Flagship Engagement · Fixed Scope
Find out where your org actually stands
Every org drifts: fields multiply, automations pile up, permissions loosen, reports stop matching reality. The Health Assessment is the scheduled reckoning — technical and governance, tactical and architectural — ending in a report your admin can execute and your executive can fund. This one page is the whole engagement, including every cloud-specific track.
Sound familiar?
- “Nobody knows what that Flow does.” — The builder left; everyone is afraid to touch it; new automation gets layered on top.
- “Reports say three different numbers.” — Dashboard, spreadsheet, and QBR deck disagree — so leadership trusts none of them.
- “Everyone's basically an admin.” — Permissions granted for one urgent task in 2021, never revoked; departed employees still holding access.
- “We pay for licenses nobody uses.” — Seats for people who log in twice a quarter; premium features enabled and untouched.
- “We want AI, but…” — Everyone suspects — correctly — that the data and security posture isn't ready to ground agents.
None of these mean your team failed. They mean the org has been succeeding for years — absorbing every urgent request without a scheduled reckoning. This is the reckoning, minus the drama.
The ten core areas — every org, every time
Security & access
Health Check score plus what it misses: permission sprawl, least-privilege gaps, departed-user access, field-level security drift.
Data quality
Duplicates, completeness where it matters, stale records, and whether the model still matches the business.
Automation & technical debt
Flow collisions, legacy Workflow/Process Builder, Apex quality, hard-coded IDs, automations firing four times per save.
Architecture & integrations
Object model, sharing architecture, integration patterns and their error handling, API consumption.
Performance & limits
Slow saves, data skew, storage burn, governor-limit near-misses, large-data-volume design.
Governance & release
Who decides what gets built, sandbox strategy, deployment discipline, and whether debt is tracked or just accumulated.
Reporting & analytics
Report sprawl, the single-source-of-truth question, and the metrics leadership actually needs.
Adoption & usability
Usage by role, layout bloat, and what your team does in spreadsheets because Salesforce made it hard.
Licensing & cost
Utilization against entitlement, feature overlap, and the renewal conversation with data in hand.

AI & agent readiness
Is your data grounded, your security agent-safe, your automation clean enough for a digital workforce? Scored against KAIROS™.
Every criterion is rated Good Standing, Improvement Opportunity, or Requires Attention — the same color-coded rubric as our DocGen assessment — so the report reads as a prioritized to-do list, not an essay.
How the engagement runs
- Week 1 — Discovery. Kickoff, stakeholder interviews (admin, architect, business owners, executive sponsor), and access setup. We learn how the org is supposed to work before judging how it does.
- Weeks 1–2 — Automated + manual review. Salesforce Optimizer and Security Health Check output, plus the part tools can't do: reading your automation, sharing model, integration patterns, and data quality against our checklist — tactical findings and architectural ones.
- Week 2–3 — Deep dives. Cloud-specific assessment areas (below), governance and release-management review, and a licensing/cost pass most assessments skip.
- Week 3 — Report & readout. A written, color-coded report: findings, ratings, effort estimates, and a sequenced 90-day/12-month remediation roadmap. Presented live to your team; yours to keep, whoever does the work.
Smaller org? The two-week Health Check
Same rubric, narrower depth, fixed price: a certified architect audits security, technical debt, automation, and data quality in two weeks and hands you the prioritized roadmap. It upgrades to the full assessment any time.
Cloud-specific tracks
Deep DivesThe core ten cover every org — including Sales Cloud, assessed in full in the general engagement. On top, your cloud gets its own issue library. Find yours below; every finding style is the same: what we see, how it happens, what it costs you.
Revenue Management & CPQ track
Cloud Deep-DiveQuote-to-cash breaks quietly: a discount that vanishes between systems, a bundle nobody can quote, a renewal co-termed by hand at midnight. We assess the catalog, the rules, and the process they're supposed to serve — and whether legacy CPQ is ready for the ARM migration on Salesforce's roadmap.
Sound familiar?
- Quotes take days, not minutes — Reps route around CPQ with spreadsheets; deal desk is a bottleneck with a backlog.
- The catalog reads like the ERP — Thousands of SKUs replicated wholesale instead of modeled for how deals are actually sold.
- Rules nobody dares touch — Price rules and product rules stacked over years; changing one breaks three quotes at month-end.
- Finance reconciles by hand — What was quoted, ordered, and billed live in three systems that almost agree.
