4fa58c31bab600dfe50790f0eb5c56388e6-1600x900-png","LBRy0x6E5f3ZYVVFRBPBz9","768dc4fa58c31bab600dfe50790f0eb5c56388e6",{"_type":50,"blurHash":8206,"dimensions":8207,"exif":8208,"hasAlpha":57,"isOpaque":56,"lqip":8209,"palette":8210},"M8C[6.94-g9lEByZD@bIs+t00W9jof%F$_",{"_type":53,"aspectRatio":5981,"height":5982,"width":5983},{"ColorSpace":6806,"PixelXDimension":5983,"PixelYDimension":5982,"_type":6807},"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7EAAAOxAGVKw4bAAACjElEQVR4nEWT709SURyH+d8yM9nKysxcUVaYllpSmQpcAQVRIJEf4g8MUCInrlq9qT+hN71prVetmitvrFptOQ7S/T7t3mv14tnZztl5zuez747jWAi9fRLV6kdavHDICy0HtGlwfAq656A3Cf0ZGFqCW3kYK4JWhqlNmN1Gkk+pp5/x2dE+Sc0UtgcQZwBMjoXgxDR0zkD3LLjuwZUUDCzC8DLczsN4EfwbEHoIM1Uk8QS18JRdR6ufmjOA6phGToZtydk5cCVskbn2zoM7fSA0E67CWAF8GxCsQGQLiT1CJZ+w62jxUTsZRvXOI+4UXM3AYM5mIAuXkjbmmVnZ3L+5AnfWYLz0r7bMbqMSjy2hUeuJoW7lkfGS4F0XtLJYdcwU5uWbyzCUg/4sXPubMg9374Nv3aot0Soq/siqbNRciaYaKzREK+8TfLBPeLNJqGLgLdlSc/Ws2kIr5aL9iJlyogiTZSS8iYpW2XU4tf3a1eR3Fd54L6mtt2S335KqfiBS+cbIcoO+g6p9abi8AO4F6E/bUs8KjK6Bt4gEy6jpiiVUtb7EJxUpvpLVrRfcrz4nVXlJqPCO6+lfuOKCK24P50Ices2Jz8NAShjKCp4lYTSPeIsobZ1dR5v/95fTkb1638JX4/biRxnNfZCRrC6DmR9yJdkQVxyLczHk3BxyPoZcTCDu+d8ynGnI6EpDJgoYvhJ1X4HPjsN+dpxBfnaEqXdGDNU1Y6gz0f+cjqC6DuieQfVEUedjhrqUaKobmT01sbanAhtGXSvxc3yNj44WL29avewc8aO3aehHNevnWDgn0Y8H0DuC6CdC6Kem0Lum0Xui6K45Q3ffa+qD6aY+kjO+eJbY8eR4/QcAfIhCmD5l7QAAAABJRU5ErkJggg==",{"_type":60,"darkMuted":8211,"darkVibrant":8214,"dominant":8217,"lightMuted":8220,"lightVibrant":8223,"muted":8226,"vibrant":8229},{"_type":62,"background":8212,"foreground":64,"population":8213,"title":64},"#525d61",0.98,{"_type":62,"background":8215,"foreground":64,"population":8216,"title":64},"#04041d",2.25,{"_type":62,"background":8218,"foreground":64,"population":8219,"title":64},"#447cfc",8.2,{"_type":62,"background":8221,"foreground":72,"population":8222,"title":72},"#dae1c7",4.52,{"_type":62,"background":8224,"foreground":72,"population":8225,"title":64},"#749bfb",6.61,{"_type":62,"background":8227,"foreground":64,"population":8228,"title":64},"#6073a0",0.88,{"_type":62,"background":8218,"foreground":64,"population":8219,"title":64},"images/9eu1m6zu/production/768dc4fa58c31bab600dfe50790f0eb5c56388e6-1600x900.png",285037,"3BDLzEykWqvI7LS3yOWvmypqlnfPSnOk","https://cdn.sanity.io/images/9eu1m6zu/production/768dc4fa58c31bab600dfe50790f0eb5c56388e6-1600x900.png",[8235],{"_key":8236,"_type":275,"cols":276,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":8237},"ff0f61f8ea00d4a9bfff21bb5c60f698","Latest reads","Salesforce Permission Sets Explained: A Complete Guide to Access Control and Custom Permissions","2026-03-17",[8241,8249,8257,8264,8278,8285,8292,8300,8308,8316,8324,8332,8340,8348,8356,8364,8380,8388,8396,8404,8412,8431,8439,8447,8455,8463,8471,8490,8498,8506,8514,8522,8530,8538,8546,8554,8562,8570,8578,8586,8594,8602,8610,8618,8626,8640,8648,8656,8664,8672,8680,8688,8703,8711,8718,8725,8732,8747],{"_key":8242,"_type":172,"children":8243,"markDefs":8248,"style":180},"2169ccedcc39",[8244],{"_key":8245,"_type":176,"marks":8246,"text":8247},"7f53c2f2b67c",[393],"Salesforce permission sets are now at the epicenter of modern access control. For admins, RevOps teams, and  othersecurity leaders, Salesforce permissions are no longer static configurations. They are a living system that directly impacts security, compliance, operational speed, and AI readiness.",[],{"_key":8250,"_type":172,"children":8251,"markDefs":8256,"style":180},"93de65eb520b",[8252],{"_key":8253,"_type":176,"marks":8254,"text":8255},"2ea4297797e8",[393],"Permission sets, permission set groups, custom permissions Salesforce patterns, and Salesforce API access control all work together to define who can access what, under which conditions, and for what purpose. When that system is clean, access is predictable and auditable. When it isn’t, access becomes guesswork.\n",[],{"_key":8258,"_type":172,"children":8259,"markDefs":8263,"style":292},"e0bf1ad2ba7f",[8260],{"_key":8261,"_type":176,"marks":8262,"text":290},"42e5104e4bfa",[],[],{"_key":8265,"_type":172,"children":8266,"level":54,"listItem":309,"markDefs":8275,"style":180},"663a2ca67272",[8267,8271],{"_key":8261,"_type":176,"marks":8268,"text":8270},[8269],"e3588f449235","Permission sets",{"_key":8272,"_type":176,"marks":8273,"text":8274},"65c5b2acec4a",[]," have become Salesforce’s primary access model, even as profiles still exist. They are additive by design, which makes composition powerful but also easy to get wrong. ",[8276],{"_key":8269,"_ref":7501,"_type":328,"linkType":33,"slug":8277},{"_type":22,"current":8167},{"_key":8279,"_type":172,"children":8280,"level":54,"listItem":309,"markDefs":8284,"style":180},"0addef519376",[8281],{"_key":8261,"_type":176,"marks":8282,"text":8283},[],"Custom permissions extend access control into logic and automation, while API access enforces the same underlying model everywhere. ",[],{"_key":8286,"_type":172,"children":8287,"level":54,"listItem":309,"markDefs":8291,"style":180},"5950d961fccf",[8288],{"_key":8261,"_type":176,"marks":8289,"text":8290},[],"The actual shift is this: access control is no longer a setup task. It is a metadata governance problem that directly impacts security, scale, and AI readiness.",[],{"_key":8293,"_type":172,"children":8294,"markDefs":8299,"style":292},"fd3be4934d76",[8295],{"_key":8296,"_type":176,"marks":8297,"text":8298},"0370e247c39c",[],"Why Salesforce Permission Sets Are Now the Center of Access Control",[],{"_key":8301,"_type":172,"children":8302,"markDefs":8307,"style":180},"5ca4139c37d5",[8303],{"_key":8304,"_type":176,"marks":8305,"text":8306},"628dd4a53b24",[],"The move toward permission sets reflects a deeper change in how access is designed. Profiles were built for a simpler world where roles were static and systems changed slowly. That world doesn’t exist anymore.",[],{"_key":8309,"_type":172,"children":8310,"markDefs":8315,"style":180},"903097159326",[8311],{"_key":8312,"_type":176,"marks":8313,"text":8314},"d5b77f21df9c",[],"Permission sets introduce modularity. Instead of assigning one rigid configuration to a user, teams can layer access in smaller, more intentional pieces. A user might inherit baseline access, gain additional permissions for their role, and receive temporary access for a specific project. Each layer adds clarity when designed well, or confusion when it isn’t.",[],{"_key":8317,"_type":172,"children":8318,"markDefs":8323,"style":180},"06a142783d4f",[8319],{"_key":8320,"_type":176,"marks":8321,"text":8322},"96229a38964b",[],"This changes the core question teams ask. Instead of deciding which profile someone belongs to, the focus shifts to defining the smallest, cleanest set of access required for someone to do their job. That is what makes least-privilege access achievable in practice.",[],{"_key":8325,"_type":172,"children":8326,"markDefs":8331,"style":292},"b68a3f92aa12",[8327],{"_key":8328,"_type":176,"marks":8329,"text":8330},"1b32d5fa2de6",[],"Salesforce Permissions vs Profiles: What Actually Belongs Where",[],{"_key":8333,"_type":172,"children":8334,"markDefs":8339,"style":180},"55bb70259e3c",[8335],{"_key":8336,"_type":176,"marks":8337,"text":8338},"00cc8eb2d5f3",[],"Profiles still play a role, but it is increasingly narrow. They are best used as a minimal baseline that defines login constraints and defaults, while permission sets handle nearly all functional access.",[],{"_key":8341,"_type":172,"children":8342,"markDefs":8347,"style":180},"780fe2aca97f",[8343],{"_key":8344,"_type":176,"marks":8345,"text":8346},"b6b4f4d9c9cd",[],"Object permissions, field-level security, app access, Apex classes, connected apps, and custom permissions Salesforce logic all belong in permission sets. Keeping that separation clean prevents access from becoming tightly coupled to a single monolithic configuration.",[],{"_key":8349,"_type":172,"children":8350,"markDefs":8355,"style":180},"8d64cc565ccf",[8351],{"_key":8352,"_type":176,"marks":8353,"text":8354},"e1e959c1dfcb",[],"When profiles carry too much responsibility, they tend to multiply. Small changes lead to cloned profiles, which leads to fragmentation, which eventually leads to a system no one fully understands. Permission sets reduce that sprawl by making access reusable and composable across users and teams.",[],{"_key":8357,"_type":172,"children":8358,"markDefs":8363,"style":292},"c642cba4ac20",[8359],{"_key":8360,"_type":176,"marks":8361,"text":8362},"6bdc5135ba49",[],"How Permission Set Groups Make Access Scalable",[],{"_key":8365,"_type":172,"children":8366,"markDefs":8379,"style":180},"fad3e11d9602",[8367,8371,8375],{"_key":8368,"_type":176,"marks":8369,"text":8370},"49938fd89c9c",[],"As organizations grow, individual permission sets alone are not enough to maintain clarity. Permission set groups introduce structure by ",{"_key":8372,"_type":176,"marks":8373,"text":8374},"c2a40ac7f8c4",[393],"bundling related permission sets ",{"_key":8376,"_type":176,"marks":8377,"text":8378},"83a1d3821823",[],"into a single assignment aligned to a role or function.",[],{"_key":8381,"_type":172,"children":8382,"markDefs":8387,"style":180},"41986252ee3c",[8383],{"_key":8384,"_type":176,"marks":8385,"text":8386},"21ed74c2e509",[],"This allows access to be designed in layers rather than accumulated over time. Foundational access can be separated from read-only visibility, which can then be separated from role-specific capabilities. The result is a system that reflects how people actually work instead of how access happened to evolve.",[],{"_key":8389,"_type":172,"children":8390,"markDefs":8395,"style":180},"8aa62eee6857",[8391],{"_key":8392,"_type":176,"marks":8393,"text":8394},"82de47077d67",[],"Without that structure, access becomes a collection of decisions. With it, access becomes a model.",[],{"_key":8397,"_type":172,"children":8398,"markDefs":8403,"style":292},"806440a4bcd2",[8399],{"_key":8400,"_type":176,"marks":8401,"text":8402},"036798f823c2",[],"The Additive Nature of Permission Sets (and Why Muting Matters)",[],{"_key":8405,"_type":172,"children":8406,"markDefs":8411,"style":180},"6be6c64bc6bb",[8407],{"_key":8408,"_type":176,"marks":8409,"text":8410},"36c822fc8776",[],"One of the most important characteristics of permission sets is that they are additive. When multiple permission sets grant access, the user receives the full combination of those permissions.",[],{"_key":8413,"_type":172,"children":8414,"markDefs":8428,"style":180},"476033e1ac4d",[8415,8419,8424],{"_key":8416,"_type":176,"marks":8417,"text":8418},"8d7200ee89f4",[],"This is where many ",{"_key":8420,"_type":176,"marks":8421,"text":8423},"c8f817059436",[8422],"17d2ea937677","access models",{"_key":8425,"_type":176,"marks":8426,"text":8427},"f6978f89cb40",[]," begin to drift. Without a way to reduce permissions, teams often duplicate configurations just to slightly limit access for different users.",[8429],{"_key":8422,"_type":151,"blank":57,"href":8430,"noOpener":57,"noReferrer":57,"url":8430},"https://trailhead.salesforce.com/content/learn/modules/data_security/data_security_objects",{"_key":8432,"_type":172,"children":8433,"markDefs":8438,"style":180},"ed5449750e88",[8434],{"_key":8435,"_type":176,"marks":8436,"text":8437},"fb2edcfda6f0",[],"Muting permission sets exist to address this. Within a permission set group, muting allows specific permissions to be suppressed without rebuilding the entire structure. It enables reuse while maintaining control, but it does not override permissions granted outside the group.",[],{"_key":8440,"_type":172,"children":8441,"markDefs":8446,"style":180},"fe4564d77c85",[8442],{"_key":8443,"_type":176,"marks":8444,"text":8445},"48195003f2b8",[],"Understanding this behavior is critical, because most “unexpected access” issues are simply additive logic working across multiple layers.",[],{"_key":8448,"_type":172,"children":8449,"markDefs":8454,"style":292},"7d1d607b705c",[8450],{"_key":8451,"_type":176,"marks":8452,"text":8453},"e94249e5f330",[],"Custom Permissions Salesforce Teams Should Treat as Feature Flags",[],{"_key":8456,"_type":172,"children":8457,"markDefs":8462,"style":180},"13d6965437c4",[8458],{"_key":8459,"_type":176,"marks":8460,"text":8461},"e85bf285b7fd",[],"Custom permissions Salesforce teams define are best understood as a control layer for logic, not just access.",[],{"_key":8464,"_type":172,"children":8465,"markDefs":8470,"style":180},"41056ca0468d",[8466],{"_key":8467,"_type":176,"marks":8468,"text":8469},"0ed398ae657b",[],"They do not directly grant object or field permissions. Instead, they act as switches that determine how custom functionality behaves across Apex, Flow, Lightning components, and validation logic.",[],{"_key":8472,"_type":172,"children":8473,"markDefs":8487,"style":180},"2d3a38bc926c",[8474,8478,8483],{"_key":8475,"_type":176,"marks":8476,"text":8477},"823979c2c1cd",[],"This makes them significantly more flexible than hardcoded profile checks or user-specific conditions. When access decisions are tied to profiles, ",{"_key":8479,"_type":176,"marks":8480,"text":8482},"a4012397935a",[8481],"b4ea910e15ac","they tend to break as roles evolve",{"_key":8484,"_type":176,"marks":8485,"text":8486},"24acf6cfae4b",[],". When they are tied to custom permissions, they remain portable and easier to maintain.",[8488],{"_key":8481,"_ref":534,"_type":328,"linkType":33,"slug":8489},{"_type":22,"current":536},{"_key":8491,"_type":172,"children":8492,"markDefs":8497,"style":180},"a0b33639e6c1",[8493],{"_key":8494,"_type":176,"marks":8495,"text":8496},"8eb91cc7eeb3",[],"Over time, this approach creates a cleaner separation between access and behavior, which is essential for scalable system design.",[],{"_key":8499,"_type":172,"children":8500,"markDefs":8505,"style":292},"a3a834bc27ef",[8501],{"_key":8502,"_type":176,"marks":8503,"text":8504},"ff4dbec68114",[],"How Salesforce Permissions Work Across Security Layers",[],{"_key":8507,"_type":172,"children":8508,"markDefs":8513,"style":180},"3d845ef5633f",[8509],{"_key":8510,"_type":176,"marks":8511,"text":8512},"b3f79dac25d5",[],"Salesforce access control is not a single system. It is a set of layered controls that interact with each other.",[],{"_key":8515,"_type":172,"children":8516,"markDefs":8521,"style":180},"87631c7916e6",[8517],{"_key":8518,"_type":176,"marks":8519,"text":8520},"3c060de70415",[],"Permission sets directly influence object-level access, determining whether users can create, read, edit, or delete records. They also control field-level security, which governs visibility and editability across every interface, including the UI and API.",[],{"_key":8523,"_type":172,"children":8524,"markDefs":8529,"style":180},"8ea412676642",[8525],{"_key":8526,"_type":176,"marks":8527,"text":8528},"6b974a4d4fff",[],"Record-level access operates differently. It is governed by sharing models, role hierarchy, and ownership rules. Permission sets only affect this layer indirectly through broad permissions that bypass restrictions.",[],{"_key":8531,"_type":172,"children":8532,"markDefs":8537,"style":180},"ad6cb434392d",[8533],{"_key":8534,"_type":176,"marks":8535,"text":8536},"a929fb450c9a",[],"This separation is why access issues are rarely straightforward. A user may