See Salesforce security exposure without digging through Setup.

Security Observatory brings OAuth grants, privileged access, licences, external exposure and retained security evidence into one Salesforce-native review surface.

Currently in sandbox validation. Not yet available for public installation.

  • Read-only assessment
  • No automatic remediation
  • Evidence retained in your org
Fortmilo

What you get from a scan

Find risky access and exposure

Bring security signals that are otherwise spread across Salesforce Setup, objects and APIs into one review surface.

See who or what is affected

Move from posture metrics into safe drill-downs that provide the context needed to investigate a finding.

Keep evidence and compare change over time

Retain sanitised scan evidence. Comparison claims remain bounded to behaviour evidenced for the release build; terminology-version stamping and gating are not claimed as current.

Missing evidence never becomes zero

Unavailable sources, Partial completeness and Incomplete licence-assignment capture remain visible on their separate axes instead of being presented as a false clean result. Capped retained assignment counts are not exact organisation totals.

References control identifiers from the independent Security Benchmark for Salesforce (SBS), licensed under CC BY-SA 4.0.

How it works

Security Observatory turns scattered Salesforce security evidence into a repeatable review workflow.

1. Configure

Configure the Observatory and the access required for supported evidence sources.

2. Run scan

Run the supported scanner families against the Salesforce organisation.

3. Review posture

Review security metrics, exposure and findings from a single dashboard.

4. Investigate findings

Open safe drill-downs to understand affected users, assets or configuration without exposing secrets.

5. Compare scans

Compare retained scans to understand what changed between assessment points.

Why not just Salesforce Setup?

Salesforce already exposes much of this security evidence across Setup, standard objects and APIs. Reviewing it manually means moving between multiple surfaces and reconstructing context each time. Security Observatory brings supported signals into one review surface, retains sanitised evidence and makes changes easier to investigate over time.

Continue the technical review

Review the product guide and evidence model, or contact Fortmilo with a technical question.