Live on AppExchange · Free · Never requires payment

Start with a user, not a permission set.

Pick anyone in your org, drill into any app, and see every object, field and record they can access, with the exact profile, permission set or sharing rule that granted it. 100% native. Read-only.

2 clicksFrom a user to a full answer
Read-onlyNo write access, ever
$0Free, never requires payment
[email protected]Sales User · 3 permission sets · EMEA role
Opportunity — ReadProfile
Opportunity — EditPerm set: Deal Desk
Opportunity.Amount — VisibleFLS
Opportunity.Discount__c — HiddenFLS
142 records visibleSharing rule
read-onlyno writes performed
Start from a userObject, field and record levelShows the granting ruleRead-only, no write accessNo external data storageSales, Service, Data and Nonprofit CloudLightning readyFree foreverStart from a userObject, field and record levelShows the granting ruleRead-only, no write accessNo external data storageSales, Service, Data and Nonprofit CloudLightning readyFree forever
01 The problem

A 30-minute investigation, every single time.

Someone asks why a user can see a record they should not. Answering it means stitching together profiles, permission sets, permission set groups, role hierarchy, sharing rules and manual shares in your head, one Setup screen at a time.

Six places, no single view

Profiles, permission sets, permission set groups, role hierarchy, sharing rules and manual shares all grant access, and nothing shows them together.

You have to reverse-engineer

Setup starts from a permission set and lists who it affects. The question you were asked started from the person.

Reviews become guesswork

Security reviews, onboarding checks and offboarding checks all stall when confirming one user's effective access takes half an hour.

An access question left half-answered is how over-permissioned users stay over-permissioned, right up until a compliance check or an incident finds them first.

02 What it is

Salesforce’s most confusing question, turned into a two-click answer.

Instead of starting from a permission set or profile and working out who it touches, Who Sees What starts with the person, and resolves everything into one clear, user-centered view.

Pick any user

Anyone in your org. No configuration, no reverse-engineering, nothing to define before you ask.

Read-only100% native

See every app, object, field and record

Along with the exact profile, permission set or sharing rule responsible for granting it.

No write access and no external data storage. Nothing to break, and nothing to expose.

It works across Sales Cloud, Service Cloud, Data Cloud and Nonprofit Cloud, on nearly every Salesforce edition, and because it is read-only it is safe to install in production and safe to hand to anyone who needs an answer.

03 How it works

From a name to a complete answer.

There is no configuration stage. Install it, pick a person, and read the result.

STEP 01

Install the managed package

Installs from AppExchange in a few clicks. Lightning ready, nothing to configure before you can use it.

STEP 02

Pick any user

Start from the person the question is actually about, rather than from a profile or permission set.

STEP 03

Drill into any app

Narrow to the app you care about, or look across the org, whichever the question calls for.

STEP 04

See every object and field

Object access and field-level security together, resolved into one view instead of several Setup screens.

STEP 05

See the records they can touch

Record visibility included, which is where role hierarchy, sharing rules and manual shares usually complicate the answer.

STEP 06

Read the granting rule

Every result names the exact profile, permission set or sharing rule responsible, so you know precisely what to change.

04 Features

What the app gives you.

One question, answered completely, without changing anything.

01

See access through a user's eyes

Pick any user and see every object, field and record they can touch. No reverse-engineering permission sets required.

02

Know the why, not just the what

Every access result shows the exact profile, permission set or sharing rule that granted it.

03

100% native and read-only

Runs entirely inside Salesforce with no write access and no external data storage. Nothing to break, nothing to expose.

04

Broad compatibility

Works across Sales Cloud, Service Cloud, Data Cloud and Nonprofit Cloud, on nearly every Salesforce edition.

05

Built for admins, consultants and developers

Speeds up troubleshooting, security reviews, onboarding and offboarding checks, and permission set cleanup.

06

Drill into any app

Scope the question to a single app or look across the whole org, whichever the situation calls for.

07

Person Accounts supported

Works in orgs using Person Accounts, so the answer is complete rather than partial.

08

Free, with no limits

Never requires payment, and there is no user cap or usage tier.

05 Inside the app

Built for the question you actually get asked.

Profile Sales User
Permission sets 3 assigned
User-first

Pick the person, not the permission set

Standard setup screens are organised around configuration objects. This one is organised around the user, which is how access questions arrive in the first place.

  • Search and select any user
  • No prior configuration needed
  • Answer in one place
Opportunity object Read, Edit
Opportunity.Amount field Visible
Opportunity.Discount__c field Hidden
Full stack view

Object, field and record together

Access is rarely explained at one level alone. Seeing object, field and record access side by side is what makes an answer conclusive rather than partial.

