FAQ
Frequently asked questions
How Who Sees What connects, what it reads and stores, and how to get started. Still stuck? The in-app assistant can answer in context.
Getting started
- Who is Who Sees What for?
-
Salesforce admins, security and compliance teams, and anyone who has to answer “who can see this data, and why?” for an audit, a customer security review, or an incident. If you own a Salesforce org’s access model, it is for you.
- What is Who Sees What?
-
Who Sees What is a read-only Salesforce access and permission auditor. It maps who can reach a record or a field across every access layer (profiles, permission sets, roles, public groups, sharing rules, and more) and shows not just who has access but why they have it. The result is a prioritized, audit-ready picture of your exposure.
- How does Who Sees What connect to my Salesforce org?
-
You connect your org with standard Salesforce OAuth. The connection is read-only: Who Sees What reads your access-configuration metadata and user directory to build the audit. You can connect a production org or a sandbox, and you can disconnect at any time.
- Does Who Sees What work with other CRMs or systems besides Salesforce?
-
No. Who Sees What is built specifically for Salesforce. It connects only to Salesforce orgs (production or sandbox) and audits access within Salesforce. It does not connect to other CRMs, databases, or applications.
- How do I get started, and how long does it take?
-
Connect your org and you will have an initial risk snapshot in under five minutes, no install required. Run a quick scan to begin.
- Why is the AI assistant named Horton?
-
Our assistant is named Horton, after Horton Hears a Who! by Dr. Seuss. In the story, Horton the elephant is the one who can hear the tiny Whos that nobody else can hear. That is a fitting name for Who Sees What: a tool whose job is to surface who can see what in your Salesforce org, including the access that nobody else notices. Horton is an AI assistant, not a person, and for anything important we will connect you with a member of our team.
Salesforce concepts
- How does Salesforce decide who can see a record, and how does Who Sees What figure it out?
-
Salesforce access is decided in layers, and Who Sees What evaluates them in the same order Salesforce enforces them:
- Object access (CRUD). A user first needs Read on the object (granted through a profile or a permission set). Without object Read, nothing else matters, the user cannot see any record of that object.
- Record access (sharing). For users who have object access, record visibility is then decided by sharing: who owns the record, the org-wide default (OWD), the role hierarchy, sharing rules, manual and team shares, and “View All” or “Modify All” permissions that override sharing.
- Field-level security (FLS). Even when a user can see a record, field-level security can hide individual fields, so two people who both see a record may see different fields.
When Who Sees What answers a question, it tells you which of these layers is the deciding one, so you see not just whether someone has access but exactly why. It reads this configuration only; it never changes it.
- What is a sharing rule in Salesforce, and why does it matter?
-
A sharing rule grants access to records beyond what the org-wide defaults allow, usually by opening records owned by one group of users to another group. Sharing rules are one of the easiest ways for access to quietly widen over time, because they grant access in addition to everything else (profiles, permission sets, roles). That is exactly why Who Sees What traces them: when it shows who can see a record, a sharing rule is often the reason, and it is the layer admins most often forget to check.
- What is a permission set?
-
A permission set is a bundle of permissions (object access, field access, system permissions, and more) that you assign to individual users on top of their profile. Permission sets are additive: they can grant access but never take it away. Because any number of them can stack on a user, they are a common source of access that is broader than anyone intended. Who Sees What attributes access back to the specific permission set that granted it, so you can see exactly why a user has the access they do.
- What is the difference between a profile and a permission set?
-
Every user has exactly one profile, which sets their baseline access. Permission sets are then layered on top to grant additional access to specific users without changing everyone on the profile. Salesforce is moving toward keeping profiles minimal and granting most access through permission sets and permission set groups. Who Sees What reads both, so when it explains who can see something, it names whether the access came from the profile or from a specific permission set.
- What are org-wide defaults (OWD)?
-
Org-wide defaults set the baseline level of access to each object’s records for users who do not own them: Private, Public Read Only, or Public Read/Write, among others. Everything else (role hierarchy, sharing rules, manual sharing, teams) only opens access up from that baseline. Getting OWD right is the foundation of a sound sharing model, so Who Sees What starts from your OWD and then shows every mechanism that widens access from there.
- What is field-level security (FLS)?
