December 12, 2023

Every Salesforce org drifts. Permissions pile up, old automation keeps running, and custom code stays long after the team that wrote it moved on. A Salesforce audit is the structured review that finds all of it and tells you what to fix first.
Most teams notice the drift indirectly. Reports stop matching each other. A deployment breaks something nobody touched. A new hire asks why three fields hold the same data, and nobody can answer. None of that means the org is broken. It means nobody has looked at the whole picture in a while, and the small decisions have added up.
This guide covers what an audit looks at and how it differs from a health check. It walks the eight areas worth examining. It also shows how to turn a long findings list into a plan leadership will approve.
A Salesforce audit is a full review of how your org is built, secured, and used. It looks at setup, data, code, integrations, and adoption together. It also looks at what you pay for.
The output is not a score. It is a ranked list of what is wrong, what it costs you, and what to do about it.
A good audit answers four questions. Is the org secure. Is the data trustworthy. Is the build maintainable. Are you paying for things nobody uses.
That last question surprises people. Unused licenses, dormant integrations, and abandoned custom objects all carry a cost. None of them show up as errors.
An audit differs from routine admin work in one way. Admin work keeps today running. An audit asks whether the shape of the org still fits the business.
That is why the timing matters. Run one before a big project and you save money. Run one after a bad release and you are doing cleanup.
These two terms get used interchangeably, and that causes real confusion when someone asks for a budget.
Health Check is a built-in Salesforce tool. It scores your security settings against a baseline. It names the settings that fall below it. It runs in minutes and it is free.
An audit is a people-led review. It covers what Health Check leaves out. That means data quality, automation logic, code, integrations, and licenses. It also asks whether people use what you built.
| Dimension | Salesforce Health Check | Salesforce Audit |
|---|---|---|
| What it reviews | Security settings only | Security, data, automation, code, integrations, adoption, licenses |
| Who runs it | Admin, self-service | Engineers and architects, often with an outside reviewer |
| Time to complete | Minutes | Days to weeks |
| Output | A numeric score and a settings list | A ranked findings register and a fix roadmap |
| Cost | Included with your org | A project with a defined scope |
| Frequency | Monthly or on demand | Annually, or before a major project |
| Best for | Catching settings that slipped below baseline | Understanding why the org behaves the way it does |
Start with Health Check if you have never looked. Our walkthrough on how to perform a Salesforce health check covers that first pass in detail. Move to a full audit once the org is a few years old. A merger or migration is another good reason. So is the moment nobody can explain why something works the way it does.
There is no universal schedule. There are reliable triggers.
Run an audit in Salesforce when you are about to start a major project. Migrations, new cloud rollouts, and integration programs all go badly on top of an org nobody has inspected.
Run one after leadership change in the admin or architect seat. Undocumented decisions are the most expensive kind.
Run one when a compliance deadline appears. Regulated industries need evidence, not assurances, and evidence takes time to assemble.
Run one when release cycles start slipping. Slow deployments usually point at technical debt that an audit can name precisely.
Outside those triggers, an annual review keeps most orgs honest. Fast-growing orgs benefit from every six months.
Access sprawl is the most common finding in any org over two years old. People change roles, but their permissions rarely follow.
Look for profiles with View All Data or Modify All Data that no longer need it. Check for permission sets granted once for a project and never removed. Flag inactive users who still hold active licenses and API access.
Sharing settings deserve the same attention. Organization-wide defaults set years ago often no longer match how teams work now. Our Salesforce administration services team treats access review as a recurring task, not a one-time cleanup.
Role hierarchy is worth a fresh look too. Most hierarchies grow by addition. Very few get pruned when a team is restructured.
Bad data breaks reports, automation, and any AI feature you plan to add later.
Measure duplicate rates on your core objects. Check field fill rates, because a field that is empty on most records is either unused or badly designed. Look for validation rules that users work around instead of following.
Also count your fields. Orgs often carry hundreds of custom fields where a few dozen see real use. Each one slows page loads and confuses new users.
Record counts matter as well. Objects holding millions of rows behave differently from small ones. Reports slow down, and some queries start hitting limits.
This is where the biggest cleanup usually waits. Many orgs still run a mix of Workflow Rules, Process Builder, and Flow doing overlapping work on the same objects.
Salesforce has moved automation firmly to Flow, and new Workflow Rules and Process Builder automations can no longer be created. Anything still running on the older tools is a migration item, not a maintenance item.
Map every automation by object and trigger order. Overlapping automation on one object is a common source of bugs nobody can reproduce.
Watch for automation that fires on every save when it only needs to fire on change. Those rules burn limits and slow every update.
Apex, triggers, and Lightning components need the same scrutiny as configuration.
Check test coverage, but read past the number. Coverage that exists only to satisfy the deployment requirement tells you nothing about quality.
Look for multiple triggers on one object, hardcoded IDs, queries inside loops, and classes on old API versions. Each is a maintenance cost and a deployment risk.
Static analysis tools catch most of this quickly. Technical writers like Jitendra Zaa publish detailed breakdowns of the patterns worth flagging.
Every connected app is a door into your data. Most orgs have more doors than they remember.
Review every authorized connected app. Confirm you know who installed it, why, and whether it is still in use. Anything you cannot account for should come out.
Check which users hold API access and whether any integration runs on a real person's login instead of a dedicated integration user. Our post on Data Loader security risks explains why that distinction matters more than it used to.
An org can be technically sound and still fail the business.
Count how many reports exist and how many were run in the last quarter. The gap is usually large. Check which dashboards leadership actually opens.
Then look at login frequency and feature usage by team. Low adoption is usually a design problem, not a training problem. Either way it belongs in the audit report.
Ask a few users what they avoid and why. That single question often explains a year of confusing usage data.
