Review 11 checks across opportunities, accounts and contacts, leads, user activity, and permissions. Get a score for completed checks, sample record IDs, and suggested next steps.
Connect an account your organization has authorized for this check. Your Salesforce permissions determine which data can be reviewed. Unavailable checks are clearly marked.
The connection requests API, identity, and refresh/offline access. These permissions are broader than the read queries used by this scan. Review Salesforce’s approval screen before connecting.
The scan retrieves counts and small record samples through CRM Hacker’s service and calculates results in your browser. Your access token is held in a secure, HTTP-only session cookie with a one-hour expiry. Disconnect clears this session; it does not revoke the connected app’s authorization in Salesforce.
Downloads can include sample record IDs. If you email a report, its PDF, message, and recipient address are sent through Resend. Only share reports with authorized recipients.
The queries use Opportunity, OpportunityContactRole, Account, Contact, Lead, Task, User, Profile, and PermissionSetAssignment data. API access is required. The scan does not edit Salesforce records and is not a complete security or configuration audit.
Review findings with your Salesforce owner before making changes. A flagged check is a starting point for investigation. Unavailable checks are excluded from the score.
Download your report for a working session, or ask CRM Hacker to help prioritize next steps.