-
Field-level security controls which fields a user can see or edit, independent of their access to the record itself. A user can have access to a record but still be blocked from a sensitive field on it (such as a salary or a national ID), or the reverse. Because FLS is set per profile and per permission set, it is easy for a sensitive field to be exposed somewhere unexpected. Who Sees What maps field-level security so you can see who can reach regulated fields, and why.
- What is the role hierarchy?
-
The role hierarchy gives users access to records owned by people below them in the hierarchy, so managers can typically see their teams’ records. It is a powerful and often invisible source of access: someone high in the hierarchy may be able to see far more than their day-to-day job suggests. Who Sees What includes the role hierarchy when it traces who can reach a record, so inherited manager access is never a blind spot.
Comparisons
- How does Who Sees What compare to other tools? What makes it different?
-
Who Sees What answers who can reach a specific record or field, and why, across every native Salesforce sharing layer (profiles, permission sets, roles, public groups, sharing rules, org-wide defaults, and field-level security), as a read-only, audit-ready exposure report for the Salesforce admin, RevOps, and compliance buyer.
To be fair and accurate: a few security-led platforms (notably Varonis, and Salesforce-owned Own Secure) also offer a per-record who-and-why view, so that capability on its own is not unique to us. Who Sees What’s honest edge is the combination: the fullest plain-language labeling of every native layer in the per-record report (including org-wide defaults, public groups, manual and implicit sharing, and account and case teams named per user); a read-only footprint with no in-org managed package; an audit-ready report rather than a posture score or dashboard; and a focused per-production-org price aimed at the admin and compliance team rather than an enterprise security deployment.
Last verified July 2, 2026
- How does Who Sees What compare to Varonis?
-
Varonis is a powerful, security-led data-security platform that also maps Salesforce access, including a per-record view, so it is a genuine overlap, not something we do that it cannot.
Who Sees What is purpose-built for the Salesforce admin and compliance team: read-only by design (Varonis is write-enabled and can commit changes), it names every native sharing layer in plain language, and it produces an audit-ready report without an enterprise security deployment or its pricing.
Last verified July 2, 2026
- How does Who Sees What compare to Salesforce Shield Event Monitoring?
-
Shield’s Event Monitoring shows what users did, the activity log. Who Sees What shows what users can reach and why, the access map. They are complementary: the map plus the log is the full story.
Last verified July 2, 2026
- How does Who Sees What compare to Salesforce Security Center?
-
Security Center gives a strong multi-org view of system permissions and who holds them. Who Sees What goes down to the record and field: who can reach this specific data and which layer grants it.
Last verified July 2, 2026
- How does Who Sees What compare to Salesforce Optimizer?
-
Optimizer is a solid free hygiene scan for things like unused permission sets. Who Sees What is the depth tier above it: who can actually reach a given record or field, and exactly why, across every sharing layer.
Last verified July 2, 2026
- How is Who Sees What different from Salesforce's built-in Sharing "Why?" button?
-
Salesforce’s Sharing button answers who can see one record and why, for an admin, one record at a time. Who Sees What answers it across your whole org, adds field-level access, and turns it into a prioritized, audit-ready report. It is read-only, and no SOQL is required.
Last verified July 2, 2026
- How does Who Sees What compare to Metazoa Snapshot?
-
Metazoa is a broad, write-capable admin toolbox with good permission reporting. Who Sees What is a focused, read-only auditor: one prioritized record and field exposure report, with nothing that can change your org.
Last verified July 2, 2026
- How does Who Sees What compare to Elements.cloud Permissions Explorer?
-
Elements.cloud explains who has access and why at the profile and permission-set level, and does it well. Who Sees What extends the same who-and-why down through the record-sharing layers (org-wide defaults, role hierarchy, sharing rules, and public groups) into one exposure report.
Last verified July 2, 2026
- How does Who Sees What compare to Sonar or Arovy?
-
Sonar (now Arovy) tells you which fields are sensitive. Who Sees What tells you who can reach them, and why. Use them together.
Last verified July 2, 2026
- How does Who Sees What compare to Spin.AI or Obsidian?
-
These give you a Salesforce posture score and misconfiguration checks. Who Sees What answers a different question: for a specific record or field, who can see it and through which access path.
Last verified July 2, 2026
- How does Who Sees What compare to AppOmni, Falcon Shield (CrowdStrike), or Own Secure?
