SALESFORCE ACCESS AND INTEGRATION RISK ASSESSMENT

Org Access Assessment

Know what breaks, and who can reach what, in your Salesforce org.

Delivered by Bergin Panimayam, Salesforce architect, fifteen-plus years on the platform.

Fixed price, scoped to your org. We size it on a short call, then send you a firm number.

Most Salesforce orgs past year two cannot answer a simple question: if a certificate expires or an integration credential changes next month, what breaks, and who quietly gains or loses access to data?

Your admin owns permissions. Your integration team owns the endpoint. The dependency between them is undocumented, and it surfaces as an outage, a failed audit, or a security finding, always at the worst possible time. Health Check and Optimizer score your settings against a Salesforce baseline. Neither one resolves which Apex class, Flow, or live integration depends on a given credential or certificate.

This engagement closes that gap using a user that can read everything and change nothing, and about four hours of your team's time across three interviews and the readout, plus initial setup for your Salesforce administrator. We agree the scope and a fixed price on a short discovery call first; the work starts when read-only access is granted and the connection is verified.

Fit

Who this is for

This is a fit if

  • Your Salesforce org has been in production two years or more
  • You have three or more external integrations or named credentials in use
  • Someone owns the outcome and can approve a fixed-price engagement
  • You can grant a read-only user within about a week

This is not the right engagement if

  • Your org is new or still in initial implementation
  • You are looking for a code review or an architecture review of a build in progress
  • You need a compliance certification or a formal audit opinion

Aetrum also does design reviews, implementation, and fractional architecture.

Those are separate engagements, scoped separately. Need the whole org reviewed, not just access? That is the Architecture Assessment. If one of those is what you need, book the same call and we will work out which.

What you keep

You receive

  • A Findings Report with a maximum of twelve ranked findings, each including the exact evidence and the steps to reproduce it, so your own architect can verify or challenge any of them
  • An Evidence Pack you can produce when an auditor or a customer's security team asks
  • A Remediation Roadmap sequenced across this week, thirty days, and ninety days, with effort estimates and owners
  • One Architecture Decision Record, written in full, as the template for the rest
  • A sixty-minute readout with your technical and business owners in the same room

See a sample Findings Report (PDF). Fictional org, real structure.

Every finding includes a remediation path that requires no product purchase. Where a tool is recommended, the commercial interest is disclosed in writing inside the report.

The full fee credits against any remediation or retainer engagement signed within thirty days of the readout.

The assessment is the scoping work. If you act on it, you have already paid for the scope.

Follow-on work is usually remediation of what the assessment found, or an ongoing advisory retainer. Both are scoped from the roadmap, so you see the price before you commit.

FAQ

Questions people ask

We have an in-house architect. Why would we need this?

Your architect is the audience, not the obstacle. The report is built to be tested rather than trusted, and every finding includes the evidence and the steps to reproduce it. What an outside pass adds is the dependency graph, which nobody builds while they are also running a roadmap.

Health Check and Optimizer are free. Isn't this the same thing?

They score your settings against a Salesforce baseline, which is worth doing. Neither one resolves which Apex class, Flow, or live integration depends on a given credential or certificate. That gap is where the breakage lives, and it is what this engagement closes.

What if you don't find anything serious?

Then you have documented evidence of that, which is what an auditor or a customer's security team is going to ask for anyway, at a fraction of what a formal audit costs. The report includes a section on what was inspected and found clean, not only what was found wrong.

Delivery

Who delivers this

Bergin Panimayam, founder of Aetrum LLC. Fifteen-plus years on the Salesforce platform, including ten years running Salesforce at AOL and Yahoo across customer support and subscription platforms.

Five Salesforce certifications, three at architect level: Application Architect, Sharing and Visibility Architect, and Platform Data Architect.

Delivery is founder-led, not subcontracted.

Find out what breaks, and who can reach what, in your Salesforce org.

Book a 30-minute call