have permission to edit an object but still be unable to see a specific record. Understanding how these layers interact is what makes troubleshooting effective.",[],{"_key":8539,"_type":172,"children":8540,"markDefs":8545,"style":292},"8593b2f07d85",[8541],{"_key":8542,"_type":176,"marks":8543,"text":8544},"eb88433ddf25",[],"Salesforce API Access Control: Where Your Model Gets Exposed",[],{"_key":8547,"_type":172,"children":8548,"markDefs":8553,"style":180},"72a673eb41e4",[8549],{"_key":8550,"_type":176,"marks":8551,"text":8552},"9d8b71776a44",[],"Salesforce API access control does not introduce a separate permission model. It enforces the same one.",[],{"_key":8555,"_type":172,"children":8556,"markDefs":8561,"style":180},"a95c135944e0",[8557],{"_key":8558,"_type":176,"marks":8559,"text":8560},"4dde78b234bd",[],"That means every design decision made in permission sets is reflected in how integrations, automations, and external systems interact with your data. Field-level security, object permissions, and system access apply consistently regardless of how access is initiated.",[],{"_key":8563,"_type":172,"children":8564,"markDefs":8569,"style":180},"a1780e332580",[8565],{"_key":8566,"_type":176,"marks":8567,"text":8568},"dbfb18f2dd9d",[],"This is where weak access design becomes visible. Over-permissioned users lead to over-permissioned integrations. Inconsistent access leads to unpredictable automation. What looks manageable in the UI can quickly become risky at the API level.",[],{"_key":8571,"_type":172,"children":8572,"markDefs":8577,"style":180},"c954a4ae0a87",[8573],{"_key":8574,"_type":176,"marks":8575,"text":8576},"c63c0da63f2d",[],"API access is not an edge case. It is where your access model is validated.",[],{"_key":8579,"_type":172,"children":8580,"markDefs":8585,"style":292},"54d2d8b1adca",[8581],{"_key":8582,"_type":176,"marks":8583,"text":8584},"0a0a2d46f66f",[],"Why Permission Sets Now Matter for AI and Agent Governance",[],{"_key":8587,"_type":172,"children":8588,"markDefs":8593,"style":180},"a11387d71a55",[8589],{"_key":8590,"_type":176,"marks":8591,"text":8592},"f52cdf66b446",[],"As AI and agents, like Agentforce, become more embedded in Salesforce, access control takes on a new dimension.",[],{"_key":8595,"_type":172,"children":8596,"markDefs":8601,"style":180},"970bd5ab4c46",[8597],{"_key":8598,"_type":176,"marks":8599,"text":8600},"ed905c9100b6",[],"Agents operate within the same permission framework as users, but they do so at scale and with less human oversight. This increases the importance of clearly defined, well-governed access.",[],{"_key":8603,"_type":172,"children":8604,"markDefs":8609,"style":180},"51a51d896a0b",[8605],{"_key":8606,"_type":176,"marks":8607,"text":8608},"ca53a14f4af8",[],"If permissions are inconsistent or overly broad, agents can surface incorrect data, take unintended actions, or expose sensitive information. The quality of your access model directly shapes the reliability and safety of AI-driven workflows.",[],{"_key":8611,"_type":172,"children":8612,"markDefs":8617,"style":180},"d2bbe7913b87",[8613],{"_key":8614,"_type":176,"marks":8615,"text":8616},"d7e4243062ad",[],"Access control is no longer just about users. It is about everything that acts on your system.",[],{"_key":8619,"_type":172,"children":8620,"markDefs":8625,"style":292},"32795bd3b0b6",[8621],{"_key":8622,"_type":176,"marks":8623,"text":8624},"b15d229fafd8",[],"The Metadata Problem Behind Salesforce Permissions",[],{"_key":8627,"_type":172,"children":8628,"markDefs":8637,"style":180},"0da40fe7eb84",[8629,8633],{"_key":8630,"_type":176,"marks":8631,"text":8270},"4d80c0667379",[8632],"c990f047336c",{"_key":8634,"_type":176,"marks":8635,"text":8636},"60dbd900e4a2",[]," are metadata, which means they behave like every other piece of metadata in Salesforce. They evolve, accumulate exceptions, and become harder to understand over time.",[8638],{"_key":8632,"_ref":737,"_type":328,"linkType":738,"slug":8639},{"_type":22,"current":740},{"_key":8641,"_type":172,"children":8642,"markDefs":8647,"style":180},"ccae225cddc2",[8643],{"_key":8644,"_type":176,"marks":8645,"text":8646},"0f9bd8be1509",[],"Without visibility into how permissions are structured and how they change, teams end up relying on trial and error to answer basic questions about access. That slows down troubleshooting, complicates audits, and introduces unnecessary risk.",[],{"_key":8649,"_type":172,"children":8650,"markDefs":8655,"style":180},"4fe769f52589",[8651],{"_key":8652,"_type":176,"marks":8653,"text":8654},"ca67cdf853c9",[],"Clean permission design reduces that friction. It makes access easier to explain, easier to audit, and easier to adapt as the system grows.",[],{"_key":8657,"_type":172,"children":8658,"markDefs":8663,"style":292},"ee7d7baee137",[8659],{"_key":8660,"_type":176,"marks":8661,"text":8662},"5c9bb343828e",[],"Permission Sets Are the Control Plane for Salesforce Access",[],{"_key":8665,"_type":172,"children":8666,"markDefs":8671,"style":180},"8a4d768b6e6e",[8667],{"_key":8668,"_type":176,"marks":8669,"text":8670},"e175b409af1c",[],"Salesforce permission sets have become the control plane for modern access.",[],{"_key":8673,"_type":172,"children":8674,"markDefs":8679,"style":180},"762214735744",[8675],{"_key":8676,"_type":176,"marks":8677,"text":8678},"78df54db0a02",[],"They shape how Salesforce permissions are granted, how custom permissions Salesforce teams implement behave, and how Salesforce API access control functions across integrations and automation.",[],{"_key":8681,"_type":172,"children":8682,"markDefs":8687,"style":180},"f88df475a32b",[8683],{"_key":8684,"_type":176,"marks":8685,"text":8686},"0240dcd1db39",[],"When designed well, they create a system that is understandable, auditable, and scalable. When designed poorly, they create hidden complexity that slows teams down and increases risk.",[],{"_key":8689,"_type":172,"children":8690,"markDefs":8702,"style":180},"25edae62c306",[8691,8695,8699],{"_key":8692,"_type":176,"marks":8693,"text":8694},"75e236744edd",[],"The difference is beyond just technical. It is ",{"_key":8696,"_type":176,"marks":8697,"text":8698},"3a36333d6fdb",[369],"operational",{"_key":8700,"_type":176,"marks":8701,"text":3667},"7374aca6b906",[],[],{"_key":8704,"_type":172,"children":8705,"markDefs":8710,"style":180},"d98a5b2beb64",[8706],{"_key":8707,"_type":176,"marks":8708,"text":8709},"cfdbc3221bac",[],"Clean access models reduce systems drag, improve trust, and make it possible to move fast without breaking what matters.",[],{"_key":8712,"_type":172,"children":8713,"markDefs":8717,"style":292},"6d7ab2084651",[8714],{"_key":8253,"_type":176,"marks":8715,"text":8716},[],"Let’s close the gap",[],{"_key":8719,"_type":172,"children":8720,"markDefs":8724,"style":180},"8fe2e414a72d",[8721],{"_key":8253,"_type":176,"marks":8722,"text":8723},[],"Sweep closes that gap by turning permissions from something you inspect into something you understand. Instead of stitching together profiles, permission sets, and access rules across dozens of screens, teams get a single, explainable view of who has access to what and why, grounded in real metadata. ",[],{"_key":8726,"_type":172,"children":8727,"markDefs":8731,"style":180},"7e20f7953e6c",[8728],{"_key":8253,"_type":176,"marks":8729,"text":8730},[],"That visibility makes it possible to catch permission drift early, answer audit questions instantly, and give both humans and AI agents a governed foundation to operate on. ",[],{"_key":8733,"_type":172,"children":8734,"markDefs":8746,"style":180},"fdf20c4181a0",[8735,8738,8742],{"_key":8253,"_type":176,"marks":8736,"text":8737},[],"When access is explainable, it’s ",{"_key":8739,"_type":176,"marks":8740,"text":8741},"18baca81b5b7",[393],"enforceable",{"_key":8743,"_type":176,"marks":8744,"text":8745},"12a8629f6306",[]," — and that’s what turns Salesforce permissions from a source of risk into a system you can actually trust.",[],{"_key":8748,"_type":172,"children":8749,"markDefs":8758,"style":180},"9c1f932ab02d",[8750,8754],{"_key":8751,"_type":176,"marks":8752,"text":8753},"0ad6891d7109",[],"See the power of Sweep! ",{"_key":8755,"_type":176,"marks":8756,"text":6757},"3e16fa7f1b75",[8757],"1e932cfa2ec1",[8759],{"_key":8757,"_ref":5541,"_type":328,"linkType":738,"slug":8760},{"_type":22,"current":5543},{"_type":17,"description":8762,"shareImage":8763,"title":8765},"Mastering Salesforce permissions is critical for security and compliance. Learn how permission sets, custom permissions, and API access control work together. ",{"_type":40,"asset":8764},{"_ref":8202,"_type":278},"Salesforce Permission Sets & Access Control: Full Guide",{"_type":22,"current":1123},{"_createdAt":8768,"_id":2768,"_rev":8769,"_type":33,"_updatedAt":8770,"author":8771,"category":8787,"featuredImage":8793,"modularContent":8826,"postTitle":8831,"publishDate":8832,"richText":8833,"seo":9410,"slug":9415},"2026-02-16T18:10:49Z","k92ulQmBInvAiRR7RIWjI2","2026-03-23T10:33:53Z",{"authorImage":8772,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":38,"image":8773},{"_type":40,"asset":8774},{"_createdAt":42,"_id":43,"_rev":44,"_type":45,"_updatedAt":46,"altText":19,"assetId":47,"description":19,"extension":48,"metadata":8775,"mimeType":83,"opt":8785,"originalFilename":86,"path":87,"sha1hash":47,"size":88,"title":19,"uploadId":89,"url":90},{"_type":50,"blurHash":51,"dimensions":8776,"hasAlpha":56,"isOpaque":57,"lqip":58,"palette":8777},{"_type":53,"aspectRatio":54,"height":55,"width":55},{"_type":60,"darkMuted":8778,"darkVibrant":8779,"dominant":8780,"lightMuted":8781,"lightVibrant":8782,"muted":8783,"vibrant":8784},{"_type":62,"background":63,"foreground":64,"population":65,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":71,"foreground":72,"population":73,"title":64},{"_type":62,"background":75,"foreground":72,"population":76,"title":72},{"_type":62,"background":78,"foreground":64,"population":79,"title":64},{"_type":62,"background":81,"foreground":64,"population":82,"title":64},{"media":8786},{"tags":19},{"_createdAt":5,"_id":6,"_rev":7,"_system":8788,"_type":11,"_updatedAt":12,"selectedColor":8790,"seo":8791,"slug":8792,"title":24},{"base":8789},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":8794,"image":8795},"The New Perimiter",{"_type":40,"asset":8796},{"_createdAt":8797,"_id":8798,"_rev":8799,"_type":45,"_updatedAt":8797,"assetId":8800,"extension":106,"metadata":8801,"mimeType":132,"originalFilename":8821,"path":8822,"sha1hash":8800,"size":8823,"uploadId":8824,"url":8825},"2026-02-16T18:10:27Z","image-a636c178f8521840cdffd4e4ed98c41d8d54df87-1600x900-png","UUbFotCrvIjcGxZ4G5VuAA","a636c178f8521840cdffd4e4ed98c41d8d54df87",{"_type":50,"blurHash":8802,"dimensions":8803,"exif":8804,"hasAlpha":57,"isOpaque":56,"lqip":8805,"palette":8806},"MISF;Mxv~p%2IVxtWAa~R+%Lt7fRM{t6xu",{"_type":53,"aspectRatio":5981,"height":5982,"width":5983},{"ColorSpace":6806,"PixelXDimension":5983,"PixelYDimension":5982,"_type":6807},"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7EAAAOxAGVKw4bAAAB/klEQVR4nH2S3W7aQBCFef+H6Av0olJvc9OkUYShAQKJbAyENDZxNjj+9/6YnTnRGpAaVe3F0c7uzH47Z7QDInolIg2AD90BspWQUkFKibZtoZTu46Zxser3x1XBGANrLdxdAArAy4CI3gBoIuKyKLF9fMJm84jVao3AD/C42WK7fUIYrrBeb465U5y8JP1j7i4RXFPJAEAPdK9UZYXlMsRsNsd0MoXnjTCb3iHwl5jfLTCZTHF7O8HIG2M8/tVDm7rpOzy5/Ax0FtI0RRzvekVRjF28gxCi7+Z4HiN6jvD8HGG/30Nr828gM6Prur7IaAOtNZqqQpFlSN9zpGmGMi+gpOzn52qtpfMM/wa6TJ9lBhOj0wbpa4L1MsC9H8J/CLHbPkG1LYgZRE50miH9H2iMhdiXCIIQo/EQN94Q3miM0A/OczvWEgFnICEZkKVPls9KM4kfXozvF3NcXd/AG17iZniNxf0Dyqo+4+CcfAIysTj9ITq13it5a/nbRcRfvi758ueC/fmE7xe3vAoDrqvaUZhsx0q23LYNKaUVEb04yxGA6gR1nWr3p6qm0zO/0FfjVK+377rIcl3m77oqct0ZowHSByN1nr1p8ZqoLMuqrut+O+ADgJiZxZ+yRMIYK6Q+iO5gBRH3co6YSDCTsIdOtG0lijwXdV3H1trFBzxNQ0CnFm9vAAAAAElFTkSuQmCC",{"_type":60,"darkMuted":8807,"darkVibrant":8810,"dominant":8812,"lightMuted":8814,"lightVibrant":8816,"muted":8818,"vibrant":8820},{"_type":62,"background":8808,"foreground":64,"population":8809,"title":64},"#343c5d",0.45,{"_type":62,"background":8811,"foreground":64,"population":1737,"title":64},"#1429a8",{"_type":62,"background":8813,"foreground":64,"population":7544,"title":64},"#4765d3",{"_type":62,"background":8815,"foreground":72,"population":125,"title":64},"#a0d0a2",{"_type":62,"background":8817,"foreground":64,"population":125,"title":64},"#6c74f6",{"_type":62,"background":8819,"foreground":64,"population":125,"title":64},"#5fa757",{"_type":62,"background":8813,"foreground":64,"population":7544,"title":64},"Blog Headers.png","images/9eu1m6zu/production/a636c178f8521840cdffd4e4ed98c41d8d54df87-1600x900.png",321718,"1G8Txm9Of03ErPZ67e1tgnd99x8iMrED","https://cdn.sanity.io/images/9eu1m6zu/production/a636c178f8521840cdffd4e4ed98c41d8d54df87-1600x900.png",[8827],{"_key":8828,"_type":275,"cols":276,"filterByCategory":8829,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":8830},"f1408a102d571bcb04fbf25c317064fc",{"_ref":6,"_type":278},"Learn more","The New Perimeter: The Agentic Layer","2026-02-16",[8834,8846,8854,8870,8885,8893,8910,8926,8946,8954,8980,8992,9011,9023,9031,9039,9047,9059,9071,9091,9103,9111,9119,9127,9135,9143,9151,9159,9167,9175,9183,9191,9199,9207,9226,9234,9246,9258,9270,9290,9298,9306,9314,9326,9338,9350,9358,9370,9378,9386,9394,9402],{"_key":8835,"_type":172,"children":8836,"markDefs":8845,"style":180},"dd9cc5618c3c",[8837,8841],{"_key":8838,"_type":176,"marks":8839,"text":8840},"e7880e826efc0",[],"If you run enterprise systems — Salesforce, Snowflake, HubSpot, the whole stack — here's the message that should land in the next board meeting: ",{"_key":8842,"_type":176,"marks":8843,"text":8844},"e7880e826efc1",[369],"The agentic layer for your systems is a new class of organizational asset.",[],{"_key":8847,"_type":172,"children":8848,"markDefs":8853,"style":180},"58427fe23aba",[8849],{"_key":8850,"_type":176,"marks":8851,"text":8852},"3bfdf2c2ac470",[],"Not a feature. Not a project. Not something you buy and deploy and move on.",[],{"_key":8855,"_type":172,"children":8856,"markDefs":8869,"style":180},"591360614710",[8857,8861,8865],{"_key":8858,"_type":176,"marks":8859,"text":8860},"d4e960e258f20",[],"It's ",{"_key":8862,"_type":176,"marks":8863,"text":8864},"2e976d5c7a7b",[393],"yours",{"_key":8866,"_type":176,"marks":8867,"text":8868},"d8f82f8e5843",[],". It will be built over time. You'll always have things to add to it. It's never complete. But it's an asset. One specific to your organization, constructed from your off-the-shelf systems and your bespoke configurations, that compounds in value the longer it runs.",[],{"_key":8871,"_type":172,"children":8872,"markDefs":8884,"style":180},"ecd3ac7793a3",[8873,8877,8881],{"_key":8874,"_type":176,"marks":8875,"text":8876},"7e94560e295e0",[],"And right now, most organizations are making a fundamental mistake: treating agents like a conglomeration of tools instead of ",{"_key":8878,"_type":176,"marks":8879,"text":8880},"1edd1b773dad",[393],"infrastructure",{"_key":8882,"_type":176,"marks":8883,"text":3667},"c00f83e8bff1",[],[],{"_key":8886,"_type":172,"children":8887,"markDefs":8892,"style":292},"7addb9ce218e",[8888],{"_key":8889,"_type":176,"marks":8890,"text":8891},"b35575d898870",[],"The Perimeter