Organization health model 2.0

A health score that shows what was measured.

Org Sentinel evaluates 22 weighted factors across eight Salesforce operational areas. Every result keeps its source, method, limitation and coverage visible, so teams can act without mistaking missing evidence for good health.

22 factorsEach with an explicit weight
8 areasOperational and technical coverage
2 coveragesComplete model and permitted access
0 invented healthUnavailable data stays unavailable

Methodology

From a Salesforce value to an explainable score

Factors are normalized to 0–100. Each area is the weighted average of the applicable factors actually evaluated. The overall result is the weighted average of areas with enough evidence.

Collect

Read permitted REST Limits, operational objects, Event Monitoring, Setup Audit Trail and Tooling API evidence.

Normalize

Convert capacity, failures, access risk and change activity into continuous or documented banded scores.

Weight

Apply factor weights inside each area, then relative area weights according to operational impact.

Explain

Show the observed value, source, calculation, limitation, recommendation and potential score contribution.

Minimum evidence rule: an area and the overall score are shown only when at least 60% of the applicable factor weight was evaluated. A new scan must confirm any improvement after remediation.

Factor inventory

Eight areas with impact-based weights

Area weights are relative and normalized across the areas that have enough evidence. Factor weights are compared only inside their own area.

Complete health-model inventory. Numbers in parentheses are factor weights inside each area.
AreaRelative weightFactorsSalesforce evidence
Security30Stale privileged profiles (4); stale elevated Permission Sets (3); login failure pressure (4); session assurance (2); weak login TLS (2)User, Profile, PermissionSetAssignment, LoginHistory and AuthSession
Automations18Failed asynchronous Apex (4); Flow interviews with errors (4); asynchronous Apex capacity (2)AsyncApexJob, FlowInterview and REST Limits
Release quality18Org-wide Apex coverage (4); Apex test outcomes (4); components below 75% (2); deployment reliability (3)Tooling API coverage, tests and DeployRequest
API15Daily API capacity (4); Bulk and asynchronous API limits (2)REST Limits
Storage15Data storage capacity (3); file storage capacity (2)REST Limits
Integrations12API-consumer concentration (3); event and streaming capacity (2)Event Monitoring ApiTotalUsage and REST Limits
Users10Dormant active accounts (3); license capacity (2)User and UserLicense
Governance10Sensitive setup changes (3); administrative change volume (2)SetupAuditTrail

Interpretation

Read the score as a decision aid, not a certification

90–100

Strong

The observed factor has operating margin. Continue monitoring and preserve the evidence.

75–89

Healthy

The current observation is acceptable, with normal review still required.

50–74

Attention

Investigate the trend, owner and business context before the signal becomes a higher risk.

25–49

Risk

Prioritize remediation or formally document why the condition is an accepted exception.

0–24

Critical

Immediate investigation is recommended; validate impact and contain the risk.

N/A

Unavailable

The signal was not evaluated. It is not counted as zero and it is never treated as healthy.

Coverage and confidence

A score is only useful when its evidence boundary is visible

Model coverage

Compares the weight collected with all 22 factors. It shows how much of the complete methodology was observed.

Access coverage

Compares collected evidence only with factors the connected account's confirmed capabilities allow Org Sentinel to attempt.

Confidence

High requires at least 90% access and 80% model coverage. Medium requires 70% and 60%. Low begins at 60% access; below that the score is unavailable.

Shared interpretation

A restricted account may receive a contextual score with low confidence. Teams should never compare two orgs without reviewing both coverages and collection time.

Boundaries

Transparent limitations are part of the result.

The score is a point-in-time operational assessment. Salesforce edition, licenses, permissions and retention can limit collection. A strong result does not prove compliance, eliminate vulnerabilities or validate every business process.

  • Read-only analysis
  • No automatic remediation
  • No automatic deployment approval
  • No presumed score for missing data
  • Human context remains required
  • Reports preserve collection limitations