FAQ
Does OrgGuard access or store credentials/secrets?
Section titled “Does OrgGuard access or store credentials/secrets?”No. OrgGuard only reads metadata about your auth assets (names, types, expiration dates, configuration). It never accesses passwords, tokens, private keys, or OAuth secrets.
Will OrgGuard impact org performance?
Section titled “Will OrgGuard impact org performance?”No. Discovery scans run as asynchronous Queueable jobs with governor limit monitoring. If limits are approached, the scan chains to a new execution context automatically. Diagnostic logging uses Platform Events in a separate execution context with zero impact on business operations.
Can I customize what asset types are scanned?
Section titled “Can I customize what asset types are scanned?”The discovery engine scans all 5 asset types by default. Individual providers cannot be disabled in v1.0. This will be configurable in a future release.
What happens when a finding is auto-resolved?
Section titled “What happens when a finding is auto-resolved?”When the next scan shows that a previously flagged asset is now compliant (e.g., a certificate was renewed), OrgGuard automatically changes the finding status to “Resolved.” No notification is sent for auto-resolutions.
Can I export data for compliance reporting?
Section titled “Can I export data for compliance reporting?”Yes. Use Export CSV on the Inventory List to download asset data. Standard Salesforce reports are also available on all OrgGuard objects for offline compliance reporting. If you are an OrgGuard Admin, use Export Bundle on the Diagnostic Log Viewer for a full operational snapshot (operational metadata only — no field values or credentials).
How do I uninstall OrgGuard?
Section titled “How do I uninstall OrgGuard?”Two prerequisites must be cleared first, or Salesforce blocks the uninstall:
- Deactivate the
OrgGuard SJH Daily Pollflow — Setup → Flows, open the flow, and click Deactivate on its active version. Skipping this produces “The flow is still active. Deactivate the flow, and try again.” - Remove the OrgGuard permission-set assignments — Setup → Permission Sets, then for OrgGuard Admin (and OrgGuard User / OrgGuard Auditor if anyone is assigned) → Manage Assignments, select all assigned users, then click Remove Assignments. Skipping this produces “This permission set is assigned to one or more users…”
Then Setup → Installed Packages → OrgGuard → Uninstall. This removes all OrgGuard objects, classes, and components, and deletes all data stored in OrgGuard custom objects (assets, findings, notifications, policies, configuration, and audit history) — export anything you need first. For the full step-by-step walkthrough, see Upgrading the Beta — the prerequisite and uninstall steps there apply to any uninstall, even though that page is written primarily for beta participants moving between builds.
Does OrgGuard show me what breaks when a certificate expires?
Section titled “Does OrgGuard show me what breaks when a certificate expires?”Yes. OrgGuard’s certificate dependency mapping discovers which Named Credentials, the Identity Provider, SAML SSO configs, Outbound Messages, and Connected-App JWT bearer flows reference each certificate. The Dependencies column in the Certificate Inventory shows the count at a glance, and the Blast Radius tab on each certificate detail page lists every affected configuration.
How is OrgGuard different from Salesforce’s built-in certificate expiration emails?
Section titled “How is OrgGuard different from Salesforce’s built-in certificate expiration emails?”Salesforce sends expiration emails only for Outbound certificates, and only to the user who originally created the cert. OrgGuard tracks three certificate classes (Outbound, Inbound mTLS, and Connected App JWT), routes alerts to the current responsible owner (not the creator), maps the full dependency context so you know what breaks, and maintains an audit trail of every alert and acknowledgment. (Reliable inbound mTLS discovery on feature-enabled orgs arrives in Pro 1.1 — see the Roadmap.)
Does OrgGuard require Event Monitoring or Security Center licensing?
Section titled “Does OrgGuard require Event Monitoring or Security Center licensing?”No. OrgGuard Pro runs entirely on standard Salesforce Platform APIs. It does not require Event Monitoring, Shield, or Security Center add-on licenses.
Who can I contact for support?
Section titled “Who can I contact for support?”Email support@orgguard.com. Include a diagnostic bundle export when reporting issues — this helps us troubleshoot faster.