Salesforce CRM audit
Nobody left at your company can explain why Salesforce behaves like that.
I audit Salesforce CRM orgs: the data model, Sales Cloud and Service Cloud processes, Flows and Apex, permissions, integrations, reporting, the release process, licences. Both packages give you prioritised findings with severity. Basic from EUR 3,250 covers the data model, data quality, automation and permissions, with quick wins and an effort estimate on each. Advanced from EUR 8,950 covers all ten areas and adds a technical debt register and a dated remediation roadmap. Fixed price, fixed scope, read-only access. Basic in 3 to 5 business days, Advanced in 2 to 3 weeks.
Six examples of what a finding looks like.
- Two reports with almost the same name, and the pipeline total in each one is different.
- A record-triggered Flow, a Process Builder and an Apex trigger all act on
Account. Their interactions are undocumented. - Forty profiles for sixty users, and nobody wants to be the person who deletes one.
- Cases get closed and reopened inside the same day. The SLA report still comes out green.
- Lead conversion drops two fields that the sales team fills in every single time.
- The sandbox was last refreshed before the current deployment process existed.
This is what the pattern costs: work that should be a two-day change takes longer, and no one can say why.
What the audit covers
Ten areas. Advanced covers all ten, with the deep dives on the data model and on automation. Basic covers the data model, data quality, automation and code, and permissions.
Data model and object architecture
Standard against custom objects, relationships and cascade behaviour, Account and Contact architecture, field inventory, picklist sprawl, external IDs. The sharing model: org-wide defaults, role hierarchy, sharing rules, ownership skew.
Data quality
Matching and duplicate rules, and which of them actually fire at save time. Validation rules users route around. Open opportunities past their close date, records owned by inactive users, contacts with no account. Storage against your allowance.
Sales process in Sales Cloud
Lead capture, assignment, conversion mapping and the fields that get dropped on the way. Opportunity stages against forecast categories. Products, price books, and which one is the price of record. What gets logged automatically, and what depends on a rep remembering.
Service process in Service Cloud
Case intake per channel, including cases received outside business hours. Assignment, queues, Omni-Channel, escalation, business hours. Entitlements and milestones: whether the SLA in the contract is the SLA the org measures. Status model, reopen behaviour, knowledge articles.
Automation and code
Flow inventory per object, entry conditions, before-save against after-save, run order between them. Workflow Rules and Process Builder still firing next to Flows. Apex: triggers per object, recursion guards, test coverage, hard-coded IDs, queries inside loops. Scheduled jobs, and who gets the email when one dies overnight.
Integrations and the Marketing Cloud seam
Every interface in and out, with direction and frequency. In Advanced, the connection to Marketing Cloud is reviewed from the CRM record side: which system owns the contact record, which owns consent, what the field mapping does to data quality, and what happens to CRM records when the sync fails. Campaign behaviour and consent at send time belong to the Marketing Cloud audit, and the report states that boundary. Error logs, alerting, retry, replay after an outage. Integration users, Connected Apps, OAuth scopes, secrets stored in code.
Permissions and security
Profile count against user count, permission set groups, permissions granted for completed projects and never withdrawn. How many people can change metadata in production. Field-level security on sensitive fields, export rights, multi-factor and session policy, Setup Audit Trail retention.
Reporting and forecasting
Report and dashboard inventory, and how many were run in the last 90 days. Whether pipeline, won and SLA mean one thing across the org. Forecast mechanics against the spreadsheet kept next to them. Scheduled exports, and which extract became the number the board sees.
Release process and governance
Sandbox strategy and refresh cadence. Change sets against tooling against direct edits in production. Naming conventions, field descriptions, the decision log. Backup, and when a restore was last tested.
Licences and cost
Licence types held against licence types used. Users who could sit on a Platform licence. Inactive users holding a seat. Add-ons provisioned and unused, storage overage, and what all of it is worth as input to your renewal.
Packages
Two audits to find the problems, one combined engagement when the problem crosses into Marketing Cloud, and monthly hours to do the work.
CRM Audit Basic
For a first look, or when one specific thing already worries you.
- 3 to 5 business days, about 14 hours of work
- Covers the data model, data quality, automation and code, and permissions
- Findings report, prioritised critical / important / nice-to-have
- Quick-wins list with an effort estimate per item
- Object and automation inventory: what exists, what runs, what is inactive
- 60-minute readout call
CRM Audit Advanced
For an org you inherited, a platform you are about to build on, or a team takeover.
- 2 to 3 weeks, about 45 hours of work
- All ten areas, with deep dives on the data model and on automation
- Full findings report with severity and the business consequence per finding
- Technical debt register with effort estimates, ordered so dependencies come first
- Data model map, and an automation map per object in run order
- Permission matrix: who can read, edit, export and configure what
- Remediation roadmap over 0-30, 30-90 and 90+ days
- Two workshops, one on findings and one on the roadmap
- Executive summary for the decision maker
Both platforms
CRM and Marketing Cloud audited together, when the problem sits on the sync between them.