Problem, Redux",[],{"_key":8894,"_type":172,"children":8895,"markDefs":8905,"style":180},"94b6d0b9a745",[8896,8901],{"_key":8897,"_type":176,"marks":8898,"text":8900},"6924c413c4d60",[8899],"db93e4dab508","Security professionals",{"_key":8902,"_type":176,"marks":8903,"text":8904},"02de0537e553",[]," understand this instinctively. Twenty years ago, \"the perimeter\" became a foundational organizational asset — not because anyone shipped a \"perimeter\" product, but because enterprises finally recognized that the boundary between inside and outside required continuous investment, continuous attention, continuous building.",[8906],{"_key":8899,"_ref":8907,"_type":328,"linkType":33,"slug":8908},"bd849998-a9ea-4ca1-84e1-701ae83866a9",{"_type":22,"current":8909},"how-cybersecurity-companies-safely-scale-salesforce",{"_key":8911,"_type":172,"children":8912,"markDefs":8925,"style":180},"09fa8546e020",[8913,8917,8921],{"_key":8914,"_type":176,"marks":8915,"text":8916},"e2d86d05dead0",[],"The perimeter wasn't a firewall alone. It was a ",{"_key":8918,"_type":176,"marks":8919,"text":8920},"e2d86d05dead1",[393],"layer ",{"_key":8922,"_type":176,"marks":8923,"text":8924},"e2d86d05dead2",[],"— one that accreted over time through policy, tooling, monitoring, and hard-won institutional knowledge about where the threats actually lived.",[],{"_key":8927,"_type":172,"children":8928,"markDefs":8941,"style":180},"5a291050f713",[8929,8932,8937],{"_key":8930,"_type":176,"marks":8931,"text":2577},"176b9c11bce00",[],{"_key":8933,"_type":176,"marks":8934,"text":8936},"2be6b802503b",[8935],"214496d0e95d","agentic layer",{"_key":8938,"_type":176,"marks":8939,"text":8940},"e9c7a470b165",[]," is the same kind of thing. Except instead of protecting the boundary, it captures how your organization actually works.",[8942],{"_key":8935,"_ref":8943,"_type":328,"linkType":738,"slug":8944},"b7e3cda5-48b3-434d-9572-1d6791d8461b",{"_type":22,"current":8945},"agentic-layer",{"_key":8947,"_type":172,"children":8948,"markDefs":8953,"style":292},"b50c51e2a96a",[8949],{"_key":8950,"_type":176,"marks":8951,"text":8952},"7a925c95391d0",[],"What's Actually Happening When Agents Run",[],{"_key":8955,"_type":172,"children":8956,"markDefs":8977,"style":180},"68f49ec765a0",[8957,8961,8966,8970,8974],{"_key":8958,"_type":176,"marks":8959,"text":8960},"7f54a8ed95370",[],"The industry is ",{"_key":8962,"_type":176,"marks":8963,"text":8965},"9d41a24782fd",[8964],"acd8c5bf4683","abuzz about \"context graphs\"",{"_key":8967,"_type":176,"marks":8968,"text":8969},"6a0fb78321bb",[]," right now — the idea that when agents execute workflows, they generate something valuable that enterprises have never systematically stored: ",{"_key":8971,"_type":176,"marks":8972,"text":8973},"7f54a8ed95371",[369],"decision traces",{"_key":8975,"_type":176,"marks":8976,"text":3667},"7f54a8ed95372",[],[8978],{"_key":8964,"_type":151,"blank":57,"href":8979,"noOpener":57,"noReferrer":57,"url":8979},"https://foundationcapital.com/context-graphs-ais-trillion-dollar-opportunity/",{"_key":8981,"_type":172,"children":8982,"markDefs":8991,"style":180},"e0ab33382ca6",[8983,8987],{"_key":8984,"_type":176,"marks":8985,"text":8986},"d51eeb76f03c0",[],"What inputs were gathered across systems. What policy was evaluated. What exception route was invoked. Who approved. What state was written. And crucially: ",{"_key":8988,"_type":176,"marks":8989,"text":8990},"d51eeb76f03c1",[393],"why it was allowed to happen.",[],{"_key":8993,"_type":172,"children":8994,"markDefs":9008,"style":180},"1769f7f5c92e",[8995,8999,9004],{"_key":8996,"_type":176,"marks":8997,"text":8998},"610ef7637a3c0",[],"Foundation Capital calls this \"AI's trillion-dollar opportunity.\" Deloitte ",{"_key":9000,"_type":176,"marks":9001,"text":9003},"3b465f0f1ab4",[9002],"c5f7deeeaa01","is still warning ",{"_key":9005,"_type":176,"marks":9006,"text":9007},"03a8c779ff9b",[],"that most agentic pilots fail to reach production. Everyone's circling the same insight: the next platform shift isn't adding AI to existing systems of record — it's building systems of record for how decisions get made.",[9009],{"_key":9002,"_type":151,"blank":57,"href":9010,"noOpener":57,"noReferrer":57,"url":9010},"https://www.deloitte.com/us/en/insights/topics/technology-management/tech-trends/2026/agentic-ai-strategy.html",{"_key":9012,"_type":172,"children":9013,"markDefs":9022,"style":180},"bd8f8babb961",[9014,9018],{"_key":9015,"_type":176,"marks":9016,"text":9017},"f7891b9963b30",[],"But here's what gets lost in the VC frameworks: ",{"_key":9019,"_type":176,"marks":9020,"text":9021},"f7891b9963b31",[369],"someone has to build the layer that captures all this.",[],{"_key":9024,"_type":172,"children":9025,"markDefs":9030,"style":180},"e2bec4ecd976",[9026],{"_key":9027,"_type":176,"marks":9028,"text":9029},"e6b80585b9890",[],"It doesn't materialize from model capabilities. It doesn't emerge from API calls. It requires infrastructure — specifically, infrastructure that understands your systems deeply enough to make agent execution meaningful.",[],{"_key":9032,"_type":172,"children":9033,"markDefs":9038,"style":292},"8ea330c91f5f",[9034],{"_key":9035,"_type":176,"marks":9036,"text":9037},"2094f64b32c40",[],"The Asset Framing Changes Everything",[],{"_key":9040,"_type":172,"children":9041,"markDefs":9046,"style":180},"a9b11f6350ae",[9042],{"_key":9043,"_type":176,"marks":9044,"text":9045},"a59000d5168b0",[],"When you treat the agentic layer as an asset, several things shift:",[],{"_key":9048,"_type":172,"children":9049,"markDefs":9058,"style":180},"2980e43894a8",[9050,9054],{"_key":9051,"_type":176,"marks":9052,"text":9053},"4ea28bf6c6fa0",[369],"Ownership becomes clear.",{"_key":9055,"_type":176,"marks":9056,"text":9057},"4ea28bf6c6fa1",[]," This isn't IT's problem or a vendor's deliverable. The CIO, the Head of Systems, the RevOps leader — whoever owns the operational infrastructure — owns this asset. It's as much theirs as the CRM or the data warehouse.",[],{"_key":9060,"_type":172,"children":9061,"markDefs":9070,"style":180},"462b06e3e4f3",[9062,9066],{"_key":9063,"_type":176,"marks":9064,"text":9065},"5b730ac79eb20",[369],"Time horizon extends.",{"_key":9067,"_type":176,"marks":9068,"text":9069},"5b730ac79eb21",[]," Assets appreciate. They require investment. You don't evaluate them on quarterly feature releases — you evaluate them on compounding capability. The question isn't \"did this agent work?\" It's \"is the layer learning?\"",[],{"_key":9072,"_type":172,"children":9073,"markDefs":9090,"style":180},"348b2e3b1f88",[9074,9078,9082,9086],{"_key":9075,"_type":176,"marks":9076,"text":9077},"090c004151950",[369],"The build vs. buy question inverts.",{"_key":9079,"_type":176,"marks":9080,"text":9081},"090c004151951",[]," You can buy tools. You can't buy your organization's decision traces. The layer has to be ",{"_key":9083,"_type":176,"marks":9084,"text":9085},"090c004151952",[393],"built",{"_key":9087,"_type":176,"marks":9088,"text":9089},"090c004151953",[],", even if the components are off-the-shelf — because what makes it valuable is its specificity to you.",[],{"_key":9092,"_type":172,"children":9093,"markDefs":9102,"style":180},"5faccfc0d514",[9094,9098],{"_key":9095,"_type":176,"marks":9096,"text":9097},"a323a0892cd40",[369],"The \"never complete\" nature becomes a feature, not a bug.",{"_key":9099,"_type":176,"marks":9100,"text":9101},"a323a0892cd41",[]," You'll always have new systems to connect, new workflows to capture, new edge cases to handle. That's not scope creep. That's the asset doing its job.",[],{"_key":9104,"_type":172,"children":9105,"markDefs":9110,"style":292},"e8cb6d1a94fa",[9106],{"_key":9107,"_type":176,"marks":9108,"text":9109},"fcbac096d9b20",[],"What This Looks Like in Practice",[],{"_key":9112,"_type":172,"children":9113,"markDefs":9118,"style":180},"aaca56fec674",[9114],{"_key":9115,"_type":176,"marks":9116,"text":9117},"4f7a062eb15b0",[],"Consider the symptoms of an organization ignoring this:",[],{"_key":9120,"_type":172,"children":9121,"level":54,"listItem":309,"markDefs":9126,"style":180},"c472a421df93",[9122],{"_key":9123,"_type":176,"marks":9124,"text":9125},"439d57cc37c50",[],"Agents that work in demos but fail in production because they can't access the full context",[],{"_key":9128,"_type":172,"children":9129,"level":54,"listItem":309,"markDefs":9134,"style":180},"4b7114c86165",[9130],{"_key":9131,"_type":176,"marks":9132,"text":9133},"ff7a78d5e78a0",[],"AI initiatives that restart from scratch every quarter because nothing persisted from the last one",[],{"_key":9136,"_type":172,"children":9137,"level":54,"listItem":309,"markDefs":9142,"style":180},"0f44fb8069d0",[9138],{"_key":9139,"_type":176,"marks":9140,"text":9141},"0a2dd50feaf00",[],"Decision-making that remains opaque even as automation increases",[],{"_key":9144,"_type":172,"children":9145,"level":54,"listItem":309,"markDefs":9150,"style":180},"46b77ae416df",[9146],{"_key":9147,"_type":176,"marks":9148,"text":9149},"7cef417cb0880",[],"Compliance teams who can't audit what the AI actually did",[],{"_key":9152,"_type":172,"children":9153,"markDefs":9158,"style":180},"753ce6eb13df",[9154],{"_key":9155,"_type":176,"marks":9156,"text":9157},"9213b08bb43f0",[],"Now consider the opposite:",[],{"_key":9160,"_type":172,"children":9161,"level":54,"listItem":309,"markDefs":9166,"style":180},"b5418c1b48a5",[9162],{"_key":9163,"_type":176,"marks":9164,"text":9165},"cf7d80bb87350",[],"An agent that proposes a 20% discount — outside policy — but can show the three prior exceptions that established precedent",[],{"_key":9168,"_type":172,"children":9169,"level":54,"listItem":309,"markDefs":9174,"style":180},"27fa5728ba87",[9170],{"_key":9171,"_type":176,"marks":9172,"text":9173},"72b9ddd784280",[],"A system that knows what \"qualified opportunity\" meant in Q2 2024 vs. Q1 2026",[],{"_key":9176,"_type":172,"children":9177,"level":54,"listItem":309,"markDefs":9182,"style":180},"a8e18adfb6f7",[9178],{"_key":9179,"_type":176,"marks":9180,"text":9181},"2cd03afe42d10",[],"New hires who can query how decisions were actually made, not just what data exists",[],{"_key":9184,"_type":172,"children":9185,"level":54,"listItem":309,"markDefs":9190,"style":180},"03aba294b201",[9186],{"_key":9187,"_type":176,"marks":9188,"text":9189},"bdd08632e2bf0",[],"Auditors who can trace any automated action back to its logic",[],{"_key":9192,"_type":172,"children":9193,"markDefs":9198,"style":180},"dd72077ebb51",[9194],{"_key":9195,"_type":176,"marks":9196,"text":9197},"d2a67554b1580",[],"The difference? You guessed it. It's the layer.",[],{"_key":9200,"_type":172,"children":9201,"markDefs":9206,"style":292},"a71b8caf35dd",[9202],{"_key":9203,"_type":176,"marks":9204,"text":9205},"0587dd8c6ae60",[],"The Context Graph Mechanism",[],{"_key":9208,"_type":172,"children":9209,"markDefs":9223,"style":180},"215015774a8a",[9210,9214,9219],{"_key":9211,"_type":176,"marks":9212,"text":9213},"0e437c9e7b580",[],"Here's where the industry discourse gets concrete: the way this layer actually builds up is through what some are calling a \"",{"_key":9215,"_type":176,"marks":9216,"text":9218},"5719353f84b7",[9217],"b834a8bbcaf2","context graph",{"_key":9220,"_type":176,"marks":9221,"text":9222},"b77400730d23",[],"\" — a living record of decision traces stitched across entities and time.",[9224],{"_key":9217,"_ref":6549,"_type":328,"linkType":33,"slug":9225},{"_type":22,"current":6551},{"_key":9227,"_type":172,"children":9228,"markDefs":9233,"style":180},"e960cc896814",[9229],{"_key":9230,"_type":176,"marks":9231,"text":9232},"fd05305184c20",[],"But a context graph doesn't build itself. It requires:",[],{"_key":9235,"_type":172,"children":9236,"level":54,"listItem":945,"markDefs":9245,"style":180},"031bb8e168b4",[9237,9241],{"_key":9238,"_type":176,"marks":9239,"text":9240},"6bc551f99dc60",[369],"Deep system understanding.",{"_key":9242,"_type":176,"marks":9243,"text":9244},"6bc551f99dc61",[]," You can't capture Salesforce decision traces without understanding Salesforce metadata — the fields, the automations, the dependencies, the tribal knowledge encoded in validation rules.",[],{"_key":9247,"_type":172,"children":9248,"level":54,"listItem":945,"markDefs":9257,"style":180},"813d24e2241e",[9249,9253],{"_key":9250,"_type":176,"marks":9251,"text":9252},"b5e330fbb1570",[369],"Temporal awareness.",{"_key":9254,"_type":176,"marks":9255,"text":9256},"b5e330fbb1571",[]," The system needs to know what was true when a decision was made, not just what's true now.",[],{"_key":9259,"_type":172,"children":9260,"level":54,"listItem":945,"markDefs":9269,"style":180},"77da528c96b6",[9261,9265],{"_key":9262,"_type":176,"marks":9263,"text":9264},"d02189e24d930",[369],"Persistent capture.",{"_key":9266,"_type":176,"marks":9267,"text":9268},"d02189e24d931",[]," Every agent run has to leave a trace. Every trace has to connect to the broader graph.",[],{"_key":9271,"_type":172,"children":9272,"level":54,"listItem":945,"markDefs":9289,"style":180},"6fdd12d15843",[9273,9277,9281,9285],{"_key":9274,"_type":176,"marks":9275,"text":9276},"61240128499f0",[369],"Organizational specificity.",{"_key":9278,"_type":176,"marks":9279,"text":9280},"61240128499f1",[]," The graph reflects how ",{"_key":9282,"_type":176,"marks":9283,"text":9284},"61240128499f2",[393],"your",{"_key":9286,"_type":176,"marks":9287,"text":9288},"61240128499f3",[]," organization works — your exceptions, your precedents, your definitions.",[],{"_key":9291,"_type":172,"children":9292,"markDefs":9297,"style":180},"eb411182c798",[9293],{"_key":9294,"_type":176,"marks":9295,"text":9296},"973958ee81040",[],"This is infrastructure work. It's not glamorous. It's not a demo. It's the difference between a toy and an asset.",[],{"_key":9299,"_type":172,"children":9300,"markDefs":9305,"style":292},"80b2b1de8d33",[9301],{"_key":9302,"_type":176,"marks":9303,"text":9304},"e49d7e81d5f70",[],"The Investment Question",[],{"_key":9307,"_type":172,"children":9308,"markDefs":9313,"style":180},"72525b992c21",[9309],{"_key":9310,"_type":176,"marks":9311,"text":9312},"ca5e533efba30",[],"If the agentic layer is an asset, then the investment model follows:",[],{"_key":9315,"_type":172,"children":9316,"level":54,"listItem":309,"markDefs":9325,"style":180},"59e3b1666639",[9317,9321],{"_key":9318,"_type":176,"marks":9319,"text":9320},"757914b8c27b0",[369],"Initial capital outlay:",{"_key":9322,"_type":176,"marks":9323,"text":9324},"757914b8c27b1",[]," Standing up the infrastructure, connecting systems, establishing the baseline",[],{"_key":9327,"_type":172,"children":9328,"level":54,"listItem":309,"markDefs":9337,"style":180},"8b53ce50567e",[9329,9333],{"_key":9330,"_type":176,"marks":9331,"text":9332},"cba38bbb33890",[369],"Ongoing operational expense:",{"_key":9334,"_type":176,"marks":9335,"text":9336},"cba38bbb33891",[]," Monitoring, extending, maintaining",[],{"_key":9339,"_type":172,"children":9340,"level":54,"listItem":309,"markDefs":9349,"style":180},"4c7ed3246b58",[9341,9345],{"_key":9342,"_type":176,"marks":9343,"text":9344},"97b7d69265630",[369],"Compounding returns:",{"_key":9346,"_type":176,"marks":9347,"text":9348},"97b7d69265631",[]," Every workflow captured makes the next one more reliable",[],{"_key":9351,"_type":172,"children":9352,"markDefs":9357,"style":180},"315c9c6837a0",[9353],{"_key":9354,"_type":176,"marks":9355,"text":9356},"0a4fa7e0d07d0",[],"The organizations that recognize this now are building while others are still evaluating point solutions. They're not asking \"which agent should we buy?