Permissions
Who can access what, read straight from source across every permission set, profile, and group. This is where a security review actually becomes possible.

Overview
How many permission sets and profiles you have, how many carry broad object access, how many grant dangerous system permissions, and the highest-priority risks first.
Object and field access
A grid of every container against every object, showing exactly what each grants: read, create, edit, delete. Drop to field level for the sensitive objects to catch the field nobody meant to expose.
Risks and lookup
The triage list of permission sets and profiles handing out Modify All Data, View All Data, and other keys-to-the-org permissions. Look up a single component, see which personas reach it, and spot overlap and over-grants.
