Skip to content

Salesforce Security In Action Workshop: What Admins Should Know

Salesforce's Security In Action workshop teaches admins to spot access risks fast; here's what it covers and how your org should prepare.

Salesforce Security In Action Workshop: What Admins Should Know
Salesforce Security In Action Workshop: What Admins Should Know

Salesforce launched a new monthly hands-on program called Security In Action in May 2026, giving admins a guided way to practice finding and fixing common security gaps inside a real Salesforce org. If you're an admin who has ever wondered "is my org actually secure, or does it just look fine?" this workshop — and the security fundamentals behind it — are worth understanding.

This post explains what the Security In Action workshop covers, why Salesforce is prioritizing hands-on security training now, and what admins and business leaders should do whether or not they attend a session. It also covers how these fundamentals apply to organizations with compliance obligations, since access and data-visibility mistakes carry more weight when regulators are involved.

Vantage Point works with Salesforce admins and business owners across industries to close exactly the kinds of gaps this workshop targets — sharing settings, field-level visibility, unused accounts, and permission sprawl — as part of ongoing Salesforce advisory and managed services.

Quick Answer

What it is: Security In Action is a free, recurring Salesforce workshop where admins work hands-on in a pre-built trial org to find and fix realistic security misconfigurations — overly open sharing settings, exposed sensitive fields, over-permissioned users, and stale accounts.

Who it matters for: Any Salesforce admin or IT/ops leader responsible for org security, especially those who inherited security responsibilities without formal training — plus organizations in regulated industries where access control is an audit requirement, not just a best practice.

What decision it supports: Whether to rely on ad hoc reviews or build a repeatable process — using Salesforce's own tools (Health Check, Security Center) plus expert guidance — to catch access and configuration risk before it becomes an incident.

Why Vantage Point is relevant: Vantage Point performs Salesforce security and access reviews as part of its compliance and security services, helping teams turn workshop takeaways into an actual remediation plan rather than a one-time exercise.

TL;DR

  • What it is: Salesforce's Security In Action is a monthly hands-on workshop that walks admins through fixing real-world sharing, access, and data-visibility issues in a guided trial org.
  • Why it matters: Most Salesforce security problems build up gradually through everyday admin decisions, not one dramatic failure — and Salesforce's own Health Check guidance notes that misconfigured access settings are a leading driver of breaches.
  • Best for: Admins who own security without formal training, and organizations that need a repeatable review process rather than a one-time cleanup.
  • Decision point: Whether your org needs a self-serve workshop, a structured internal Health Check cadence, or an outside Salesforce security assessment to close gaps faster.
  • How Vantage Point helps: Vantage Point runs Salesforce security and access reviews and pairs them with ongoing managed services so fixes don't quietly drift back open.

What Is the Security In Action Workshop?

Security In Action is a recurring, free virtual workshop from Salesforce built for admins who manage security without formal security training. Instead of a slide deck of best practices, participants work inside a pre-built trial org modeled on a fictional company, where common security issues have been deliberately built in. Working alongside a Salesforce expert, admins identify and fix problems like:

  • Sharing settings that are more open than they need to be
  • Sensitive fields visible to more users than intended
  • Users carrying more access than their role requires
  • Accounts that should have been deactivated but remain active

The first session ran in May 2026, focused on Data & Access. Salesforce has said the workshop will run monthly, using the same core structure (data, users, sessions) with different scenarios each time, and it has previewed a follow-up session on Agent Safeguards for AI agent security later in the year.

Why Security In Action Matters in 2026

Security in Salesforce is rarely one big decision — it's shaped by dozens of small ones made over time: how a sharing rule got set up two years ago, who got broad access during a rushed project, which accounts never got deactivated after someone left. Individually, each choice usually made sense in the moment. Collectively, they create gaps that are easy to miss.