\" They're asking \"how do we build the layer that makes all agents more effective?\"",[],{"_key":9359,"_type":172,"children":9360,"markDefs":9369,"style":292},"4feb2f79b33c",[9361,9365],{"_key":9362,"_type":176,"marks":9363,"text":9364},"c7354c8507f00",[],"A Different Category of.... ",{"_key":9366,"_type":176,"marks":9367,"text":9368},"fa91bb53dc91",[393],"Thing",[],{"_key":9371,"_type":172,"children":9372,"markDefs":9377,"style":180},"d7148ea43d2d",[9373],{"_key":9374,"_type":176,"marks":9375,"text":9376},"2b3dc27d830b0",[],"The mistake most organizations make is treating each AI initiative as a standalone project. Buy a tool. Deploy it. Measure ROI. Move on.",[],{"_key":9379,"_type":172,"children":9380,"markDefs":9385,"style":180},"ece8336cc0c8",[9381],{"_key":9382,"_type":176,"marks":9383,"text":9384},"434699cee9ce0",[],"That framing misses the asset that's being built — or not built — underneath.",[],{"_key":9387,"_type":172,"children":9388,"markDefs":9393,"style":180},"4a49cd6493c1",[9389],{"_key":9390,"_type":176,"marks":9391,"text":9392},"67e51c5e03ca0",[],"The agentic layer isn't Salesforce AI or Snowflake AI or whatever vendor slaps \"AI\" on their product. It's the infrastructure that sits across all of them, capturing how your organization actually makes decisions, and making that knowledge actionable.",[],{"_key":9395,"_type":172,"children":9396,"markDefs":9401,"style":180},"ddf2270f43f3",[9397],{"_key":9398,"_type":176,"marks":9399,"text":9400},"f644031865260",[],"CIOs and heads of systems: this is yours. Not a vendor's. Not IT's. Yours.",[],{"_key":9403,"_type":172,"children":9404,"markDefs":9409,"style":180},"4bbd9d5d9549",[9405],{"_key":9406,"_type":176,"marks":9407,"text":9408},"8f058942666d0",[],"Build accordingly. ",[],{"_type":17,"description":9411,"shareImage":9412,"title":9414},"Most orgs treat AI agents as tools. The real opportunity? Building an agentic layer — a durable organizational asset that captures how your enterprise actually makes decisions.",{"_type":40,"asset":9413},{"_ref":8798,"_type":278},"The Agentic Layer Is an Asset, Not a Feature | Sweep",{"_type":22,"current":2770},{"_createdAt":9417,"_id":9418,"_rev":9419,"_system":9420,"_type":33,"_updatedAt":9423,"author":9424,"category":9440,"featuredImage":9446,"modularContent":9482,"postSubtitle":9486,"postTitle":9447,"publishDate":9487,"richText":9488,"seo":10045,"slug":10050},"2026-02-06T19:26:36Z","f143a7da-54f5-4182-920b-b2c5af42eba7","nzZ4yidQWUBixWjztcQs8B",{"base":9421},{"id":9418,"rev":9422},"J5j1hv5WW9LqWb2ruri1ec","2026-07-02T18:27:41Z",{"authorImage":9425,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":38,"image":9426},{"_type":40,"asset":9427},{"_createdAt":42,"_id":43,"_rev":44,"_type":45,"_updatedAt":46,"altText":19,"assetId":47,"description":19,"extension":48,"metadata":9428,"mimeType":83,"opt":9438,"originalFilename":86,"path":87,"sha1hash":47,"size":88,"title":19,"uploadId":89,"url":90},{"_type":50,"blurHash":51,"dimensions":9429,"hasAlpha":56,"isOpaque":57,"lqip":58,"palette":9430},{"_type":53,"aspectRatio":54,"height":55,"width":55},{"_type":60,"darkMuted":9431,"darkVibrant":9432,"dominant":9433,"lightMuted":9434,"lightVibrant":9435,"muted":9436,"vibrant":9437},{"_type":62,"background":63,"foreground":64,"population":65,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":71,"foreground":72,"population":73,"title":64},{"_type":62,"background":75,"foreground":72,"population":76,"title":72},{"_type":62,"background":78,"foreground":64,"population":79,"title":64},{"_type":62,"background":81,"foreground":64,"population":82,"title":64},{"media":9439},{"tags":19},{"_createdAt":5,"_id":6,"_rev":7,"_system":9441,"_type":11,"_updatedAt":12,"selectedColor":9443,"seo":9444,"slug":9445,"title":24},{"base":9442},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":9447,"image":9448}," The Hidden Risk in Cybersecurity's GTM Systems",{"_type":40,"asset":9449},{"_createdAt":9450,"_id":9451,"_rev":9452,"_type":45,"_updatedAt":9450,"assetId":9453,"extension":106,"metadata":9454,"mimeType":132,"originalFilename":9477,"path":9478,"sha1hash":9453,"size":9479,"uploadId":9480,"url":9481},"2026-02-06T19:26:19Z","image-bab1cf7fba5f5fd1459bd1b370fdac2201feedc8-1600x900-png","oZtVdTig458mpRHoOSpjRD","bab1cf7fba5f5fd1459bd1b370fdac2201feedc8",{"_type":50,"blurHash":9455,"dimensions":9456,"hasAlpha":57,"isOpaque":56,"lqip":9457,"palette":9458,"thumbHash":9476},"M47B7+MaI~Mx0QrlxwkbIQSR00oQ$]p1~7",{"_type":53,"aspectRatio":5981,"height":5982,"width":5983},"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7EAAAOxAGVKw4bAAACe0lEQVR4nI3S3U/TUBjH8f0Ta3u6ntOuW0db2q3t3t90Ha++oEAIQ4hTNyBEQqJE5MIL+Uv8p4x/gJGA9dIbzo3nZzYNSEyMF9/kufrkSZ4npaS1r0RmXFV0oSoMRKbTFOn/UokBw6yKmWBwNdt4eZFSZfZNVXROM6agGROTMiQLIjPIaTrtXyDTA9jhlvDq+3wm2rmcghli8Kw+I5yCh8ArIip68G0LeSMLmjGgKvothEwgSYOhmLCcZbjVscg5C5yy4mVKTmvTDa2cK5rVCtaXKxhvBBit+1hbLKFeDpE3nWtUnmAyRY1qmMv7qEcD2KUNoZt1bhbiG9Au+GLuThu7gw7ejOo4flHDeNDB/cU+ymEDBrOgyhQsoyNyPQz7DRzOx3jQ3UJU3xJedYf7rVc3oGsXRe9OD2sPl7D5eAHrK/N4uDyPfm8OlagJK+eikLXQqxTxfHMDZyenOB3vYm35CTrxSAStPe7U9v8ES6LTjhHfXUTc+1W3O4cwqKFgFZGzmiiHMQYLXRwNt3FyfIb94QGW+qsIK4+EEw14sft2AtJvqsKmR3GdEjw3hD8bwvcizLoBctkZ6GYFdjRE2BiiW+1iqdPD6v2nWLk3Qqu9jdnyjvDbr3lz7cNlSlVYoirGlaoYP3794u+IcT0b+Y7wmkfCaxwIp7QqiuWBaPbfiPbSmQhah8IOt3645Z2rIH53kSIy+5Ih+vcJSiTK5bR2K0WiXNN8bnmPuVN+xu1oyN3aHg/j99xvH3PT7nPG/CtKve96rvE5JUv0E5HZ+WRTIrFESdO/ImmWEJJPNOonmlZK9Fw7cSqjxPJWk4xqJSStJYrEziWJffwJL5ZM41B0AxUAAAAASUVORK5CYII=",{"_type":60,"darkMuted":9459,"darkVibrant":9462,"dominant":9465,"lightMuted":9466,"lightVibrant":9468,"muted":9471,"vibrant":9474},{"_type":62,"background":9460,"foreground":64,"population":9461,"title":64},"#2c2e45",2.48,{"_type":62,"background":9463,"foreground":64,"population":9464,"title":64},"#10236e",0.49,{"_type":62,"background":9460,"foreground":64,"population":9461,"title":64},{"_type":62,"background":9467,"foreground":72,"population":117,"title":64},"#b7b1b7",{"_type":62,"background":9469,"foreground":72,"population":9470,"title":72},"#f8df55",0.19,{"_type":62,"background":9472,"foreground":64,"population":9473,"title":64},"#4c5fa8",0.89,{"_type":62,"background":9475,"foreground":64,"population":1371,"title":64},"#3174e9","iweGE4APg0aVWYBPe/XiBggIj4dw+Ag=","Blog Headers (1).png","images/9eu1m6zu/production/bab1cf7fba5f5fd1459bd1b370fdac2201feedc8-1600x900.png",402241,"J6YDfjYkUhrO5RNUXeKB7cA5ViaWjRdp","https://cdn.sanity.io/images/9eu1m6zu/production/bab1cf7fba5f5fd1459bd1b370fdac2201feedc8-1600x900.png",[9483],{"_key":9484,"_type":275,"cols":276,"filterByCategory":9485,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":8830},"00df8fe302383238dba514a66a8873ee",{"_ref":6,"_type":278},"Why fast-growing cybersecurity companies are rethinking how they govern Salesforce","2026-02-06",[9489,9497,9509,9517,9525,9533,9552,9560,9568,9576,9595,9603,9621,9629,9637,9645,9664,9672,9680,9688,9696,9704,9712,9720,9728,9736,9744,9752,9760,9768,9776,9784,9792,9800,9819,9826,9834,9842,9850,9858,9866,9874,9882,9890,9898,9906,9925,9933,9941,9949,9957,9965,9973,9981,9989,9997,10005,10013,10021,10029,10037],{"_key":9490,"_type":172,"children":9491,"markDefs":9496,"style":292},"ca2122e6bcb5",[9492],{"_key":9493,"_type":176,"marks":9494,"text":9495},"2ff8a5150de40",[],"Executive Summary",[],{"_key":9498,"_type":172,"children":9499,"markDefs":9508,"style":180},"d81804b2144d",[9500,9504],{"_key":9501,"_type":176,"marks":9502,"text":9503},"38867d0e84220",[393],"Cybersecurity companies the world over sell trust. ",{"_key":9505,"_type":176,"marks":9506,"text":9507},"38867d0e84221",[],"Their entire value proposition hinges on their abilities to protect their customers from operational risk, data exposure, and systemic failure. Yet, beneath the surface of many fast-growing cybersecurity vendors lies an uncomfortable irony: their own Go-to-Market infrastructure often harbors the very risks they help customers mitigate.",[],{"_key":9510,"_type":172,"children":9511,"markDefs":9516,"style":180},"9ce18d8d06c4",[9512],{"_key":9513,"_type":176,"marks":9514,"text":9515},"f99c9bc682dd0",[],"Salesforce, the operational GTM backbone of most B2B revenue organizations, has become simultaneously indispensable and ungovernable. As cybersecurity companies scale, their Salesforce environments accumulate complexity: hundreds of automation rules, thousands of custom fields, dozens of integrations, and layer upon layer of configuration decisions made by teams that have long since moved on. The result is a system that powers critical business processes but operates largely as a black box.",[],{"_key":9518,"_type":172,"children":9519,"markDefs":9524,"style":180},"fb81c40b57bc",[9520],{"_key":9521,"_type":176,"marks":9522,"text":9523},"024056a313690",[],"This piece examines why Salesforce governance has become a strategic imperative for cybersecurity GTM organizations, where blind spots create the most significant operational exposure, and how forward-thinking revenue leaders are deploying system intelligence to transform their CRM from a liability into a competitive advantage.",[],{"_key":9526,"_type":172,"children":9527,"markDefs":9532,"style":920},"c20bf2bcef38",[9528],{"_key":9529,"_type":176,"marks":9530,"text":9531},"89ae7783339a0",[],"Selling Security While Operating Blind",[],{"_key":9534,"_type":172,"children":9535,"markDefs":9549,"style":180},"9fde9b1631d9",[9536,9540,9545],{"_key":9537,"_type":176,"marks":9538,"text":9539},"7b12e8af57680",[],"The global cybersecurity market is ",{"_key":9541,"_type":176,"marks":9542,"text":9544},"5fa594a88a74",[9543],"f00d97d5ab6f","projected to hit $644 billion",{"_key":9546,"_type":176,"marks":9547,"text":9548},"ed980a460fa8",[]," by 2033. This explosive growth has created a generation of cybersecurity vendors scaling at rates that would have been unimaginable a decade ago. Companies like SentinelOne have achieved 70% year-over-year revenue growth, while the broader market expands at compound rates exceeding 12% annually.",[9550],{"_key":9543,"_type":151,"blank":57,"href":9551,"noOpener":57,"noReferrer":57,"url":9551},"https://www.fortunebusinessinsights.com/industry-reports/cyber-security-market-101165",{"_key":9553,"_type":172,"children":9554,"markDefs":9559,"style":180},"8352ff33970d",[9555],{"_key":9556,"_type":176,"marks":9557,"text":9558},"0d2f50242e750",[],"But growth at this pace creates a particular kind of operational debt. Every new sales territory requires new routing rules. Every product launch spawns new fields and picklist values. Every acquisition brings another Salesforce org to integrate. Every quarter, the gap between what leadership thinks happens in Salesforce and what actually happens grows wider.",[],{"_key":9561,"_type":172,"children":9562,"markDefs":9567,"style":180},"83889476cbcd",[9563],{"_key":9564,"_type":176,"marks":9565,"text":9566},"9cfdde80bd720",[],"For cybersecurity companies specifically, this gap carries reputational weight. When a cybersecurity vendor suffers a breach traced to poor internal system governance, the damage extends beyond the immediate incident. It undermines the fundamental trust that makes their customer relationships possible.",[],{"_key":9569,"_type":172,"children":9570,"markDefs":9575,"style":920},"4446ba6dc4d4",[9571],{"_key":9572,"_type":176,"marks":9573,"text":9574},"3a4e7dcabfbe0",[],"Salesforce as Critical Infrastructure",[],{"_key":9577,"_type":172,"children":9578,"markDefs":9592,"style":180},"3fefa294aff6",[9579,9583,9588],{"_key":9580,"_type":176,"marks":9581,"text":9582},"f975d07eb6270",[],"The first step toward ",{"_key":9584,"_type":176,"marks":9585,"text":9587},"8b66693b01ee",[9586],"e0b173080ae7","more robust governance",{"_key":9589,"_type":176,"marks":9590,"text":9591},"bd873de3d9a1",[]," is acknowledging what Salesforce has become. For most B2B cybersecurity companies, Salesforce is not merely a contact database or deal tracker: it is the system of record for customer relationships, the execution layer for go-to-market motions, and increasingly, the data foundation for AI-powered sales and service automation.",[9593],{"_key":9586,"_ref":3743,"_type":328,"linkType":33,"slug":9594},{"_type":22,"current":3745},{"_key":9596,"_type":172,"children":9597,"markDefs":9602,"style":920},"ec13cce19694",[9598],{"_key":9599,"_type":176,"marks":9600,"text":9601},"8d47a1c738a30",[],"The Revenue Nerve Center",[],{"_key":9604,"_type":172,"children":9605,"markDefs":9618,"style":180},"98043fe2ce67",[9606,9610,9615],{"_key":9607,"_type":176,"marks":9608,"text":9609},"156b6d64ae220",[],"Salesforce orchestrates the entire customer lifecycle. Lead routing rules determine which prospects reach which reps. Opportunity stage definitions drive forecasting accuracy. CPQ configurations govern what sellers can quote and at what price. Territory assignments control compensation calculations. Each of these processes runs on Salesforce metadata that most organizations ",{"_key":9611,"_type":176,"marks":9612,"text":9614},"be0990dfd4cd",[9613],"03f6594cd318","cannot fully see or explain",{"_key":9616,"_type":176,"marks":9617,"text":3667},"62b2493e2f9a",[],[9619],{"_key":9613,"_ref":3515,"_type":328,"linkType":33,"slug":9620},{"_type":22,"current":4068},{"_key":9622,"_type":172,"children":9623,"markDefs":9628,"style":920},"97618560fdc9",[9624],{"_key":9625,"_type":176,"marks":9626,"text":9627},"effdc87ec6230",[],"The Integration Hub",[],{"_key":9630,"_type":172,"children":9631,"markDefs":9636,"style":180},"01e5228bae2c",[9632],{"_key":9633,"_type":176,"marks":9634,"text":9635},"115349b2ade60",[],"Modern revenue tech stacks connect dozens of applications through Salesforce. Marketing automation platforms sync lead data. Conversation intelligence tools write meeting summaries. Revenue intelligence platforms pull activity signals. Each integration adds dependencies, creates data flows, and introduces potential failure points that compound with every new tool added to the stack.