A Salesforce data risk assessment is a structured review of how data is accessed, exported, and governed inside a Salesforce org. It helps reveal overexposed permissions, inactive accounts, risky integrations, and unusual user activity so security teams can reduce breach, privacy, and compliance risk.
What Salesforce Data Risk Assessment Covers
A Salesforce data risk assessment is not just a permissions review. It looks at where business data can be viewed, copied, exported, synced, or exposed through users, integrations, and automation, then measures how much sensitive information is reachable.
That broader view matters because Salesforce often sits at the center of customer records, sales activity, support cases, and connected apps. A weak assessment misses the paths that attackers and insiders actually use, especially when access is inherited through roles, OAuth connections, or third-party apps.
Core Data Exposure Areas
The first priority is understanding which data sets are most exposed and by whom. That includes profiles and permission sets, shared records, report access, API visibility, file attachments, and export rights, along with any object or field level permissions that reveal more than intended.
Inactive accounts and stale access deserve special attention because they can quietly retain reach long after business need has changed. In practical terms, the assessment should also cover system users, connected apps, and delegated access paths that may bypass normal user workflows.
Integrations, Tokens, and Export Paths
Salesforce risk is often created outside Salesforce itself, especially through connected applications and vendor integrations. OAuth grants, API tokens, SSO links, and synchronized data flows can extend access far beyond the original user boundary, which is why integration review is a core part of the assessment.
For that reason, the most serious findings are often not obvious UI misconfigurations but trust relationships that are too broad or too persistent. A compromised third-party app, stolen token, or overbroad integration can turn a small access issue into large-scale data exposure.
NHIMG’s Salesloft OAuth token breach and Klue OAuth Supply Chain Breach show why token and integration review belongs inside a Salesforce data risk assessment, not as an afterthought.
What Good Assessment Output Should Show
A useful assessment should distinguish high-risk data, high-risk identities, and high-risk connections. The output is not just a list of findings, it is a map of which controls are failing, which data is most exposed, and which access paths create the highest likelihood of breach or privacy impact.
That makes the assessment useful for security, privacy, and compliance teams at the same time. It also gives administrators a clear basis for reducing exposure without breaking business workflows, which is the central trade-off in Salesforce governance.
Relevant external reference points for this kind of review include the CSA Cloud Controls Matrix, the SOC 2 Trust Services Criteria (AICPA), and the NIST SP 800-53 Rev 5 Security and Privacy Controls.
Risk and Threat Considerations
Salesforce becomes risky when excess access, dormant accounts, or connected-app trust gaps let sensitive data move farther than the business expects. The main danger is not a single weak setting, but the combination of broad permissions, long-lived tokens, and high-value data concentrated in one platform.
Failure mechanism: Attackers, insiders, or compromised integrations can abuse overprivileged access, export rights, or stolen OAuth grants to read records, move data out of the org, or pivot into connected systems.
Impact: The result can be customer-data exposure, privacy incidents, unauthorized disclosure of commercial records, and a larger blast radius than the original access issue suggests.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP API Security Top 10 address the attack and risk surface, while CSA Cloud Controls Matrix, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | Salesforce data exposure depends on identity, access, and shared trust across cloud connections. |
| DSP — Data Security and Privacy | The assessment centers on exposing, exporting, and governing sensitive business data in Salesforce. | |
| AIS — Application and Interface Security | Connected apps, API links, and OAuth flows are material to Salesforce data risk assessment. | |
| Recommendation — Map Salesforce users, admins, and integrations to IAM controls and reduce access to the minimum needed. Classify Salesforce data sets and apply privacy and protection controls to high-risk records and fields. Review Salesforce integrations and enforce tighter controls on application-to-application access paths. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication and Access Control | Directly addresses limiting and governing access to data and services in a cloud application. |
| Recommendation — Restrict Salesforce access with least-privilege identity and access controls. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Inactive accounts and overbroad user access are central findings in Salesforce reviews. |
| Recommendation — Review and remove unnecessary Salesforce accounts and access paths. | ||
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | OAuth tokens and integration secrets can expose Salesforce data when leaked or stolen. |
| NHI-05 — Overprivileged NHI | Connected apps and service identities can hold excessive access to Salesforce data. | |
| NHI-07 — Long-Lived Secrets | Persistent tokens make Salesforce integration exposure last longer than intended. | |
| Recommendation — Prevent Salesforce integration secrets from leaking into logs, code, or exposed stores. Reduce integration privileges to only the Salesforce data and actions they need. Replace long-lived Salesforce tokens with tighter rotation and expiry controls. | ||
| OWASP API Security Top 10 | API2 — Broken Authentication | API-linked access and token misuse are common paths into Salesforce data. |
| API5 — Broken Function Level Authorization | Salesforce risk assessments often find users or apps can perform actions they should not. | |
| Recommendation — Harden authentication for Salesforce APIs and connected applications. Verify Salesforce functions and admin actions are authorized at the right level. | ||
Practitioner Guidance
Governance implication: Treat Salesforce assessment as an access-and-data-governance exercise, not a one-time configuration check. The highest-value findings usually come from reviewing who can access data, how long that access lasts, and which integrations inherit it.
What to watch for: Pay special attention to exported reports, connected apps, stale accounts, and any workflow where business users, admins, and third-party tools all touch the same data sets. Those are the paths most likely to hide excessive exposure.
Related resources from NHI Mgmt Group
- Why do Salesforce workflows create hidden HIPAA risk when PHI is embedded in support data?
- Why do personal data disclosures in Salesforce create governance and compliance risk?
- Why do Salesforce environments create more data exposure risk than many security teams expect?
- Why do AI agents accessing Salesforce through MCP increase data exposure risk?