Frequently asked questions
Does Sweep replace our existing security tools?
No. Sweep complements your security stack. Threat detection, identity governance, SSPM, native Salesforce tooling, logs all answer important questions. Sweep focuses on the layer most of these tools miss: how Salesforce configuration, permissions, automation, code, integrations, public surfaces, and dependencies combine to create real exposure.
How is Sweep different from an SSPM or scanner?
A scanner can tell you that something looks risky. Sweep helps explain why it matters, who or what can reach it, what data or processes it touches, and what could break if you fix it the wrong way. The goal is to identify misconfigurations and to turn them into prioritized, dependency-aware remediation work.
Why wouldn’t our threat detection tools catch this?
Many Salesforce exposure paths don’t look like attacks. For example, an unauthenticated guest user accessing records through a public Experience Cloud endpoint may be using allowed configuration, not triggering suspicious behavior. Sweep helps teams find those exposure paths before they become incidents.
What does the AI Exposure Assessment actually review?
The assessment is primarily metadata- and configuration-led. Sweep maps approved areas of your Salesforce environment across permissions, sharing, public access, connected apps, service accounts, files, automation, Apex, integrations, and sensitive data paths to show where exposure exists and how it connects.
Does Sweep automatically make changes to our Salesforce org?
No. Sweep works within the scope you approve, and remediation remains human-reviewed. Approved findings can become remediation plans, owners, validation steps, acceptance criteria, and delivery-ready tickets, but your team stays in control of what changes and when.