\n",[],{"_key":9638,"_type":172,"children":9639,"markDefs":9644,"style":920},"b6c273385027",[9640],{"_key":9641,"_type":176,"marks":9642,"text":9643},"ff294013b0db0",[],"The AI Foundation",[],{"_key":9646,"_type":172,"children":9647,"markDefs":9661,"style":180},"ccaab1cac930",[9648,9652,9657],{"_key":9649,"_type":176,"marks":9650,"text":9651},"6ca1190216780",[],"As organizations also rush to ",{"_key":9653,"_type":176,"marks":9654,"text":9656},"23a1edcd5c65",[9655],"0a64372f6494","deploy AI agents",{"_key":9658,"_type":176,"marks":9659,"text":9660},"1fcee3c49d8c",[]," for sales and service automation, Salesforce data quality becomes existential. According to recent research, 48% of IT security leaders worry their data foundation is not set up to get the most out of agentic AI, while 55% lack confidence they have appropriate guardrails for AI agent deployment. For cybersecurity companies building AI-powered products, this concern hits especially close to home. The same data hygiene they advise customers to maintain often eludes their own internal systems.",[9662],{"_key":9655,"_ref":3064,"_type":328,"linkType":738,"slug":9663},{"_type":22,"current":3066},{"_key":9665,"_type":172,"children":9666,"markDefs":9671,"style":292},"296e9b052f0e",[9667],{"_key":9668,"_type":176,"marks":9669,"text":9670},"4f2c1791ffb30",[],"Where Blind Spots Create Risk",[],{"_key":9673,"_type":172,"children":9674,"markDefs":9679,"style":180},"34f18a7b0047",[9675],{"_key":9676,"_type":176,"marks":9677,"text":9678},"0e445a3fe0960",[],"Unlike application security vulnerabilities that trigger alerts or infrastructure issues that cause outages, Salesforce complexity degrades performance gradually until a seemingly minor change cascades into major business disruption.",[],{"_key":9681,"_type":172,"children":9682,"markDefs":9687,"style":920},"bb8701e6c492",[9683],{"_key":9684,"_type":176,"marks":9685,"text":9686},"0d85dde72e4f0",[],"Automation Chaos",[],{"_key":9689,"_type":172,"children":9690,"markDefs":9695,"style":180},"74ee4e6b9d27",[9691],{"_key":9692,"_type":176,"marks":9693,"text":9694},"a59190ccd52c0",[],"The most dangerous blind spots hide in automation layers. Organizations accumulate Process Builders, Flows, Apex triggers, and workflow rules over years of iterative development. These automations frequently target the same objects, creating recursive loops, unpredictable behavior, and debugging sessions where tracking down a single field update can take days. When overlapping automations fire in unexpected sequences, opportunities may route incorrectly, data may corrupt silently, and revenue may leak through gaps nobody realizes exist.",[],{"_key":9697,"_type":172,"children":9698,"markDefs":9703,"style":920},"4c1c2bcabd2b",[9699],{"_key":9700,"_type":176,"marks":9701,"text":9702},"39c99b5f048a0",[],"Configuration Sprawl",[],{"_key":9705,"_type":172,"children":9706,"markDefs":9711,"style":180},"8c7507237281",[9707],{"_key":9708,"_type":176,"marks":9709,"text":9710},"2df0971dc5a50",[],"Fast-growing organizations produce configuration sprawl at alarming rates: duplicate approval processes, nearly identical email templates, and feature bloat where half the solutions in the org sit unused but still clutter user experience and degrade performance. According to McKinsey research, CIOs report that 10 to 20 percent of their technology budgets go toward managing technical debt. In Salesforce environments specifically, this manifests as slower page loads, confused users, and administrative overhead that consumes resources better spent on strategic initiatives.",[],{"_key":9713,"_type":172,"children":9714,"markDefs":9719,"style":920},"42b5ea965f98",[9715],{"_key":9716,"_type":176,"marks":9717,"text":9718},"06ac50cfa2600",[],"Permission Creep",[],{"_key":9721,"_type":172,"children":9722,"markDefs":9727,"style":180},"8b15eb656ad7",[9723],{"_key":9724,"_type":176,"marks":9725,"text":9726},"6b13a90713e50",[],"Security configurations in Salesforce environments often represent the worst kind of technical debt: the kind that can leave organizations vulnerable to attack. Overly complex sharing models and role hierarchies make it difficult to understand and manage data visibility. Permission sets accumulate without review. Users retain access to data and functionality long after their roles change. For cybersecurity companies subject to customer security questionnaires and compliance audits, this exposure creates both operational risk and sales cycle friction.",[],{"_key":9729,"_type":172,"children":9730,"markDefs":9735,"style":920},"694729fa79e0",[9731],{"_key":9732,"_type":176,"marks":9733,"text":9734},"b7a43de180980",[],"Documentation Gaps",[],{"_key":9737,"_type":172,"children":9738,"markDefs":9743,"style":180},"113145d6f17b",[9739],{"_key":9740,"_type":176,"marks":9741,"text":9742},"95ec5c7dabd70",[],"Perhaps most insidiously of all, documentation debt surfaces whenever context is missing. Without clear guidance on why something was built, new developers default to creating redundant components rather than modifying existing ones. Critical knowledge concentrates in a handful of individuals, creating key-person dependencies that stall progress when those team members are unavailable. The institutional knowledge required to safely modify Salesforce erodes with every departure, acquisition, and reorganization.",[],{"_key":9745,"_type":172,"children":9746,"markDefs":9751,"style":292},"5593ba61ad1c",[9747],{"_key":9748,"_type":176,"marks":9749,"text":9750},"26d1e6537f500",[],"Why Manual Governance Breaks at Scale",[],{"_key":9753,"_type":172,"children":9754,"markDefs":9759,"style":180},"026481ec4328",[9755],{"_key":9756,"_type":176,"marks":9757,"text":9758},"a32ce77e36180",[],"Organizations often respond to Salesforce complexity with manual governance processes: spreadsheet-based inventories, periodic audits, change advisory boards, and documentation requirements. These approaches work at a modest scale but also fail systematically as organizations grow.",[],{"_key":9761,"_type":172,"children":9762,"markDefs":9767,"style":920},"4ea5912f7c6b",[9763],{"_key":9764,"_type":176,"marks":9765,"text":9766},"cd750cd263230",[],"The Velocity Problem",[],{"_key":9769,"_type":172,"children":9770,"markDefs":9775,"style":180},"1136634a3901",[9771],{"_key":9772,"_type":176,"marks":9773,"text":9774},"af6e89be23070",[],"Cybersecurity companies operate in markets where speed matters. Product capabilities expand. Competitors move fast. Customer expectations shift faster. When every configuration change requires manual impact analysis, regression testing, and documentation updates, the governance process itself becomes a bottleneck. Teams choose between moving slowly with proper governance or moving fast with fingers crossed. Most choose speed.",[],{"_key":9777,"_type":172,"children":9778,"markDefs":9783,"style":920},"c13eb050b293",[9779],{"_key":9780,"_type":176,"marks":9781,"text":9782},"92ccfd2c1a050",[],"The Knowledge Problem",[],{"_key":9785,"_type":172,"children":9786,"markDefs":9791,"style":180},"32260197c4a6",[9787],{"_key":9788,"_type":176,"marks":9789,"text":9790},"0b3c1ca4b5f60",[],"Manual governance assumes someone understands the full system. But in organizations with thousands of metadata components, dozens of integrations, and years of accumulated configuration decisions, no single person holds complete knowledge. The complexity exceeds human comprehension. Even experienced administrators find themselves uncertain about the downstream effects of seemingly simple changes.",[],{"_key":9793,"_type":172,"children":9794,"markDefs":9799,"style":920},"dff390e46ec1",[9795],{"_key":9796,"_type":176,"marks":9797,"text":9798},"7d7ddd8436f60",[],"The Consistency Problem",[],{"_key":9801,"_type":172,"children":9802,"markDefs":9816,"style":180},"9f93aec2c143",[9803,9807,9812],{"_key":9804,"_type":176,"marks":9805,"text":9806},"d6607f9d41c40",[],"Manual processes produce inconsistent results. ",{"_key":9808,"_type":176,"marks":9809,"text":9811},"7712f3190a99",[9810],"25fc66b63459","Documentation standards",{"_key":9813,"_type":176,"marks":9814,"text":9815},"614945a29fd1",[]," drift. Impact assessments vary by analyst. Institutional memory fades as team members turn over. The governance quality depends on whoever happens to perform it, creating variability that undermines the entire effort.",[9817],{"_key":9810,"_ref":6128,"_type":328,"linkType":738,"slug":9818},{"_type":22,"current":6130},{"_key":9820,"_type":172,"children":9821,"markDefs":9825,"style":180},"4fa39136aff8",[9822],{"_key":9823,"_type":176,"marks":9824,"text":187},"d19c3a7c0eda0",[],[],{"_key":9827,"_type":172,"children":9828,"markDefs":9833,"style":292},"19a34c95a497",[9829],{"_key":9830,"_type":176,"marks":9831,"text":9832},"63ab988137cb0",[],"Intelligent Governance: Sweep’s Approach",[],{"_key":9835,"_type":172,"children":9836,"markDefs":9841,"style":180},"807f39ea9ecc",[9837],{"_key":9838,"_type":176,"marks":9839,"text":9840},"f5d87a27d2a00",[],"Forward-thinking cybersecurity revenue organizations are moving beyond manual governance toward platform-based approaches that make Salesforce complexity visible, understandable, and manageable. Sweep provides the system intelligence layer that transforms Salesforce from a black box into a transparent, governable asset.",[],{"_key":9843,"_type":172,"children":9844,"markDefs":9849,"style":292},"7e15a0bcb79f",[9845],{"_key":9846,"_type":176,"marks":9847,"text":9848},"0866f77bfa5d0",[],"System-Wide Visibility",[],{"_key":9851,"_type":172,"children":9852,"markDefs":9857,"style":180},"cbe427725618",[9853],{"_key":9854,"_type":176,"marks":9855,"text":9856},"c073065143090",[],"Sweep automatically discovers and maps your complete Salesforce environment, providing comprehensive visibility into every object, field, automation, and integration. This metadata intelligence layer creates an always-current inventory that eliminates the need for manual documentation while surfacing the relationships between components that manual processes miss.",[],{"_key":9859,"_type":172,"children":9860,"markDefs":9865,"style":180},"80b1b48558f9",[9861],{"_key":9862,"_type":176,"marks":9863,"text":9864},"ac56e60798ef0",[],"With Sweep, revenue operations leaders can answer questions that previously required weeks of investigation: Which automations affect this field? What integrations depend on this object? Who has access to this data? How did this configuration change over time?",[],{"_key":9867,"_type":172,"children":9868,"markDefs":9873,"style":180},"0362c7784478",[9869],{"_key":9870,"_type":176,"marks":9871,"text":9872},"351cb8f498ed0",[],"The platform transforms tribal knowledge into institutional knowledge accessible to anyone who needs it.",[],{"_key":9875,"_type":172,"children":9876,"markDefs":9881,"style":292},"2ede0b29efa5",[9877],{"_key":9878,"_type":176,"marks":9879,"text":9880},"237f569ce7d30",[],"Change Impact Analysis",[],{"_key":9883,"_type":172,"children":9884,"markDefs":9889,"style":180},"51aa4c06a540",[9885],{"_key":9886,"_type":176,"marks":9887,"text":9888},"23ed14c3f2280",[],"Every Salesforce change carries potential downstream consequences. Sweep provides impact analysis that shows exactly what will be affected before changes are made. When you modify a field, Sweep identifies every report, automation, validation rule, and integration that references it. When you update a workflow, Sweep maps the cascade of effects through dependent processes.",[],{"_key":9891,"_type":172,"children":9892,"markDefs":9897,"style":180},"91a4819ca06d",[9893],{"_key":9894,"_type":176,"marks":9895,"text":9896},"995cbcb8f0240",[],"This proactive visibility eliminates the guesswork that makes Salesforce changes risky. Teams can move faster because they understand consequences clearly. Regression testing becomes targeted rather than comprehensive. The time from requirement to deployment compresses while the quality of changes improves.",[],{"_key":9899,"_type":172,"children":9900,"markDefs":9905,"style":292},"0255ad8055c4",[9901],{"_key":9902,"_type":176,"marks":9903,"text":9904},"0db473e4f1b90",[],"Safe Automation",[],{"_key":9907,"_type":172,"children":9908,"markDefs":9922,"style":180},"ec7ce467c307",[9909,9913,9918],{"_key":9910,"_type":176,"marks":9911,"text":9912},"d8b8f84b368f0",[],"Sweep enables ",{"_key":9914,"_type":176,"marks":9915,"text":9917},"5f9fb1dd7bf4",[9916],"b4d197ff5c84","automation governance that scales",{"_key":9919,"_type":176,"marks":9920,"text":9921},"d1d46e18a9d8",[]," with organizational complexity. Rather than hoping automations do not conflict, teams can see the complete automation landscape and design new processes with full awareness of existing logic. The platform identifies redundant automations, flags potential conflicts, and ensures new automation integrates cleanly with established patterns.",[9923],{"_key":9916,"_ref":8907,"_type":328,"linkType":33,"slug":9924},{"_type":22,"current":8909},{"_key":9926,"_type":172,"children":9927,"markDefs":9932,"style":180},"5c9466ec7f65",[9928],{"_key":9929,"_type":176,"marks":9930,"text":9931},"c4aeefcc65350",[],"For cybersecurity companies deploying AI agents that depend on Salesforce data and processes, this automation visibility is essential. Agents inherit the quality and consistency of the systems they operate within. Organizations cannot build reliable AI on unreliable foundations.",[],{"_key":9934,"_type":172,"children":9935,"markDefs":9940,"style":292},"b3696dfc38eb",[9936],{"_key":9937,"_type":176,"marks":9938,"text":9939},"0bd50748ffe30",[],"The Business Case for Salesforce Governance",[],{"_key":9942,"_type":172,"children":9943,"markDefs":9948,"style":180},"6ae3e5aee7bf",[9944],{"_key":9945,"_type":176,"marks":9946,"text":9947},"9f2bb1ed89bb0",[],"Salesforce governance delivers measurable returns across multiple dimensions of business performance.",[],{"_key":9950,"_type":172,"children":9951,"markDefs":9956,"style":920},"06886542f959",[9952],{"_key":9953,"_type":176,"marks":9954,"text":9955},"c4ff7969378c0",[],"Reduced Operational Risk",[],{"_key":9958,"_type":172,"children":9959,"markDefs":9964,"style":180},"d1756acd0d6f",[9960],{"_key":9961,"_type":176,"marks":9962,"text":9963},"49e042e7066d0",[],"Configuration errors and automation failures create real business costs: missed leads, incorrect forecasts, compliance violations, and revenue leakage. Systematic visibility into Salesforce operations reduces the frequency and severity of these incidents while accelerating resolution when issues occur.",[],{"_key":9966,"_type":172,"children":9967,"markDefs":9972,"style":920},"96e87ea9ce7b",[9968],{"_key":9969,"_type":176,"marks":9970,"text":9971},"d9641b9c66450",[],"Accelerated Change Velocity",[],{"_key":9974,"_type":172,"children":9975,"markDefs":9980,"style":180},"91a1d5f2c10c",[9976],{"_key":9977,"_type":176,"marks":9978,"text":9979},"914e22679eac0",[],"When teams understand change impact clearly, they can implement changes faster with less risk. The administrative overhead that slows Salesforce evolution diminishes. Organizations can respond to market opportunities and competitive pressures without sacrificing stability.",[],{"_key":9982,"_type":172,"children":9983,"markDefs":9988,"style":920},"92187fed4680",[9984],{"_key":9985,"_type":176,"marks":9986,"text":9987},"0274b093866b0",[],"AI Readiness",[],{"_key":9990,"_type":172,"children":9991,"markDefs":9996,"style":180},"a3db93057cb9",[9992],{"_key":9993,"_type":176,"marks":9994,"text":9995},"277785e5fdaa0",[],"The organizations best positioned to benefit from AI-powered GTM tools are those with clean, well-documented, consistently governed Salesforce environments. Sweep creates the foundation that makes AI deployment successful rather than problematic.",[],{"_key":9998,"_type":172,"children":9999,"markDefs":10004,"style":920},"ff6e0958c7bf",[10000],{"_key":10001,"_type":176,"marks":10002,"text":10003},"b5085f8166230",[],"Competitive Differentiation",[],{"_key":10006,"_type":172,"children":10007,"markDefs":10012,"style":180},"e8936ddaa8b4",[10008],{"_key":10009,"_type":176,"marks":10010,"text":10011},"b54a90bcf6310",[],"For cybersecurity companies, demonstrating internal operational excellence reinforces external market positioning. Organizations that govern their own systems rigorously can speak with greater authority about governance to their customers.",[],{"_key":10014,"_type":172,"children":10015,"markDefs":10020,"style":292},"3dc5c20b0cc3",[10016],{"_key":10017,"_type":176,"marks":10018,"text":10019},"af5c0c1feffb0",[],"Conclusion: From Liability to AI-powered Advantage",[],{"_key":10022,"_type":172,"children":10023,"markDefs":10028,"style":180},"0083b94299d5",[10024],{"_key":10025,"_type":176,"marks":10026,"text":10027},"a372762fa5450",[],"Salesforce complexity is not going away. As organizations grow, integrate more tools, deploy more automation, and pursue AI-powered transformation, the demands on Salesforce governance will only increase. The question is not whether to invest in governance but how to do so effectively.",[],{"_key":10030,"_type":172,"children":10031,"markDefs":10036,"style":180},"bd9c8314b677",[10032],{"_key":10033,"_type":176,"marks":10034,"text":10035},"631cc5b12ff60",[],"Manual approaches have reached their limits. Spreadsheet inventories cannot keep pace with change velocity. Periodic audits cannot provide continuous visibility. Human analysts cannot comprehend system complexity at scale. The future of Salesforce governance is platform-based, automated, and intelligent.",[],{"_key":10038,"_type":172,"children":10039,"markDefs":10044,"style":180},"bde5397e3a36",[10040],{"_key":10041,"_type":176,"marks":10042,"text":10043},"26bdb3ca7f400",[],"Sweep provides the system intelligence that transforms how organizations understand and manage their Salesforce environments. For cybersecurity companies committed to operational excellence, Sweep offers the visibility, impact analysis, and automation governance capabilities required to turn Salesforce from a hidden risk into a strategic asset.