Recurring Platform Reviews
Keep your Salesforce org on course for the long term and catch adverse trends before they take hold. At regular intervals we review what has changed since the last review and surface new technical debt, deviations from your architecture standards, and patterns worth revisiting. That includes the changes AI coding agents introduce between two reviews.
Why regular reviews are worth it
A one-time assessment shows how your org stands today. It does not keep that state in place, though. Salesforce orgs change constantly. New features, projects, automations, and releases bring a steady stream of change into the platform.
Under real delivery pressure, shortcuts, inconsistent patterns, or technical debt creep in quickly. Especially as more and more development work is supported by AI coding agents, a lot of change can arrive in a short time — changes that work, but that bypass your existing architecture and quality standards.
Recurring platform reviews give you a fixed checkpoint here. We compare your current org against a defined baseline, evaluate the changes that matter, and show you where the platform is drifting in an unfavourable direction.
How it works
Define the Baseline
At the outset we establish a reliable reference state for your org. We build on the results of an existing Platform Assessment, or start with a baseline assessment of our own.
This reference state becomes the basis for every review that follows, so new or changed structures can be spotted and placed in context.
Regular Deep-Dive Review
Each quarter, or after every major Salesforce release (the Spring, Summer, and Winter cadence), we examine what has changed since the last review.
We look beyond the obvious metadata changes and pay particular attention to new patterns that can lead to maintenance effort, security exposure, or architecture patterns that are hard to maintain over time.
Documenting Changes and Regressions
We bring the relevant deviations together in a delta report. You can see clearly what has changed, which developments are harmless, and where action is needed.
That includes, for example, new Apex classes, Flows, or automations that do not follow established architecture and development standards. Changes introduced by AI coding agents can be surfaced this way too, between one review and the next.
Reviewing the Findings Together
In a shared architecture review, we talk through the most important changes and their impact on your platform. We prioritise what needs attention and give concrete recommendations for the road ahead.
Where the reviews reveal new patterns or recurring findings, we can also derive adjustments to your development guidelines and architecture standards from them.
Engagement scope
All Modules at a Glance
During the Platform Assessment, we examine 15 topic areas, each forming its own module. These range from architecture and data modelling to automation, code, access controls, DevOps, and AI readiness. Each module includes its own checks and assessment categories, giving you more than a list of individual findings: a complete view of how mature and future-ready your Salesforce platform is. We bring the results together in a clear executive summary and a prioritised Action Plan.
Data Model
28 checksCustom objects, fields, relationships, and field utilisation across the whole data model.
Data Governance
12 checksValidation rules, duplicate rules, matching rules, and their documentation quality.
Access Control
30 checksProfiles, permission sets, permission set groups, sharing rules, and field-level security.
Org Security
16 checksOrg-wide settings, SSL certificates, session security, login policies, and certificate expiry.
Apex Health
20 checksApex classes, triggers, test coverage, and the Apex actions exposed to Flows and agents.
Automation
25 checksFlows, workflow rules, Process Builder, and approval processes, including legacy automation.
Agentforce
18 checksPrompts, agents, actions, subagents, knowledge articles, and Einstein feature configuration.
Integrations
14 checksNamed credentials, connected apps, remote site settings, auth providers, and browser security.
Packages
8 checksInstalled managed and unmanaged packages, license expiry dates, and deprecation status.
User Health
10 checksActive users, license utilisation, MFA enforcement, frozen accounts, and admin hygiene.
UI Components
15 checksAura components, LWCs, Visualforce pages, and SLDS 2 compliance across the UI layer.
Layouts
10 checksPage layouts, Lightning record pages, and mobile parity across object families.
Reports & Dashboards
12 checksReports, dashboards, folder structure, ownership, and staleness across the analytics layer.
DevOps
10 checksDeployment history from the Metadata API, regardless of whether your team ships via change sets, SF CLI, or a DevOps tool.
Object Maturity
CompositeComposite score that rolls up field quality, automation load, data model complexity, and permission scope into one score per object.
Common questions
No. Each Platform Review is scoped and billed as a separate engagement based on hours worked. There is no auto-renewal and no fixed term. After each review, you decide for yourself whether and when another review makes sense.
Ideally yes, but it is not strictly required. For recurring reviews we need a reliable reference state to compare later changes against. If a current Platform Assessment already exists, we can use its results as the starting point. If not, we can define the reference state together as part of the first review.