The findings we see most
| Common finding | How it happens | What it costs you |
|---|---|---|
| Catalog sprawl / ERP replication | The ERP catalog imported wholesale at go-live 'to be safe' | Unquotable products, slow config screens, rules debt compounding |
| Over-complex product & price rules | Each edge case patched with another rule; no periodic consolidation | Fragile quoting, month-end failures, fear-driven change freeze |
| Pricing model ≠ how deals are sold | System modeled from the price book, not from real deal patterns (ramps, co-terms, usage) | Reps discount off-system; approved margins exist only on paper |
| Quote/order/billing sync gaps | Integration field mappings incomplete; async timing drops changes | Discounts and line changes silently lost between systems |
| Amendment & renewal debt | Amendments handled manually because the model can't express them | Co-term errors, revenue leakage, renewal surprises |
| Approval sprawl | Approval chains added per stakeholder request, never rationalized | Deals wait days for approvals nobody remembers instituting |
| Quote document drift | Templates cloned per team; branding and legal terms diverge | Wrong terms reach customers; legal finds out later |
| Legacy CPQ migration blindness | No inventory of what's actually used ahead of the ARM roadmap | The migration happens on a deadline's terms instead of yours |
Related: Agentforce Revenue Management · CPQ → RCA migration offer · our quote-to-cash practice (Cummins, ATCO, MongoDB, Palo Alto Networks).
Field Service track
Cloud Deep-DiveIndustry research says almost half of field appointments don't go as planned. Most of the causes live in configuration: territories drawn wrong, durations guessed at go-live and never corrected, an optimization engine nobody trusts because nobody tuned it. We assess all of it — before you put agents on top.

Sound familiar?
- Dispatchers override everything — The schedule the engine builds gets rebuilt by hand every morning — so why run the engine?
- Technicians arrive blind — No asset history, no parts context; first-time-fix rate says so.
- The mobile app is optional — Techs call in updates; admin staff re-key them; data quality decays from the field inward.
- Every day has holes — Cancellations and early finishes leave gaps nobody fills until tomorrow.
The findings we see most
| Common finding | How it happens | What it costs you |
|---|---|---|
| Territory misdesign | Territories drawn by org chart or geography guesswork, overloaded beyond practical resource counts | Slow dispatch console, poor optimization, burned-out crews |
| Work types with fictional durations | Durations set once at go-live from estimates, never trued against actuals | Overruns cascade through every schedule daily |
| Inconsistent travel buffers | Each territory configured differently, some not at all | Engine promises impossible days; customers get missed windows |
| Scheduling policies unexamined | Default policies live untouched; business objectives (SLA vs overtime) never encoded | The engine optimizes for goals nobody chose |
| Optimization mistrust | Early bad results (from the issues above) taught dispatchers to override | Paying for an engine while scheduling by hand |
| Mobile adoption gaps | Clunky layouts, offline problems, no technician voice in design | Status updates late or absent; the office flies blind |
| Parts & inventory blindness | Van stock and parts data not maintained in the system | 38% of disrupted jobs involve missing parts — an industry-reported pattern we see constantly |
| Appointment data volume debt | Years of completed appointments never archived | Console performance decays; optimization windows stretch |
Related: Agentforce Field Service · our Field Service practice — including a 12-month energy-sector program whose UAT packages the client called the best they'd received.
Service Cloud track
Cloud Deep-DiveService orgs accumulate debt faster than any other cloud — every escalation spawns a status, every reorg a queue, every tool a channel. We assess the case lifecycle end to end, and score whether your knowledge and data could actually ground an AI agent.
Sound familiar?
- Cases bounce between queues — Routing logic from three reorgs ago; agents cherry-pick; the oldest cases are the least loved.
- Knowledge exists but nobody uses it — Articles stale, search unhelpful, agents keep answers in personal docs.
- SLAs are aspirational — Entitlements configured once, milestones ignored, breaches discovered in QBRs.
- Handle time climbs anyway — More macros, more tabs, more tools — and somehow slower resolution.
The findings we see most
| Common finding | How it happens | What it costs you |
|---|---|---|
| Routing & queue sprawl | Queues added per team per reorg; omni-channel half-adopted | Cases wait in queues nobody watches; SLAs breach silently |
| Case status inflation | Every team added statuses; no lifecycle owner | Reporting mush — nobody can say how many cases are truly open |
| Stale or orphaned knowledge | No review cycle, no ownership, no feedback loop from cases to articles | Agents answer from memory; customers get inconsistent answers |
| Entitlements not enforced | Milestones configured at go-live, alerts routed to a dead inbox | Paying-for-priority customers wait like everyone else |
| Channel fragmentation | Email, phone, chat, and social each bolted on separately | Customers repeat themselves; context dies at every hop |
| Console clutter | Layouts grown by committee; every field someone once wanted | Seconds lost per case, thousands of cases per week |
| Escalation loops | Escalation defined socially, not systemically | High-severity cases depend on who's in the Slack channel that day |
| Deflection-unready knowledge | KB too thin or stale to ground an agent | Agentforce Service pilots underperform and get blamed unfairly |
Related: Agentforce Service · the customer service agent, explained · our Service Cloud practice (certified since 2019).