Governor limits and storage caps rarely cause problems until they suddenly do.
Check data and file storage against your allocation. Review API call consumption against your daily limit, especially if integrations have been added recently.
Then project forward. An org near a limit today will hit it during your next growth spurt. Fixing that under pressure costs far more.
This is the section that pays for the audit.
Compare license counts against active users. Check for users holding a full license who only need a lighter one. Review add-on products nobody adopted.
Community and platform license assignments are worth a close look too. Mismatched license types are common and quietly expensive.
A Salesforce security audit is the narrow, urgent version of the full review. Here is the order that works.
The documentation step is the one teams skip. Without it, you will run the same audit next year and find the same problems.
You do not need to inspect an org by hand. These tools cover most of the ground.
| Tool | What It Covers | Where It Fits |
|---|---|---|
| Health Check | Security settings scored against a baseline | First step of any security review |
| Setup Audit Trail | Who changed what, and when | Tracing unexplained configuration changes |
| Login History | Access patterns, locations, failed attempts | Spotting credential and session risk |
| Security Center | Cross-org security posture in one view | Multi-org estates |
| Salesforce Shield | Event Monitoring, Field Audit Trail, encryption | Regulated industries and sensitive data |
| Field Trip | Field fill rates across objects | Finding unused fields fast |
| Perm Comparator | Side-by-side profile and permission set comparison | Untangling access sprawl |
| Static code analysis | Apex quality, security patterns, anti-patterns | Custom code and technical debt review |
| Salesforce Optimizer | Storage, custom code, and layout insights | Confirm availability in your edition first |
What is available depends on your edition and on what Salesforce ships today. Confirm each tool is present in your org before you build a plan around it. Community walkthroughs on Salesforce Geek are useful when you are setting one up for the first time.
A raw findings list is not useful to anyone above the admin team. Leadership needs a decision, not an inventory.
Sort every finding into three buckets. Fix now covers security gaps and anything blocking a deadline. Fix next covers debt that slows delivery but is not urgent. Watch covers items that only matter at a larger scale.
Then attach a consequence to each one. Forty-two users hold Modify All Data means little on its own. Forty-two users can export the full customer database is a sentence a board understands.
Sequence the work by dependency, not by severity alone. Cleaning data before migrating automation saves you from migrating broken logic.
Finally, set a re-check date. An audit that ends with a document and no follow-up date becomes shelfware within a quarter. Ongoing administration and governance is what keeps the findings from returning.
Auditors trip over this constantly, and stale naming inside an org is itself a finding.
Several Salesforce products have been renamed, and older documentation, field names, and internal runbooks often still use the previous terms. Pardot is now Marketing Cloud Account Engagement. Data Cloud is now Data 360. Salesforce CPQ has given way to Revenue Cloud Advanced. Einstein capabilities now sit under the Agentforce banner.
Why it matters for an audit. Internal documentation that references retired names usually references retired processes too. When you find one, check whether the process behind it is still current.
Automation naming carries the same signal. An org with objects named after Workflow Rules is an org that has not revisited its automation strategy in years. Community sites like Salesforce Codex and Forcetalks track these changes closely. They help when you need to check whether a pattern is still current.
We treat an audit as an engineering assessment, not a checklist exercise. Anyone can list findings. The value is in knowing which ones matter for your business and in what order.
Our engineers run the review across all eight areas above, then produce two documents. One is the technical findings register for your admin and developer teams. The other is a one-page business case for leadership, written in cost and risk terms.
We bring pre-built audit accelerators that cover the repeatable parts. Your engineers do not rebuild permission matrices and field usage reports from scratch.
Industry starter packs cover BFSI, Manufacturing, Healthcare, Automotive, and Real Estate. Each one measures the audit against the data model your sector needs.
We also stay for the remediation. Findings without a fix plan help nobody, so every engagement ends with a sequenced roadmap, owners, and a re-check date.
A focused security review takes a few days. A full audit across all eight areas usually runs two to four weeks. Org size, custom code, and integration count drive that range.
Health Check is a built-in tool that scores your security settings in minutes. An audit is a people-led review covering data, automation, code, integrations, adoption, and licenses as well as security.
Internal teams know the business context. External reviewers see the things familiarity hides. A mixed team usually produces the most useful result, with an outside engineer leading the technical review.
Annually for stable orgs, every six months for fast-growing ones. Always before a migration, a merger, or a major new cloud rollout.
It varies with scope and org complexity. A focused security review costs far less than a full review. Many teams recover a good share of the cost through license cleanup alone.
A Salesforce audit earns its cost when it ends in a decision. Findings that name the risk, rank the work, and set a date are what separate a useful audit from a filed report. Your org does not need to be in trouble to benefit. It only needs to have grown faster than the documentation behind it, which describes almost every org after a few good years.
Minuscule Technologies approaches that review as Salesforce engineering partners, not reviewers with a checklist. Our certified engineers examine your configuration, security, data, code, and licenses, then turn what they find into cost and risk your leadership can act on. Pre-built audit accelerators handle the repeatable work, so permission matrices and field usage reports arrive ready. Industry starter packs for BFSI, Manufacturing, Healthcare, Automotive, and Real Estate measure your org against the data model your sector runs on.
What you get back is a ranked roadmap with owners, sequencing, and a re-check date, not a document that quietly ages on a shared drive. Every finding arrives with the fix that follows it, so the work can start the week the audit ends. Book a free strategic call with our Salesforce engineers and we will show you exactly where your org stands and what to tackle first.
You've seen what's possible. Now, let's make it happen for your business. Whether you need an end-to-end Salesforce solution, a complex integration, or ongoing managed services, our team is ready to deliver.
Schedule a Free Strategic Call