\n",[],{"_type":17,"description":10046,"shareImage":10047,"title":10049},"Fast-growing cybersecurity vendors face hidden risk inside Salesforce. This guide explains where governance breaks down, why manual controls fail at scale, and how intelligent system visibility enables safe AI-powered growth.",{"_type":40,"asset":10048},{"_ref":9451,"_type":278},"Why Cybersecurity Companies Need Salesforce Governance Before AI",{"_type":22,"current":10051},"the-hidden-risk-in-cybersecurity-s-gtm-systems",{"_createdAt":10053,"_id":8907,"_rev":10054,"_type":33,"_updatedAt":10055,"author":10056,"category":10072,"featuredImage":10078,"modularContent":10114,"postTitle":10079,"publishDate":10117,"richText":10118,"seo":10532,"slug":10537},"2026-02-04T18:20:44Z","1j2P1LzCZw1VBHySYLlw7T","2026-07-02T18:29:20Z",{"authorImage":10057,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":38,"image":10058},{"_type":40,"asset":10059},{"_createdAt":42,"_id":43,"_rev":44,"_type":45,"_updatedAt":46,"altText":19,"assetId":47,"description":19,"extension":48,"metadata":10060,"mimeType":83,"opt":10070,"originalFilename":86,"path":87,"sha1hash":47,"size":88,"title":19,"uploadId":89,"url":90},{"_type":50,"blurHash":51,"dimensions":10061,"hasAlpha":56,"isOpaque":57,"lqip":58,"palette":10062},{"_type":53,"aspectRatio":54,"height":55,"width":55},{"_type":60,"darkMuted":10063,"darkVibrant":10064,"dominant":10065,"lightMuted":10066,"lightVibrant":10067,"muted":10068,"vibrant":10069},{"_type":62,"background":63,"foreground":64,"population":65,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":67,"foreground":64,"population":68,"title":64},{"_type":62,"background":71,"foreground":72,"population":73,"title":64},{"_type":62,"background":75,"foreground":72,"population":76,"title":72},{"_type":62,"background":78,"foreground":64,"population":79,"title":64},{"_type":62,"background":81,"foreground":64,"population":82,"title":64},{"media":10071},{"tags":19},{"_createdAt":5,"_id":6,"_rev":7,"_system":10073,"_type":11,"_updatedAt":12,"selectedColor":10075,"seo":10076,"slug":10077,"title":24},{"base":10074},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":10079,"image":10080},"How Cybersecurity Companies Safely Scale Salesforce",{"_type":40,"asset":10081},{"_createdAt":10082,"_id":10083,"_rev":10084,"_type":45,"_updatedAt":10082,"assetId":10085,"extension":106,"metadata":10086,"mimeType":132,"originalFilename":9477,"path":10110,"sha1hash":10085,"size":10111,"uploadId":10112,"url":10113},"2026-02-04T19:22:06Z","image-5bec55f9d89f7f2070d92a9a8e0d951c302aac80-1600x900-png","zauLsYIXJFOxrJAMF5FFGs","5bec55f9d89f7f2070d92a9a8e0d951c302aac80",{"_type":50,"blurHash":10087,"dimensions":10088,"hasAlpha":57,"isOpaque":56,"lqip":10089,"palette":10090,"thumbHash":10109},"MRRp8,NGbce--;?H%Mt7RiM{~qoJWAxuM{",{"_type":53,"aspectRatio":5981,"height":5982,"width":5983},"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7EAAAOxAGVKw4bAAACHElEQVR4nI2Sy2sTURTG8++5Ffeu6qLSfaHqpqtiheJjoWgFXQhClWKDtk0mD2oqpebdzkxJ08SaSSZ0OmQmc3Pncc4nk7G0UMFe+MHlcPjd74ObIqIBEUkAjBseZp5ydQRgAsBIRRENAUyFF4sJVwWXkn8BgONQROiniK4Lr6aICUMfwcRCMO7Cd9rw3RME3gCB9OD7PoIg4CiKYkciDIJQjkYe27YLKf3LOox4GbZlYnCyg776HoPDNzC1dxi2t2AaLQwGJizLYillIowrO66Q9WaHd0pNHLdP4QkB+pvOdcdoHWmo/EijXHiNZmkV2v4HHOyn0ajuoV5v4rjV5tHISYRhGA17hiXXN0r84tUavmzk0Ol0IYRAGEY4P7dR/lmBktmGkvmGYn4bu98LKOYVZDNZ5JQ8KuUqn51ZiVBKOdzdq8nF5ec8N/8AS0+fYDO7jlZbheM6GI0cNBsHyOeLKBR2kFMKUJQ8spkctja3p/datc62bUsi6qfcsTv89HVN3pu/y3fmbmFm4TYWn83i89ZbnPbjpBMYRh+6pkPXdWiqBlXVoGka1EMVun6EXs9gIUSS0BOeWdzLTJZXH9HCyiw/fDzDSyv3+WP6JXeNNodhyFL67HneFCHENXzfJyK6+IfhqWUPndYvbdLUK7JW3ZWNckl2upoce25cI375f8QyB0A3BeAAwG9mNpkSKCKTmMzp7IbEDgCNP6hYKVEpx5LxAAAAAElFTkSuQmCC",{"_type":60,"darkMuted":10091,"darkVibrant":10094,"dominant":10097,"lightMuted":10100,"lightVibrant":10103,"muted":10106,"vibrant":10108},{"_type":62,"background":10092,"foreground":64,"population":10093,"title":64},"#353a59",0.74,{"_type":62,"background":10095,"foreground":64,"population":10096,"title":64},"#091f0a",0.24,{"_type":62,"background":10098,"foreground":72,"population":10099,"title":64},"#d0bd49",1.95,{"_type":62,"background":10101,"foreground":72,"population":10102,"title":64},"#babcc2",0.71,{"_type":62,"background":10104,"foreground":72,"population":10105,"title":72},"#e2d58f",0.55,{"_type":62,"background":10107,"foreground":64,"population":4123,"title":64},"#6b9546",{"_type":62,"background":10098,"foreground":72,"population":10099,"title":64},"OfiJA4APhbaraH8GKATSeggIj4dw+Ag=","images/9eu1m6zu/production/5bec55f9d89f7f2070d92a9a8e0d951c302aac80-1600x900.png",420096,"CZgQBLabBToJAb99U007dpnHaEvNlXIB","https://cdn.sanity.io/images/9eu1m6zu/production/5bec55f9d89f7f2070d92a9a8e0d951c302aac80-1600x900.png",[10115],{"_key":10116,"_type":275,"cols":276,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":279},"d7016ad219f0c024b72c053c7f959b5f","2026-02-04",[10119,10127,10135,10151,10158,10166,10174,10182,10190,10198,10206,10220,10228,10236,10244,10265,10277,10285,10305,10313,10321,10329,10355,10363,10371,10390,10398,10406,10422,10430,10438,10456,10464,10472,10480,10488,10496,10504,10524],{"_key":10120,"_type":172,"children":10121,"markDefs":10126,"style":180},"c53d7b96e9b9",[10122],{"_key":10123,"_type":176,"marks":10124,"text":10125},"64abf7912bc80",[],"Cybersecurity companies live in a permanent state of tension: move fast, but never break trust. That mindset shapes everything from product decisions to internal systems.",[],{"_key":10128,"_type":172,"children":10129,"markDefs":10134,"style":180},"796e47bd4060",[10130],{"_key":10131,"_type":176,"marks":10132,"text":10133},"d6e51f1989500",[],"And yet, as these companies scale, Salesforce almost always becomes the bottleneck.",[],{"_key":10136,"_type":172,"children":10137,"markDefs":10150,"style":180},"33040b000954",[10138,10142,10146],{"_key":10139,"_type":176,"marks":10140,"text":10141},"1e8388554f7e0",[],"Not because Salesforce itself can’t scale. Because the system ",{"_key":10143,"_type":176,"marks":10144,"text":10145},"1e8388554f7e1",[393],"around",{"_key":10147,"_type":176,"marks":10148,"text":10149},"1e8388554f7e2",[]," it wasn’t designed to.",[],{"_key":10152,"_type":172,"children":10153,"markDefs":10157,"style":292},"8ff63d227d14",[10154],{"_key":10155,"_type":176,"marks":10156,"text":290},"5fddb87c35d00",[],[],{"_key":10159,"_type":172,"children":10160,"level":54,"listItem":309,"markDefs":10165,"style":180},"92c505577429",[10161],{"_key":10162,"_type":176,"marks":10163,"text":10164},"b7969d2efe620",[],"Cybersecurity companies slow down because metadata becomes invisible, unmanaged, and fragile.",[],{"_key":10167,"_type":172,"children":10168,"level":54,"listItem":309,"markDefs":10173,"style":180},"3b794d1c2b31",[10169],{"_key":10170,"_type":176,"marks":10171,"text":10172},"5602d1b1d4ec0",[],"“Safe scale” means governed speed, not frozen systems.",[],{"_key":10175,"_type":172,"children":10176,"level":54,"listItem":309,"markDefs":10181,"style":180},"b71d65344e4e",[10177],{"_key":10178,"_type":176,"marks":10179,"text":10180},"3525e6d9491e0",[],"Metadata clarity is the difference between confident change and operational paralysis.",[],{"_key":10183,"_type":172,"children":10184,"markDefs":10189,"style":292},"4af44d555040",[10185],{"_key":10186,"_type":176,"marks":10187,"text":10188},"03ab8fab81bb0",[],"Why Salesforce Slows Down in Security-First Organizations",[],{"_key":10191,"_type":172,"children":10192,"markDefs":10197,"style":180},"88bffea2873d",[10193],{"_key":10194,"_type":176,"marks":10195,"text":10196},"0ea155d73c9c0",[],"Security organizations are built to reduce risk. That instinct is healthy — until it leaks into how their systems evolve.",[],{"_key":10199,"_type":172,"children":10200,"markDefs":10205,"style":180},"f4be39f36895",[10201],{"_key":10202,"_type":176,"marks":10203,"text":10204},"5670460cf8d30",[],"As cybersecurity companies grow, Salesforce accumulates what you might call \"scar tissue\": custom fields get added for one-off deals; flows are built under deadline pressure, then never revisited; validation rules appear during audits and linger long after their original purpose has faded; routing logic gets patched, stacked, and worked around rather than redesigned.",[],{"_key":10207,"_type":172,"children":10208,"markDefs":10219,"style":180},"cf31f61eb2e0",[10209,10213,10216],{"_key":10210,"_type":176,"marks":10211,"text":10212},"6bd64451c0ed0",[],"Over time, the system still functions — but nobody fully understands ",{"_key":10214,"_type":176,"marks":10215,"text":664},"6bd64451c0ed1",[393],{"_key":10217,"_type":176,"marks":10218,"text":3667},"6bd64451c0ed2",[],[],{"_key":10221,"_type":172,"children":10222,"markDefs":10227,"style":180},"b8584dd40df8",[10223],{"_key":10224,"_type":176,"marks":10225,"text":10226},"9fbcc7e0f1740",[],"Eventually, every proposed change triggers the same reaction:\n“Let’s not touch that. It might break something.”",[],{"_key":10229,"_type":172,"children":10230,"markDefs":10235,"style":180},"1fe0bcbf270f",[10231],{"_key":10232,"_type":176,"marks":10233,"text":10234},"3240c65e22c60",[],"That response gets framed as governance. In reality, it’s fear. And fear is heavy and slow.",[],{"_key":10237,"_type":172,"children":10238,"markDefs":10243,"style":292},"e8aa2c51324c",[10239],{"_key":10240,"_type":176,"marks":10241,"text":10242},"362ce6d67db70",[],"The Real Bottleneck: Metadata Debt",[],{"_key":10245,"_type":172,"children":10246,"markDefs":10260,"style":180},"7bd52ddeeaf6",[10247,10251,10256],{"_key":10248,"_type":176,"marks":10249,"text":10250},"1cc6742dc4ac0",[],"Most teams think ",{"_key":10252,"_type":176,"marks":10253,"text":10255},"eba296bf14c0",[10254],"c25f0da6981f","technical debt",{"_key":10257,"_type":176,"marks":10258,"text":10259},"ebffd4974a74",[]," lives in code. For go-to-market teams, that’s rarely true.",[10261],{"_key":10254,"_ref":10262,"_type":328,"linkType":33,"slug":10263},"b5b1eade-19f7-46af-9ed2-1ecb627165bb",{"_type":22,"current":10264},"7-metrics-that-reveal-your-true-salesforce-technical-debt",{"_key":10266,"_type":172,"children":10267,"markDefs":10276,"style":180},"dc35b866219d",[10268,10272],{"_key":10269,"_type":176,"marks":10270,"text":10271},"7b2b2edc30ed0",[],"The real drag comes from ",{"_key":10273,"_type":176,"marks":10274,"text":10275},"0fd7386fc933",[369],"metadata debt.",[],{"_key":10278,"_type":172,"children":10279,"markDefs":10284,"style":180},"a0fa6f16c883",[10280],{"_key":10281,"_type":176,"marks":10282,"text":10283},"bace2213b3ef0",[],"Metadata is the hidden logic of Salesforce. It defines what fields actually mean, which automations fire when, how objects depend on one another, and why certain rules exist at all. When that logic isn’t visible or documented, every change becomes a gamble.",[],{"_key":10286,"_type":172,"children":10287,"markDefs":10300,"style":180},"6fd825c9ed51",[10288,10292,10297],{"_key":10289,"_type":176,"marks":10290,"text":10291},"9cb9711808290",[],"Each quick fix adds interest. Each undocumented dependency expands the ",{"_key":10293,"_type":176,"marks":10294,"text":10296},"1a1356ae7c01",[10295],"4853f4fd9196","blast radius",{"_key":10298,"_type":176,"marks":10299,"text":3667},"2b5febf6119d",[],[10301],{"_key":10295,"_ref":10302,"_type":328,"linkType":33,"slug":10303},"f248d134-1fa1-498f-9554-9fa270d55d16",{"_type":22,"current":10304},"what-is-blast-radius-in-salesforce",{"_key":10306,"_type":172,"children":10307,"markDefs":10312,"style":180},"0ab8a3c41c00",[10308],{"_key":10309,"_type":176,"marks":10310,"text":10311},"857abba97838",[],"Eventually, speed collapses under its own weight.",[],{"_key":10314,"_type":172,"children":10315,"markDefs":10320,"style":180},"4eac5815cc1b",[10316],{"_key":10317,"_type":176,"marks":10318,"text":10319},"3b7579adcbc10",[],"This is systems drag. The invisible force that makes even small changes feel dangerous.",[],{"_key":10322,"_type":172,"children":10323,"markDefs":10328,"style":292},"586b64c8311a",[10324],{"_key":10325,"_type":176,"marks":10326,"text":10327},"199d992c7c430",[],"What “Safe Scale” Actually Means in Cybersecurity",[],{"_key":10330,"_type":172,"children":10331,"markDefs":10352,"style":180},"8fe2e4d11afc",[10332,10336,10340,10345,10349],{"_key":10333,"_type":176,"marks":10334,"text":10335},"dc0fde56d73d0",[],"In cybersecurity, scaling safely doesn’t mean slowing down. It means being able to move ",{"_key":10337,"_type":176,"marks":10338,"text":10339},"dc0fde56d73d1",[393],"with confidence that all ",{"_key":10341,"_type":176,"marks":10342,"text":10344},"062bcd6b7d35",[393,10343],"4369a48f4637","hidden risk in your systems",{"_key":10346,"_type":176,"marks":10347,"text":10348},"be5ab8074dbb",[393]," has been attended to",{"_key":10350,"_type":176,"marks":10351,"text":3667},"dc0fde56d73d2",[],[10353],{"_key":10343,"_ref":9418,"_type":328,"linkType":33,"slug":10354},{"_type":22,"current":10051},{"_key":10356,"_type":172,"children":10357,"markDefs":10362,"style":180},"861ce5ab9295",[10358],{"_key":10359,"_type":176,"marks":10360,"text":10361},"098ceb7f94b60",[],"At a minimum, teams need to answer three questions before making a change: What will this affect? Who relies on it downstream? And how do we roll it back if needed?",[],{"_key":10364,"_type":172,"children":10365,"markDefs":10370,"style":180},"c3077c352f27",[10366],{"_key":10367,"_type":176,"marks":10368,"text":10369},"7ecaa52f906d0",[],"If