Salesforce Permission Sprawl: How to Audit Profiles and Permission Sets
Open your Salesforce Setup and count your profiles. If you have more than 15, check how many are actually different. In most orgs, profiles accumulate the same way custom fields do: someone needed slightly different access, a new profile was cloned, and now you have 30 profiles where 8 would suffice.
Why permission sprawl matters now
Two recent shifts have made it urgent. First, breaches like the Salesforce-Salesloft incident highlighted that over-broad permissions increase the blast radius of any security event. Second, AI agents like Agentforce operate within your permission model. An agent with an over-broad profile can surface data it should not or create audit trail gaps.
The audit process
Export all profiles and their object-level permissions. For each profile, document: which objects have read/write access, how many users are assigned, and when it was last modified. Group profiles by similarity: if two profiles differ only on a few field-level permissions, they are candidates for consolidation.
Then review permission sets. Many orgs use them inconsistently: some users get permissions from their profile, some from a permission set, some from both. The net result is difficult to audit.
Consolidation approach
The modern best practice is a minimum viable profile (limited base permissions) plus permission set groups that grant access by role or function. Map each existing profile to a proposed permission set group. Build the new structure, test with a pilot group, and migrate users in batches.
Governance and Access is one of six dimensions in the AI-Ready RevOps Framework. Profile and permission discipline determines what your AI tools can see, modify, and act on.
Try it free →Free Assessment
Frequently asked questions
How many Salesforce profiles should an org have?
Most mid-market orgs can operate with 5-10 profiles. If you have more than 20, you almost certainly have redundant profiles that should be consolidated.
What is the risk of permission sprawl?
Over-broad permissions mean users and AI agents can see and modify data they should not. This creates compliance risk, audit trail gaps, and data quality issues.
Score your stack.
The free 15-question assessment produces a Readiness Index in under four minutes. See where your foundation stands across six weighted dimensions.
Take the assessment