Flagship Engagement · Fixed Scope

Find out where your org actually stands

Every org drifts: fields multiply, automations pile up, permissions loosen, reports stop matching reality. The Health Assessment is the scheduled reckoning — technical and governance, tactical and architectural — ending in a report your admin can execute and your executive can fund. This one page is the whole engagement, including every cloud-specific track.

Sound familiar?

  • “Nobody knows what that Flow does.” — The builder left; everyone is afraid to touch it; new automation gets layered on top.
  • “Reports say three different numbers.” — Dashboard, spreadsheet, and QBR deck disagree — so leadership trusts none of them.
  • “Everyone's basically an admin.” — Permissions granted for one urgent task in 2021, never revoked; departed employees still holding access.
  • “We pay for licenses nobody uses.” — Seats for people who log in twice a quarter; premium features enabled and untouched.
  • “We want AI, but…” — Everyone suspects — correctly — that the data and security posture isn't ready to ground agents.

None of these mean your team failed. They mean the org has been succeeding for years — absorbing every urgent request without a scheduled reckoning. This is the reckoning, minus the drama.

The ten core areas — every org, every time

1

Security & access

Health Check score plus what it misses: permission sprawl, least-privilege gaps, departed-user access, field-level security drift.

2

Data quality

Duplicates, completeness where it matters, stale records, and whether the model still matches the business.

3

Automation & technical debt

Flow collisions, legacy Workflow/Process Builder, Apex quality, hard-coded IDs, automations firing four times per save.

4

Architecture & integrations

Object model, sharing architecture, integration patterns and their error handling, API consumption.

5

Performance & limits

Slow saves, data skew, storage burn, governor-limit near-misses, large-data-volume design.

6

Governance & release

Who decides what gets built, sandbox strategy, deployment discipline, and whether debt is tracked or just accumulated.

7

Reporting & analytics

Report sprawl, the single-source-of-truth question, and the metrics leadership actually needs.

8

Adoption & usability

Usage by role, layout bloat, and what your team does in spreadsheets because Salesforce made it hard.

9

Licensing & cost

Utilization against entitlement, feature overlap, and the renewal conversation with data in hand.

Salesforce keynote: Humans + Agents + Data + CRM on one platform
Why area ten exists: Salesforce’s own story is humans + agents + data + CRM — the first nine areas are the foundation it stands on — image © Salesforce, branding unaltered. Source: salesforce.com.
10

AI & agent readiness

Is your data grounded, your security agent-safe, your automation clean enough for a digital workforce? Scored against KAIROS™.

Every criterion is rated Good Standing, Improvement Opportunity, or Requires Attention — the same color-coded rubric as our DocGen assessment — so the report reads as a prioritized to-do list, not an essay.

How the engagement runs

  1. Week 1 — Discovery. Kickoff, stakeholder interviews (admin, architect, business owners, executive sponsor), and access setup. We learn how the org is supposed to work before judging how it does.
  2. Weeks 1–2 — Automated + manual review. Salesforce Optimizer and Security Health Check output, plus the part tools can't do: reading your automation, sharing model, integration patterns, and data quality against our checklist — tactical findings and architectural ones.
  3. Week 2–3 — Deep dives. Cloud-specific assessment areas (below), governance and release-management review, and a licensing/cost pass most assessments skip.
  4. Week 3 — Report & readout. A written, color-coded report: findings, ratings, effort estimates, and a sequenced 90-day/12-month remediation roadmap. Presented live to your team; yours to keep, whoever does the work.

Smaller org? The two-week Health Check

Same rubric, narrower depth, fixed price: a certified architect audits security, technical debt, automation, and data quality in two weeks and hands you the prioritized roadmap. It upgrades to the full assessment any time.

Cloud-specific tracks

Deep Dives

The core ten cover every org — including Sales Cloud, assessed in full in the general engagement. On top, your cloud gets its own issue library. Find yours below; every finding style is the same: what we see, how it happens, what it costs you.

Revenue Management & CPQ track

Cloud Deep-Dive

Quote-to-cash breaks quietly: a discount that vanishes between systems, a bundle nobody can quote, a renewal co-termed by hand at midnight. We assess the catalog, the rules, and the process they're supposed to serve — and whether legacy CPQ is ready for the ARM migration on Salesforce's roadmap.

Sound familiar?

  • Quotes take days, not minutes — Reps route around CPQ with spreadsheets; deal desk is a bottleneck with a backlog.
  • The catalog reads like the ERP — Thousands of SKUs replicated wholesale instead of modeled for how deals are actually sold.
  • Rules nobody dares touch — Price rules and product rules stacked over years; changing one breaks three quotes at month-end.
  • Finance reconciles by hand — What was quoted, ordered, and billed live in three systems that almost agree.