Experience Cloud track
Cloud Deep-DiveSalesforce Security has publicly warned about threat actors mass-scanning Experience Cloud sites for over-permissive guest access — a configuration problem, not a platform one. If you run a portal or public site, this is the assessment with the shortest path from finding to 'fix it today.'
Sound familiar?
- Nobody has reviewed guest access since launch — The guest profile was opened up to make something work in UAT; it stayed open.
- Sharing model is folklore — Why external users see what they see is explained by 'it's always been like that.'
- The portal is slow — Components stacked without performance budgets; every page loads everything.
- License costs surprise everyone — Member-based versus login-based chosen years ago, never revisited against actual usage.
The findings we see most
| Common finding | How it happens | What it costs you |
|---|---|---|
| Over-permissive guest user profile | Object/field access granted to unblock a build; API access left enabled | Unauthenticated data exposure — the exact pattern in active theft campaigns |
| External org-wide defaults too open | Default external access never restricted after go-live | Records visible to anyone on the internet, no login required |
| Sharing sets & rules drift | Rules accreted per use case; no periodic review | External users seeing other customers' data — found by them, or worse |
| Aura/GraphQL exposure unexamined | Public endpoints never tested the way attackers test them | Mass extraction at scale before anyone notices |
| Self-registration handler flaws | Custom registration code written fast, reviewed never | Account-creation abuse and privilege mistakes |
| License-type mismatch | Member vs login-based chosen on a guess | Five or six figures of annual overspend |
| Performance debt | Rich components, no lazy loading, unbounded queries | Slow pages, abandoned sessions, support tickets about the support portal |
| Stale content & broken journeys | No content owner after launch team disbanded | The public face of your brand, quietly rotting |
Related: our Experience Cloud practice · the security pass follows Salesforce's published guest-user guidance and current threat-research patterns.
Nonprofit Cloud track
Cloud Deep-DiveNonprofit orgs carry a special kind of debt: built by volunteers and rotating admins, customized around every campaign, and now facing the NPSP-to-Nonprofit-Cloud question. We assess what you have, what it costs you, and what the migration decision actually looks like for your data — the practice behind our NAACP award-winning delivery.

Sound familiar?
- Donors exist three times — Same constituent, three records, three giving histories — and a development officer merging by hand.
- Reports take a specialist — Answering 'how much did we raise from this campaign' crosses four objects and two workarounds.
- Gift entry is a bottleneck — Batch entry slow, recurring donations fragile, finance reconciliation manual.
- Everyone asks about Nonprofit Cloud — The board read an article; nobody can say what migrating would actually take.
The findings we see most
| Common finding | How it happens | What it costs you |
|---|---|---|
| Constituent duplicates | Imports, event tools, and online giving each creating records freely | Split giving histories; stewardship built on wrong numbers |
| NPSP customization debt | Years of custom fields and triggers layered over the managed package | Upgrades painful; rollups slow; each change riskier than the last |
| Rollup performance decay | Legacy rollups over growing gift volumes | Nightly jobs stretch; totals lag reality |
| Soft credit confusion | Household, soft, and matching credit conventions never standardized | Donor totals disagree depending on who runs the report |
| Recurring donation fragility | Legacy RD model, payment-processor sync gaps | Failed payments unnoticed; sustainer revenue leaks |
| Reporting complexity | The same person's data spread across many objects, heavily customized | Basic questions need a consultant; leadership stops asking |
| Integration patchwork | Giving platform, email tool, and events each integrated differently | Data arrives duplicated, delayed, or not at all |
| The unexamined NPC question | No usage inventory or data-model mapping toward Nonprofit Cloud | Decisions made on articles and anxiety instead of evidence |
Related: our Nonprofit practice — including the NAACP program that won the 2022 Nintex Solution Innovation Award · DocGen for acknowledgment letters and grant documents.
Education Cloud track
Cloud Deep-DiveHigher-ed orgs are where data models go to be tested: every student is a person, an applicant, an enrollee, an alum, and sometimes an employee — simultaneously. We assess how your EDA or Education Cloud org holds up, with delivery experience at the University of British Columbia behind the checklist.

Sound familiar?
- Students exist in duplicate — Recruiting created one record, the SIS integration another, an event signup a third.
- The SIS sync is a nightly adventure — Banner/Colleague/Workday sync errors reviewed manually — when someone remembers.
- Advisors can't see the whole student — Program, term, and success data scattered; the 360 view requires six tabs.
