Least Privilege.
All posts.
Deployable Permission Sets for a Salesforce Delivery Team: Metadata, the CI User, and OmniStudio
Permission set XML you can deploy, how to get the right permission API names out of your own org, and how to scope the CI user and OmniStudio builder roles.
Sizing a Salesforce Access Model: Team Shape, Internal vs External Admins, and What It Costs to Run
A full access model is not always the right one. How to size it to your team, flex it for external delivery partners, and what the whole thing costs to run.
Which of Your Salesforce Connected Apps Use Less Than They're Granted? Ask Your Own Logs
Static scanners tell you what a connected app was granted, not what it uses. Here is how to measure the over-grant per object from your own EventLogFile.
A Least-Privilege Access Model for the Salesforce Delivery Team: Tiers, Roles, and Where the Escalation Chain Breaks
How to tier sandboxes, layer profiles and permission set groups, and use the one fact that stops a developer escalating from a sandbox into your production org.
Why Your Developers Don't Need Modify All Data (And What They Actually Need Instead)
Modify All Data is org-wide read and write that does not even override field-level security. Here are the five real requests behind it, and what each one needs.
Agentforce Agent User Least Privilege: What the Wizard Grants, What Your Agent Actually Needs, and How to Audit the Gap
What the Agentforce setup wizard grants your service agent user, what it actually needs, and how to audit both before an attacker maps the gap for you.