Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should security teams do first if Salesforce…
Governance, Ownership & Risk

What should security teams do first if Salesforce access has never been formally reviewed?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Governance, Ownership & Risk

Start with the highest-risk permissions. Verify that only administrators have the System Administrator profile, then map who can view and edit sensitive data across roles and permission sets. From there, tighten access to the least privilege needed for each job function. That sequence gives the fastest reduction in exposure without waiting for a full redesign.

What to check first when Salesforce access has never been reviewed

Start with the access paths that can expose the most data and change the most records. In practice, that means identifying who holds the highest-risk permissions and checking whether those privileges are justified by the job role. A first-pass review should focus on administrators, broad data visibility, and permission sets that silently expand access.

The reason to begin there is simple: Salesforce risk is usually driven less by the total number of users than by a small set of accounts with exceptional reach. If a profile can see, export, edit, or administer sensitive objects, that access creates outsized exposure even before deeper configuration issues are examined. A focused review gives immediate reduction in blast radius.

How to prioritize roles, profiles, and permission sets

Begin with the administrative and integration paths that can reach customer data, then move to functional roles that combine read and write permissions across multiple objects. Profiles are only the starting point, because permission sets, permission set groups, and sharing rules can create broader access than the base profile suggests. The practical test is whether a user can view, export, or modify data outside the minimum needed for the role.

For a first review, teams should map access in this order: system administrators, privileged support or operations users, sales and service users with broad object access, and any integration or third-party accounts. That sequence catches the permissions most likely to drive a fast and meaningful reduction in exposure. It also prevents teams from wasting the first review cycle on low-impact accounts.

What good first-pass remediation looks like

The first remediation goal is not a redesign, it is to remove obvious excess. Reduce the number of users with System Administrator, validate that edit rights are limited to people who truly need them, and make sure sensitive fields are not broadly readable by default. Where possible, consolidate access to the fewest permission sets that still support the job function.

A disciplined first pass also distinguishes between business necessity and convenience. If a permission only exists because someone once needed it for troubleshooting, it should be treated as a candidate for removal or time-bound access. If a role needs occasional elevated access, use a controlled exception rather than leaving standing privilege in place.

Risk and Threat Considerations

Unreviewed Salesforce access creates a classic privilege and exposure problem: the longer broad access remains in place, the more likely it is that data can be overshared, altered, or exported without a clear business need. In a platform that concentrates customer, sales, and service records, a single excessive role can become a high-value target or an easy path to accidental disclosure.

Failure mechanism: Overbroad profiles, permission sets, and admin access let users or integrations reach data and functions beyond their job scope, which expands blast radius and weakens accountability.

Impact: Sensitive records can be exposed, modified, or extracted, and a compromise of one powerful account can turn into broad tenant-wide damage.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeSalesforce access review is fundamentally about reducing excess privilege.
Recommendation — Limit users to the minimum Salesforce access needed for their role.
CIS Controls v8CIS-6 — Access Control ManagementThe question asks how to start reviewing and tightening user access.
Recommendation — Inventory high-risk accounts and remove unneeded access paths first.
ISO/IEC 27001:2022A.5.15 — Access controlThe topic concerns reviewing who can access sensitive business data in Salesforce.
A.8.2 — Privileged access rightsSystem Administrator access is the highest-risk permission in the review.
Recommendation — Define and enforce access rules for Salesforce roles and permission sets. Review and restrict privileged Salesforce access to approved administrators.

Practitioner Guidance

What to prioritise: Review the smallest number of users that can cause the largest amount of damage, starting with administrators and any account that can read, edit, export, or manage security settings.

What to verify: Confirm that every elevated permission has an owner, a business justification, and a removal path. If a permission cannot be explained in operational terms, it should be treated as suspect until proven necessary.

Practitioner takeaway: The first review should be a blast-radius exercise, not a completeness exercise, because the fastest security gain comes from cutting the most powerful unnecessary access first.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org