By NHI Mgmt Group Editorial TeamBased on Cyera: “Are Your Salesforce Permissions Protecting You - or Exposing You?” (November 12, 2025)

TL;DR: Over 80% of Salesforce access is still managed through profiles, a quarter of users rely only on profiles, and some environments have 30% admin-level access, creating rigidity, overexposure, and audit problems according to Cyera Research Labs. Static access models are failing because Salesforce governance must behave like a living control process, not a one-time configuration.


At a glance

What this is: Cyera’s analysis shows that Salesforce permission sprawl is creating overexposure, with profiles carrying too much access and admin-level rights appearing too broadly.

Why it matters: IAM and IGA teams should treat Salesforce access as an ongoing governance model, because excessive privilege in a core customer-data platform can quickly turn into privacy, compliance, and operational risk.


Context

Salesforce permission sprawl is a governance problem, not just an administration problem. When profiles carry too much access and admin rights spread beyond a small trusted group, the platform stops behaving like a controlled access layer and starts behaving like a broad exposure surface for customer data.

Cyera’s analysis argues that the control model has drifted away from Salesforce best practice. The issue is not whether access exists, but whether the access architecture still supports least privilege, reviewability, and role boundaries as teams and integrations change.

For identity programmes, the question is whether Salesforce access is being governed as a living entitlement model or left as a static configuration. The article’s core point is that the latter creates audit friction, excessive privilege, and silent overexposure.


Key questions

Q: What breaks when Salesforce access is built mainly on profiles?

A: Profiles become overloaded with exceptions, which makes least privilege hard to maintain and even harder to audit. Because a single profile change affects every assigned user, control becomes rigid, overexposure spreads quietly, and small role changes turn into broad entitlement changes. The model stops supporting scalable governance and starts preserving legacy access.

Q: Why do excessive Salesforce permissions create such a high risk of data loss and misuse?

A: Excessive permissions turn ordinary users into high-impact risk points. If someone can export reports, use APIs, or log in with elevated rights, they may remove sensitive data, share it externally, or change controls that protect the org. The problem is not just malicious intent. Overbroad access also increases the chance of accidental exposure, compromised credentials, and untracked third-party activity.

Q: How do security teams know whether Salesforce access reviews are actually working?

A: Access reviews are working only if they remove stale privileges before they become usable in production. Good signals include fewer dormant service accounts, faster revocation after role or workflow changes, and audit logs that consistently match approved principals to real activity. If reviews happen but access patterns do not change, the process is cosmetic.

Q: What should IAM teams do when Salesforce admin access is too broad?

A: Revalidate every elevated assignment against current job duties, remove standing admin access that is not essential, and move temporary elevation into a governed approval process. The objective is to shrink the number of people who can alter or expose all records and to make any exception easy to track and recertify.


Technical breakdown

Why profile sprawl breaks least privilege in Salesforce

Salesforce profiles define baseline access, but they are not meant to carry every role-specific permission. When organisations keep adding access to profiles, each profile becomes a dense bundle of entitlements that is hard to review and hard to change safely. That creates profile sprawl: too many variants, too much inherited access, and too much risk when one profile change affects all assigned users. Permission sets exist to separate baseline access from additional privilege, which is what makes the model scalable.

Practical implication: keep profiles minimal and push role-specific access into permission sets and groups.

How high-privilege permissions override the sharing model

Permissions such as View All Data and Modify All Data bypass the normal record-sharing logic that limits who can see or edit data. In practice, these privileges collapse granular access controls into org-wide visibility or org-wide write access. That is why they behave like nuclear buttons: once assigned, they can defeat the intended separation between ordinary users and administrators. This is not just a usability shortcut. It changes the trust boundary for the entire Salesforce organisation.

Practical implication: treat override permissions as exceptional access and review every assignment as if it were a privileged access grant.

Why admin-level access becomes a governance failure

Administrator access is supposed to be rare, task-bound, and tightly governed. When a large share of users hold admin rights, the organisation loses any meaningful distinction between operators and ordinary business users. That weakens separation of duties, makes misconfiguration more likely, and creates a larger blast radius for mistakes or abuse. The article’s example of 30% admin-level access is not just a permissions problem. It is evidence that role design, review cadence, and access ownership have broken down.

Practical implication: cap admin distribution, verify business justification, and recertify elevated access regularly.


NHI Mgmt Group analysis

Salesforce permission sprawl is a governance failure before it is a security failure. When profiles absorb too much access, the control model stops separating baseline access from role-specific privilege. That makes least privilege difficult to apply and even harder to prove during audit. The practical conclusion is that Salesforce access has to be governed as a living entitlement model, not a static setup.

