Your org's security score
Every analyzed org gets a security score — a single number summarizing how safely the org is configured, so you can track posture over time and compare orgs at a glance.
Where the score comes from
bluefactory evaluates your captured security metadata — profiles, permission sets, and org-wide security settings — against a catalog of security rules. Each rule that fails produces a finding; the findings are weighted into the score. Typical factors include:
- Dangerous permissions (such as Modify All Data) granted broadly.
- Weak org-wide security settings (password policies, session settings).
- Over-permissive profiles or permission sets.
The score updates with each new metadata capture, so it always reflects a real, dated state of your org. The score card's headline reads it for you: Strong posture, Some gaps to close, Needs attention, or — when criticals exist — the number of critical risks to fix. Four indicators sit alongside: Critical risks, Warnings, New since last capture, and Resolved.
[SCREENSHOT REQUIRED: Org security score card with the headline and KPI indicators]
Watching the trend
The score card shows the change since the previous capture, plus how many findings are new and how many were resolved. A sudden drop usually means a recent change granted risky access — check the Change Tracker for what changed in the same period, then use the user access analysis to see who is affected.
Improving your score
- Open the org's Security Center page and look at what "needs attention".
- Drill into affected users and items to understand the impact.
- Fix the configuration in Salesforce (tighten a permission set, adjust a setting).
- Run a fresh metadata capture and watch the score move.