The findings we see most

Common findingHow it happensWhat it costs you
Catalog sprawl / ERP replicationThe ERP catalog imported wholesale at go-live 'to be safe'Unquotable products, slow config screens, rules debt compounding
Over-complex product & price rulesEach edge case patched with another rule; no periodic consolidationFragile quoting, month-end failures, fear-driven change freeze
Pricing model ≠ how deals are soldSystem modeled from the price book, not from real deal patterns (ramps, co-terms, usage)Reps discount off-system; approved margins exist only on paper
Quote/order/billing sync gapsIntegration field mappings incomplete; async timing drops changesDiscounts and line changes silently lost between systems
Amendment & renewal debtAmendments handled manually because the model can't express themCo-term errors, revenue leakage, renewal surprises
Approval sprawlApproval chains added per stakeholder request, never rationalizedDeals wait days for approvals nobody remembers instituting
Quote document driftTemplates cloned per team; branding and legal terms divergeWrong terms reach customers; legal finds out later
Legacy CPQ migration blindnessNo inventory of what's actually used ahead of the ARM roadmapThe migration happens on a deadline's terms instead of yours

Related: Agentforce Revenue Management · CPQ → RCA migration offer · our quote-to-cash practice (Cummins, ATCO, MongoDB, Palo Alto Networks).

Field Service track

Cloud Deep-Dive

Industry research says almost half of field appointments don't go as planned. Most of the causes live in configuration: territories drawn wrong, durations guessed at go-live and never corrected, an optimization engine nobody trusts because nobody tuned it. We assess all of it — before you put agents on top.

Horus running a field service operation

Sound familiar?

  • Dispatchers override everything — The schedule the engine builds gets rebuilt by hand every morning — so why run the engine?
  • Technicians arrive blind — No asset history, no parts context; first-time-fix rate says so.
  • The mobile app is optional — Techs call in updates; admin staff re-key them; data quality decays from the field inward.
  • Every day has holes — Cancellations and early finishes leave gaps nobody fills until tomorrow.

The findings we see most

Common findingHow it happensWhat it costs you
Territory misdesignTerritories drawn by org chart or geography guesswork, overloaded beyond practical resource countsSlow dispatch console, poor optimization, burned-out crews
Work types with fictional durationsDurations set once at go-live from estimates, never trued against actualsOverruns cascade through every schedule daily
Inconsistent travel buffersEach territory configured differently, some not at allEngine promises impossible days; customers get missed windows
Scheduling policies unexaminedDefault policies live untouched; business objectives (SLA vs overtime) never encodedThe engine optimizes for goals nobody chose
Optimization mistrustEarly bad results (from the issues above) taught dispatchers to overridePaying for an engine while scheduling by hand
Mobile adoption gapsClunky layouts, offline problems, no technician voice in designStatus updates late or absent; the office flies blind
Parts & inventory blindnessVan stock and parts data not maintained in the system38% of disrupted jobs involve missing parts — an industry-reported pattern we see constantly
Appointment data volume debtYears of completed appointments never archivedConsole performance decays; optimization windows stretch

Related: Agentforce Field Service · our Field Service practice — including a 12-month energy-sector program whose UAT packages the client called the best they'd received.

Service Cloud track

Cloud Deep-Dive

Service orgs accumulate debt faster than any other cloud — every escalation spawns a status, every reorg a queue, every tool a channel. We assess the case lifecycle end to end, and score whether your knowledge and data could actually ground an AI agent.

Sound familiar?

  • Cases bounce between queues — Routing logic from three reorgs ago; agents cherry-pick; the oldest cases are the least loved.
  • Knowledge exists but nobody uses it — Articles stale, search unhelpful, agents keep answers in personal docs.
  • SLAs are aspirational — Entitlements configured once, milestones ignored, breaches discovered in QBRs.
  • Handle time climbs anyway — More macros, more tabs, more tools — and somehow slower resolution.

The findings we see most

Common findingHow it happensWhat it costs you
Routing & queue sprawlQueues added per team per reorg; omni-channel half-adoptedCases wait in queues nobody watches; SLAs breach silently
Case status inflationEvery team added statuses; no lifecycle ownerReporting mush — nobody can say how many cases are truly open
Stale or orphaned knowledgeNo review cycle, no ownership, no feedback loop from cases to articlesAgents answer from memory; customers get inconsistent answers
Entitlements not enforcedMilestones configured at go-live, alerts routed to a dead inboxPaying-for-priority customers wait like everyone else
Channel fragmentationEmail, phone, chat, and social each bolted on separatelyCustomers repeat themselves; context dies at every hop
Console clutterLayouts grown by committee; every field someone once wantedSeconds lost per case, thousands of cases per week
Escalation loopsEscalation defined socially, not systemicallyHigh-severity cases depend on who's in the Slack channel that day
Deflection-unready knowledgeKB too thin or stale to ground an agentAgentforce Service pilots underperform and get blamed unfairly

Related: Agentforce Service · the customer service agent, explained · our Service Cloud practice (certified since 2019).

