Free scorecard

Salesforce org health check scorecard

Direct answer

A Salesforce org health check measures whether the org is secure, maintainable, reliable, and used. The free ForceFolks scorecard covers seven areas and produces a weighted score out of 100. Download it, attach evidence, assign owners, and turn each gap into a dated action.

What does this Salesforce health check cover?

Salesforce has an official Security Health Check. It compares selected security settings with the Salesforce Baseline Standard or a custom baseline. Use it. Do not treat its percentage as a complete measure of org health.

The ForceFolks Salesforce org health check adds the operational areas that decide whether CRM work is safe and dependable: access design, data quality, automation, integrations, release control, adoption, and ownership. It is an assessment framework, not a Salesforce product and not a substitute for a penetration test or compliance audit.

How to use the scorecard

  • Score every check from 0 to 3.
  • Link evidence instead of relying on opinion.
  • Record the risk, owner, next action, and due date.
  • Re-score after remediation and keep the old result as a baseline.
Scoring model

Seven health areas, weighted to 100

Score 0 for absent or uncontrolled, 1 for high risk, 2 for partly controlled, and 3 for controlled with current evidence.

AreaWeightEvidence to inspectTypical risk
Security baseline20%Security Health Check, session settings, connected apps, audit trailExcess access or weak controls
Access model15%Profiles, permission sets, groups, roles, sharing rulesAccess cannot be explained or removed safely
Data quality15%Duplicates, required fields, stale records, ownership, retentionReports and automation use unreliable data
Automation15%Flows, Apex, scheduled jobs, errors, limits, test coverageConflicting logic or fragile transactions
Integrations15%System ownership, API users, retries, monitoring, reconciliationSilent data loss and unclear source of truth
Release and testing10%Source control, deployment path, UAT, rollback, release logProduction changes cannot be reproduced
Adoption and operations10%Usage, training, backlog, support metrics, named product ownerThe org works technically but users bypass it

Formula: add each area weight multiplied by its average score divided by 3. A blank check is not evidence of a pass.

Interpretation

What the final score means

85–100Controlled. Maintain evidence and address isolated risks.
70–84Stable with gaps. Fund a focused remediation backlog.
50–69Material risk. Sequence fixes before major expansion.
0–49Uncontrolled. Stabilize security, data, and releases first.

The score is a triage aid. A single critical issue can outweigh the total. For example, an exposed integration credential, an unowned production deployment path, or unreconciled financial data requires immediate action even if the overall number looks acceptable.

Review sequence

Run the health check in five steps

  1. Set the scope: production orgs, sandboxes, Clouds, integrations, and business processes.
  2. Collect current evidence. Do not score from memory.
  3. Interview the product owner, admin, architect, data owner, security lead, and key users.
  4. Score each control, record the business impact, and assign an accountable owner.
  5. Approve a 30-, 60-, and 90-day remediation plan, then re-run the scorecard.
FAQ

Salesforce org health check FAQ

What is a Salesforce org health check?

A Salesforce org health check is a structured review of security, access, data quality, automation, integrations, release controls, adoption, and operating ownership. It finds risks and turns them into a prioritized action plan.

Is this the same as Salesforce Security Health Check?

No. Salesforce Security Health Check compares security settings with a baseline. The ForceFolks scorecard includes that result, then reviews the wider operational health of the org. It does not replace a formal security or compliance assessment.

How often should a Salesforce org health check be run?

Run a full review before a major program, after a rescue, and at least once each year. Review critical security, integration, data, and release signals more often when the org changes quickly.

Who should own the health-check actions?

Assign one accountable owner and a due date to every accepted action. The owner may be a Salesforce product owner, admin, architect, security lead, data owner, or integration owner, depending on the finding.

Turn the score into a safer Salesforce org.

Share the completed scorecard with ForceFolks. We will verify the highest risks and define the smallest safe remediation plan.