Profile-heavy access creates a rigidity debt that compounds over time. If a quarter of users rely only on profiles, the organisation is depending on a coarse access structure that resists change. That pattern makes small business adjustments expensive and pushes teams toward broad permissions instead of reusable entitlement building blocks. The result is not just inefficiency. It is a persistent overexposure problem that keeps reappearing in new forms.

High-privilege permissions should be treated as a blast-radius control issue. View All Data and Modify All Data do not merely expand convenience for administrators. They redefine how far a single account can reach if it is misused or misassigned. In identity terms, the governance question is not whether access exists, but how quickly that access can be narrowed back down when roles change. Practitioners should read broad admin assignments as an indicator that entitlement governance is losing containment.

Salesforce access models must be designed for reviewability, not just assignment. A control that cannot be recertified cleanly is already failing its governance purpose. When permissions are spread through profiles and elevated roles are common, access reviews turn into archaeology instead of validation. The named concept here is profile sprawl: a condition where the base access layer becomes overloaded with exceptions, making the system harder to govern with each exception added.

This article points to a shift from permission administration to entitlement lifecycle management. The issue is not one bad setting but a control philosophy that treats access as a one-time configuration. Salesforce needs lifecycle governance because users, integrations, and business roles all change faster than static access models can absorb. The practitioner takeaway is that access design, review, and exception handling have to be managed as one continuous process.

What this signals

Salesforce governance should be treated as entitlement lifecycle management, not as one-off access administration. When profiles carry too much privilege, the real failure is not only exposure but the loss of a clean control boundary that can be reviewed, recertified, and safely changed as business roles evolve.

Profile sprawl: this is the point at which the base access layer becomes the place where exceptions accumulate, making governance brittle and audit evidence noisy. Teams that manage Salesforce this way usually discover that their access model is being preserved for convenience rather than for control.


For practitioners

  • Reduce profile complexity Strip profiles back to baseline access only, then move role-specific entitlements into permission sets and permission set groups.
  • Restrict override permissions Limit View All Data and Modify All Data to the smallest vetted admin group and require explicit business justification for every assignment.
  • Recertify elevated access Run regular access reviews on admin roles and other high-impact permissions, with special attention to temporary grants that tend to become permanent.
  • Measure role drift Track the share of users who rely only on profiles and the percentage holding admin access, then treat spikes as governance exceptions.
  • Align Salesforce access to job function Compare assigned permissions to actual responsibilities so that access changes follow role change rather than legacy configuration.

Key takeaways

  • Salesforce permission sprawl turns access governance into a structural risk when profiles absorb too much privilege and admin rights spread too widely.
  • Cyera Research Labs found that over 80% of access is still managed through profiles, a quarter of users rely only on profiles, and some environments reach 30% admin-level access.
  • The practical response is to compress baseline access, shift privilege into permission sets, and recertify elevated access as part of a living entitlement model.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsSalesforce profiles and permission sets are an entitlement governance issue.
Recommendation — Apply PR.AA-05 to keep Salesforce access aligned to role need and recertify broad entitlements.
CIS Controls v8CIS-5 — Account ManagementThe article is about managing privileged and routine access assignments.
Recommendation — Use CIS-5 to review Salesforce account access, remove excess admin rights, and keep assignments current.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeThe core problem is excessive access beyond role need.
Recommendation — Enforce AC-6 by limiting Salesforce privileges to the minimum required for each role.
ISO/IEC 27001:2022A.5.15 — Access controlSalesforce access governance maps directly to access control policy and review.
Recommendation — Apply A.5.15 to govern Salesforce access rights, review exceptions, and reduce overexposure.

Key terms

  • Profile Sprawl: Profile sprawl is the accumulation of too many profile variants to handle small access differences. It makes governance brittle because access logic gets buried in duplicated base configurations, which increases review effort and makes it harder to understand who can do what.
  • Permission Set: A permission set is an additive access package in Salesforce that grants extra privileges without changing the base profile. It is the preferred way to extend access because it keeps the underlying role definition small and makes review and reuse easier across different users and functions.
  • Override Permission: An override permission is a high-impact Salesforce entitlement such as View All Data or Modify All Data that bypasses normal record-level sharing. These permissions expand trust boundaries across the org and therefore require tighter approval, review, and recertification than ordinary access.
  • Entitlement Lifecycle: The entitlement lifecycle covers how access is created, reviewed, used, changed, and removed over time. Strong lifecycle control prevents old permissions from lingering after a role, project, or need has ended, which is essential for least privilege and audit readiness.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org