How to govern Security in Salesforce
A step-by-step guide to governing Security in Salesforce with Rencore: detect, review by owner and severity, and remediate with an audit trail.
Governing Security in Salesforce means finding where it goes wrong, reviewing the findings by owner and severity, and remediating with an audit trail. Rencore covers this concern for Salesforce with the pre-built controls below, so it becomes a repeatable check rather than a one-off cleanup. The steps that follow apply the same detect, review, remediate loop to Security.
Steps
-
Inventory Salesforce
Connect Salesforce and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.
-
Detect with policies
Turn on the pre-built policies that cover Security in Salesforce to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.
-
Review by owner and severity
Use the Salesforce reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.
-
Remediate and automate
Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.
Salesforce controls for Security
Grounded in the Rencore catalog. See the full Salesforce catalog on the Salesforce connector page.
-
Salesforce agent is active and callable
Active Agentforce agents are callable and exercised against real user input, raising the likelihood of exploitation
Severity: Medium -
Salesforce System Administrator is active
Active System Administrators are full-access, high-value targets, raising the likelihood that weaknesses are exploited
Severity: High -
Salesforce permission set grants Modify All Data
Permission sets that grant Modify All Data have org-wide blast radius, raising the likelihood of exploitation
Severity: High -
Salesforce org with too many System Administrators
Detects orgs with more than 5 active users on the System Administrator profile
Severity: High -
Salesforce profiles with Modify All Data
Detects profiles that grant the Modify All Data system permission
Severity: High -
Salesforce permission sets with Modify All Data
Detects custom permission sets that grant the Modify All Data system permission
Severity: High -
Inactive Salesforce users with permission set assignments
Detects deactivated users that still hold permission set assignments
Severity: High -
Salesforce failed login attempts
Detects login history entries with a non-success status
Severity: Medium -
Salesforce users by profile
Shows the number of users assigned to each profile
-
Salesforce permission sets by Modify All Data
Shows how many permission sets grant Modify All Data
-
Salesforce logins by status
Shows the distribution of login outcomes (success vs failure)
-
Permission Sets with Modify All Data
Shows permission sets that grant the Modify All Data system permission
-
Profiles with Modify All Data
Shows profiles that grant the Modify All Data system permission
-
Create Salesforce Case for External User with Permission Set
When an external Salesforce user is found holding a permission set, create a Salesforce case for access review.
-
Create Salesforce Case for Open Connected App
When a connected app is not restricted to admin-approved users, create a Salesforce case for the security team.
-
Create Salesforce Case for Profile with Modify All Data
When a profile grants Modify All Data, create a Salesforce case to track a least-privilege review.