Salesforce org health check scorecard
A Salesforce org health check measures whether the org is secure, maintainable, reliable, and used. The free ForceFolks scorecard covers seven areas and produces a weighted score out of 100. Download it, attach evidence, assign owners, and turn each gap into a dated action.
What does this Salesforce health check cover?
Salesforce has an official Security Health Check. It compares selected security settings with the Salesforce Baseline Standard or a custom baseline. Use it. Do not treat its percentage as a complete measure of org health.
The ForceFolks Salesforce org health check adds the operational areas that decide whether CRM work is safe and dependable: access design, data quality, automation, integrations, release control, adoption, and ownership. It is an assessment framework, not a Salesforce product and not a substitute for a penetration test or compliance audit.
How to use the scorecard
- Score every check from 0 to 3.
- Link evidence instead of relying on opinion.
- Record the risk, owner, next action, and due date.
- Re-score after remediation and keep the old result as a baseline.
Seven health areas, weighted to 100
Score 0 for absent or uncontrolled, 1 for high risk, 2 for partly controlled, and 3 for controlled with current evidence.
| Area | Weight | Evidence to inspect | Typical risk |
|---|---|---|---|
| Security baseline | 20% | Security Health Check, session settings, connected apps, audit trail | Excess access or weak controls |
| Access model | 15% | Profiles, permission sets, groups, roles, sharing rules | Access cannot be explained or removed safely |
| Data quality | 15% | Duplicates, required fields, stale records, ownership, retention | Reports and automation use unreliable data |
| Automation | 15% | Flows, Apex, scheduled jobs, errors, limits, test coverage | Conflicting logic or fragile transactions |
| Integrations | 15% | System ownership, API users, retries, monitoring, reconciliation | Silent data loss and unclear source of truth |
| Release and testing | 10% | Source control, deployment path, UAT, rollback, release log | Production changes cannot be reproduced |
| Adoption and operations | 10% | Usage, training, backlog, support metrics, named product owner | The org works technically but users bypass it |
Formula: add each area weight multiplied by its average score divided by 3. A blank check is not evidence of a pass.
What the final score means
The score is a triage aid. A single critical issue can outweigh the total. For example, an exposed integration credential, an unowned production deployment path, or unreconciled financial data requires immediate action even if the overall number looks acceptable.
Run the health check in five steps
- Set the scope: production orgs, sandboxes, Clouds, integrations, and business processes.
- Collect current evidence. Do not score from memory.
- Interview the product owner, admin, architect, data owner, security lead, and key users.
- Score each control, record the business impact, and assign an accountable owner.
- Approve a 30-, 60-, and 90-day remediation plan, then re-run the scorecard.
Salesforce org health check FAQ
What is a Salesforce org health check?
A Salesforce org health check is a structured review of security, access, data quality, automation, integrations, release controls, adoption, and operating ownership. It finds risks and turns them into a prioritized action plan.
Is this the same as Salesforce Security Health Check?
No. Salesforce Security Health Check compares security settings with a baseline. The ForceFolks scorecard includes that result, then reviews the wider operational health of the org. It does not replace a formal security or compliance assessment.
How often should a Salesforce org health check be run?
Run a full review before a major program, after a rescue, and at least once each year. Review critical security, integration, data, and release signals more often when the org changes quickly.
Who should own the health-check actions?
Assign one accountable owner and a due date to every accepted action. The owner may be a Salesforce product owner, admin, architect, security lead, data owner, or integration owner, depending on the finding.
Turn the score into a safer Salesforce org.
Share the completed scorecard with ForceFolks. We will verify the highest risks and define the smallest safe remediation plan.