-
These SaaS-security platforms inventory Salesforce permissions as part of broad, security-team posture management, and some (notably Salesforce-owned Own Secure) also offer a per-record access view.
Who Sees What answers the narrower, deeper question for the admin and compliance buyer: who can reach this exact record or field and why, named across every layer, as a read-only audit (Falcon Shield, by contrast, is positioned around detection plus automated remediation rather than a read-only audit), without an enterprise-platform footprint.
Last verified July 2, 2026
- How does Who Sees What compare to Strongpoint, Salto, or CodeScan?
-
These are governance, DevOps, and code-quality tools focused on change and metadata management. Who Sees What is a dedicated, read-only access auditor focused on the record and field who-and-why.
Last verified July 2, 2026
All product names and trademarks are the property of their respective owners. Comparisons are based on publicly available information and were last verified on the date shown.
Compliance
- Are you ISO 27001 certified? Do you have HIPAA, PCI, or other compliance certifications?
-
Who Sees What does not currently hold ISO 27001, HIPAA, PCI, or similar certifications, and Digadop does not claim certifications it does not hold. SOC 2 is on the roadmap and GovCloud support is planned. Digadop describes the status of certifications and attestations accurately as it changes.
Separately, Who Sees What is engineered to be safe to connect: least-privilege access, per-tenant isolation, credentials encrypted with AWS Key Management Service (KMS), and hosted in the United States on AWS. Digadop is happy to provide security diligence materials to prospective customers under an appropriate confidentiality agreement (NDA).
- Can Who Sees What help with HIPAA compliance?
-
Who Sees What does not make your organization HIPAA compliant, and it is not a HIPAA certification. What it does is help with the access-control side of HIPAA: it shows who can see protected health information (PHI) across every Salesforce access layer, so you can confirm that access to PHI is limited to the right people and catch access that is too broad.
The audit-ready report (who can reach a record or field and why, plus overexposed and dormant access with remediation guidance) is the kind of evidence a HIPAA access review calls for. You and your compliance team still own the overall program. Who Sees What gives you clear, repeatable answers about access to regulated data.
- Does Who Sees What help with GDPR data access requests?
-
Who Sees What is not a GDPR compliance certification, but it helps with the access side of GDPR. It shows who within your Salesforce org can see personal data, across every access layer, so you can confirm that access to personal data is limited appropriately and demonstrate it in an audit-ready form.
Note this is about who can access personal data in your org, which is different from fulfilling a data subject’s request for a copy of their own data. Your team owns the GDPR program. Who Sees What gives you clear, repeatable answers about who can access regulated personal data.
- Does Who Sees What help with SOX or financial controls?
-
Who Sees What helps with the access-review side of SOX and similar financial controls. It shows who can see and change financial data in your Salesforce org, across every access layer, and produces an audit-ready report of who has access and why. That is the kind of evidence an access-control review calls for. It does not replace your overall SOX program or your auditors: it gives your team a fast, repeatable, provable answer to who can reach regulated data.
Pricing and plans
- How much does Who Sees What cost?
-
Who Sees What starts with a free trial, so you can connect an org and see the full product before you pay. After the trial, pricing is per production org, billed monthly:
- Who Sees What Professional: $499 per org per month. Access visibility: the question library, the audit explorer, full risk-finding detail, and on-demand scans.
- Who Sees What Enterprise: $1,299 per org per month. Everything above, plus multiple connected orgs with cross-org comparison, SSO and team access, Experience Cloud coverage, “what changed over time” questions, API access for your CI/CD and DevOps pipelines, and MCP access so any AI agent can run audits and pull reports.
- Lynceon (coming soon): the next product in the Digadop security family. Where Who Sees What shows you the facts of access, Lynceon is designed to judge them and help you act, adding risk remediation, continuous monitoring, and code-security scanning. It is on the roadmap, not yet available for purchase; the planned price is $2,499 per org per month. Choose “Learn more” to follow it.
There is introductory pricing right now: 33% off with a one-year contract and 50% off with a two or three-year contract. See the pricing page for the current numbers and to start a free trial.
- Do you offer refunds? What is your refund policy?
-
We offer a full free trial first, so you can evaluate Who Sees What on your own org before you pay anything. After you sign up for a paid plan, we do not offer refunds. If you would rather not commit long-term, you can choose monthly service and pay month to month instead of committing to a longer term.
- Is there a free trial?
