Skip to main content
Scope

What We Review

Our comprehensive analysis framework considers only the structure of your org. We therefore read only metadata and aggregate statistics, never your business data.

What we read

  • Metadata: objects, fields, Flows, Apex, and configuration
  • Aggregate statistics and usage counts
  • Naming, descriptions, and the structure of your org
  • Permissions, profiles, and the sharing model
  • User Health basics: name, email, role, last login, MFA status (this module can be excluded on request)

What we never touch

  • Business records: Accounts, Contacts, Opportunities, and custom records
  • Attachments, Files, and Chatter posts
  • Email messages, tasks, events, and private notes
  • Financial data: pricing, contract values, commission amounts
  • Personal data beyond the User Health basics
01
Engagement Scope

All Modules at a Glance

During the Platform Assessment, we examine 15 topic areas, each forming its own module. These range from architecture and data modelling to automation, code, access controls, DevOps, and AI readiness. Each module includes its own checks and assessment categories, giving you more than a list of individual findings: a complete view of how mature and future-ready your Salesforce platform is. We bring the results together in a clear executive summary and a prioritised Action Plan.

200+ checks
01

Data Model

28 checks

Custom objects, fields, relationships, and field utilisation across the whole data model.

Field UtilisationNamingDescriptions & Help TextAI Readiness
02

Data Governance

12 checks

Validation rules, duplicate rules, matching rules, and their documentation quality.

Validation RulesDuplicate RulesMatching RulesDescriptions
03

Access Control

30 checks

Profiles, permission sets, permission set groups, sharing rules, and field-level security.

Profile SprawlPermission SetsField-Level SecuritySharing Model
04

Org Security

16 checks

Org-wide settings, SSL certificates, session security, login policies, and certificate expiry.

Session SecuritySSL CertificatesLogin PoliciesOrg Settings
05

Apex Health

20 checks

Apex classes, triggers, test coverage, and the Apex actions exposed to Flows and agents.

Code QualityTest CoverageGovernor LimitsSecurity
06

Automation

25 checks

Flows, workflow rules, Process Builder, and approval processes, including legacy automation.

Flow ComplexityTrigger OrderLegacy PatternsError Handling
07

Agentforce

18 checks

Prompts, agents, actions, subagents, knowledge articles, and Einstein feature configuration.

Prompt ArchitectureAgent ActionsSubagent CoverageGrounding Sources
08

Integrations

14 checks

Named credentials, connected apps, remote site settings, auth providers, and browser security.

Named CredentialsConnected AppsRemote SitesAuth Providers
09

Packages

8 checks

Installed managed and unmanaged packages, license expiry dates, and deprecation status.

Installed PackagesLicense ExpiryDeprecation StatusDependencies
10

User Health

10 checks

Active users, license utilisation, MFA enforcement, frozen accounts, and admin hygiene.

Active AccountsLicense UtilisationMFA EnforcementInactive Accounts
11

UI Components

15 checks

Aura components, LWCs, Visualforce pages, and SLDS 2 compliance across the UI layer.

LWC AdoptionLegacy ComponentsSLDS 2 ComplianceHardcoded Styles
12

Layouts

10 checks

Page layouts, Lightning record pages, and mobile parity across object families.

AssignmentsField PlacementLightning AdoptionMobile Parity
13

Reports & Dashboards

12 checks

Reports, dashboards, folder structure, ownership, and staleness across the analytics layer.

StalenessOwnershipFolder HygieneUnused Assets
14

DevOps

10 checks

Deployment history from the Metadata API, regardless of whether your team ships via change sets, SF CLI, or a DevOps tool.

Deployment VelocityClickOps DetectionSandbox StrategyRelease Patterns
15

Object Maturity

Composite

Composite score that rolls up field quality, automation load, data model complexity, and permission scope into one score per object.

Field QualityAutomation LoadData Model ComplexityPermission Scope
02

Individual Criteria in Detail

The maturity scores across the 15 modules draw on more than 200 individual criteria. The six examples below show which aspects of your org we examine more closely. They range from the complexity of a single Flow to fields that should be classified before any AI is switched on.

01

Flow Complexity Analysis

Automation

Counts elements, decision branches, loops, and nesting depth per flow. Flags flows exceeding 40 elements or 3+ nested loops as high complexity.

02

Recursive Flow Detection

Automation

Traces cross-object field update chains to detect flows that trigger themselves indirectly. Identifies self-referencing record-update paths.

03

GDPR / PII Field Risk Detection

Data Model

Reviews all 2,700+ custom field API names and labels against a PII risk dictionary (national ID, IBAN, passport, payment data, health status) to flag fields requiring formal data classification before AI grounding.

04

Organization-Wide Defaults Set to Public Read/Write

Access Control

Maps all org-wide sharing defaults against object-level sensitive fields, quantifying how broadly AI agents (and every internal user) can read and modify records without explicit sharing context.

05

Flow Bypass Mechanism Audit

Automation

Checks whether record-triggered flows include a Custom Metadata or Feature Flag bypass switch, a deployment prerequisite for sandbox data scripts and migrations that should not trigger live automation.

06

Named Credential Architecture Review

Integrations

Detects integrations still using the pre-API v55 single-credential model, which cannot support the per-user OAuth contexts required by AI agent callouts and modern external services.

03Methodology

How this assessment is produced

Every score comes together in two steps. First, deterministic, versioned checks run against your metadata, so the same org produces the same result on every run. We then review those findings and translate them into a maturity baseline you can act on today and re-measure at the next assessment.

Reproducible

Same org, same score on every run. Findings do not drift between assessments.

Release-current

Checks are kept current with each Salesforce release (Spring, Summer, Winter).

Traceable

Every finding maps to a concrete metadata pattern, not a model's interpretation.

04
Engagement output

One executive PDF. Typically within 5 to 10 business days.

What you receive is a single PDF report with three layers for different readers: an executive summary for the overview, an architect deep-dive for the technical detail, and a developer punch list for the work itself. It comes in English or German, by email, with no portal, account, or subscription.

Format
Executive PDF
Scope
15 modules + cross-module executive summary
Turnaround
Typically 5 to 10 business days after access is granted
Language
English or German
Audiences
Executive summary · Architect deep-dive · Developer punch list
05
Prerequisites

What we need from you

  • A Salesforce org (Production, Sandbox, or Scratch), any edition from Professional to Unlimited
  • A read-only OAuth connection via External Client App (~30 minutes to set up, guided)
  • A named integration user with metadata read permissions, revocable at any time

Want this for your org?

Book a free 30-minute discovery call. In it, we identify which points matter most to you and focus the assessment accordingly. You then receive your executive report within 5 to 10 business days after access is granted.

Book a Discovery Call