Pricing
Start free. Pay per org, not per seat.
Every plan starts with a free trial you start yourself, in the app, with no sales call and no waiting list. About 3 days with no credit card, or about 10 days when you add one (which unlocks CSV, Excel, and PDF export). Checkout is self-serve too, so you can go from trial to paid without talking to us. Pricing is per production org, billed monthly. No per-seat math.
Introductory pricing: 17% off a 1-year contract, 25% off a 2-year contract, and 33% off a 3-year contract.
Who Sees What Professional
See who can see what, whenever you ask.
or $414.17/mo on a 1-year, $374.25/mo on a 2-year, and $334.33/mo on a 3-year contract
Start your free trial- Connect one production org
- The full template question library, including the flagship "Who can see this record"
- Audit explorer: People, Profiles, Fields, Objects, and sharing paths
- Who can export: the bulk-egress report on every user who can get data out
- Connected app and OAuth authorization inventory, with dormant-app flags
- Sensitivity-ranked field exposure, and over-permissioned and dormant-access findings
- On-demand, point-in-time scans
- Export to CSV, multi-sheet Excel (XLSX), and print-ready PDF
- Risks tab: full risk-finding detail, every severity, traced to the Apex, Flow, Visualforce, or formula behind it
Who Sees What Enterprise
The edit, inactive-user, and external-detail upgrade.
or $1,078.17/mo on a 1-year, $974.25/mo on a 2-year, and $870.33/mo on a 3-year contract
Start your free trialEverything in Who Sees What Professional, plus
- Who-can-edit audits for records, objects, and fields
- Load inactive (deactivated) users on demand, beyond the active-user audit
- Itemized external, Experience Cloud, community, and guest-user detail
- Permission-change simulation: what access would change if you changed a role, group, or sharing rule
- Extended audit history and retention
- Priority support, onboarding, and an SLA
Sandboxes are 50% of the org rate, added to a licensed production org. In development, not included yet: REST API, MCP server, and access-change tracking over time.
In development
Lynceon
The direct upgrade from Who Sees What, in the same Digadop security family.
planned pricing: discounted rates on a committed term
Learn moreEverything in Enterprise, plus (on the roadmap)
- Remediation guidance and code recommendations for each finding
- Continuous monitoring and scheduled scans
- Code-security scanning across Apex and dependencies
- Security posture score and trend over time
- Risk prioritization by severity, exposure, and blast radius
- Compliance mapping for your access posture
- Threat and anomaly detection for unusual access patterns
A separate Digadop product, on the roadmap and not yet available for purchase. The price shown is planned.
The org is the licensed unit: whoever pays holds the license, and access is decoupled from who pays, so you can grant a consultant access to your org. Questions about pricing or volume? Get in touch.
Compare editions
Every paid edition includes the full audit engine. Higher editions add scale, team reach, and (soon) the Lynceon security layer.
| Feature | Trial | Professional | Enterprise | Lynceon |
|---|---|---|---|---|
| Audit and analysis | ||||
| Connect a Salesforce org (production or sandbox) | ✓ Included | ✓ Included | ✓ Included | ✓ Included |
| Object, record, and field access audits | ✓ Included | ✓ Included | ✓ Included | ✓ Included |
| Audit active users | ✓ Included | ✓ Included | ✓ Included | ✓ Included |
| Load inactive (deactivated) users on demand | · Not included | · Not included | ✓ Included | ✓ Included |
| Full sharing-model evaluation (profiles, permission sets, roles, sharing rules, FLS) | ✓ Included | ✓ Included | ✓ Included | ✓ Included |
| Code and automation risk scan (Apex, Flows, Visualforce) | ✓ Included | ✓ Included | ✓ Included | ✓ Included |
| People, Fields, and Risks views with per-record "why" | ✓ Included | ✓ Included | ✓ Included | ✓ Included |
| Horton, the in-app assistant | ✓ Included | ✓ Included | ✓ Included | ✓ Included |
| Exposure views others do not answer | ||||
| Who can export: bulk data-egress capability report | ✓ Included | ✓ Included | ✓ Included | ✓ Included |
| Connected app and OAuth authorization inventory, with dormant flags | ✓ Included | ✓ Included | ✓ Included | ✓ Included |
| Sensitivity-ranked field exposure | ✓ Included | ✓ Included | ✓ Included | ✓ Included |
| Over-permissioned and dormant-access findings | ✓ Included | ✓ Included | ✓ Included | ✓ Included |
| Dependency map: what Apex, Flows, and formulas touch an object | ✓ Included | ✓ Included | ✓ Included | ✓ Included |
| Cross-object formula exposure, reported as a confirmed leak | ✓ Included | ✓ Included | ✓ Included | ✓ Included |
| Findings and evidence | ||||
| Critical risk findings, full detail | ✓ Included | ✓ Included | ✓ Included | ✓ Included |
| Medium and low risk findings, full detail | Preview | ✓ Included | ✓ Included | ✓ Included |
| Audit history: save and re-run snapshots | ✓ Included | ✓ Included | ✓ Included | ✓ Included |
| Export to CSV, multi-sheet Excel (XLSX), and print-ready PDF | · Not included | ✓ Included | ✓ Included | ✓ Included |
| Scale, team, and integration | ||||
| Multiple connected orgs with one-click switching | ✓ Included | ✓ Included | ✓ Included | ✓ Included |
| Itemized Experience Cloud, community, and guest-user detail | · Not included | · Not included | ✓ Included | ✓ Included |
| Permission-change simulation | · Not included | · Not included | ✓ Included | ✓ Included |
| REST API and MCP server | · Not included | · Not included | Soon | Soon |
| Access-change tracking over time | · Not included | · Not included | Soon | Soon |
| Scheduled exports and integrations (SIEM, warehouse, ticketing) | · Not included | · Not included | Soon | Soon |
| Security layer (Lynceon, in development) | ||||
| Remediation guidance and code recommendations | · Not included | · Not included | · Not included | Soon |
| Continuous monitoring and scheduled scans | · Not included | · Not included | · Not included | Soon |
| Code-security scanning (Apex and dependencies) | · Not included | · Not included | · Not included | Soon |
| Compliance mapping for your access posture | · Not included | · Not included | · Not included | Soon |
| Threat and anomaly detection | · Not included | · Not included | · Not included | Soon |
Every edition audits your active users by default. Loading inactive (deactivated) users is an on-demand, second step available on Enterprise and Lynceon; Professional audits active users only. Lynceon is on the roadmap and not yet available for purchase. "Soon" marks planned Lynceon capabilities. "Preview" means the trial shows that findings exist while full detail unlocks on a paid edition.