Kenseda Salesforce org analysis

Know exactly what your Salesforce org does. Every answer cited to the line.

Kenseda reads your org's metadata the way the Apex compiler does, and reports which code reads and writes which fields, where, and what it could not determine. Comments, class names and documentation are not evidence. The code is.

Exhibit 1 · One class, two readings DocLie_CitySync.cls · test class, planted to mislead
2 * @description Keeps Contact addresses in step with their Account.3 * Copies the Account's BillingCity onto the MailingCity of every related Contact.4 * Contacts are the only records this class ever modifies.…13        for (Contact c : [SELECT Id, AccountId, MailingCity FROM Contact WHERE AccountId IN :accountIds ...]) {14            if (!accounts.containsKey(c.AccountId) && c.MailingCity != null) {15                accounts.put(c.AccountId, new Account(Id = c.AccountId, ShippingCity = c.MailingCity));…18        update accounts.values();
The documentation

Copies Account.BillingCity onto Contact.MailingCity. Contacts are the only records modified.

Wrong: direction, object and fields
Kenseda
  • ReadsContact.MailingCity L13, L15
  • WritesAccount.ShippingCity L15
  • UpdatesAccount L18
  • Neverwrites any Contact field
What the code does, cited to the line

Kenseda doesn't read comments. It reads the code, and cites every fact to the line.

When to call us

The questions teams can't answer with confidence

"Why did this account's shipping address change when nobody edited it?"

An account's address changes, and nobody on the team remembers changing it. It's the pattern in Exhibit 1: code that copies a contact's mailing city onto its account. It only fires when a contact has a city, and the oldest contact wins, so only some accounts change and it looks random. We name the class, the line that writes the field and the condition that decides it, from the code.

"What breaks if we change this?"

A field, a picklist value or a class is about to change. Every Apex reader and writer and every trigger that touches it, cited to the line, before anyone commits to a plan.

"What do we actually need to test?"

A release is scoped and the test plan is being written from memory and interviews. Kenseda shows what the change really reaches, so testing covers what it affects and nothing is guessed.

"We inherited this org. What does it do?"

The original developers have gone, and the comments may no longer match the code. The report describes what the code does, not what anyone says it does.

"What has to move?"

A migration to a new data model or package, or a merger of two orgs. Every customisation that touches the affected objects and fields, so the work is sized from evidence.

Services

Fixed scope, delivered as a cited report

Each engagement answers a defined question about your org. Every finding points to the file and line it came from, and the report says plainly what could not be determined.

Change Impact Report

Before you change a field, object or process

Every piece of Apex and every trigger that reads it or writes it, each cited to the line, plus a list of what we could not see.

Price on request

Org Health Audit

Taking on or inheriting an org

Code nothing calls, comments that contradict the code, fields written from more than one place, and the gaps an analysis could not close.

Price on request

Migration Evidence

Planning a migration or org merger

Every customisation that touches the objects and fields being moved, with where and how, so the work is scoped from evidence rather than interviews.

Price on request

Change Guard

Ongoing

A rescan on each release, reporting new dependencies and risks before they reach production.

Price on requestmonthly
How it works

You supply metadata. We return a report you can check.

  1. 1

    Connect or upload

    Connect your org securely, using a metadata-only integration user, or upload a retrieve made with our one-command kit if you would rather not grant access.

  2. 2

    Isolate

    Your metadata goes into an area only your organisation can reach, encrypted with a key of its own.

  3. 3

    Scan

    Each scan runs in its own isolated environment, which is destroyed when the scan finishes.

  4. 4

    Report

    A report in which every statement cites its source file and line, with a section listing what could not be determined.

Kenseda runs only on our infrastructure. Nothing is installed in your environment, and the analysis works from metadata files. No live connection to production is needed.

Limits

What Kenseda cannot see yet, and says so

An answer is only safe to act on if you know where it stops. When Kenseda cannot determine something, the report names the location and the reason. It never reports "nothing found" when the truth is "not examined".

Queries built from strings

SOQL assembled at run time and run with Database.query. The call is recorded; what the string queries is marked as not determined.

Schema tokens

Field references such as String.valueOf(Installation_Project__c.Status__c) are currently recorded as unresolved references, not dropped.

Managed package code

Apex inside installed managed packages cannot be retrieved from any org. Reports list the packages present and state that their code was not analysed.

Security

How our hosted service handles your metadata

These are the terms our hosted service runs under:

Metadata only
We work from configuration and code. We never ask for, receive or store your customer records.
Processed in the UK
Hosted in UK data centres. Your metadata is not processed outside the UK.
Your own encryption key
Each client's data is encrypted with a key of its own, usable only by that client's scans.
Kept only while you need it
Your metadata and everything derived from it is kept, encrypted, only while your engagement or subscription is active, so reports can show you the exact lines they cite. It is deleted within 30 days of the end, or sooner on request, backups included. You keep the report.
No AI reads your metadata
Kenseda never sends your metadata to an AI service. Optionally, you can connect your own AI assistant to your scans through our MCP server. It is off by default and under your control.
Cyber Essentials In progress
We are completing the UK government-backed Cyber Essentials certification.
About

Built by a Salesforce consultant

Paul Taylor is an independent Salesforce consultant who founded Kenseda Ltd to answer questions about Salesforce orgs with evidence — every answer traced to the line of code that produced it. He has worked on the Salesforce platform for [BRACKETED: years on the platform], holds [BRACKETED: certifications], and has worked mainly with clients in [BRACKETED: sectors]. Kenseda grew out of that consulting work: the questions clients kept asking about their orgs that comments, tribal knowledge and documentation couldn't reliably answer.

Contact

Start with one question about your org

Tell us what you are about to change, or what you have inherited. We will say whether a report can answer it, and what it would cost.

[email protected]