How do you know when your Salesforce security model needs more than another incremental fix? In my experience, there are a few warning signs I look for: an org with more than 10 Profiles, a role hierarchy with more than 10 roles, or business users regularly complaining that they can see too much data—for example, a sales rep seeing Accounts outside their territory. These can be signals that it is time to step back and look at the security architecture as a whole. But I don’t believe architects should sell a security redesign simply as a Salesforce technical exercise of moving access from Profiles to Permission Sets. The bigger opportunity is to use the redesign to increase user adoption by showing users the right data, reduce the maintenance burden created by years of security technical debt, and lower security and compliance risk. Those are business outcomes leadership can understand—and much stronger reasons to invest in redesigning Salesforce security.
This is why I am excited about Colleen Esper Negrón’s Dreamforce 2026 session on Salesforce security redesign. The session will cover how to assess profile sprawl and access patterns, design scalable Profiles, Permission Sets and Permission Set Groups, and plan rollout waves that validate access while reducing user disruption. But based on my conversations with Colleen, I think attendees will get something equally valuable: the strategy and the tactics required to actually execute a major security redesign. You can expect practical lessons around implementation and testing, insights into using AI and other tools to reduce the manual effort of analyzing permissions across Profiles and Permission Sets, and lessons on engaging users and gaining stakeholder buy-in throughout the transformation.

If you are a Salesforce architect or admin attending Colleen’s session, I believe you will walk away with:
- Strategy + Tactics: A practical approach for planning and implementing a Salesforce security redesign—not just understanding the target architecture.
- Scalable Security Architecture: Strategies to reduce unwanted Profiles, design scalable Permission Sets and Permission Set Groups, and reduce security and compliance risks.
- Phased Implementation: Practical approaches for rolling out a security redesign in phases, engaging users in testing, validating access, and reducing disruption during implementation.
Want to learn how Colleen and her team approached the journey?
View Colleen’s Dreamforce 2026 session and add it to your agenda
After Dreamforce, I will also publish my deeper interview with Colleen covering her security redesign journey, lessons learned, and practical implementation experience.