those answers aren’t obvious, the system is basically opaque.",[],{"_key":10372,"_type":172,"children":10373,"markDefs":10387,"style":180},"9568998bfd35",[10374,10378,10383],{"_key":10375,"_type":176,"marks":10376,"text":10377},"943142380aa30",[],"True safe scale is predictable, ",{"_key":10379,"_type":176,"marks":10380,"text":10382},"9706cbc023cc",[10381],"75c3cc2c39c1","auditable",{"_key":10384,"_type":176,"marks":10385,"text":10386},"0c61209773be",[],", and reversible. Without visibility into metadata, none of those qualities exist. Teams become cautious because they’re operating totally in the dark.",[10388],{"_key":10381,"_ref":3515,"_type":328,"linkType":33,"slug":10389},{"_type":22,"current":4068},{"_key":10391,"_type":172,"children":10392,"markDefs":10397,"style":292},"832cf00030aa",[10393],{"_key":10394,"_type":176,"marks":10395,"text":10396},"599639689e490",[],"How High-Growth Security Teams Reduce Systems Drag",[],{"_key":10399,"_type":172,"children":10400,"markDefs":10405,"style":180},"2d694771bb82",[10401],{"_key":10402,"_type":176,"marks":10403,"text":10404},"16f10e4efecf0",[],"The fastest security companies don’t freeze their Salesforce orgs. They invest in clarity.",[],{"_key":10407,"_type":172,"children":10408,"markDefs":10421,"style":180},"3fffa065a7a7",[10409,10413,10417],{"_key":10410,"_type":176,"marks":10411,"text":10412},"73694625bb7a0",[],"That clarity comes from understanding how the system actually works, not how people ",{"_key":10414,"_type":176,"marks":10415,"text":10416},"73694625bb7a1",[393],"think",{"_key":10418,"_type":176,"marks":10419,"text":10420},"73694625bb7a2",[]," it works. Dependencies are mapped across objects, fields, and automations. System logic is visible to both admins and operators, not locked away in tribal knowledge. Drift is detected early, before it breaks routing, reporting, or compliance workflows.",[],{"_key":10423,"_type":172,"children":10424,"markDefs":10429,"style":180},"5a6ae4bdfeae",[10425],{"_key":10426,"_type":176,"marks":10427,"text":10428},"71f89d759dd40",[],"When Salesforce is treated like a living system instead of a museum, change stops being scary. It becomes routine.",[],{"_key":10431,"_type":172,"children":10432,"markDefs":10437,"style":292},"f867b2c448e0",[10433],{"_key":10434,"_type":176,"marks":10435,"text":10436},"91234ce651e30",[],"How Sweep Enables Governed Speed (Without Breaking Things)",[],{"_key":10439,"_type":172,"children":10440,"markDefs":10453,"style":180},"08cf7498b241",[10441,10445,10449],{"_key":10442,"_type":176,"marks":10443,"text":10444},"5066620524c20",[],"Sweep acts as the ",{"_key":10446,"_type":176,"marks":10447,"text":8936},"802021d733e4",[10448],"633be8e8524b",{"_key":10450,"_type":176,"marks":10451,"text":10452},"46bc4518b29d",[]," for Salesforce metadata.",[10454],{"_key":10448,"_ref":3064,"_type":328,"linkType":738,"slug":10455},{"_type":22,"current":3066},{"_key":10457,"_type":172,"children":10458,"markDefs":10463,"style":180},"6bd424bcaaa4",[10459],{"_key":10460,"_type":176,"marks":10461,"text":10462},"105d10711cde0",[],"Instead of relying on memory, superstition, or outdated documentation, teams get a continuously updated understanding of how their org functions. Sweep maps how fields, flows, and rules connect. It tracks what changed, when, and why. It highlights where risk is accumulating and shows which downstream systems will feel the impact of a change.",[],{"_key":10465,"_type":172,"children":10466,"markDefs":10471,"style":180},"8efa3df5f71c",[10467],{"_key":10468,"_type":176,"marks":10469,"text":10470},"14d46e9001670",[],"That operational truth changes behavior.",[],{"_key":10473,"_type":172,"children":10474,"markDefs":10479,"style":180},"70068e8aeda3",[10475],{"_key":10476,"_type":176,"marks":10477,"text":10478},"63c44b407f1c0",[],"Releases get faster because teams know what they’re touching. Audits get cleaner because system logic is explainable. Emergency freezes become rare because issues are spotted before they escalate. Governance stops being a brake and starts acting like a stabilizer.",[],{"_key":10481,"_type":172,"children":10482,"markDefs":10487,"style":292},"a02c350c47c1",[10483],{"_key":10484,"_type":176,"marks":10485,"text":10486},"c962d8e111ed0",[],"Scaling Without Slowing Is a Metadata Problem",[],{"_key":10489,"_type":172,"children":10490,"markDefs":10495,"style":180},"35a1064863d5",[10491],{"_key":10492,"_type":176,"marks":10493,"text":10494},"4974b21a22100",[],"Cybersecurity companies fail when systems become too opaque to trust.",[],{"_key":10497,"_type":172,"children":10498,"markDefs":10503,"style":180},"afbe256e13c9",[10499],{"_key":10500,"_type":176,"marks":10501,"text":10502},"ea5853c4eed30",[],"The fix here isn’t fewer changes. It’s better understanding.",[],{"_key":10505,"_type":172,"children":10506,"markDefs":10519,"style":180},"789fe6ddbf59",[10507,10510,10515],{"_key":10508,"_type":176,"marks":10509,"text":6976},"4a96142a70fd0",[],{"_key":10511,"_type":176,"marks":10512,"text":10514},"1fabef845a9f",[10513],"9888c4c49a98","metadata is visible",{"_key":10516,"_type":176,"marks":10517,"text":10518},"076281314df7",[],", governed, and continuously maintained, Salesforce stops being fragile. It scales alongside the business instead of holding it back.",[10520],{"_key":10513,"_ref":10521,"_type":328,"linkType":33,"slug":10522},"1ad4dddb-0499-4369-89c2-b03634499ddf",{"_type":22,"current":10523},"why-ai-can-t-understand-your-salesforce-yet",{"_key":10525,"_type":172,"children":10526,"markDefs":10531,"style":180},"38c75587e5a7",[10527],{"_key":10528,"_type":176,"marks":10529,"text":10530},"55971c497a650",[],"That’s what safe speed actually looks like.",[],{"_type":17,"description":10533,"shareImage":10534,"title":10536},"Learn why Salesforce slows down as cybersecurity companies scale, and how metadata governance enables safe, auditable change without freezing your org.\n",{"_type":40,"asset":10535},{"_ref":10083,"_type":278},"How Cybersecurity Companies Safely Scale Salesforce | Sweep",{"_type":22,"current":8909},{"_createdAt":10539,"_id":3743,"_rev":10540,"_type":33,"_updatedAt":10541,"author":10542,"category":10577,"featuredImage":10583,"modularContent":10618,"postTitle":10621,"publishDate":10622,"richText":10623,"seo":11111,"slug":11116},"2026-02-04T19:24:23Z","J5j1hv5WW9LqWb2rume8OY","2026-03-23T09:50:14Z",{"authorImage":10543,"authorJobTitle":91,"authorName":86},{"_type":37,"altText":38,"image":10544},{"_type":40,"asset":10545},{"_createdAt":10546,"_id":10547,"_rev":10548,"_type":45,"_updatedAt":10546,"assetId":10549,"extension":2449,"metadata":10550,"mimeType":2475,"originalFilename":10572,"path":10573,"sha1hash":10549,"size":10574,"uploadId":10575,"url":10576},"2025-08-06T14:00:29Z","image-110fbd6ed7521eeb9ddb42fc4a74589fbbea234f-491x491-jpg","n73s3PlPuC6MMWGp2VFyEa","110fbd6ed7521eeb9ddb42fc4a74589fbbea234f",{"_type":50,"blurHash":10551,"dimensions":10552,"hasAlpha":56,"isOpaque":57,"lqip":10553,"palette":10554},"eNJ%Us}R1i4:sD-rxAElNFWX0gELnjW=S2o#$zkDS4xD9vRj%2xtWo",{"_type":53,"aspectRatio":54,"height":55,"width":55},"data:image/jpeg;base64,/9j/2wBDAAYEBQYFBAYGBQYHBwYIChAKCgkJChQODwwQFxQYGBcUFhYaHSUfGhsjHBYWICwgIyYnKSopGR8tMC0oMCUoKSj/2wBDAQcHBwoIChMKChMoGhYaKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCgoKCj/wAARCAAUABQDASIAAhEBAxEB/8QAGQABAAMBAQAAAAAAAAAAAAAAAAQFBgcC/8QAJRAAAgEEAgEDBQAAAAAAAAAAAQIDAAQFEQYhEhNBUQcUIlJx/8QAFQEBAQAAAAAAAAAAAAAAAAAABQb/xAAgEQEAAgIBBAMAAAAAAAAAAAABAAIDETEEBRITIUGh/9oADAMBAAIRAxEAPwC0+nuHt3nvrrM26MUOu+9CoXLcRx97iPIYtjDIsgAKnQPfY1Wuxtx5WS/Zzws9wm1kAHiayHOWlXM4jGTW8cyqTJ6o/HR96Ope3t8t/MatjxmFPqenxURO1k6PfdKk3LAuPTkTXiPcUqhO6Iabfkm3oBdlZxjHcgyNstxaxXDLCI/JV/U/I+KtOLTTcmigOWnmkdJCocOQ2v7SlE5QGyROipUnQ4OO2NvGFT1iD32+6UpRjZ3zECprif/Z",{"_type":60,"darkMuted":10555,"darkVibrant":10558,"dominant":10560,"lightMuted":10561,"lightVibrant":10564,"muted":10567,"vibrant":10570},{"_type":62,"background":10556,"foreground":64,"population":10557,"title":64},"#58362a",7.44,{"_type":62,"background":10559,"foreground":64,"population":2461,"title":64},"#53100c",{"_type":62,"background":10556,"foreground":64,"population":10557,"title":64},{"_type":62,"background":10562,"foreground":72,"population":10563,"title":64},"#b9becc",1.77,{"_type":62,"background":10565,"foreground":72,"population":10566,"title":64},"#fcb59f",3.59,{"_type":62,"background":10568,"foreground":64,"population":10569,"title":64},"#ae7b5f",2.54,{"_type":62,"background":10571,"foreground":64,"population":82,"title":64},"#4484cc","nick-gaudio.jpg","images/9eu1m6zu/production/110fbd6ed7521eeb9ddb42fc4a74589fbbea234f-491x491.jpg",12243,"ndRRD5X3t2TDtACdLs63QQ4DVBuQA9Bw","https://cdn.sanity.io/images/9eu1m6zu/production/110fbd6ed7521eeb9ddb42fc4a74589fbbea234f-491x491.jpg",{"_createdAt":5,"_id":6,"_rev":7,"_system":10578,"_type":11,"_updatedAt":12,"selectedColor":10580,"seo":10581,"slug":10582,"title":24},{"base":10579},{"id":6,"rev":10},{"title":14,"value":15},{"_type":17,"description":18,"title":20},{"_type":22,"current":23},{"_type":37,"altText":10584,"image":10585},"Use Agentic AI to Govern Salesforce at Scale",{"_type":40,"asset":10586},{"_createdAt":10587,"_id":10588,"_rev":10589,"_type":45,"_updatedAt":10587,"assetId":10590,"extension":106,"metadata":10591,"mimeType":132,"originalFilename":10613,"path":10614,"sha1hash":10590,"size":10615,"uploadId":10616,"url":10617},"2026-02-04T19:31:39Z","image-da187f15ce120e5c2865d8cbdd279f289caf7f44-1600x900-png","zauLsYIXJFOxrJAMF5JzXk","da187f15ce120e5c2865d8cbdd279f289caf7f44",{"_type":50,"blurHash":10592,"dimensions":10593,"hasAlpha":57,"isOpaque":56,"lqip":10594,"palette":10595,"thumbHash":10612},"MKFsg607s%_00Z%0xSjXbKR;52?SfRIXxm",{"_type":53,"aspectRatio":5981,"height":5982,"width":5983},"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABQAAAALCAYAAAB/Ca1DAAAACXBIWXMAAA7EAAAOxAGVKw4bAAACzElEQVR4nF3O60+SYRzGcf63xFFWPIBYWNqWoCsP0w76HBCZbZVNbb0QtLS10rZyubnWYTMTSzyBIipmggpqInjEhOc2fX5XU8s5X3x27/69+O5S6URlxSDJLFPcpkwxgQPGw/c39CIDJyjgBJxC4Hg6/usEECdC5nhlWWWq3ImXPZxiVfU9ZK/rQlVdF+z1XbDVuVB8fwaXrKnDgE4ErlYDpU8IfCNBONB0pNwBMtfsMYO0H1XlVK3Hq+t7mNPZTI0OB5wNDjQ5HWhwtEB89A0mKQ5txS4yrQr4RuC9mzAc+IPB8RTc/iTc/hS6h3bo8esEy7bJUZWeT8RzhQCzCD1kEbph5r/CzH9BHu+C6c4YLpSGkVG2AaP0BzVthOnwHjbW1jEXDGHyRxA/pmcxOR6ilx0RlmPbjKou3EnGzxYtMLXFT2l5o0gzjyHN7IPa4oe6IABN4SzOl60hy7qLmlYFvukdzM7OwesZRG9fPwYGhzA0MELP3wZZjm3jfzDC1BYfnbk+jLQ8L9T5fqQXTECdP34UvL2OLGsK1S0yOrpW8OHrJLpdfejt7ca3PhdcfcP09E2Q5djX/wULwycW+pBeMAXNjWmcu+HDxSIPLpZMwFixCFtTAk3tv9DQNoXOT154Br7D63HDPeCl5rdBlms/WHhXjmeUrjBNYYg0N0PQFM7hbFEYGSVhGG+N41q5C1duf4eJD+JeSwLvvqyi/fM83J4IlhYWEVteQHBmnl51Ro4WaoX9mJbflbUVSUVbniRtxYEUcXySjOImXbEuk0mK0uXKBNmeMfroTlC/L0ajgVX6ObdJM/ObNDK5pjjbo3K2bWtZxUlY1FmxrRMh60QwnXSCCKYXFaaXwAxWsLwHe8zenGS1rQlW27p17P6LLbm4bmvbKMkRFSciwAlY4gSKnaY94f9NLyoxg6TEMo/txwzSfkwvKEuciIm/rAR3soDUc2kAAAAASUVORK5CYII=",{"_type":60,"darkMuted":10596,"darkVibrant":10599,"dominant":10602,"lightMuted":10604,"lightVibrant":10606,"muted":10608,"vibrant":10611},{"_type":62,"background":10597,"foreground":64,"population":10598,"title":64},"#3f5263",0.72,{"_type":62,"background":10600,"foreground":64,"population":10601,"title":64},"#16298f",0.42,{"_type":62,"background":840,"foreground":64,"population":10603,"title":64},27.58,{"_type":62,"background":10605,"foreground":72,"population":1737,"title":64},"#94c698",{"_type":62,"background":846,"foreground":64,"population":10607,"title":64},10.19,{"_type":62,"background":10609,"foreground":64,"population":10610,"title":64},"#4a609c",3.06,{"_type":62,"background":840,"foreground":64,"population":10603,"title":64},"6MSFI4IPgFx4h7eRqRCZCggIj4dw+Ag=","Blog Headers (2).png","images/9eu1m6zu/production/da187f15ce120e5c2865d8cbdd279f289caf7f44-1600x900.png",324567,"2Pbw652iRT3KdlRiZfnGtgj7twMQG7zm","https://cdn.sanity.io/images/9eu1m6zu/production/da187f15ce120e5c2865d8cbdd279f289caf7f44-1600x900.png",[10619],{"_key":10620,"_type":275,"cols":276,"offset":82,"rows":54,"showControls":56,"showModule":57,"showTotal":56,"title":279},"9b88d8ad377797e2b9c72d05eca03856","How Cybersecurity Companies Use Agentic AI to Govern Salesforce at Scale","2026-02-03",[10624,10631,10639,10647,10655,10663,10670,10678,10686,10705,10713,10729,10737,10745,10753,10773,10781,10789,10809,10817,10825,10833,10841,10849,10857,10865,10873,10881,10900,10908,10916,10924,10932,10940,10948,10956,10975,10983,10991,10999,11007,11015,11023,11031,11039,11047,11055,11063,11071,11079,11087,11095],{"_key":10625,"_type":172,"children":10626,"markDefs":10630,"style":292},"2e8d51e30169",[10627],{"_key":10628,"_type":176,"marks":10629,"text":290},"681d65503ab2",[],[],{"_key":10632,"_type":172,"children":10633,"level":54,"listItem":309,"markDefs":10638,"style":180},"b7921cc5cca9",[10634],{"_key":10635,"_type":176,"marks":10636,"text":10637},"62712b988451",[],"Cybersecurity companies operate Salesforce under extreme change velocity and audit pressure. ",[],{"_key":10640,"_type":172,"children":10641,"level":54,"listItem":309,"markDefs":10646,"style":180},"716a7b623568",[10642],{"_key":10643,"_type":176,"marks":10644,"text":10645},"a97f30aeb27c",[],"The biggest risk isn’t bad actors or misconfigured permissions — it’s actually metadata drift. ",[],{"_key":10648,"_type":172,"children":10649,"level":54,"listItem":309,"markDefs":10654,"style":180},"41ce634f1c7f",[10650],{"_key":10651,"_type":176,"marks":10652,"text":10653},"b3d6ff46da91",[],"Agentic AI governs Salesforce by maintaining continuous system awareness, replacing brittle documentation with living system truth.",[],{"_key":10656,"_type":172,"children":10657,"level":54,"listItem":309,"markDefs":10662,"style":180},"373db3c1b275",[10658],{"_key":10659,"_type":176,"marks":10660,"text":10661},"626cee89e10d",[],"The result is steady-state audit readiness, fewer surprises, and speed that doesn’t erode trust.",[],{"_key":10664,"_type":172,"children":10665,"markDefs":10669,"style":180},"af3b4188e9b7",[10666],{"_key":10667,"_type":176,"marks":10668,"text":187},"606c1db100ff",[],[],{"_key":10671,"_type":172,"children":10672,"markDefs":10677,"style":180},"037889f1916e",[10673],{"_key":10674,"_type":176,"marks":10675,"text":10676},"40d2f9e3b620",[],"***",[],{"_key":10679,"_type":172,"children":10680,"markDefs":10685,"style":180},"3595e809da57",[10681],{"_key":10682,"_type":176,"marks":10683,"text":10684},"79914dc42725",[],"Like it or not, Salesforce is production infrastructure. It controls revenue motion, customer access, entitlements, renewals, and support workflows. It feeds the downstream data systems that executives, auditors, and increasingly AI agents rely on to make decisions that actually matter.",[],{"_key":10687,"_type":172,"children":10688,"markDefs":10702,"style":180},"b6f89500c128",[10689,10693,10698],{"_key":10690,"_type":176,"marks":10691,"text":10692},"6f8e431d8fc80",[],"And yet, most organizations still try to ",{"_key":10694,"_type":176,"marks":10695,"text":10697},"c72a001cf01d",[10696],"136824b8c22f","govern Salesforce",{"_key":10699,"_type":176,"marks":10700,"text":10701},"f75ba0f629ad",[]," the same way they did a decade ago: with static documentation, point-in-time audits, and human memory loosely stitched together by Slack