Experience Cloud track

Cloud Deep-Dive

Salesforce Security has publicly warned about threat actors mass-scanning Experience Cloud sites for over-permissive guest access — a configuration problem, not a platform one. If you run a portal or public site, this is the assessment with the shortest path from finding to 'fix it today.'

Sound familiar?

  • Nobody has reviewed guest access since launch — The guest profile was opened up to make something work in UAT; it stayed open.
  • Sharing model is folklore — Why external users see what they see is explained by 'it's always been like that.'
  • The portal is slow — Components stacked without performance budgets; every page loads everything.
  • License costs surprise everyone — Member-based versus login-based chosen years ago, never revisited against actual usage.

The findings we see most

Common findingHow it happensWhat it costs you
Over-permissive guest user profileObject/field access granted to unblock a build; API access left enabledUnauthenticated data exposure — the exact pattern in active theft campaigns
External org-wide defaults too openDefault external access never restricted after go-liveRecords visible to anyone on the internet, no login required
Sharing sets & rules driftRules accreted per use case; no periodic reviewExternal users seeing other customers' data — found by them, or worse
Aura/GraphQL exposure unexaminedPublic endpoints never tested the way attackers test themMass extraction at scale before anyone notices
Self-registration handler flawsCustom registration code written fast, reviewed neverAccount-creation abuse and privilege mistakes
License-type mismatchMember vs login-based chosen on a guessFive or six figures of annual overspend
Performance debtRich components, no lazy loading, unbounded queriesSlow pages, abandoned sessions, support tickets about the support portal
Stale content & broken journeysNo content owner after launch team disbandedThe public face of your brand, quietly rotting

Related: our Experience Cloud practice · the security pass follows Salesforce's published guest-user guidance and current threat-research patterns.

Nonprofit Cloud track

Cloud Deep-Dive

Nonprofit orgs carry a special kind of debt: built by volunteers and rotating admins, customized around every campaign, and now facing the NPSP-to-Nonprofit-Cloud question. We assess what you have, what it costs you, and what the migration decision actually looks like for your data — the practice behind our NAACP award-winning delivery.

Horus presents nonprofit Salesforce patterns

Sound familiar?

  • Donors exist three times — Same constituent, three records, three giving histories — and a development officer merging by hand.
  • Reports take a specialist — Answering 'how much did we raise from this campaign' crosses four objects and two workarounds.
  • Gift entry is a bottleneck — Batch entry slow, recurring donations fragile, finance reconciliation manual.
  • Everyone asks about Nonprofit Cloud — The board read an article; nobody can say what migrating would actually take.

The findings we see most

Common findingHow it happensWhat it costs you
Constituent duplicatesImports, event tools, and online giving each creating records freelySplit giving histories; stewardship built on wrong numbers
NPSP customization debtYears of custom fields and triggers layered over the managed packageUpgrades painful; rollups slow; each change riskier than the last
Rollup performance decayLegacy rollups over growing gift volumesNightly jobs stretch; totals lag reality
Soft credit confusionHousehold, soft, and matching credit conventions never standardizedDonor totals disagree depending on who runs the report
Recurring donation fragilityLegacy RD model, payment-processor sync gapsFailed payments unnoticed; sustainer revenue leaks
Reporting complexityThe same person's data spread across many objects, heavily customizedBasic questions need a consultant; leadership stops asking
Integration patchworkGiving platform, email tool, and events each integrated differentlyData arrives duplicated, delayed, or not at all
The unexamined NPC questionNo usage inventory or data-model mapping toward Nonprofit CloudDecisions made on articles and anxiety instead of evidence

Related: our Nonprofit practice — including the NAACP program that won the 2022 Nintex Solution Innovation Award · DocGen for acknowledgment letters and grant documents.

Education Cloud track

Cloud Deep-Dive

Higher-ed orgs are where data models go to be tested: every student is a person, an applicant, an enrollee, an alum, and sometimes an employee — simultaneously. We assess how your EDA or Education Cloud org holds up, with delivery experience at the University of British Columbia behind the checklist.

Horus presents Agentforce use cases in higher education

Sound familiar?

  • Students exist in duplicate — Recruiting created one record, the SIS integration another, an event signup a third.
  • The SIS sync is a nightly adventure — Banner/Colleague/Workday sync errors reviewed manually — when someone remembers.
  • Advisors can't see the whole student — Program, term, and success data scattered; the 360 view requires six tabs.
  • Access reviews scare everyone — FERPA-relevant data, and nobody can crisply say who can see what.