We usually recommend a quarterly cadence, or a custom one that matches your release and development activity. For many orgs, a review after every major Salesforce release works well. If your rate of change is especially high, your projects are large, or you use AI coding agents intensively, a shorter interval can make sense.
The Platform Assessment answers where your org stands today and which improvements make sense. The recurring Platform Review, by contrast, looks at how things develop over time. We compare the current state against a defined reference state and make visible what has changed since the last review, and whether new findings or technical debt arise from it.
No, it complements it. Your team's QA checks, for example, whether new features work technically and functionally. The Platform Review is about the long-term quality of the platform. We look at patterns, dependencies, and changes that are easy to miss in day-to-day development and that can make your org harder to maintain over time.
Yes. With AI-assisted development in particular, it matters to look not just at individual changes but at their impact on the existing architecture. We can detect, for example, when newly created Apex code, Flow automations, or other metadata deviate from established patterns and development guidelines. That makes it visible whether the speed AI brings leads to additional technical debt over the long term.
An automated analysis can surface plenty of signals. For reliable regression tracking, though, what matters is that the assessment stays comparable between two runs.
Our reviews are therefore built on a versioned, traceable assessment approach. The reference state stays stable, and changes are evaluated deliberately against it. That lets us tell whether your org has actually changed or the assessment simply came out differently. It is exactly this comparability that makes regular reviews valuable for catching regressions.
You receive a structured delta report documenting the relevant changes since the last review. In it, we distinguish between harmless changes and findings that need action.
You also receive an updated assessment of your org's technical state and concrete recommendations for the next steps. We then discuss the results together in an architecture session.
We keep the effort for your team as low as possible. For the analysis we need access to the relevant metadata and, depending on the agreed scope, information about recent developments or notable changes in your org.
If there have been larger projects, migrations, new integrations, or a shift in how you use AI coding agents since the last review, it helps to know about those developments in advance. That lets us place the results in context and evaluate relevant changes more precisely.
Yes. Not every org needs the same depth of review each time. We can adapt the scope to your current situation and, for example, put more weight on code, automation, permissions, architecture, or AI-relevant changes.
That is especially useful when your development activity between two reviews concentrates on particular areas, or when a specific project carries particular impact for the platform.
Yes. We can look at several production orgs or environments together, as long as a comparison makes sense for your situation. That can be relevant for international Salesforce landscapes, after a merger, or with separately developed business units.
Together we define which orgs serve as the reference and which changes should be looked at across all of them.
Tailored to your org
A recurring review is not a standardised scan run against every org by the same rules. We take the specific architecture of your platform, its development history, and its current goals into account.
So the scope depends on how large and complex your org is, how many environments you want covered, and which areas matter most to you.
What shapes the scope
- Size and complexity of the orgThe larger and more bespoke your org, the more change there is to account for over time — for example custom objects, Apex classes and triggers, Flows, Visualforce, and other custom work.
- Number of orgs and environmentsWe can look at a single production org or monitor several production environments together. That makes sense, for example, when orgs are merged after an acquisition, when business units develop separately, or during an international rollout.
- Desired scope of analysisNot every change matters equally to every organisation. So we tune the review to your goals and agree which areas to look at regularly, and in how much depth.
- Integration landscapeThe systems around Salesforce can matter for the assessment too. Depending on the environment, we take Connected Apps, external systems, relevant credentials, and the existing sandboxes into account.
- Development and AI practiceAs your team works more with AI coding agents, we can focus the review on the changes those development processes produce. That makes it easy to see early whether AI-generated code and automations line up with your existing architecture and quality standards.
- Advisory supportOn request, we go beyond the regular review and support your team through implementation. In additional sessions we can prioritise specific findings, sharpen development guidelines, or define new architecture standards for future initiatives.
From assessment to continuous quality
The one-time Platform Assessment gives you a solid baseline and defines where your org stands today. The recurring platform reviews build on it and make sure that quality is not quietly lost.
A one-time snapshot turns into a continuous quality process that makes change visible, catches technical debt early, and helps your team keep the platform on course over the long term.
Let's keep your org on course together
Book a free 30-minute discovery call. We'll look at your current setup together and discuss what scope makes sense for your org. You'll then receive a proposal tailored to your situation – with no obligation.