A few reasons this matters more right now:

  • Admins often inherit security duties without training. Security is one of the five core responsibilities of a Salesforce admin, but many admins pick it up on the job rather than through formal preparation.
  • Access misconfiguration is a well-documented breach driver. Salesforce's own admin guidance on Health Check notes that misconfigured access settings account for a significant share of data breaches — small setting changes can meaningfully reduce that risk.
  • MFA enforcement is tightening. Salesforce has been rolling out stricter multi-factor authentication requirements for privileged users, making authentication hygiene a live compliance topic, not a future one.
  • Agentforce raises the stakes on access control. As more automation and AI agents act on Salesforce data, who can see and touch what becomes more consequential — over-permissioned users and agents both carry more risk than they used to.
  • For regulated organizations, this isn't optional. Financial services, healthcare, and other compliance-driven teams are expected to demonstrate access governance during audits, not just describe it after the fact.

How the Workshop (and Ongoing Security Review) Works

Security In Action follows a hands-on format, and the same general approach applies whether you attend the workshop or run a similar review internally:

  1. Start with the big picture. Use Salesforce's Security Health Check to see where your org's configuration stands against the Salesforce Baseline Standard.
  2. Review access structure. Look at org-wide defaults, role hierarchy, and sharing rules — these determine who can see records by default, before any individual permission is applied.
  3. Check field-level security. Confirm that sensitive fields (financial data, personal information, contract terms) are visible only to the roles that actually need them.
  4. Audit users and accounts. Identify inactive users who are still marked active, orphaned system accounts with no clear owner, and users who received broad access for a past project and never had it scaled back.
  5. Fix, document, and re-check. Apply changes individually or through bulk fixes aligned to the Baseline Standard, then re-run Health Check to confirm your score improved and nothing broke for end users.
  6. Repeat on a schedule. Security drifts as teams, projects, and integrations change — a single cleanup won't hold without a recurring review cadence.

Workshop vs. Health Check vs. Outside Security Review

Approach Best for Time investment Depth Ongoing coverage
Security In Action workshop Learning the fundamentals hands-on, admins new to security ownership ~1 session, monthly cadence Guided scenarios in a trial org, not your live data No — training only, not a review of your org
Self-run Health Check Admins comfortable interpreting scores and settings independently Ongoing, self-paced Covers your actual org configuration Yes, if scheduled regularly
Vantage Point security review Teams that need findings translated into a prioritized fix list, especially regulated orgs Project-based, typically days not weeks Full assessment of sharing, permissions, field security, and integration access in your live org Yes, paired with managed services for continuous monitoring

None of these are mutually exclusive. Many teams use the workshop to build admin fluency, run Health Check regularly as a baseline, and bring in outside help when they need an independent assessment or don't have bandwidth to run remediation themselves.

What Businesses Should Do Next

  • Register admins for the workshop if your team is still building security fundamentals — it's free and low-risk since it runs in a trial org, not production.
  • Run Health Check this quarter if you haven't looked at your Security Score recently. Treat a low or declining score as a signal to prioritize a review, not just a number to note.
  • Audit users and permission sets, especially anyone who received temporary or project-based access more than six months ago.
  • Document your MFA status for all privileged users ahead of Salesforce's enforcement timelines, and confirm phishing-resistant MFA options are supported where required.
  • Treat security as a recurring process, not a one-time project — schedule reviews the same way you'd schedule a release readiness check.
  • Bring in an outside review if your org supports regulated activity (financial services, healthcare, insurance) or if internal bandwidth doesn't allow for a thorough, independent look at access and sharing configuration.

How Vantage Point Helps

Vantage Point helps Salesforce admins and business leaders move from "probably fine" to "actually verified." Our compliance and security services include Salesforce access and sharing reviews, field-level security audits, and MFA/authentication readiness checks — the same categories the Security In Action workshop is designed to teach.

For organizations planning broader platform work, our Salesforce implementation and advisory services build security and governance into the design from the start, rather than retrofitting it later. And because access configuration drifts over time, our managed services and ongoing support keep security reviews on a recurring schedule instead of a one-time event.

If your team is evaluating how this applies to Salesforce security, access governance, or compliance readiness, Vantage Point can help assess the right next step and build a practical remediation plan.

