Skip to main content

Your org's security score

Every analyzed org gets a security score — a single number summarizing how safely the org is configured, so you can track posture over time and compare orgs at a glance.

Where the score comes from

bluefactory evaluates your captured security metadata — profiles, permission sets, and org-wide security settings — against a catalog of security rules. Each rule that fails produces a finding; the findings are weighted into the score. Typical factors include:

  • Dangerous permissions (such as Modify All Data) granted broadly.
  • Weak org-wide security settings (password policies, session settings).
  • Over-permissive profiles or permission sets.

The score updates with each new metadata capture, so it always reflects a real, dated state of your org. The score card's headline reads it for you: Strong posture, Some gaps to close, Needs attention, or — when criticals exist — the number of critical risks to fix. Four indicators sit alongside: Critical risks, Warnings, New since last capture, and Resolved.

[SCREENSHOT REQUIRED: Org security score card with the headline and KPI indicators]

Watching the trend

The score card shows the change since the previous capture, plus how many findings are new and how many were resolved. A sudden drop usually means a recent change granted risky access — check the Change Tracker for what changed in the same period, then use the user access analysis to see who is affected.

Improving your score

  1. Open the org's Security Center page and look at what "needs attention".
  2. Drill into affected users and items to understand the impact.
  3. Fix the configuration in Salesforce (tighten a permission set, adjust a setting).
  4. Run a fresh metadata capture and watch the score move.