-
Yes. Who Sees What begins with a free trial of the full Who Sees What experience, so you can connect your org with read-only Salesforce OAuth and run real audits before you decide, with the complete risk findings included. You start the trial yourself from the app, no sales call required. When the trial ends you choose a plan: plans are tiered (see Pricing), so some detail like the full risk findings moves to a higher tier, but your work carries over.
- Is Who Sees What priced per user or per org?
-
Per org, not per user. You pay one flat monthly price for each connected production org, and you can invite the admins on your team without paying for more seats. Who Sees What is an admin tool used by a few people, so per-org pricing keeps it simple and predictable: you are paying for visibility into the org, not for the number of people who look at it.
- What is your cancellation policy? Can I cancel anytime?
-
On a month-to-month plan, you can choose to stop at any time. If you have already paid for the current month, that month is not refunded, but you keep access for the rest of that paid term. Multi-year contracts cannot be cancelled: they remain in effect for the full term you agreed to, even if you stop using the service. If staying flexible matters to you, the month-to-month plan is the better fit.
- Is there a contract or minimum term? Can I go month-to-month?
-
There is no minimum term required. Who Sees What is available month-to-month at the standard per-org rate, so you are not locked into a long contract. If you want a lower rate, you can optionally commit to a one-year term (33% off) or a two to three-year term (50% off), but that longer commitment is your choice, not a requirement.
- What is the difference between Who Sees What and Who Sees What Enterprise?
-
Who Sees What Professional answers “who can see what, when I ask.” You connect one production org, use the full question library and audit explorer, see full risk-finding detail, and run scans on demand.
Who Sees What Enterprise turns that into a team-wide, multi-org capability. It adds:
- multiple connected orgs plus sandboxes, with comparison across them
- “what changed over time” questions: who gained access to something since a previous scan
- Experience Cloud, community, and guest-user coverage
- SSO, roles, and access for your whole team
- API access, to build access checks into your CI/CD and DevOps pipelines and verify access programmatically
- MCP access, to connect Who Sees What to any AI agent so it can run audits and pull reports
- scheduled exports for your other systems
- longer audit history and priority support
A simple rule: if you want to connect or compare more than one org (for example production versus a sandbox, or one client org versus another), that is Enterprise.
- What payment methods do you accept?
-
We accept invoice, purchase order (PO), and ACH. We also accept credit cards with no fee for monthly billing. If you would like to pay for an annual plan by credit card, a 3% convenience fee applies; you can avoid that fee by paying annually with ACH, invoice, or PO.
- Do you offer annual or multi-year billing?
-
Who Sees What is priced per production org and is billed monthly at the standard rate, with no commitment required. You can also commit for a longer term to lock in a lower rate: a one-year commitment is 33% off, and a two or three-year commitment is 50% off (introductory pricing). So you can stay month-to-month, or choose an annual or multi-year term for the discount. See Pricing for current rates.
- Is there a setup or onboarding fee?
-
No. There is no setup or onboarding fee. You connect your org yourself with a read-only OAuth login, with no managed package to install, and you can start with a free trial.
- What does Lynceon add on top of Who Sees What?
-
Lynceon is the next product in the Digadop security family, and it is coming soon. Where Who Sees What shows you the facts of access (who can see what, and what changed), Lynceon is designed to judge those facts and help you act on them. The direction we are building toward includes:
- remediation guidance for each finding, so you know how to fix it
- continuous monitoring and scheduled scans
- code-security scanning across Apex and dependencies
- a security posture score and trend over time
- risk prioritization, so you fix the most important things first
- compliance mapping for your access posture
- threat and anomaly detection for unusual access patterns
Lynceon is a separate product. It is on the roadmap, not yet available for purchase, and its capabilities are not sold today. Choose “Learn more” to follow it.
- Do you offer a nonprofit or education discount?
-
We offer a 20% discount for charitable nonprofits. To qualify, you need to provide proof of charitable nonprofit status; being a nonprofit organization alone is not enough. We do not offer a discount for government or other public entities, so a public school, university, or government agency would not qualify, though a qualifying charitable nonprofit would.
- How are sandboxes and multiple orgs priced?
-
Each production org you connect carries its own license. Connecting more than one org, and comparing access across them, is part of Who Sees What Enterprise.
