What We Review
Our comprehensive analysis framework considers only the structure of your org. We therefore read only metadata and aggregate statistics, never your business data.
What we read
- Metadata: objects, fields, Flows, Apex, and configuration
- Aggregate statistics and usage counts
- Naming, descriptions, and the structure of your org
- Permissions, profiles, and the sharing model
- User Health basics: name, email, role, last login, MFA status (this module can be excluded on request)
What we never touch
- Business records: Accounts, Contacts, Opportunities, and custom records
- Attachments, Files, and Chatter posts
- Email messages, tasks, events, and private notes
- Financial data: pricing, contract values, commission amounts
- Personal data beyond the User Health basics
All Modules at a Glance
During the Platform Assessment, we examine 15 topic areas, each forming its own module. These range from architecture and data modelling to automation, code, access controls, DevOps, and AI readiness. Each module includes its own checks and assessment categories, giving you more than a list of individual findings: a complete view of how mature and future-ready your Salesforce platform is. We bring the results together in a clear executive summary and a prioritised Action Plan.
Data Model
28 checksCustom objects, fields, relationships, and field utilisation across the whole data model.
Data Governance
12 checksValidation rules, duplicate rules, matching rules, and their documentation quality.
Access Control
30 checksProfiles, permission sets, permission set groups, sharing rules, and field-level security.
Org Security
16 checksOrg-wide settings, SSL certificates, session security, login policies, and certificate expiry.
Apex Health
20 checksApex classes, triggers, test coverage, and the Apex actions exposed to Flows and agents.
Automation
25 checksFlows, workflow rules, Process Builder, and approval processes, including legacy automation.
Agentforce
18 checksPrompts, agents, actions, subagents, knowledge articles, and Einstein feature configuration.
Integrations
14 checksNamed credentials, connected apps, remote site settings, auth providers, and browser security.
Packages
8 checksInstalled managed and unmanaged packages, license expiry dates, and deprecation status.
User Health
10 checksActive users, license utilisation, MFA enforcement, frozen accounts, and admin hygiene.
UI Components
15 checksAura components, LWCs, Visualforce pages, and SLDS 2 compliance across the UI layer.
Layouts
10 checksPage layouts, Lightning record pages, and mobile parity across object families.
Reports & Dashboards
12 checksReports, dashboards, folder structure, ownership, and staleness across the analytics layer.
DevOps
10 checksDeployment history from the Metadata API, regardless of whether your team ships via change sets, SF CLI, or a DevOps tool.
Object Maturity
CompositeComposite score that rolls up field quality, automation load, data model complexity, and permission scope into one score per object.
Individual Criteria in Detail
The maturity scores across the 15 modules draw on more than 200 individual criteria. The six examples below show which aspects of your org we examine more closely. They range from the complexity of a single Flow to fields that should be classified before any AI is switched on.
Flow Complexity Analysis
AutomationCounts elements, decision branches, loops, and nesting depth per flow. Flags flows exceeding 40 elements or 3+ nested loops as high complexity.
Recursive Flow Detection
AutomationTraces cross-object field update chains to detect flows that trigger themselves indirectly. Identifies self-referencing record-update paths.
GDPR / PII Field Risk Detection
Data ModelReviews all 2,700+ custom field API names and labels against a PII risk dictionary (national ID, IBAN, passport, payment data, health status) to flag fields requiring formal data classification before AI grounding.
Organization-Wide Defaults Set to Public Read/Write
Access ControlMaps all org-wide sharing defaults against object-level sensitive fields, quantifying how broadly AI agents (and every internal user) can read and modify records without explicit sharing context.
Flow Bypass Mechanism Audit
AutomationChecks whether record-triggered flows include a Custom Metadata or Feature Flag bypass switch, a deployment prerequisite for sandbox data scripts and migrations that should not trigger live automation.
Named Credential Architecture Review
IntegrationsDetects integrations still using the pre-API v55 single-credential model, which cannot support the per-user OAuth contexts required by AI agent callouts and modern external services.
How this assessment is produced
Every score comes together in two steps. First, deterministic, versioned checks run against your metadata, so the same org produces the same result on every run. We then review those findings and translate them into a maturity baseline you can act on today and re-measure at the next assessment.
Reproducible
Same org, same score on every run. Findings do not drift between assessments.
Release-current
Checks are kept current with each Salesforce release (Spring, Summer, Winter).
Traceable
Every finding maps to a concrete metadata pattern, not a model's interpretation.
One executive PDF. Typically within 5 to 10 business days.
What you receive is a single PDF report with three layers for different readers: an executive summary for the overview, an architect deep-dive for the technical detail, and a developer punch list for the work itself. It comes in English or German, by email, with no portal, account, or subscription.
- Format
- Executive PDF
- Scope
- 15 modules + cross-module executive summary
- Turnaround
- Typically 5 to 10 business days after access is granted
- Language
- English or German
- Audiences
- Executive summary · Architect deep-dive · Developer punch list
What we need from you
- A Salesforce org (Production, Sandbox, or Scratch), any edition from Professional to Unlimited
- A read-only OAuth connection via External Client App (~30 minutes to set up, guided)
- A named integration user with metadata read permissions, revocable at any time
Want this for your org?
Book a free 30-minute discovery call. In it, we identify which points matter most to you and focus the assessment accordingly. You then receive your executive report within 5 to 10 business days after access is granted.
Book a Discovery Call