Security.
All posts.
Salesforce Is Retiring the Email Change Verification Exemption: Set Up Authorized Email Domains Before Winter '27
Salesforce is retiring the Support exemption for email change verification. Set up Authorized Email Domains and DKIM before Winter '27 enforcement hits.
Deployable Permission Sets for a Salesforce Delivery Team: Metadata, the CI User, and OmniStudio
Permission set XML you can deploy, how to get the right permission API names out of your own org, and how to scope the CI user and OmniStudio builder roles.
Salesforce Report-Export Step-Up Enforcement: The Known Issues and Gotchas Nobody Warned You About
Blocked exports, a broken Login As, and RPA jobs failing: the practitioner known issues behind Salesforce report-export step-up enforcement in July 2026.
Sizing a Salesforce Access Model: Team Shape, Internal vs External Admins, and What It Costs to Run
A full access model is not always the right one. How to size it to your team, flex it for external delivery partners, and what the whole thing costs to run.
A Guest IP Got Flagged for Log4j: Scanner or Breach? Triage Salesforce EventLogFile in One Command
A guest Experience Cloud IP is flagged for Log4j exploitation. Scanner or real attacker? How to tell it apart from your EventLogFile logs, in one command.
Which of Your Salesforce Connected Apps Use Less Than They're Granted? Ask Your Own Logs
Static scanners tell you what a connected app was granted, not what it uses. Here is how to measure the over-grant per object from your own EventLogFile.
A Least-Privilege Access Model for the Salesforce Delivery Team: Tiers, Roles, and Where the Escalation Chain Breaks
How to tier sandboxes, layer profiles and permission set groups, and use the one fact that stops a developer escalating from a sandbox into your production org.
Why Your Developers Don't Need Modify All Data (And What They Actually Need Instead)
Modify All Data is org-wide read and write that does not even override field-level security. Here are the five real requests behind it, and what each one needs.
Agentforce Agent User Least Privilege: What the Wizard Grants, What Your Agent Actually Needs, and How to Audit the Gap
What the Agentforce setup wizard grants your service agent user, what it actually needs, and how to audit both before an attacker maps the gap for you.
Locked Out After Salesforce MFA Enforcement: Recovery Paths, Temporary Codes, and the Break-Glass Account You Should Have Built
Locked out after Salesforce MFA enforcement? The recovery paths, temporary codes, Support realities, and how to build a break-glass admin account for your org.
Audit Your Agentforce Footprint: Every Agent, Agent User, and Permission in One Pass
Inventory every Agentforce agent, agent user, and permission with sf CLI and SOQL: the exact queries to see what your agents can touch, and from where.
Post-ForcedLeak: Hardening Agentforce Against Prompt Injection (The Setup Steps Nobody Published)
ForcedLeak turned a $5 domain into an Agentforce data-exfiltration channel. The concrete Setup hardening steps to shrink your prompt-injection blast radius.
IPP 3A Is Live: Building New Zealand's Indirect-Collection Notice into Salesforce
New Zealand's IPP 3A now requires notice when you collect personal data indirectly. Build compliance into Salesforce with source fields, a Flow, one report.
Free Salesforce Event Monitoring: Build a Security Baseline from EventLogFile Without Shield
Salesforce gives Enterprise, Unlimited and Performance orgs free EventLogFile logs, but only for a day. How to capture them into a baseline without Shield.
Salesforce MFA Enforcement Update: What Was Paused, What Still Applies, and the Revised 2026 Dates
Salesforce paused its all-employee MFA enforcement over a security-key enrolment bug and revised the 2026 dates. Here is what moved and what still applies.
Salesforce Data Sovereignty in New Zealand: There's No NZ Region, So What Actually Protects Your Data?
Salesforce has no New Zealand region, so your data sits offshore. What data residency, the US CLOUD Act, and NZISM actually mean for NZ gov and health orgs.
Salesforce Retires the OAuth Username-Password Flow in Winter '27: Migrate Before Your Integrations Break
Salesforce retires the OAuth 2.0 username-password flow for connected apps in Winter '27. What breaks, how to find affected integrations, and how to migrate.
Salesforce Guest User Exposure: How sf-audit Grades It by Real Reachability
sf-audit now grades Salesforce guest user exposure by real UI API reachability, not just the sharing model, and adds six new external-facing security checks.
sf-audit vs sf-cli-security-audit: Two Salesforce Security CLIs Compared
Two open-source sf CLI plugins audit Salesforce security from the terminal. One is opinionated and broad, the other configurable and focused. How to pick.
Salesforce Summer '26: The SAML Retirement and Apex Secure-by-Default Changes That Break Orgs Quietly
Two Summer '26 changes break orgs without warning: retiring single-configuration SAML stops SSO logins, and Apex now defaults to with sharing. What to check, where.
Salesforce Security Enforcement in 2026: Every Change, Date, and What Admins Must Do
Across 2026 Salesforce turns a stack of security recommendations into hard enforcement: MFA, report step-up auth, IP blocking and more. The full list and dates.
Salesforce MFA Enforcement in 2026: What Admins Must Verify and Do
Salesforce moves from contractual MFA to hard enforcement in mid-2026, with a stricter phishing-resistant bar for admins. How to verify your org and comply.
Why Salesforce Health Cloud Needs Its Own Security Review
Salesforce Health Cloud holds your most sensitive data, and the features that make it useful are the ones that expose it. What a security review checks.
Mapping Salesforce Security to NZISM, the NZ Privacy Act and ISO 27001
How to map Salesforce security findings to NZISM, the NZ Privacy Act, HISO 10029 and ISO 27001 using a source-verified, version-pinned control catalogue.
sf-audit: 61 Checks, Attack Chains, and Compliance Mapping
We shipped sf-audit v1.0 in April with 23 checks. It's now at 61. Along the way it gained attack chain detection, posture history tracking, and compliance tags across OWASP, SOC 2, ISO 27001, HIPAA, and GDPR.
Fetching Security Metadata from Salesforce with sf CLI: Profile, PermissionSet, Role
How to retrieve Profile, PermissionSet, PermissionSetGroup, MutingPermissionSet, and Role metadata from Salesforce using sf CLI, including partial retrieval patterns for large Profile XML.
sf-audit v1.0: New Checks, Configurable Scoring, and Externalized Queries
The audit plugin has grown from 22 checks to 23, added four new threat surfaces, and gained a fully configurable scoring model. Here is what changed and why it matters.
Catch Salesforce Security Gaps in One Command
Most Salesforce orgs are carrying security debt they don't know about. This plugin surfaces it in a single command.
How We Built a Native sf Plugin for Salesforce Security
We had a working Python script. Here is why we rewrote it as a native sf plugin, and the design decisions that made 22 parallel security checks practical.
Mixed DML Operations: Enterprise User Provisioning Patterns for Salesforce
Master the complex challenge of mixing setup and non-setup object operations in Salesforce user provisioning workflows with production-proven patterns and error handling strategies.
Secure APIs against XEE Attacks (XML Injection Attacks)
Learn how to secure your APIs against XML External Entity (XEE) attacks, including XML Injection and XML Expansion attacks, with practical mitigation steps for Java and RestEasy.