Sandboxes are priced at 50% of the org’s rate, added on to a licensed production org. So if you license a production org on Enterprise, you can add its sandboxes at half price to compare access between them and catch changes before they reach production. Any non-production org (full, partial, or developer) counts as a sandbox at the same 50% rate.
- What happens to my price at renewal? Can it go up?
-
For multi-year agreements, any price escalators are agreed up front and written into your contract when you sign, and they do not change during the contract term, so you know your pricing for the life of the agreement. On a month-to-month plan you are on the current standard rate with no long-term commitment. If locking in your pricing matters to you, a multi-year agreement with its agreed escalators is the way to do that.
- What is the introductory pricing?
-
For a limited time, a longer contract earns a larger introductory discount off the per-org rate:
- one-year contract: 33% off
- two or three-year contract: 50% off
Month-to-month is at the standard rate. The discount applies to both Who Sees What Professional and Who Sees What Enterprise. See the pricing page for the current introductory rates.
- Do you offer discounts for consultants or partners, and can a consultant manage my org?
-
Yes. Consultants and AppExchange partners can enroll as resellers and earn a partner discount, then resell Who Sees What to their clients or set up and pay for client orgs themselves.
On access and who pays: each org carries one license, and access is separate from who pays for it. You can give your consultant a login to your licensed org, and a consultant can set up and pay for an org while you still log in. Either way the org is licensed once and never charged twice. If you were given a referral or partner code, you can enter it when you start, and the discount applies to your plan.
- How is Who Sees What worth the price? What is the return on investment?
-
Our pricing is set to be fair, and based on our own market analysis it is one of the highest values available for what it does. The return on investment is naturally variable: the value to a given organization depends on factors like your security maturity, the number of employees, contractors, and third parties with access to your systems, how many integrations you run, your DevOps process, how sensitive your data is, and the impact a failed security audit or a breach would have on you.
For an organization with real exposure, getting a clear, audit-ready answer to who can see what across every layer can pay for itself the first time it catches something. Pricing is per production org, not per seat, so your whole team is covered, and every plan starts with a full free trial, so you can see the value on your own org before you pay.
Security and data
- Does Who Sees What modify my org or my records?
-
No. Who Sees What is strictly read-only. It inspects how access is configured. It never changes your configuration, your data, or your records, and it never writes to your org.
- What data does Who Sees What read and store?
-
Who Sees What reads your access-configuration metadata (profiles, permission sets, field-level security, org-wide defaults, sharing rules, roles, public groups, queues) and your user directory. It does not read the contents of your business or customer records.
It stores the access metadata needed to build and retain your audit reports, the encrypted credential needed to re-read your configuration, and account plus usage telemetry. It does not copy or store your business-record contents. For the full detail, see our Data scope and handling page.
- Where is my data hosted? What cloud or region is it in?
-
Who Sees What runs entirely on Amazon Web Services (AWS) in the United States, inside Digadop’s own AWS environment. Your records and configuration are read to analyze them and are not copied into a permanent store.
The one credential kept (the encrypted Salesforce refresh token behind the optional keep-me-signed-in feature) is encrypted at rest with AWS Key Management Service (KMS) and never stored in plaintext. Connections use TLS, and every saved audit is isolated per Salesforce org with PostgreSQL row-level security, so one customer’s data is never readable in another customer’s session.
- Is my data isolated from other customers? Is it multi-tenant safe?
-
Yes. Every record Who Sees What stores is keyed to your Salesforce organization id and isolated using PostgreSQL row-level security. That isolation is enforced at the database, because the application connects with a non-privileged database role, so one customer’s data can never be read by another customer’s session.
On top of that, audited record values are not retained, and what little is stored (such as your encrypted Salesforce refresh token if you choose to stay signed in, and the fingerprints of risks you have ignored) is encrypted and scoped to your organization.
- Do you sell or share my data with anyone?
-
No. Digadop does not sell your data, and does not share it for cross-context behavioral advertising. Who Sees What uses no analytics, advertising, or session-replay vendors.
We rely on a small, disclosed set of trusted sub-processors strictly to run the service: Amazon Web Services for hosting; GitHub only for the feedback you choose to submit through the in-product assistant (used for support triage); and Amazon Bedrock for Horton, the assistant, which only ever sees your typed question and public product documentation, never your Salesforce data. Each sub-processor is bound by our Data Processing Addendum, and we give at least 30 days notice before adding or replacing one. The current list is at /legal/sub-processors.
