Governance guide

How to govern Security in Salesforce

A step-by-step guide to governing Security in Salesforce with Rencore: detect, review by owner and severity, and remediate with an audit trail.

Definition

Governing Security in Salesforce means finding where it goes wrong, reviewing the findings by owner and severity, and remediating with an audit trail. Rencore covers this concern for Salesforce with the pre-built controls below, so it becomes a repeatable check rather than a one-off cleanup. The steps that follow apply the same detect, review, remediate loop to Security.

Steps

  1. Inventory Salesforce

    Connect Salesforce and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.

  2. Detect with policies

    Turn on the pre-built policies that cover Security in Salesforce to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.

  3. Review by owner and severity

    Use the Salesforce reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.

  4. Remediate and automate

    Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.

Salesforce controls for Security

Grounded in the Rencore catalog. See the full Salesforce catalog on the Salesforce connector page.

  • Salesforce agent is active and callable

    Active Agentforce agents are callable and exercised against real user input, raising the likelihood of exploitation

    Severity: Medium
  • Salesforce System Administrator is active

    Active System Administrators are full-access, high-value targets, raising the likelihood that weaknesses are exploited

    Severity: High
  • Salesforce permission set grants Modify All Data

    Permission sets that grant Modify All Data have org-wide blast radius, raising the likelihood of exploitation

    Severity: High
  • Salesforce org with too many System Administrators

    Detects orgs with more than 5 active users on the System Administrator profile

    Severity: High
  • Salesforce profiles with Modify All Data

    Detects profiles that grant the Modify All Data system permission

    Severity: High
  • Salesforce permission sets with Modify All Data

    Detects custom permission sets that grant the Modify All Data system permission

    Severity: High
  • Inactive Salesforce users with permission set assignments

    Detects deactivated users that still hold permission set assignments

    Severity: High
  • Salesforce failed login attempts

    Detects login history entries with a non-success status

    Severity: Medium
  • Salesforce users by profile

    Shows the number of users assigned to each profile

  • Salesforce permission sets by Modify All Data

    Shows how many permission sets grant Modify All Data

  • Salesforce logins by status

    Shows the distribution of login outcomes (success vs failure)

  • Permission Sets with Modify All Data

    Shows permission sets that grant the Modify All Data system permission

  • Profiles with Modify All Data

    Shows profiles that grant the Modify All Data system permission

  • Create Salesforce Case for External User with Permission Set

    When an external Salesforce user is found holding a permission set, create a Salesforce case for access review.

  • Create Salesforce Case for Open Connected App

    When a connected app is not restricted to admin-approved users, create a Salesforce case for the security team.

  • Create Salesforce Case for Profile with Modify All Data

    When a profile grants Modify All Data, create a Salesforce case to track a least-privilege review.

Explore the full Salesforce governance catalog | All guides

Trusted by

MAPALBAMVille de LuxembourgWACKERGRUNDFOSAMGENOsramLufthansaThyssenKruppSunrisePattern