Almost every Org has the same story. Permission Sets copied from a departed Admin, never revisited. Sharing Rules built for a re-org that happened three years ago. Guest User Object access nobody remembers granting. Field-Level Security that was "temporary" during a data migration in 2022.
None of this shows up in a demo. None of it slows down a Sprint. So it never gets prioritized.
Here's the misconception: security is something you configure once, at launch, and then maintain by exception. A ticket comes in, you patch it, you move on.
That's not how Orgs actually decay. Access accumulates the same way Fields and Flows do: Quietly, additively, one "just give them the permission for now" at a time. Eighteen months later you have a Permission Set structure nobody can explain, and an audit that takes three weeks instead of three days.I've been talking about cleanup as capacity, the 15% every program should spend on cleaning instead of only shipping new features. Security isn't a separate workstream from that. It's the same cleaning discipline pointed at Profiles, Sharing Rules, and API access instead of Objects and Automation.
The Orgs that get breached are the ones where access control quietly stopped matching reality, and nobody was assigned to notice.
Book a free 60-minute Salesforce Technical Debt Audit: a score for Usability and Build Quality, and your top cleanup priorities.