Paste your Profile or PermissionSet XML
Retrieve from SFDX: sf project retrieve start -m Profile,PermissionSet then paste. Multiple files supported — concatenate them.

Paste one or multiple .profile-meta.xml / .permissionset-meta.xml files — the auditor detects file boundaries automatically.

🔐

Drop your Profile & PermissionSet files here

Retrieve from SFDX: sf project retrieve start -m Profile,PermissionSet

.profile-meta.xml .permissionset-meta.xml Multiple files OK
Each file is one Profile or PermissionSet. Drop multiple to audit your full permission landscape.

Auditing your permissions…

Running all risk checks. Usually takes under a second.

Parsing Profile & PermissionSet metadata
Scanning for admin cloning smells and over-privilege
Checking FLS exposure and sharing risks
Detecting stale and unused permission sets
Auditing license waste and naming quality
🔐 Permission Audit
Permission Bloat Report
0 entities
/100
Over-Privileged
Admin Cloning
Sharing & FLS
Stale / License
Naming Quality
🧬 Admin Cloning Smells
🚨 Over-Privileged Access
🕳 Unused / Stale Permissions
🔓 Sharing & FLS Exposure
💸 License Waste
📝 Naming & Documentation

📋 Share with your team

Copy a plain-text executive summary to paste into Slack, Jira, or your next sprint review. Or download a formatted PDF to share with stakeholders and auditors.

Ready to go deeper?

Get live permission risk analysis across your whole org

This auditor catches what's visible in exported metadata. A live org connection cross-references permission sets against actual user assignments, last-login dates, and license types — so you get a true exposure picture, not just a flag list.

Live permset-to-user assignment cross-reference
Unused permsets with zero active assignments
Over-licensed users (Salesforce Platform vs. full CRM)
Weekly risk score with prioritized remediation queue

No spam. Get notified when live org permission analysis ships. Cancel anytime.

🔗 Permissions control what users can do — sharing rules control what records they can see.

→ Audit your Sharing Rules at /sharing

Further Reading

→ Salesforce Admin Debt: 7 Signs Your Org Needs an Audit