How we found 78 forgotten permissions in one Salesforce system
You can look at your CRM system and think it is perfectly safe. We looked at an eight-year-old Salesforce org with 1,200 users. From the outside, it had a clean list of profiles and a neat handful of public groups. The setup looked tidy. You assume your data is locked down, wanting your sales reps to see what they need to move deals through the pipeline and close quotes. But what you see on the surface is rarely the whole story.
When we looked inside, the reality was different. We found 78 dormant access bundles that nobody had touched in three years. We found a third-party app reading 14 fields it had no business reading. We also found a sharing setting that, under one specific edge case, exposed customer profile data across a partition that should have been opaque. In a busy sales team, reps change roles, people leave, and new tools get added to help with renewals. Over time, these small changes leave large gaps.
This is what a thorough review finds. We do not look for a headline-grabbing zero day bug. We look for the slow permission bleed that compounds quietly, building up over a decade until someone exploits it. IT teams are busy keeping the system running, so they do not always have time to clean up old access rules.
Why access bundles become a blind spot
An access bundle accumulates like inbox debt. Each new feature launch ships its own set, each acquisition arrives with a stack of them, and each temporary elevation gets created on Friday and never removed on Monday. After three years in, the org has 200+ access bundles. Most of these apply to fewer than five users, and a quarter of them apply to zero users but remain assignable.
That last category is the real bleed. Zero current assignments does not mean zero historical risk. An access bundle with no assignees this quarter is still a set of grants holding object-level grants, field-level visibilities, and custom code accesses. Anyone with the right Setup access can attach it to a user account. They are loaded ammunition.
An access bundle without assignees is not unused. It is a pre-staged escalation path. Anyone who can assign one has a 30-second privilege escalation tool sitting in Setup.
What our audit looked for, in order
Stage one: enumeration. We pull every access bundle, assignment, and grant, tagging the dormant ones that have zero assignments in 90 days. For this client, we found 78 of 234 access bundles were dormant. We look closely at how the sales team uses the system to make sure only the right reps can see sensitive pipeline data. We check who can approve quotes and who can see renewals.
Stage two: third-party connected app review. We check OAuth (the login handshake apps use) scopes against actual usage. We found one connected app with full scope making zero API calls in the last 60 days, and another app reading customer fields outside its documented surface. Many teams install apps to help sales reps work faster and forget to remove them when they stop using them, leaving a door open.
Stage three: sharing setting edge cases. We model the sharing settings as a graph and walk it looking for strange sequences. We look for sequences where ownership changes, group membership, and a public-read flag combine to surface data across partitions. One such sequence had been there for four years. This kind of leak can expose quotes or renewals to the wrong people.
Stage four: page layout grants. Some escalation paths in modern CRM orgs are not direct grants, but visibility rules on a page layout. These rules reveal record fields to roles that security would otherwise hide. We always check this, though most playbooks do not. A sales rep might see a field on a page layout that they should not see, causing problems with sensitive deal data.
The result
Our review delivered clear outcomes.
- We revoked 78 dormant access bundles.
- We tightened OAuth (the login handshake apps use) scopes for 2 connected apps.
- We rewrote 1 sharing setting to close the partition leak.
- We reduced the attack surface by 41% in one engagement.
- We lost zero new functionality, and no user complained: the org held less ammunition.
We make sure your sales team can still do their jobs. They can still build pipeline, but they do it in a safer system.
What we do
If you have a CRM org older than three years, you should check your access model. If you have never had a review specifically for this, you have gaps. This is the short engagement we run, and the findings list is always longer than the client expects.
If you have AI integrations on top of that org, the surface multiplies. We address those in the same audit, because you want your sales reps to trust the tools they use.
Next step
If this sounds like your team, we can look at it together. A free pipeline review takes thirty minutes and ends with a written list of what to fix first. Book a review.