Skip to content
Who Sees What

Salesforce permission audit

Who sees what in your Salesforce org?

Expose risky access before auditors, customers, or incident response force the question. Who Sees What scans your Salesforce security model and turns permission sprawl into a prioritized remediation plan.

Safe by design. You authorize access through Salesforce OAuth and revoke it anytime, and we read only your access metadata, never your business-record contents. Read-only today, and it never modifies your org.

8
Tier-one Salesforce access audits in the v0.1 scanner
0
Business-record contents read or stored by the audit
<5 min
Typical setup for an initial risk snapshot
Horton ✨ AI Tap to ask a question

Powered by Digadop

Ask, don't browse. Horton answers anything about Who Sees What.

What gets flagged

Permission risk, translated into decisions.

Salesforce access is spread across profiles, permission sets, groups, roles, sharing rules, queues, teams, and managed-package defaults. The audit connects those layers so teams can answer who can see what, why, and what to fix first.

Overexposed profiles

Find profiles and permission sets granting broad object, field, or system access beyond the role that needs it.

Sensitive data paths

Map who can reach regulated fields, revenue data, customer records, and internal-only objects across every access layer.

Dormant access

Surface users, groups, and assignments that still carry meaningful access after the business process moved on.

Audit-ready evidence

Produce a concise report with findings, severity, affected users, and the exact grant behind each one, so your admin team knows what to fix.

What you get

A report you can act on.

Every scan produces a prioritized exposure report: findings ranked by severity, the users and metadata affected, and the specific grant to fix. Here is the shape of it.

See it in action

Every answer shows its work.

Two ways to get an answer, both read-only against your org and both showing the reason behind every result: ask Horton in plain English, or build a precise audit by hand.

Who Sees What app: Horton answers the question "Who has the View All Data permission?" showing that 7 users hold it via 11 permission set and profile paths.
Ask in plain English. Horton runs the audit and shows who, how many, and the exact paths behind it.
Who Sees What advanced audit builder: choose to audit an object, a record, or metadata, with a read-only badge and object search.
Or build a precise audit. Pick an object, field, or record and get the full access path, no query language required.

How it works

From OAuth to a remediation plan in minutes.

Connect Salesforce with read-only OAuth.

Scan metadata, permission sets, groups, profiles, roles, and sharing rules.

Receive a prioritized exposure report with the reason behind every finding.

Security

Security first. You're in control.

Protecting your data is the whole job, and it is engineered into how Who Sees What is designed, authorized, and operated. Here are the controls that keep it safe. The full specifics are on our trust pages.

Least privilege by design

Who Sees What requests only what its audit needs, through standard Salesforce OAuth. No password is shared. It is read-only today and never writes to your org.

You authorize and stay in control

You connect the org and choose what to enable, and you can revoke access from Salesforce Connected Apps at any time. Disconnect in one step and we delete the audit data we hold for your org.

What we read

Only access configuration: profiles, permission sets, roles, groups, sharing rules, and field-level security. The metadata that decides who can see what.

What we never read

Your business-record contents. We never read or store the data inside your Accounts, Opportunities, or custom objects, only how access to them is configured.

Isolated, encrypted, deterministic

Tenants are isolated with org-scoped access and row-level security, stored credentials are encrypted with AWS KMS, and the audit is computed by deterministic analysis you can re-run. Your data is never used to train models that benefit other customers.

See who can reach your most sensitive data.

Nothing to install, and you stay in control. You authorize access, and we read only your access metadata, never your business-record contents. Connect your org and get an initial risk snapshot in under five minutes.