- How is my data secured?
-
Your Salesforce refresh token is encrypted at rest with AWS Key Management Service (KMS) and stored only in encrypted form. Audit data is retained while your account is active (the default audit-history retention is 12 months, configurable from 1 to 120 months). When you close your account, all stored data, including backups, is deleted within 90 days. See the Privacy Policy and Data scope and handling for more.
- Does Who Sees What work with Government Cloud (GovCloud)? Are you GovCloud certified?
-
Who Sees What is not GovCloud certified, and is not currently in the certification process. GovCloud support is on our roadmap (planned), and Digadop describes the status of certifications accurately as it changes. If you have a Government Cloud or specific compliance requirement, reach the team through whoseeswhat.com/contact and we can walk through where that stands for your org.
- Does Who Sees What use AI? Is my data sent to or used to train an AI model?
-
The access audit is computed by deterministic software, with no AI involved. Separately, Who Sees What offers an optional in-product assistant, Horton, that uses a third-party AI model (Amazon Bedrock) only to answer the product questions you type, drawing on our public product documentation. Your Salesforce data (your configuration, your user directory, and your records) is never sent to the AI model, and your data is never used to train any model. The questions you type to the assistant may be logged to improve the Service. See the Data scope and handling and Privacy Policy pages for detail.
- What AI model does Horton use? And does Who Sees What use AI on my Salesforce data?
-
We’re happy to be transparent about this.
Horton, the in-product assistant, is built on large language models accessed through Amazon Bedrock. There isn’t one fixed model: the specific model varies by the type of request, because our products dynamically select the model best suited to each task (for example, a fast model for a simple classification, a more capable one for a detailed explanation). So “which model” depends on what you asked.
Just as important: Who Sees What does not use AI models to access or analyze your Salesforce data. Your access analysis, who can see which record or field, and why, is produced from your org’s configuration, not by an AI model. We use AI only to help you use the product: Horton answers questions about Who Sees What (like this one) and helps you navigate it. Horton does not read, analyze, or train on your customer data.
- Do you perform penetration testing?
-
Penetration testing is coming with Lynceon, Digadop’s dedicated Salesforce security product, which is on the roadmap. For security diligence on Who Sees What today, Digadop is happy to provide security materials to prospective customers under an appropriate confidentiality agreement (NDA). Reach the team through whoseeswhat.com/contact.
- How do I revoke Who Sees What's access?
-
You can disconnect Who Sees What at any time, either from within the app or from Salesforce Setup (Connected Apps OAuth Usage), which immediately invalidates its access. Our Revoke access page walks through both paths step by step.
Using Who Sees What
- How is Who Sees What different from Salesforce's own permission tools?
-
Salesforce Setup shows you access one piece at a time: a profile here, a sharing rule there, a permission set somewhere else. It does not answer the real question, which is “who can see this specific record or field, and through which path?” Who Sees What consolidates every access layer (profiles, permission sets, roles, groups, sharing rules, field-level security) into one answer and shows the reason for each grant. It turns a manual, multi-screen investigation into a single, audit-ready report.
- How is Who Sees What different from Salesforce Health Check?
-
They answer different questions. Salesforce Health Check scores your org’s security settings (password policies, session settings, and similar configuration) against a baseline and flags settings that drift from recommended values. Who Sees What answers who can actually see what: it computes effective record and field access across profiles, permission sets, sharing rules, the role hierarchy, and more, and shows who can reach a given record or field and why.
Health Check is about configuration hygiene. Who Sees What is about effective access. The two are complementary.
- What does a Who Sees What audit report include?
-
An audit gives you a prioritized view of exposure: overexposed profiles and permission sets, who can reach sensitive fields and objects, dormant access that outlived its purpose, and for any record or field the list of users who can see it with the reason each one can. Each finding comes with its severity, the affected users, and the reason for each grant, so your admin team knows exactly what is exposed and how. The result is concise and audit-ready, built to hand to security, compliance, or an auditor.
- Can I run Who Sees What against a sandbox?
-
Yes. You can connect either a production org or a sandbox with read-only Salesforce OAuth, so you can try Who Sees What safely against a sandbox first and run it against production when you are ready. Either way the connection is read-only: it reads access-configuration metadata to build the audit and never changes your org.
- How do I find out who can see a specific record?