  • Object-level create, read, edit, delete
  • Field-level security surfaced
  • Record reachability included
Read on Opportunity granted by Profile
Edit on Opportunity granted by Perm set: Deal Desk
Record access granted by Sharing rule
Traceability

Every grant, with its reason

Knowing a user can see something is only half the answer. Knowing which rule granted it is what lets you fix an over-permissioned user with confidence.

  • Shows the specific granting rule
  • Distinguishes profile from permission set
  • Makes an audit defensible
06 Security

Nothing to break, nothing to expose.

A permission inspector that could also change permissions would be a liability. This one cannot, which is what makes it safe to install in production and safe to hand to anyone who needs an answer.

No write operations

Nothing about a profile, permission set, role or sharing rule can be modified from inside the app.

Nothing leaves the org

It is a native package. Your permission model is never transmitted to an external service for analysis.

Safe to share

Because it cannot change anything, access to it can be granted more widely than access to Setup.

Evidence for audits

Showing the specific granting rule turns an assertion about a user's access into something you can put in front of a reviewer.

07 Benefits

What it changes for an admin.

Same question, minutes instead of an afternoon, and an answer you can defend.

Speed

Answers in minutes

An access question stops being an afternoon of cross-referencing setup screens.

Confidence

Complete answers

Object, field and record access together means fewer partial answers that later turn out wrong.

Safety

Nothing can break

Read-only means installing it and using it cannot change a single permission in the org.

Audit

Defensible sign-off

Being able to show the granting rule turns an assertion about access into evidence.

Security

Catch over-permissioning

Access that nobody intended is far easier to find when it is visible in one place.

Cost

Free to run

No license, no per-user fee, and nothing to renew.

08 Comparison

Against how this gets answered today.

Standard setup screensManual spreadsheet auditWho Sees What
Direction of enquiryPermission set firstWhatever you assembleUser first
Object accessSeveral screensManualOne view
Field-level detailSeparate screenManualIncluded
Record-level accessHard to confirmEstimatedIncluded
Shows the granting ruleInferredInferredShown
Risk of changing somethingYes, you are in setupNoneNone, read-only
Time to an answerHoursLongerMinutes

Comparison reflects publicly documented behaviour at time of writing. Verify before publishing.

09 Who it is for

The five moments that cost teams the most time.

01

Troubleshooting access

Resolve a user's access question in seconds instead of a 30-minute investigation across Setup.

02

Security and access reviews

Run them properly before a compliance check or an org health check, rather than sampling and hoping.

03

Onboarding checks

Confirm a new joiner's access is exactly what it should be on day one, not three weeks later.

04

Offboarding checks

Verify that access has actually been removed everywhere it was granted, with evidence.

05

Permission set cleanup

See which rules are actually doing the work before deleting anything from a sprawling permission model.

06

Consulting handovers

Document and explain an org's access model to stakeholders during an implementation.

10 FAQ

The questions admins ask first.

What does Who Sees What do?

It shows the effective access of a single Salesforce user: every app, object, field and record they can reach, and the exact profile, permission set or sharing rule that granted each piece of access.

How is it different from the standard setup screens?

Setup is organised around permission sets and profiles, so you work backwards from configuration to people. This starts from the user, which is the direction access questions are actually asked in.

Can it change permissions?

No. It is read-only by design. Nothing about a profile, permission set or sharing rule can be modified from inside the app.

Is it safe to install in production?

It is native and read-only, which is exactly the combination that makes it safe to install in a production org.

Does it show record-level access, or only object-level?

Both, along with field-level security, since record access is where role hierarchy, sharing rules and manual shares usually complicate the answer.

Which clouds and editions does it work with?

It works across Sales Cloud, Service Cloud, Data Cloud and Nonprofit Cloud, on nearly every Salesforce edition, and supports orgs using Person Accounts.

Does my data leave Salesforce?

No. It runs entirely inside your org with no external service involved.

What does it cost?

It is free and never requires payment. There is no user cap and no usage tier.

Who is it built for?

Administrators, consultants and developers. It speeds up troubleshooting, security reviews, onboarding and offboarding checks, and permission set cleanup.

Stop reverse-engineering permission sets.

Install Who Sees What from the Salesforce AppExchange and answer your next access question in two clicks.

Get it on AppExchange

Free managed package · No credit card · Published by TwinStack Solutions

11 From TwinStack

Our other AppExchange products.

Native apps built around the same idea: less manual work between your data and your Salesforce org.

12 Blog

Notes from the team.

New posts most weeks: setup guides, integration patterns, and what we learn from the Salesforce community.