Skip to main content
Recurring Assessment
Best Long-Term Value

Recurring Platform Reviews

Keep your Salesforce org on course for the long term and catch adverse trends before they take hold. At regular intervals we review what has changed since the last review and surface new technical debt, deviations from your architecture standards, and patterns worth revisiting. That includes the changes AI coding agents introduce between two reviews.

01What we see

Why regular reviews are worth it

A one-time assessment shows how your org stands today. It does not keep that state in place, though. Salesforce orgs change constantly. New features, projects, automations, and releases bring a steady stream of change into the platform.

Under real delivery pressure, shortcuts, inconsistent patterns, or technical debt creep in quickly. Especially as more and more development work is supported by AI coding agents, a lot of change can arrive in a short time — changes that work, but that bypass your existing architecture and quality standards.

Recurring platform reviews give you a fixed checkpoint here. We compare your current org against a defined baseline, evaluate the changes that matter, and show you where the platform is drifting in an unfavourable direction.

02The Process

How it works

1

Define the Baseline

At the outset we establish a reliable reference state for your org. We build on the results of an existing Platform Assessment, or start with a baseline assessment of our own.

This reference state becomes the basis for every review that follows, so new or changed structures can be spotted and placed in context.

2

Regular Deep-Dive Review

Each quarter, or after every major Salesforce release (the Spring, Summer, and Winter cadence), we examine what has changed since the last review.

We look beyond the obvious metadata changes and pay particular attention to new patterns that can lead to maintenance effort, security exposure, or architecture patterns that are hard to maintain over time.

3

Documenting Changes and Regressions

We bring the relevant deviations together in a delta report. You can see clearly what has changed, which developments are harmless, and where action is needed.

That includes, for example, new Apex classes, Flows, or automations that do not follow established architecture and development standards. Changes introduced by AI coding agents can be surfaced this way too, between one review and the next.

4

Reviewing the Findings Together

In a shared architecture review, we talk through the most important changes and their impact on your platform. We prioritise what needs attention and give concrete recommendations for the road ahead.

Where the reviews reveal new patterns or recurring findings, we can also derive adjustments to your development guidelines and architecture standards from them.

03What the engagement covers

Engagement scope

Recurring analysis of your Salesforce org for relevant changes
Changes documented in a structured delta report (PDF)
Detection of newly emerging technical debt and patterns worth revisiting
Comparison against your org's defined baseline
Assessment of changes in code, Flows, automations, and relevant metadata
Coverage of changes introduced by AI coding agents
Updated maturity and architecture assessment
Recommendations to prevent recurring architecture and quality drift
Recurring architect strategy session to put the results in context
04
Engagement Scope

All Modules at a Glance

During the Platform Assessment, we examine 15 topic areas, each forming its own module. These range from architecture and data modelling to automation, code, access controls, DevOps, and AI readiness. Each module includes its own checks and assessment categories, giving you more than a list of individual findings: a complete view of how mature and future-ready your Salesforce platform is. We bring the results together in a clear executive summary and a prioritised Action Plan.

200+ checks
01

Data Model

28 checks

Custom objects, fields, relationships, and field utilisation across the whole data model.

Field UtilisationNamingDescriptions & Help TextAI Readiness
02

Data Governance

12 checks

Validation rules, duplicate rules, matching rules, and their documentation quality.

Validation RulesDuplicate RulesMatching RulesDescriptions
03

Access Control

30 checks

Profiles, permission sets, permission set groups, sharing rules, and field-level security.

Profile SprawlPermission SetsField-Level SecuritySharing Model
04

Org Security

16 checks

Org-wide settings, SSL certificates, session security, login policies, and certificate expiry.

Session SecuritySSL CertificatesLogin PoliciesOrg Settings
05

Apex Health

20 checks

Apex classes, triggers, test coverage, and the Apex actions exposed to Flows and agents.

Code QualityTest CoverageGovernor LimitsSecurity
06

Automation

25 checks

Flows, workflow rules, Process Builder, and approval processes, including legacy automation.

Flow ComplexityTrigger OrderLegacy PatternsError Handling
07

Agentforce

18 checks

Prompts, agents, actions, subagents, knowledge articles, and Einstein feature configuration.

Prompt ArchitectureAgent ActionsSubagent CoverageGrounding Sources
08

Integrations

14 checks

Named credentials, connected apps, remote site settings, auth providers, and browser security.

Named CredentialsConnected AppsRemote SitesAuth Providers
09

Packages

8 checks

Installed managed and unmanaged packages, license expiry dates, and deprecation status.

Installed PackagesLicense ExpiryDeprecation StatusDependencies
10

User Health

10 checks

Active users, license utilisation, MFA enforcement, frozen accounts, and admin hygiene.

Active AccountsLicense UtilisationMFA EnforcementInactive Accounts
11

UI Components

15 checks

Aura components, LWCs, Visualforce pages, and SLDS 2 compliance across the UI layer.

LWC AdoptionLegacy ComponentsSLDS 2 ComplianceHardcoded Styles
12

Layouts

10 checks

Page layouts, Lightning record pages, and mobile parity across object families.

AssignmentsField PlacementLightning AdoptionMobile Parity
13

Reports & Dashboards

12 checks

Reports, dashboards, folder structure, ownership, and staleness across the analytics layer.

StalenessOwnershipFolder HygieneUnused Assets
14

DevOps

10 checks

Deployment history from the Metadata API, regardless of whether your team ships via change sets, SF CLI, or a DevOps tool.

Deployment VelocityClickOps DetectionSandbox StrategyRelease Patterns
15

Object Maturity

Composite

Composite score that rolls up field quality, automation load, data model complexity, and permission scope into one score per object.

Field QualityAutomation LoadData Model ComplexityPermission Scope
05FAQ

Common questions

06Engagement & Pricing

Tailored to your org

A recurring review is not a standardised scan run against every org by the same rules. We take the specific architecture of your platform, its development history, and its current goals into account.

So the scope depends on how large and complex your org is, how many environments you want covered, and which areas matter most to you.

What shapes the scope

  • Size and complexity of the org
    The larger and more bespoke your org, the more change there is to account for over time — for example custom objects, Apex classes and triggers, Flows, Visualforce, and other custom work.
  • Number of orgs and environments
    We can look at a single production org or monitor several production environments together. That makes sense, for example, when orgs are merged after an acquisition, when business units develop separately, or during an international rollout.
  • Desired scope of analysis
    Not every change matters equally to every organisation. So we tune the review to your goals and agree which areas to look at regularly, and in how much depth.
  • Integration landscape
    The systems around Salesforce can matter for the assessment too. Depending on the environment, we take Connected Apps, external systems, relevant credentials, and the existing sandboxes into account.
  • Development and AI practice
    As your team works more with AI coding agents, we can focus the review on the changes those development processes produce. That makes it easy to see early whether AI-generated code and automations line up with your existing architecture and quality standards.
  • Advisory support
    On request, we go beyond the regular review and support your team through implementation. In additional sessions we can prioritise specific findings, sharpen development guidelines, or define new architecture standards for future initiatives.

From assessment to continuous quality

The one-time Platform Assessment gives you a solid baseline and defines where your org stands today. The recurring platform reviews build on it and make sure that quality is not quietly lost.

A one-time snapshot turns into a continuous quality process that makes change visible, catches technical debt early, and helps your team keep the platform on course over the long term.

Get Started

Let's keep your org on course together

Book a free 30-minute discovery call. We'll look at your current setup together and discuss what scope makes sense for your org. You'll then receive a proposal tailored to your situation – with no obligation.