Salesforce launched a new monthly hands-on program called Security In Action in May 2026, giving admins a guided way to practice finding and fixing common security gaps inside a real Salesforce org. If you're an admin who has ever wondered "is my org actually secure, or does it just look fine?" this workshop — and the security fundamentals behind it — are worth understanding.
This post explains what the Security In Action workshop covers, why Salesforce is prioritizing hands-on security training now, and what admins and business leaders should do whether or not they attend a session. It also covers how these fundamentals apply to organizations with compliance obligations, since access and data-visibility mistakes carry more weight when regulators are involved.
Vantage Point works with Salesforce admins and business owners across industries to close exactly the kinds of gaps this workshop targets — sharing settings, field-level visibility, unused accounts, and permission sprawl — as part of ongoing Salesforce advisory and managed services.
Quick Answer
What it is: Security In Action is a free, recurring Salesforce workshop where admins work hands-on in a pre-built trial org to find and fix realistic security misconfigurations — overly open sharing settings, exposed sensitive fields, over-permissioned users, and stale accounts.
Who it matters for: Any Salesforce admin or IT/ops leader responsible for org security, especially those who inherited security responsibilities without formal training — plus organizations in regulated industries where access control is an audit requirement, not just a best practice.
What decision it supports: Whether to rely on ad hoc reviews or build a repeatable process — using Salesforce's own tools (Health Check, Security Center) plus expert guidance — to catch access and configuration risk before it becomes an incident.
Why Vantage Point is relevant: Vantage Point performs Salesforce security and access reviews as part of its compliance and security services, helping teams turn workshop takeaways into an actual remediation plan rather than a one-time exercise.
Security In Action is a recurring, free virtual workshop from Salesforce built for admins who manage security without formal security training. Instead of a slide deck of best practices, participants work inside a pre-built trial org modeled on a fictional company, where common security issues have been deliberately built in. Working alongside a Salesforce expert, admins identify and fix problems like:
The first session ran in May 2026, focused on Data & Access. Salesforce has said the workshop will run monthly, using the same core structure (data, users, sessions) with different scenarios each time, and it has previewed a follow-up session on Agent Safeguards for AI agent security later in the year.
Security in Salesforce is rarely one big decision — it's shaped by dozens of small ones made over time: how a sharing rule got set up two years ago, who got broad access during a rushed project, which accounts never got deactivated after someone left. Individually, each choice usually made sense in the moment. Collectively, they create gaps that are easy to miss.
A few reasons this matters more right now:
Security In Action follows a hands-on format, and the same general approach applies whether you attend the workshop or run a similar review internally:
| Approach | Best for | Time investment | Depth | Ongoing coverage |
|---|---|---|---|---|
| Security In Action workshop | Learning the fundamentals hands-on, admins new to security ownership | ~1 session, monthly cadence | Guided scenarios in a trial org, not your live data | No — training only, not a review of your org |
| Self-run Health Check | Admins comfortable interpreting scores and settings independently | Ongoing, self-paced | Covers your actual org configuration | Yes, if scheduled regularly |
| Vantage Point security review | Teams that need findings translated into a prioritized fix list, especially regulated orgs | Project-based, typically days not weeks | Full assessment of sharing, permissions, field security, and integration access in your live org | Yes, paired with managed services for continuous monitoring |
None of these are mutually exclusive. Many teams use the workshop to build admin fluency, run Health Check regularly as a baseline, and bring in outside help when they need an independent assessment or don't have bandwidth to run remediation themselves.
Vantage Point helps Salesforce admins and business leaders move from "probably fine" to "actually verified." Our compliance and security services include Salesforce access and sharing reviews, field-level security audits, and MFA/authentication readiness checks — the same categories the Security In Action workshop is designed to teach.
For organizations planning broader platform work, our Salesforce implementation and advisory services build security and governance into the design from the start, rather than retrofitting it later. And because access configuration drifts over time, our managed services and ongoing support keep security reviews on a recurring schedule instead of a one-time event.
If your team is evaluating how this applies to Salesforce security, access governance, or compliance readiness, Vantage Point can help assess the right next step and build a practical remediation plan.
It's a free, recurring hands-on workshop where Salesforce admins work in a guided trial org to identify and fix common security misconfigurations, such as overly open sharing settings, exposed sensitive fields, and over-permissioned or inactive user accounts.
Any Salesforce admin responsible for security, especially those who inherited the responsibility without formal training. IT leaders and ops managers who oversee Salesforce access decisions also benefit from understanding the workshop's core concepts.
No. Health Check is a built-in tool that scores your live org's configuration against Salesforce's Baseline Standard. Security In Action is a training workshop that runs in a separate trial org designed to teach the concepts behind those settings.
Salesforce has said Security In Action runs monthly, using a consistent core structure (data, users, sessions) with different scenarios featured over time, plus a planned session on Agent Safeguards for AI agent security.
Access accumulation is one of the most common patterns: users are granted broad or temporary access for a specific project and never have it scaled back afterward, leaving more people with more visibility than their role requires.
Yes, and it applies more directly. Regulated organizations are typically expected to demonstrate access governance during audits — documented reviews, timely deactivation, and least-privilege permissions — rather than simply describe good intentions.
As AI agents interact with Salesforce data and take actions on users' behalf, the access and permissions those agents inherit matter as much as human user access. Salesforce has previewed an upcoming Agent Safeguards workshop specifically to address this.
Vantage Point performs independent Salesforce security and access reviews, translates findings into a prioritized remediation plan, and can maintain ongoing monitoring through managed services so fixes hold over time instead of drifting back open.