Loading
Prepare for Email to Become the Default Login ExperienceRead More
Secure Your Salesforce Org
Access and Use the Security Health Review Tool

Access and Use the Security Health Review Tool

The Security Health Review tool provides an expert-grade assessment of your org’s security posture by analyzing metadata signals directly in Salesforce Setup. Use it to identify critical security findings, track remediation progress, and maintain compliance with Salesforce security standards.

Available in: Lightning Experience in Enterprise and Unlimited editions
User Permissions Needed
To access the Security Health Review tool: Customize Application OR Modify All Data

Access to Security Health Review is limited to Signature Success customers. The Health Assessments Agent requires the Salesforce Foundations add-on. To inquire about access, contact your Salesforce account executive.

Users whose profile includes the Customize Application or Modify All Data permission can access the Security Health Review tool by default, including the System Administrator profile. To grant access to users without these permissions, see Assign Access to the Security Health Review Tool.

Navigate to Security Health Review

  1. Log in to your Salesforce org.
  2. Click the gear icon in the top-right navigation bar and select Setup.
  3. In the Quick Find box, enter health assessments.
  4. Under Health Assessments, click Security Health Review.

Understand the Report Page

When you open Security Health Review, the most recent report for your org loads automatically. The page includes:

  • Reports remaining this week—shows how many reports you can still generate before the weekly limit resets.
  • Viewing dropdown—switch between previously generated reports. Each entry shows the generation timestamp and org name. The most recent report is labeled Latest.
  • Refresh—reloads the current report view.
  • PDF / CSV—download the current report as a PDF or a CSV.
  • Ask Agentforce—opens the Health Assessments Agent for an interactive analysis session.
  • Generate Report—initiates a new real-time scan of your org’s metadata.

Generate a Report

Click + Generate Report.

The scan runs in real time. The page updates automatically when the report is ready.

Note
Note

You can generate one report per week per org. The reports remaining this week counter at the top of the page tracks your usage. When you reach the report limit, the + Generate Report button is disabled until the limit resets.

Understand Report Sections

The report renders inline in Setup, organized into these sections:

Section Description
Disclaimer Describes the scope and limitations of the assessment. Security Health Review analyzes your org’s configuration against the Ideal Salesforce Org Security Hardening Benchmark. It isn’t a penetration test, compliance audit, or attestation. Salesforce security follows a shared responsibility model.
Report Overview Executive Summary summarizes the total number of critical-severity findings and identifies the security domains that require immediate executive attention, with a count of unique critical findings per domain. Findings that have been accepted as risk, mitigated, or marked not applicable are noted inline. Executive Call for Action provides a prioritized list of recommended executive sponsorship actions, mapped to the security domains with the highest critical finding counts.
Salesforce Mandated Critical Security Controls Lists the controls that Salesforce has identified as the mandatory baseline for all orgs. These controls can’t be dispositioned—they must be remediated. Each entry shows the finding ID, title, and instance count. Mandatory controls require remediation and can’t be accepted as risk, marked not applicable, or assigned a compensating control.
Severity Summary Tiles Displays finding counts across six categories: Compliant, Mandatory, Critical, High, Medium, and Low. Critical, High, and Low tiles also show a breakdown of accepted risk, mitigated, and not-applicable dispositions.
Remediation Progress Bar Shows the percentage of active findings currently in progress, with a breakdown of Blocked, In Progress, and Open findings.
Findings Tabs Provides the full detail view of all assessed controls, organized into three tabs: Findings (all active findings grouped by severity), Customized Controls (findings that have been dispositioned), and Compliant Controls (controls that passed the benchmark). For details on working with findings, see Review and Manage Security Health Review Findings.
Note
Note

If you fix a finding in your org, it only appears as compliant after you generate a new report. Disposition changes take effect immediately without requiring a new report.

Analyze Your Report with the Health Assessments Agent

Click Ask Agentforce to open the Health Assessments Agent directly in Setup. The agent can:

  • Generate summaries of your security findings.
  • Investigate critical issues within specific security domains.
  • Provide step-by-step remediation guidance.
  • Compare results across multiple scans.

Start with a prompt such as “Analyze my report” and continue with suggested actions or custom queries.

Note
Note

All standard actions in the Health Assessments Agent are available at no additional cost and do not consume Flex Credits.

Monitor Activity with the User Activity Log

The User Activity Log records all actions taken on the Security Health Review tool within your org, providing an audit trail for security governance and compliance purposes.

  1. In Setup, enter health assessments in the Quick Find box.
  2. Under Health Assessments, click User Activity Log.

The History table shows every user action, including:

Action Description
Report Generated A new report was generated, with org name and Org ID.
Disposition Added A finding was dispositioned for the first time, including the disposition type.
Disposition Changed An existing disposition was updated to a new type.
Disposition Removed A disposition was removed, returning the finding to the active findings list.
Remediation Status Changed A finding’s remediation status changed (such as from Open to In Progress, or from Blocked to Open).

Each entry shows the timestamp (UTC), the user who performed the action, the action type, and the finding ID affected.

To filter and search activity:

  • Use the Search activity box to search by keyword.
  • Use the All Actions dropdown to filter by action type.
  • Use the Filter by Finding ID field to view all activity for a specific finding.
 
Loading
Salesforce Help | Article