- Access reviews scare everyone — FERPA-relevant data, and nobody can crisply say who can see what.
The findings we see most
| Common finding | How it happens | What it costs you |
|---|---|---|
| Account model misconfiguration | Administrative vs Household model chosen by default at go-live | Reporting and relationships fight the model forever after |
| Duplicate student records | Recruiting, SIS, and events each inserting without matching rules | Advisors act on partial histories; communications double-send |
| SIS integration fragility | Point-to-point sync built once, error handling minimal | Term data late or wrong at the moments that matter most |
| Affiliation & relationship sprawl | EDA's flexible model used inconsistently across departments | The same relationship encoded four ways; reports disagree |
| Program & term data drift | Conventions unowned across recruiting, registrar, and advancement | Cohort reporting requires manual reconciliation each cycle |
| FERPA access ambiguity | Sharing grown organically across recruiting, advising, and faculty | Compliance exposure and over-broad visibility |
| Funnel blind spots | Admissions stages tracked outside the platform in parallel sheets | Yield decisions made on last month's numbers |
| EDA-to-Education-Cloud blindness | No inventory of EDA usage against the new model | Migration conversations run on rumor instead of a map |
Related: our Education practice — current Education/Sales Cloud architecture work at the University of British Columbia.
Financial Services Cloud track
Cloud Deep-DiveFSC orgs answer to two masters: advisors who need everything one click away, and regulators who need least privilege provable. Most orgs drift toward one at the other's expense. We assess both sides — the data model and the compliance posture — with financial-sector delivery from Shift4 to OTIP behind the checklist.

Sound familiar?
- Households don't match reality — Trusts, businesses, and multi-generational relationships flattened into whatever fit at go-live.
- Access reviews take weeks — Book-of-business sharing built from exceptions; proving least privilege is archaeology.
- KYC data ages in place — Refreshed at onboarding, then never; reviews run on stale facts.
- Advisors keep shadow books — The real client picture lives in a spreadsheet because the org's one is incomplete.
The findings we see most
| Common finding | How it happens | What it costs you |
|---|---|---|
| Household model misuse | Complex structures (trusts, LLCs, blended families) forced into simple groupings | Wrong share-of-wallet math; advice built on partial pictures |
| Person account decision debt | Chosen (or avoided) early without weighing downstream reporting and integration | Every integration and report pays a small tax forever |
| Compliance sharing sprawl | Book-of-business access granted case by case under deadline | Least privilege unprovable; audit findings and remediation fire drills |
| Stale KYC & client data | No refresh cadence or ownership after onboarding | Regulatory exposure and reviews that miss real risk |
| Financial account rollup decay | Rollups over growing account volumes never re-architected | Slow pages for advisors; nightly jobs stretching into mornings |
| Core-system integration gaps | Banking/portfolio sync built minimally, exceptions handled by email | The CRM trusted least exactly where it must be trusted most |
| Action plans unused | Compliant workflows configured, then bypassed under time pressure | The audit trail exists for the process nobody follows |
| Permission set sprawl | Cloned and tweaked per team for years | Nobody can say what a role can do — and the regulator will ask |
Related: our Financial Services practice — delivery for Shift4 Payments, Big I New York, Alitis Investment Counsel, OTIP RAEO, and CSC Leasing.
What you walk away with
The report
Color-coded findings across all areas — written for the admin who'll fix things and the executive who'll fund them.
The roadmap
A sequenced 90-day/12-month plan with effort estimates — quick wins first, architectural moves staged.
The baseline
Scores you can re-measure annually — the delta is your governance story, for leadership and auditors alike.
Frequently asked questions
FAQWhat is a Salesforce Health Assessment?
A structured audit of your Salesforce org across ten areas — security, data quality, automation debt, architecture, performance, governance, reporting, adoption, licensing, and AI readiness — plus cloud-specific deep tracks, ending in a color-coded report and sequenced remediation roadmap.
How long does it take and what does it cost?
Typically three weeks, fixed scope and price. A lighter fixed-price two-week Health Check is available for smaller orgs — same rubric, narrower depth.
How is this different from Salesforce Optimizer?
We run the automated tools — then do what they can't: read your automation logic, evaluate architecture against how the business works, interview stakeholders, and weigh governance and cost. Tools find symptoms; the assessment finds causes and sequences fixes.
Nothing escapes the falcon eye
Ten assessment areas, tactical to architectural — presented the way Horus likes it: on one dashboard, color-coded, with nowhere for technical debt to hide.
Horus™ is the Kemisoft falcon — named for the sky-eyed guardian of ancient Kemet.
Three weeks to the truth
Fixed scope, color-coded report, sequenced roadmap — yours to keep, whoever does the work.
Scope Your Assessment

