Salesforce cost + security

Salesforce spend and risk, in plain English.

SF2BI connects to your Salesforce org read-only through OAuth and turns it into a cost and security control center. It reads what Salesforce actually invoiced you — not a list-price guess — finds idle licences and what they really cost at your negotiated rate, ranks dollar-saving actions with step-by-step instructions, scores your security posture 0–100, and audits privileged access and login activity. Ask any of it in plain English.

No credit card. Read-only OAuth connection. About ten minutes to connect.

Ask the copilot

  • Which Salesforce licences haven’t been used in 60+ days, and what are they costing us?
  • What did Salesforce actually invoice us over the last twelve months?
  • Which contracts auto-renew, and how many days until each one does?
  • Show me every user with Modify All Data and when they last logged in.
  • Failed login attempts in the last 7 days, grouped by source IP.
  • Which add-on licences are sitting idle?
Salesforce runs $165+ per user per month — and most orgs have no idea how many of those seats logged in last quarter, which admins hold Modify All Data, or whether MFA is actually on. Every cost or security answer means a SOQL query, the Report Builder, or an admin ticket that sits for days.

Why

Your org already holds every answer

It just won’t surface them without a specialist in the loop.

Idle seats renew because nobody has time to audit them

Finding which seats have not been used means a SOQL query or a report someone has to build, so it does not get done — and the renewal quote arrives based on last year’s count plus growth.

The rate you actually pay exists only on the PDF

Salesforce’s API exposes invoice headers — a number and a total — and no line detail. So cost tools work from list price, which for a discounted contract can be double what you pay.

Cost and security answers route through the same admin

Which licences are idle, who holds Modify All Data, whether MFA is enforced, which OAuth grants are stale — every one is a query, a Report Builder session or a ticket.

Privileged access accumulates and nobody reviews it

Admin rights get granted for a migration and never removed. Permission sets multiply. None of it is visible until an audit asks.

Auto-renewal arrives before anyone prepares for it

The window to renegotiate opens months before the renewal date and closes silently. Most teams find out after the contract has renewed.

The reports worth circulating are full of your colleagues

An inactive-user list is exactly what finance should see — and exactly the list full of names, work addresses and login times. So it gets redacted by hand, or never sent.

What you get

One place for Salesforce cost and security

Find licence waste

Idle seats, over-bought add-ons and never-logged-in users — ranked by annual dollar impact.

Your real rates

Upload a Salesforce invoice and every figure is recalculated at what you actually pay.

Security posture

A 0–100 score with ranked fixes across privileged access, MFA, logins and OAuth grants.

Ask in plain English

The copilot picks the right report from a reviewed, read-only query catalog — never free-form SOQL.

Read-only by design

Every call is a SOQL SELECT. No package, no Apex, nothing written to your org.

Your Connected App

You create the External Client App in your own org and can revoke it any time.

Who uses it

Built for the people who pay for Salesforce and the people who secure it

CFO / Finance

Today: Pays six figures a year for Salesforce with no view of which seats are actually used.

With SF2BI: Estimated annual spend, an idle-licence list, and ranked dollar-saving actions.

CISO / Security

Today: No standing view of who holds admin rights, whether MFA is on, or which OAuth grants are stale.

With SF2BI: A 0–100 posture score with ranked findings across privileged access, login activity and OAuth hygiene.

Salesforce Admin

Today: Licence clean-up, permission drift and audit prep eat the whole week.

With SF2BI: Inactive-user, over-privileged, frozen-account and stale-token lists on demand.

RevOps / Ops

Today: Every cost or access question routes through a SOQL query or an admin ticket.

With SF2BI: Plain-English answers from an audited, read-only query catalog in seconds.

How it works

From sign-up to answers in four steps

  1. 1

    Create your account

    Sign up with your work email. You get 50K free tokens — no credit card.

  2. 2

    Create an External Client App in your org

    The setup wizard walks the exact Setup screens and shows the callback URL to paste. About five minutes, once.

  3. 3

    Choose the user it runs as

    We recommend a dedicated integration user with a read-only profile, so Salesforce itself enforces that SF2BI can only read.

  4. 4

    Paste the keys and authorise

    Paste the Consumer Key and Secret, log in to your own org and click Allow. Dashboards fill from your live org; connect UAT and sandboxes the same way.

See where your Salesforce spend leaks — and who holds too much access.

Read-only. No package to install. 50K free tokens, no credit card.