Every public Experience Cloud site works through a guest user — an unauthenticated context with a real profile and real object grants. That is by design, and it is fine — until the grants accumulate past what the public site was meant to show.
How exposure happens without anyone deciding it
A component needs one object readable, so the grant is added. A form needs create on another. A troubleshooting session in 2022 adds read on a parent object “temporarily.” Guest sharing rules widen things further. No single step was wrong; the sum is an unauthenticated surface nobody has reviewed as a whole. Salesforce itself has been tightening guest defaults since Winter ’21 — hard-restricting guest writes — precisely because this accumulation pattern kept producing incidents.
The review that works
List the guest profile’s object grants and read the list as a persona: should an anonymous visitor reach this object at all? Write-class grants deserve immediate scrutiny. Then review guest sharing rules alongside — access is the union. And re-check after site changes, because the grants drift.
Horus Eye files one finding per guest profile, mechanism-graded — critical when any write-class grant survives, high for read — while saying plainly what the scan cannot judge: whether each object belongs in your public persona. That call stays yours; the evidence shouldn’t take a week to assemble.