The findings we see most

Common findingHow it happensWhat it costs you
Account model misconfigurationAdministrative vs Household model chosen by default at go-liveReporting and relationships fight the model forever after
Duplicate student recordsRecruiting, SIS, and events each inserting without matching rulesAdvisors act on partial histories; communications double-send
SIS integration fragilityPoint-to-point sync built once, error handling minimalTerm data late or wrong at the moments that matter most
Affiliation & relationship sprawlEDA's flexible model used inconsistently across departmentsThe same relationship encoded four ways; reports disagree
Program & term data driftConventions unowned across recruiting, registrar, and advancementCohort reporting requires manual reconciliation each cycle
FERPA access ambiguitySharing grown organically across recruiting, advising, and facultyCompliance exposure and over-broad visibility
Funnel blind spotsAdmissions stages tracked outside the platform in parallel sheetsYield decisions made on last month's numbers
EDA-to-Education-Cloud blindnessNo inventory of EDA usage against the new modelMigration conversations run on rumor instead of a map

Related: our Education practice — current Education/Sales Cloud architecture work at the University of British Columbia.

Financial Services Cloud track

Cloud Deep-Dive

FSC orgs answer to two masters: advisors who need everything one click away, and regulators who need least privilege provable. Most orgs drift toward one at the other's expense. We assess both sides — the data model and the compliance posture — with financial-sector delivery from Shift4 to OTIP behind the checklist.

Horus presents governed, compliant Salesforce patterns

Sound familiar?

  • Households don't match reality — Trusts, businesses, and multi-generational relationships flattened into whatever fit at go-live.
  • Access reviews take weeks — Book-of-business sharing built from exceptions; proving least privilege is archaeology.
  • KYC data ages in place — Refreshed at onboarding, then never; reviews run on stale facts.
  • Advisors keep shadow books — The real client picture lives in a spreadsheet because the org's one is incomplete.

The findings we see most

Common findingHow it happensWhat it costs you
Household model misuseComplex structures (trusts, LLCs, blended families) forced into simple groupingsWrong share-of-wallet math; advice built on partial pictures
Person account decision debtChosen (or avoided) early without weighing downstream reporting and integrationEvery integration and report pays a small tax forever
Compliance sharing sprawlBook-of-business access granted case by case under deadlineLeast privilege unprovable; audit findings and remediation fire drills
Stale KYC & client dataNo refresh cadence or ownership after onboardingRegulatory exposure and reviews that miss real risk
Financial account rollup decayRollups over growing account volumes never re-architectedSlow pages for advisors; nightly jobs stretching into mornings
Core-system integration gapsBanking/portfolio sync built minimally, exceptions handled by emailThe CRM trusted least exactly where it must be trusted most
Action plans unusedCompliant workflows configured, then bypassed under time pressureThe audit trail exists for the process nobody follows
Permission set sprawlCloned and tweaked per team for yearsNobody can say what a role can do — and the regulator will ask

Related: our Financial Services practice — delivery for Shift4 Payments, Big I New York, Alitis Investment Counsel, OTIP RAEO, and CSC Leasing.

What you walk away with

The report

Color-coded findings across all areas — written for the admin who'll fix things and the executive who'll fund them.

The roadmap

A sequenced 90-day/12-month plan with effort estimates — quick wins first, architectural moves staged.

The baseline

Scores you can re-measure annually — the delta is your governance story, for leadership and auditors alike.

Frequently asked questions

FAQ
What is a Salesforce Health Assessment?

A structured audit of your Salesforce org across ten areas — security, data quality, automation debt, architecture, performance, governance, reporting, adoption, licensing, and AI readiness — plus cloud-specific deep tracks, ending in a color-coded report and sequenced remediation roadmap.

How long does it take and what does it cost?

Typically three weeks, fixed scope and price. A lighter fixed-price two-week Health Check is available for smaller orgs — same rubric, narrower depth.

How is this different from Salesforce Optimizer?

We run the automated tools — then do what they can't: read your automation logic, evaluate architecture against how the business works, interview stakeholders, and weigh governance and cost. Tools find symptoms; the assessment finds causes and sequences fixes.

Horus, the Kemisoft falcon mascot

Nothing escapes the falcon eye

Ten assessment areas, tactical to architectural — presented the way Horus likes it: on one dashboard, color-coded, with nowhere for technical debt to hide.

Scope Your Assessment

Horus™ is the Kemisoft falcon — named for the sky-eyed guardian of ancient Kemet.

Three weeks to the truth

Fixed scope, color-coded report, sequenced roadmap — yours to keep, whoever does the work.

Scope Your Assessment