messages.",[10703],{"_key":10696,"_ref":3313,"_type":328,"linkType":33,"slug":10704},{"_type":22,"current":3315},{"_key":10706,"_type":172,"children":10707,"markDefs":10712,"style":180},"19e42a9f0274",[10708],{"_key":10709,"_type":176,"marks":10710,"text":10711},"f4687f44fe050",[],"That approach doesn’t survive scale. It collapses fastest in security-first environments, where velocity is high, scrutiny is constant, and failure modes are expensive.",[],{"_key":10714,"_type":172,"children":10715,"markDefs":10728,"style":180},"4f03cc334fd1",[10716,10720,10724],{"_key":10717,"_type":176,"marks":10718,"text":10719},"fe71b22eed500",[],"Cybersecurity companies are taking a different path. They’re using agentic AI grounded in metadata — not to move faster recklessly, but to move fast ",{"_key":10721,"_type":176,"marks":10722,"text":10723},"fe71b22eed501",[393],"without",{"_key":10725,"_type":176,"marks":10726,"text":10727},"fe71b22eed502",[]," losing control.",[],{"_key":10730,"_type":172,"children":10731,"markDefs":10736,"style":292},"3d2d83b09802",[10732],{"_key":10733,"_type":176,"marks":10734,"text":10735},"729cbeebe8d20",[],"Why Salesforce Governance Breaks First in Cybersecurity Companies",[],{"_key":10738,"_type":172,"children":10739,"markDefs":10744,"style":180},"97065f2de86e",[10740],{"_key":10741,"_type":176,"marks":10742,"text":10743},"1e1ac7ebe5db0",[],"Cybersecurity organizations are built to ship quickly while being watched closely. Product lines evolve fast. Go-to-market models change often. Compliance requirements are strict and rarely optional. Internal audits are frequent and unforgiving.",[],{"_key":10746,"_type":172,"children":10747,"markDefs":10752,"style":180},"1e95c0269d65",[10748],{"_key":10749,"_type":176,"marks":10750,"text":10751},"fafba876730a0",[],"Salesforce sits at the center of all of this.",[],{"_key":10754,"_type":172,"children":10755,"markDefs":10768,"style":180},"5eacb475d317",[10756,10760,10765],{"_key":10757,"_type":176,"marks":10758,"text":10759},"b72b2c04e04f0",[],"Every new pricing model, territory shift, lifecycle update, or entitlement rule leaves its mark in metadata — fields, flows, validation rules, routing logic, integrations. Over time, the org doesn’t become fragile because someone made a mistake. It becomes fragile ",{"_key":10761,"_type":176,"marks":10762,"text":10764},"9aeae831f13c",[10763],"b5968d00c87a","because context disappears",{"_key":10766,"_type":176,"marks":10767,"text":3667},"7febe7aaee7e",[],[10769],{"_key":10763,"_ref":10770,"_type":328,"linkType":33,"slug":10771},"bb7a913c-555f-4c1d-b029-235d0ff59b92",{"_type":22,"current":10772},"the-context-effect-new-study-proves-ai-fails-without-it",{"_key":10774,"_type":172,"children":10775,"markDefs":10780,"style":180},"fbb34ec3acab",[10776],{"_key":10777,"_type":176,"marks":10778,"text":10779},"cb471ad0f77e0",[],"That’s when the warnings start to sound familiar.",[],{"_key":10782,"_type":172,"children":10783,"markDefs":10788,"style":180},"53a4cb93bb77",[10784],{"_key":10785,"_type":176,"marks":10786,"text":10787},"0f143b1134190",[],"“Don’t touch that field — it’s important.”\n“I think this Flow controls routing, but I’m not totally sure.”\n“The docs might be outdated.”",[],{"_key":10790,"_type":172,"children":10791,"markDefs":10804,"style":180},"4addd42851a2",[10792,10795,10800],{"_key":10793,"_type":176,"marks":10794,"text":3774},"56e48b9a73250",[],{"_key":10796,"_type":176,"marks":10797,"text":10799},"4bcd303d2e1d",[10798],"8be83594d16f","systems drag",{"_key":10801,"_type":176,"marks":10802,"text":10803},"2f2264d775be",[],". And it compounds quietly, right up until it doesn’t.",[10805],{"_key":10798,"_ref":10806,"_type":328,"linkType":33,"slug":10807},"0cb19aaf-25d7-41a9-8c46-d1bdff0ee3af",{"_type":22,"current":10808},"systems-drag-the-compound-interest-of-complexity",{"_key":10810,"_type":172,"children":10811,"markDefs":10816,"style":292},"5379a119b57d",[10812],{"_key":10813,"_type":176,"marks":10814,"text":10815},"a040697f3eab0",[],"The Real Risk: Metadata Drift",[],{"_key":10818,"_type":172,"children":10819,"markDefs":10824,"style":180},"48711d77227d",[10820],{"_key":10821,"_type":176,"marks":10822,"text":10823},"e7efbaeb6a240",[],"When Salesforce governance fails, teams often reach for the usual explanations. Access controls weren’t tight enough. Process wasn’t followed. Someone made a bad change.",[],{"_key":10826,"_type":172,"children":10827,"markDefs":10832,"style":180},"446d86ce2fe2",[10828],{"_key":10829,"_type":176,"marks":10830,"text":10831},"04fe0abcf4ae0",[],"In mature security organizations, those are rarely the root cause.",[],{"_key":10834,"_type":172,"children":10835,"markDefs":10840,"style":180},"414cb833d813",[10836],{"_key":10837,"_type":176,"marks":10838,"text":10839},"4ea3cd207d660",[],"The real issue is metadata drift.",[],{"_key":10842,"_type":172,"children":10843,"markDefs":10848,"style":180},"e6761a34eaad",[10844],{"_key":10845,"_type":176,"marks":10846,"text":10847},"fe395ccf94b70",[],"Fields slowly change meaning without anyone noticing. Automations accumulate hidden dependencies. Logic gets added to solve urgent, short-term problems and never gets revisited. Each change makes sense on its own. Together, they create a system no one fully understands.",[],{"_key":10850,"_type":172,"children":10851,"markDefs":10856,"style":180},"73f0d4a529e0",[10852],{"_key":10853,"_type":176,"marks":10854,"text":10855},"958bab10c4d40",[],"That lack of understanding becomes dangerous when AI enters the picture — forecasting, routing, enrichment, decisioning. AI doesn’t fail with a big bang when its assumptions are wrong. It fails confidently, and at scale.",[],{"_key":10858,"_type":172,"children":10859,"markDefs":10864,"style":292},"14c9d603f206",[10860],{"_key":10861,"_type":176,"marks":10862,"text":10863},"e0e355113f3a0",[],"What Agentic AI Actually Does (and What It Doesn’t)",[],{"_key":10866,"_type":172,"children":10867,"markDefs":10872,"style":180},"64b07896f905",[10868],{"_key":10869,"_type":176,"marks":10870,"text":10871},"5b373f752c540",[],"Agentic AI in Salesforce governance is often misunderstood, mostly because the word “agentic” gets abused.",[],{"_key":10874,"_type":172,"children":10875,"markDefs":10880,"style":180},"3af2cc509021",[10876],{"_key":10877,"_type":176,"marks":10878,"text":10879},"d3752d23b16b0",[],"It is not a chatbot answering admin questions.\nIt is not a macro engine running tasks faster.\nIt is not an autonomous system making business decisions on its own.",[],{"_key":10882,"_type":172,"children":10883,"markDefs":10897,"style":180},"85abce0c4658",[10884,10888,10893],{"_key":10885,"_type":176,"marks":10886,"text":10887},"6148c471e4490",[],"Sweep’s ",{"_key":10889,"_type":176,"marks":10890,"text":10892},"308f62748538",[10891],"f4f5786b204c","agentic AI ",{"_key":10894,"_type":176,"marks":10895,"text":10896},"c968170625e2",[],"operates one layer deeper. It works continuously on metadata.",[10898],{"_key":10891,"_ref":3064,"_type":328,"linkType":738,"slug":10899},{"_type":22,"current":3066},{"_key":10901,"_type":172,"children":10902,"markDefs":10907,"style":180},"b1d15ad6ebfc",[10903],{"_key":10904,"_type":176,"marks":10905,"text":10906},"1fe88286b8b50",[],"In practice, that means it observes every object, field, flow, rule, and dependency in Salesforce. It tracks configuration changes as they happen. It understands upstream and downstream impact across the org. It explains why the system behaves the way it does, and preserves historical context for how — and why — changes were made.",[],{"_key":10909,"_type":172,"children":10910,"markDefs":10915,"style":180},"b1d689f47593",[10911],{"_key":10912,"_type":176,"marks":10913,"text":10914},"e2701a87dbb70",[],"This is the distinction that matters. Traditional AI reacts to prompts. Agentic AI maintains situational awareness.",[],{"_key":10917,"_type":172,"children":10918,"markDefs":10923,"style":180},"7da0b43f38fa",[10919],{"_key":10920,"_type":176,"marks":10921,"text":10922},"6b4a87a06f670",[],"For cybersecurity companies, that difference separates automation from governance.",[],{"_key":10925,"_type":172,"children":10926,"markDefs":10931,"style":292},"949784e66e4b",[10927],{"_key":10928,"_type":176,"marks":10929,"text":10930},"e0fce8c1dbbd0",[],"Why Static Documentation Fails at Scale",[],{"_key":10933,"_type":172,"children":10934,"markDefs":10939,"style":180},"3be141fa933e",[10935],{"_key":10936,"_type":176,"marks":10937,"text":10938},"58a072f2cb740",[],"Most Salesforce documentation is obsolete the moment it’s written.",[],{"_key":10941,"_type":172,"children":10942,"markDefs":10947,"style":180},"43e758f3df04",[10943],{"_key":10944,"_type":176,"marks":10945,"text":10946},"e7bf63bbad530",[],"Wikis, diagrams, and spreadsheets assume a stable system. Cybersecurity orgs don’t have one. A Flow update here, a routing tweak there, a new integration added under pressure — and suddenly the documentation becomes fiction. Worse, it creates false confidence.",[],{"_key":10949,"_type":172,"children":10950,"markDefs":10955,"style":180},"06165fd55f1e",[10951],{"_key":10952,"_type":176,"marks":10953,"text":10954},"069c516ff23c0",[],"Agentic AI replaces brittle documentation with living system truth.",[],{"_key":10957,"_type":172,"children":10958,"markDefs":10972,"style":180},"857db03fffb7",[10959,10963,10968],{"_key":10960,"_type":176,"marks":10961,"text":10962},"7756b28325220",[],"Instead of humans trying to keep docs up to date, ",{"_key":10964,"_type":176,"marks":10965,"text":10967},"7b985a68b1ba",[10966],"3a6a779ec2f1","agents generate documentation",{"_key":10969,"_type":176,"marks":10970,"text":10971},"f5a4c820b5da",[]," directly from live metadata. Explanations update the moment something changes. Every element stays linked to its dependencies and downstream effects, with full historical context preserved automatically.",[10973],{"_key":10966,"_ref":6128,"_type":328,"linkType":738,"slug":10974},{"_type":22,"current":6130},{"_key":10976,"_type":172,"children":10977,"markDefs":10982,"style":180},"1c6c46f71f11",[10978],{"_key":10979,"_type":176,"marks":10980,"text":10981},"18945a4611f00",[],"What results is documentation as a byproduct of governance — which is the only kind that actually scales.",[],{"_key":10984,"_type":172,"children":10985,"markDefs":10990,"style":292},"76228f13eb1b",[10986],{"_key":10987,"_type":176,"marks":10988,"text":10989},"cb69bc8c29810",[],"Audit Readiness as a Steady State (Not a Panic Event)",[],{"_key":10992,"_type":172,"children":10993,"markDefs":10998,"style":180},"f906f6c38dac",[10994],{"_key":10995,"_type":176,"marks":10996,"text":10997},"9da1d6670b480",[],"Security audits fail when teams can’t reconstruct system behavior over time.",[],{"_key":11000,"_type":172,"children":11001,"markDefs":11006,"style":180},"c33ed22f3e99",[11002],{"_key":11003,"_type":176,"marks":11004,"text":11005},"22d9220887d10",[],"Auditors want to know who changed something, when it changed, what else it affected, whether it was reviewed, and what risk it introduced. Without agentic governance, answering those questions means digging through logs, chasing institutional memory, and hoping the documentation is still accurate.",[],{"_key":11008,"_type":172,"children":11009,"markDefs":11014,"style":180},"69847b943b8d",[11010],{"_key":11011,"_type":176,"marks":11012,"text":11013},"619fd3853ab00",[],"With agentic AI, the answers already exist. Changes are tracked continuously. Dependencies are mapped automatically. System behavior is explainable by default.",[],{"_key":11016,"_type":172,"children":11017,"markDefs":11022,"style":180},"9710004d0322",[11018],{"_key":11019,"_type":176,"marks":11020,"text":11021},"931e02df24c10",[],"Audit readiness stops being a scramble and becomes a steady state. And long before an audit ever happens, reliability improves. Dashboards break less often. Leads get routed correctly. AI decisions make sense. Fewer incidents start with, “How did this happen?”",[],{"_key":11024,"_type":172,"children":11025,"markDefs":11030,"style":180},"f2084041b951",[11026],{"_key":11027,"_type":176,"marks":11028,"text":11029},"1c4fb681a5b50",[],"Governance stops being reactive.",[],{"_key":11032,"_type":172,"children":11033,"markDefs":11038,"style":292},"eacf978d5484",[11034],{"_key":11035,"_type":176,"marks":11036,"text":11037},"fe9521e2397c0",[],"Why Cybersecurity Companies Are Ahead of Everyone Else",[],{"_key":11040,"_type":172,"children":11041,"markDefs":11046,"style":180},"2226f6f92557",[11042],{"_key":11043,"_type":176,"marks":11044,"text":11045},"b1481063fbd10",[],"Cybersecurity teams already understand principles many organizations are still learning the hard way. Controls must be continuous, not periodic. Visibility beats policy. Context is everything.",[],{"_key":11048,"_type":172,"children":11049,"markDefs":11054,"style":180},"5b301984fb25",[11050],{"_key":11051,"_type":176,"marks":11052,"text":11053},"1636fab89b6a0",[],"Applying agentic AI to Salesforce is simply extending those principles to go-to-market systems. Instead of locking everything down, teams let systems evolve — and use agents to enforce guardrails.",[],{"_key":11056,"_type":172,"children":11057,"markDefs":11062,"style":180},"059fb3dc275c",[11058],{"_key":11059,"_type":176,"marks":11060,"text":11061},"e92425277d9c0",[],"Sweep becomes the control plane for admins, operators, and AI agents themselves. Not by adding friction, but by removing uncertainty.",[],{"_key":11064,"_type":172,"children":11065,"markDefs":11070,"style":292},"2eadf07c0b04",[11066],{"_key":11067,"_type":176,"marks":11068,"text":11069},"73ad892e6e580",[],"The Bottom Line",[],{"_key":11072,"_type":172,"children":11073,"markDefs":11078,"style":180},"16789219f0a5",[11074],{"_key":11075,"_type":176,"marks":11076,"text":11077},"15edafe6c2550",[],"Agentic AI maintains the conditions under which safe decisions are possible.",[],{"_key":11080,"_type":172,"children":11081,"markDefs":11086,"style":180},"5bac9a4bc294",[11082],{"_key":11083,"_type":176,"marks":11084,"text":11085},"2d19766c9daf0",[],"For cybersecurity companies, governing Salesforce with agentic, metadata-driven systems isn’t a nice-to-have. It’s how Salesforce finally gets treated like the critical infrastructure it is.",[],{"_key":11088,"_type":172,"children":11089,"markDefs":11094,"style":180},"04b0e2aa649d",[11090],{"_key":11091,"_type":176,"marks":11092,"text":11093},"de2f2469e5430",[],"Clarity replaces fear. Governance replaces guesswork. And speed no longer comes at the cost of control.",[],{"_key":11096,"_type":172,"children":11097,"markDefs":11110,"style":180},"1825d11fc78d",[11098,11102,11106],{"_key":11099,"_type":176,"marks":11100,"text":11101},"0642ee24eb450",[],"And that — ",{"_key":11103,"_type":176,"marks":11104,"text":11105},"62a1bfde7763",[393],"that",{"_key":11107,"_type":176,"marks":11108,"text":11109},"1d23207bd4c7",[]," is governed scale.",[],{"_type":17,"description":11112,"shareImage":11113,"title":11115},"How cybersecurity companies use agentic, metadata-driven AI to govern Salesforce at scale — prevent drift, stay audit-ready, and move fast without losing control.",{"_type":40,"asset":11114},{"_ref":10588,"_type":278},"Agentic AI for Salesforce Governance in Cybersecurity | Sweep",{"_type":22,"current":3745},1791356695088]