-
Ask the “Who can see this record?” question and give it the record. You can paste the record’s 15- or 18-character Salesforce Id, or pick a recent record, and Who Sees What returns every user who can see that record along with the reason each one has access (the deciding grant, such as record owner, role hierarchy, an org-wide default, a sharing rule, a public-group or queue share, or a “View All” permission). You can also ask “Who can edit this record?” to narrow the list to people with edit access.
“Who can see this record?” is a free question on the trial. It answers at the record level: it tells you who can see the record and why, without changing anything in your org.
- How do I read a Who Sees What result?
-
Every answer leads with a plain verdict, then shows the “why” behind it.
- For “who can see” questions: you get the list of people who have access. Each person shows their access level (for example, Read or Edit) and the deciding reason they have it, with the full grant path when there is more than one step (for example, “Role hierarchy, because they are above the owner”).
- For “why can (or can’t) someone see this” questions: you get a yes or no verdict plus the single binding reason. When access is blocked, the binding reason is the one layer that stops it: no Read on the object, no record-level sharing, or field-level security hiding the field. When access is granted, the binding reason is the grant that provides it, followed by any other paths.
- Supporting evidence names the metadata behind the answer, such as the record owner, the org-wide default, and any groups, queues, or roles involved.
The verdict is the ground truth (it reflects what Salesforce actually enforces); the binding reason and full path explain it. Who Sees What never changes your org to produce these answers.
- How long does a scan take?
-
It depends on the size of your Salesforce org. A simple scan can take a few seconds. For a large org, generating the full report may take as long as a few minutes.
- Is there an org size limit? How many users or objects can Who Sees What handle?
-
There are no fixed org size limits. Who Sees What works with Salesforce orgs of any size. Larger orgs simply take longer to scan: a simple scan takes a few seconds, and for a large org, generating the full report may take as long as a few minutes.
- Does Who Sees What work with Person Accounts?
-
Yes. A Person Account is a Salesforce record type that combines an Account and a Contact into a single record, and Who Sees What audits who can see Person Account records the same way it does for other objects. You see who has access to them and why.
- Does Who Sees What have an API I can call from my CI/CD pipeline?
-
Programmatic access through a REST API is part of Who Sees What Enterprise and is currently in development. With it, your own systems and scripts can run audits and pull or export reports, for example to build access checks into your CI/CD and DevOps pipelines. The same capabilities are also available over MCP for AI agents. Reach the team through /contact to confirm current availability.
- Does Who Sees What support MCP? Can I connect it to an AI agent like Claude?
-
An MCP server, so your own AI agent (Claude or any MCP client) can use Who Sees What as tools to run audits and pull reports, is part of Who Sees What Enterprise and is currently in development. The same capabilities are also available as a directly callable REST API. Reach the team through /contact to confirm current availability.
- Do you have a mobile app?
-
Today Who Sees What runs in your web browser, so you can use it on any device that has a browser. A dedicated mobile app is coming soon.
- Which Salesforce editions does Who Sees What support?
-
Who Sees What connects through the standard Salesforce API, so it works with any edition that has API access enabled. That includes Enterprise, Unlimited, and Performance editions, as well as Developer edition. Professional edition works if your org has the API access add-on enabled.
The connecting user needs the API Enabled permission (along with View Setup and Configuration, View All Data, and Manage Users for a full org-wide audit). If you are unsure whether your edition has API access, your Salesforce administrator can confirm it.
- Does Who Sees What work with custom objects?
-
Yes. Who Sees What audits access for both standard objects (such as Accounts, Contacts, Opportunities, and Cases) and custom objects, along with their custom fields. For any object, standard or custom, it evaluates the full access configuration that decides who can see a record: org-wide defaults, the role hierarchy, sharing rules, profiles, permission sets, and field-level security.
So you can ask who can see a given custom-object record and why, exactly as you would for a standard object. As always, Who Sees What reads only the access configuration and metadata that governs visibility, never the contents of your records.
- Does Who Sees What cover Experience Cloud, communities, or guest users?
-
Yes, with Who Sees What Enterprise. Experience Cloud, community, and guest-user coverage is part of the Enterprise plan, so you can audit access for external-facing users alongside your internal ones, including how the Experience Cloud sharing model (such as sharing sets) grants access.
On the Professional plan this external exposure is detected and flagged, and the full details are available when you move up to Enterprise.