Experience Cloud.
All posts.
Salesforce Guest User Anomaly Fired: Scanner, Tester, or Data Leaving? Investigate It with sf audit incident
A Salesforce Guest User Anomaly fired. Scanner, tester, or data leaving? How sf audit incident turns the alert into a cited, defensible verdict, offline.
Salesforce Security Audit Tools Compared: Health Check, Code Analyzer, AuraInspector, Org Check and sf-audit
Salesforce Health Check scores settings, not exposure. What Code Analyzer, AuraInspector, Org Check, Security Center and sf-audit each cover, and what to use.
Salesforce Attack Chain Correlation: Five New Chains and the Blind Spot That Hid Them
sf-audit's attack chain model could not see half its own checks. Fixing the capability grants unlocked five new Salesforce attack chains, taking it to sixteen.
An Experience Cloud Tile Launch Is a Session Hand-Off, Not a Login
Moving between Experience Cloud sites reuses one session, so a Login Flow on the destination never fires. Here is how to prove it from the login records.
SAME_ORG_SSO: Why One Experience Cloud Site Cannot Be an Identity Provider for Another
Salesforce blocks OIDC between two Experience Cloud sites in one org. Why a site is not an identity authority, and why SAML is the one route still open.
Building a Terms Acceptance Gate in Experience Cloud That Actually Fires
A Login Flow cannot gate an Experience Cloud site reached from another. Here is the component and Apex pattern that does, using the standard Consent objects.
Salesforce Lets You Allowlist Chrome Extensions on Experience Cloud Sites
Winter '27 lets you allowlist specific Chrome extensions as trusted URLs on an Experience Cloud site. What it controls, and the two limits that matter.
A Guest IP Got Flagged for Log4j: Scanner or Breach? Triage Salesforce EventLogFile in One Command
A guest Experience Cloud IP is flagged for Log4j exploitation. Scanner or real attacker? How to tell it apart from your EventLogFile logs, in one command.
Salesforce Guest User Exposure: How sf-audit Grades It by Real Reachability
sf-audit now grades Salesforce guest user exposure by real UI API reachability, not just the sharing model, and adds six new external-facing security checks.