Security
- 100 %
- inside your org
- 0
- outbound data by default
- 71/255
- controls self-assessed
- 10 min
- to install
The French text governs. This page is the English version of Sécurité FR.
35 capabilities. What the Discovery offer opens among them: none. It is written here as it is written in the pricing grid: security starts at the Small business tier. A free evaluation measures the health of the org, not its security posture.
- 35
- capabilities in this family
- 0
- active on installation day, on the Discovery offer
- Small business
- entry tier of the family
What this family measures
Four angles, in the order of the table — word for word, the four sub-headings you will find below, row by row.
- Identities and their privileges
- who can do what, who no longer uses it, which privileges piled up without ever being removed, and which logins fall outside the ordinary — never-seen country, impossible travel, off-hours login by a privileged account.
- Exposed surfaces
- what your org exposes without authentication, what its public sites let through, which sensitive fields are readable, who can export in bulk, and which connected apps look like an exfiltration tool.
- Data, certificates and agents
- encryption at rest, native classification, certificate expiry, and the security posture of your Agentforce agents — a subject that did not exist two years ago and that no vendor questionnaire asks about yet.
- What you tune yourself
- custom rules, thresholds, views, per-finding SLA, business criticality scopes, and the costing of risk in euros — with your weights, because an amount computed on the publisher's scale means nothing in your steering committee.
Metrics here too carry stable keys: Security:Score,
Security:PermSprawl, Security:GuestSurface,
Security:OAuthRisk, Security:BlastRadius,
Security:MfaCoverage.
The 35 capabilities, one by one
| Capability | Minimum offer | At install |
|---|---|---|
| Identities and their privileges | ||
Over-privilege postureSecurity_OverPrivilege | Small business | —, display tier: nothing to toggle, the offer is enough |
Privilege containmentSecurity_PrivilegeContainer | Small business | Open |
Effective-permission sprawl and driftSecurity_PermSprawl | Small business | Closed |
Dormant-user postureSecurity_DormantUsers | Small business | —, display tier: nothing to toggle, the offer is enough |
Exposure through the role hierarchySecurity_RoleHierarchy | Small business | Closed |
Privilege matrix and consolidation planSecurity_PrivilegeMatrix · shows the grid and proposes a consolidation plan; it changes no permission | Small business | Closed |
Public groups and queues as an access channelSecurity_PublicGroups · third effective-access channel, after org-wide defaults and the role hierarchy | Small business | Closed |
Privileged-login anomalies (country, impossible travel, off-hours)Login_Anomaly · no Shield required: derived from LoginHistory and LoginGeo, at every scan | Small business | Closed |
Backup postureSecurity_BackupPosture | Small business | Closed |
| Exposed surfaces | ||
Guest-user exposureSecurity_Guest | Small business | —, display tier: nothing to toggle, the offer is enough |
Public-site posture and site-to-guest inventorySecurity_SitePosture | Small business | Closed |
Read exposure of sensitive fields (FLS)Security_FieldExposure | Small business | Closed |
Bulk data-export capabilitySecurity_DataExport | Small business | Closed |
API data-exfiltration detectionSecurity_ApiExfiltration | Small business | Closed |
API clients: first use and wideningSecurity_ApiExfil_Clients | Small business | Closed |
OAuth application postureSecurity_OAuth | Small business | —, display tier: nothing to toggle, the offer is enough |
Blast-radius analysisSecurity_BlastRadius | Small business | —, display tier: nothing to toggle, the offer is enough |
Attack paths (read-only)Attack_Path_Engine · composes OPEN findings into named paths per principal; it adds no detector | Small business | Closed |
| Data, certificates and agents | ||
Encryption at rest of regulated dataSecurity_Encryption | Small business | Closed |
Native data classification (security level, compliance)Security_DataClassification | Small business | Closed |
Certificate expiry and TLS monitoringCert_Monitor · org certificates read through a self-call through a named credential, never the session token; the external TLS probe goes through the hosted viewer and needs its consent | Mid-market | Closed |
Outbound endpoint reachability probeConnectivity_Probe · active probe: an outbound call goes to the endpoint you designate | Mid-market | Closed |
Security posture of Agentforce AI agentsAgentforce_Posture | Small business | Closed |
Data Cloud posture (data spaces, DMO access, ingestion shares)Data_Cloud_Posture | Small business | Closed |
Functional impact of encrypting a field, before encrypting itSecurity_EncryptionImpact | Small business | Closed |
Field-history tracking postureSecurity_FieldHistory | Small business | Closed |
| What you tune yourself | ||
Custom rulesCustom_Rules | Small business | Closed |
Detector tuningDetector_Tuning | Small business | Closed |
Saved viewsSaved_Views | Small business | Closed |
Per-finding SLAFinding_SLA | Small business | Closed |
Business criticality scopesCriticality_Scoping | Small business | Closed |
Cost of riskCost_Of_Risk · adjustable weights: the amount is yours, not an imposed scale | Small business | Closed |
Accepted-risk policyAccepted_Risk_Policy | Small business | Open |
Rule portabilityRule_Portability | Small business | Open |
Natural-language queryNL_Query | Small business | Open |
— display tier: nothing to toggle, the offer is enough
Source: read from the package code at the moment this page is built — FeatureGate.FEATURE_TIER for the offer, FeatureGate.CODE_DEFAULTS for the state at install. The label is the one exception: the in-org feature editor is French only, so the English wording in this column was written for this site. Its French counterpart, on /produit/, is the exact string your administrator reads, and the site build fails if the two lists move apart. “Closed” does not mean absent: the capability is shipped, it is waiting for a human to open it inside the org — and a capability whose implementation nothing in the package can reach appears on none of these pages: the build drops it instead of selling it.
What this family does not do
- No remediation. The product does not remove a permission, close a guest access or revoke a token. It names, it costs, it ranks; you decide.
- It does not read your business data. It reads the configuration and the metadata describing who may see what. It does not walk your records and does no content DLP and no antivirus.
- It is not a penetration test. A detector observes one named facet; it does not prove the absence of an attack path it does not observe.
- It is not a SIEM. Login anomalies are derived from
LoginHistoryandLoginGeoat every scan; they do not replace continuous event correlation. - Every query runs with your rights. What the user running the scan may not see, the product does not see either — and it says so instead of concluding “healthy”.
The other families
Is this family in your offer? The grid says so line by line.
See the pricing grid Back to the seven families