FAQ

What is the Salesforce Security In Action workshop?

It's a free, recurring hands-on workshop where Salesforce admins work in a guided trial org to identify and fix common security misconfigurations, such as overly open sharing settings, exposed sensitive fields, and over-permissioned or inactive user accounts.

Who should attend Security In Action?

Any Salesforce admin responsible for security, especially those who inherited the responsibility without formal training. IT leaders and ops managers who oversee Salesforce access decisions also benefit from understanding the workshop's core concepts.

Is Security In Action the same as a Salesforce Health Check?

No. Health Check is a built-in tool that scores your live org's configuration against Salesforce's Baseline Standard. Security In Action is a training workshop that runs in a separate trial org designed to teach the concepts behind those settings.

How often does the workshop run?

Salesforce has said Security In Action runs monthly, using a consistent core structure (data, users, sessions) with different scenarios featured over time, plus a planned session on Agent Safeguards for AI agent security.

What's the most common Salesforce security mistake admins make?

Access accumulation is one of the most common patterns: users are granted broad or temporary access for a specific project and never have it scaled back afterward, leaving more people with more visibility than their role requires.

Does this apply to organizations with compliance requirements, like financial services or healthcare?

Yes, and it applies more directly. Regulated organizations are typically expected to demonstrate access governance during audits — documented reviews, timely deactivation, and least-privilege permissions — rather than simply describe good intentions.

How does Agentforce change the security picture?

As AI agents interact with Salesforce data and take actions on users' behalf, the access and permissions those agents inherit matter as much as human user access. Salesforce has previewed an upcoming Agent Safeguards workshop specifically to address this.

How can Vantage Point help beyond the workshop?

Vantage Point performs independent Salesforce security and access reviews, translates findings into a prioritized remediation plan, and can maintain ongoing monitoring through managed services so fixes hold over time instead of drifting back open.

David Cockrum

David Cockrum

David Cockrum is the founder and CEO of Vantage Point, a specialized Salesforce consultancy exclusively serving financial services organizations. As a former Chief Operating Officer in the financial services industry with over 13 years as a Salesforce user, David recognized the unique technology challenges facing banks, wealth management firms, insurers, and fintech companies—and created Vantage Point to bridge the gap between powerful CRM platforms and industry-specific needs. Under David’s leadership, Vantage Point has achieved over 150 clients, 400+ completed engagements, a 4.71/5 client satisfaction rating, and 95% client retention. His commitment to Ownership Mentality, Collaborative Partnership, Tenacious Execution, and Humble Confidence drives the company’s high-touch, results-oriented approach, delivering measurable improvements in operational efficiency, compliance, and client relationships. David’s previous experience includes founder and CEO of Cockrum Consulting, LLC, and consulting roles at Hitachi Consulting. He holds a B.B.A. from Southern Methodist University’s Cox School of Business.

Elements Image

Subscribe to our Blog

Get the latest articles and exclusive content delivered straight to your inbox. Join our community today—simply enter your email below!

Need help applying this to your CRM roadmap?

Talk to Vantage Point

Vantage Point helps regulated and growth-focused teams implement Salesforce, HubSpot, integrations, data migration, and managed services with practical, senior-led guidance.

Latest Articles

Salesforce Security In Action Workshop: What Admins Should Know

Salesforce Security In Action Workshop: What Admins Should Know

Salesforce's Security In Action workshop teaches admins to spot access risks fast; here's what it covers and how your org should prepare.

Measuring iPaaS ROI: A Framework for Automation Investments

Measuring iPaaS ROI: A Framework for Automation Investments

Learn a practical iPaaS ROI framework covering cost baselines, common mistakes, and how Workato compares to custom integration.

Orchestrating AI Agents Across Your Stack With Workato

Orchestrating AI Agents Across Your Stack With Workato

AI agents fail without orchestration. See how Workato connects AI agents to CRM, ERP, and HR systems with governed, auditable actions.