As GDPR came into view, I took a closer look at the security settings in our Salesforce org. Probably nothing novel about that statement, but I'll share a few of the changes that resulted. First, I ran the Health Check. It's under Setup | Security. It provides an immediate view of some big-picture security issues. I'll confess that I knowingly have not taken all the recommended actions. In some cases, that's for my own convenience (I do want to be able to log in as any of my users, and I don't want to log in under my own credentials after I log out under a user's id). But some of the isues identified are no-brainers and do leave you in a better security posture. But that's primarily about ensuring that the a user should indeed be logged in to your org. What about the permissions that those legit users have? I've taken a number of steps to further limit access to company data. First, I inherited an org with roughly a hundred users and nearly a d...