- 4 to 5 weeks, about 70 hours of work
- Advanced coverage on both sides: ten CRM areas and seven Marketing Cloud areas
- The sync and the consent model get audited once, from both sides, instead of twice
- One report in two parts, one roadmap, two workshops
- About 70 hours instead of the 90 the two audits take separately. Kickoff, interviews, the integration and consent review, the roadmap and the workshops are shared, which works out at about EUR 184/h across the engagement instead of about EUR 199/h for the CRM audit alone
Monthly Support Hours
A booked block of my time, every month, for the fixes, the builds and the questions. The same hours can go to the CRM side, the Marketing Cloud side, or both in one month.
| Hours per month | Rate | Monthly |
|---|---|---|
| 4 h | EUR 200/h | EUR 800 |
| 8 h | EUR 175/h | EUR 1,400 |
| 16 h | EUR 150/h | EUR 2,400 |
Bigger block, lower hourly rate. Blocks above 16 hours per month are quoted on request.
Terms: minimum 3 months, then rolling. Invoiced monthly in advance. 30 days notice to stop. Unused hours carry over one month, then expire. Response within 1 business day. A short written report every month: what ran, what broke, where the hours went, and what is next.
All prices net, excluding VAT.
What the audit does not do
- No changes. Read-only access. Nothing deployed, nothing deleted, nothing switched off while I am in there.
- No cleanup execution. The report specifies the cleanup and estimates it. Running it is monthly hours or a separate project.
- No Apex rewrite. I read the code and report on it.
- No migration or rebuild, including the move off Workflow Rules and Process Builder. The audit identifies what needs to move and its priority. Migration work is separate.
- No legal opinion. Consent and retention risks go in the report in writing. Your lawyer signs off on them.
- CPQ, Revenue Cloud, Field Service and the industry clouds sit outside the fixed scope. Tell me on the call if you run them and we price that separately.
- Anything I cannot get access to is recorded as a gap in the report.
How it works
- Call, 30 minutes.You describe the org. I tell you which audit fits, or that you do not need one.
- Access and kickoff.A read-only production user with View Setup and Configuration and View All Data, or a full-copy sandbox refreshed inside the last month. Metadata through API access on that user or a retrieval from your own tooling. The licence and contract summary, and whatever documentation exists, even if it is out of date. Two process owners, one for sales and one for service, plus an admin or developer who can answer “why is this here”. Interviews take three to four hours in total.
- Analysis.Configuration and metadata first, interviews second, so the interviews go on why rather than on what exists. Questions go to you in one thread.
- Report, then readout.Written first. Then we walk through it together on a call.
- Decision.Your team can use the findings to carry out fixes internally, take monthly hours with me, or scope it as a project.
Who does this
I am Lukasz Czarnecki. Twenty years in CRM and marketing automation, Salesforce Certified Advanced Administrator and Salesforce Certified Administrator.
- Marketing Cloud architect for Jaguar Land Rover.
- Implemented Salesforce Marketing Cloud for Volkswagen Group Poland and Audi.
- Delivery work for Viessmann and Betsson, among others.
- Before that, global CRM at Procter & Gamble: platform transitions, SIT, UAT and production releases, audits, and coordination of a campaign team of several dozen people.
- Earlier still, CRM and marketing manager on the client side at Volkswagen Bank Polska.
- I lead the work, with a team behind me.
Questions I get asked
- Is this the Salesforce Security Health Check?
- No. That is a free feature in Setup that scores your security settings against a Salesforce baseline; if you have a recent score, you can hand it over as an audit input. This audit is wider and depends on your package: Basic covers the data model, data quality, automation and code, and permissions. Advanced covers all ten areas, from the data model and the sales and service processes through automation and code, integrations, reporting, the release process and licences, and it hands you an order of work.
- What access do you need?
- A read-only production user with View Setup and Configuration and View All Data, or a full-copy sandbox refreshed inside the last month. No write access, no deployment rights. Metadata has to be readable, either through API access on that user or as a retrieval from your own tooling. On top of access I need the licence and contract summary, any existing documentation, two process owners for sales and service, an admin or developer, and three to four hours for interviews.
- We are planning Agentforce. Does this help?
- It tells you what the AI will be reading and writing against: the data model, field-level security, record ownership, and which automation fires when something changes a record. Building Agentforce is not part of the audit.
- Do you audit Marketing Cloud as well?
- Yes, that is a separate audit with its own page. Bought together, the engagement takes about 70 hours rather than 90: kickoff, interviews, the integration and consent review, the roadmap and the workshops are shared. That works out at about EUR 184/h across the engagement, instead of about EUR 199/h for the CRM audit on its own.
- Do you fix what you find?
- Remediation is separate work. It can be booked through monthly hours or as a separate project, or your own team can carry out the fixes using the findings.
- We run Dynamics or HubSpot as the CRM.
- Not my area. This audit covers Salesforce Sales Cloud and Service Cloud. Happy to point you to someone if you need a referral.
Book a 30-minute call.
Thirty minutes on your org and which audit fits it, or whether you need one at all. Worst case, you leave with a shortlist of what to check first.








