Manual reviews are usually failing when teams rely on spreadsheets, miss accounts, overlook excessive access, or cannot produce reliable audit evidence. Another warning sign is rubber-stamping, where reviewers approve access without checking whether it is still needed. As Salesforce usage grows and roles keep changing, manual processes become slower, more error-prone, and less able to surface real security or compliance issues.
What failure looks like in a manual Salesforce review cycle
Manual access reviews fail in very specific ways, and the warning signs are usually visible before a serious control breakdown. The process starts to lose value when it cannot keep pace with Salesforce change, when reviewers are working from stale data, or when approval decisions become routine rather than evidential. At that point, the review is still happening, but it is no longer reliably testing actual access risk.
A common pattern is that the review output begins to look complete while the underlying coverage is poor. That happens when teams depend on spreadsheets, export snapshots, or email threads that are hard to reconcile, especially in orgs with frequent role changes, multiple permission sources, and large numbers of accounts. In practice, the control fails first as a visibility problem and only later as an audit or compliance problem.
Another sign is that the review no longer distinguishes between appropriate and inappropriate access. If reviewers consistently approve broad access without checking job function, business need, or recent activity, the process has become a formality. For Salesforce specifically, this is more likely when permission sets, profiles, and shared operational responsibilities have grown faster than the review method itself can handle. The issue is not the presence of access, but the inability to judge whether it still belongs there.
Failure modes that show the process has lost control value
The most obvious failure mechanism is incomplete coverage. That can mean missing dormant accounts, service accounts, contractors, integration users, or users granted access through multiple paths that are never consolidated into one reviewer view. It can also mean that entitlements are checked at a high level but not at the level where risk actually lives, such as object permissions, field-level access, admin-like capabilities, or app-specific access paths.
Another failure mode is evidence weakness. If the organization cannot reproduce who approved what, when they approved it, what data they reviewed, and what exception was accepted, then the review may not stand up to audit scrutiny even if the checklist was technically completed. Reliable evidence should show that the reviewer saw the current entitlement set, not just a prior export or a summary row from a spreadsheet.
Scale makes the failure more visible. As Salesforce usage grows, manual reviews slow down, pile up exceptions, and encourage broad sign-off simply to finish on time. That is often the point where teams stop catching excessive access, stale access, and conflicting approvals. A useful benchmark is that manual review quality should improve with better data quality and tighter scope; if it only gets slower as the environment grows, the control is no longer fit for purpose. For deeper lifecycle and audit context, see Ultimate Guide to NHIs, lifecycle processes and its regulatory and audit perspectives.
- Coverage gaps, such as users, roles, or permissions that never reach the reviewer.
- Rubber-stamping, where approvals happen without testing ongoing business need.
- Stale exports, mismatched snapshots, or missing audit trails.
- Failure to spot broad access that is technically granted but operationally unjustified.
- Review cycles that take longer than the rate of access change.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6 — Access Control Management | Manual access reviews directly support account and entitlement governance in Salesforce. |
| 8 — Audit Log Management | Reliable review evidence depends on traceable approval and review records. | |
| 5 — Account Management | Missed, stale, or unowned Salesforce accounts are a core sign of failing reviews. | |
| Recommendation — Review and remove unnecessary Salesforce access on a recurring schedule. Retain review evidence that ties each approval to a specific account and reviewer. Inventory all Salesforce accounts and reconcile them before each access review. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication and Access Control | Salesforce reviews are intended to validate that access remains appropriate and controlled. |
| GV.RM — Risk Management Strategy | When manual reviews cannot keep pace, the control is no longer an effective risk treatment. | |
| DE.CM — Continuous Monitoring | Slow, stale, or incomplete reviews indicate inadequate monitoring of access change. | |
| Recommendation — Validate that Salesforce access remains authorized and aligned to business need. Escalate manual review breakdown as a control effectiveness and risk issue. Use continuous monitoring to detect Salesforce access drift between review cycles. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Visibility and Discovery | Missing accounts and poor coverage are visibility failures in access review programs. |
| NHI-06 — Lifecycle and Offboarding | Stale access and delayed removal are classic signs that the review lifecycle is broken. | |
| NHI-01 — Secret Management | If Salesforce access depends on tokens or integration credentials, review failure can leave them unchecked. | |
| Recommendation — Maintain an authoritative inventory of all Salesforce identities and entitlements. Remove stale Salesforce access promptly when a review identifies it. Track and rotate any Salesforce-linked credentials that fall outside human review coverage. | ||
Practitioner Guidance
What to verify: Confirm that each review uses a current entitlement source, not a hand-curated spreadsheet, and that every approval can be traced to a specific account, reviewer, date, and decision. If the evidence cannot distinguish active access from inherited or duplicated access, the review is too weak to trust.
Decision rule: If the review cannot reliably identify excessive access or missing accounts, treat it as a control-design problem rather than a reviewer-training problem. Rework the data feed, scope, and ownership model before asking reviewers to “be more careful.”
What practitioners underestimate: The hardest failure is not a missed account, it is normalization of weak scrutiny. Once reviewers learn that every cycle ends in approval anyway, the process stops functioning as an access control and becomes a record-keeping exercise.
Practitioner takeaway: A manual Salesforce review is failing when it no longer changes access decisions, only records them. The control is healthy only if it can still surface a specific account or permission set that someone is willing to challenge.
Related resources from NHI Mgmt Group
- What are the signs that manual Dropbox access reviews are failing in practice?
- What are the signs that manual Concur access reviews are failing?
- What are the signs that manual access reviews are failing in a code collaboration environment?
- What are the signs that DocuSign access reviews are failing in practice?