Help & Support
Elevate Your Agents with AgentExchange Solutions
Easily enhance Agentforce with pre-built AI solutions from AgentExchange. Browse, install, and deploy agents, actions, and apps directly into your environment. Tell Me More
Have Questions?
Guest User Access Report (Deprecated)
See which objects and permissions community guest users can access
- Business Need
- Admin & Developer Tools
- Requires
- Experience Cloud
The Guest User Access report is no longer being updated, and lacks some security features included in the Authenticated and Guest User Access Report and Monitoring package (https://appexchange.salesforce.com/appxListingDetail?listingId=a0N3A00000FYkDDUA1)
Rating
Reputation
MVP
Recognized by Salesforce for their leadership, expertise, and generosity
Top Reviewer
Contribute reviews that encourage conversation and help others make informed decisions
Ranger
Lifelong learners who have earned the Ranger rank or higher on Trailhead
Showing 10 of 46 Reviews
Storing of Data
Could you please help to confirm, once this app is installed on the org it does not store or send any data outside?
Value of incorrect type when assigning the visualforce page
Getting an error Parent ID: id value of incorrect type: 00e0c0000024Qi3AAE when assigning visualforce page access. Any suggestions?
I'm not sure, I can't find anything in release notes that references this, although I did find one article that said that by Spring '26 profile-level permissions are going to be very limited, and mostly moving things to permission sets. I believe there is a closed pilot going on for that, so not sure if your org is included in that. Can you try assigning it via a permission set instead of the profile?
Excellent tool for understanding the Guest user's view of data
It just works. Read the instructions linked on AppExchange and it all just works. I think that the section about which Release Updates may affect you could be removed now since these have long since been in production.
Error while installing Package
Hi, I receive the below error. Can anyone advise ? This package can’t be installed. There are problems that prevent this package from being installed. Variable does not exist: PermissionSetGroupId GuestAccessReportController: Variable does not exist: PermissionSetGroupId Dependent class is invalid and needs recompilation: Class guar.GuestAccessReportController : Variable does not exist: PermissionSetGroupId GuestAccessReportControllerTest: Dependent class is invalid and needs recompilation: Class guar.GuestAccessReportController : Variable does not exist: PermissionSetGroupId Regards, Avinash
Requires time & Analysis
Make sure you set aside time to look things up when you use this app. You get a long list of potential risks in the report and then need to assess them based on your org set up. Some things flagged as risks for us and are not going to be changed due to the settings necessary to run other items (like anonymous Salesforce Surveys). If you're looking for a definitive answer as to what to change that will apply across the board you are bound to be disappointed.
Like most things in salesforce it leaves you holding the bag
Another terrible implementation. Salesforce once again offloads all the work onto this developer who in turn offloads all of the work onto us admins. I do not have time in my extremely tight schedule to do all of this work and figure out how to install/run this. The directions left me with nothing. No information and it doesn't work. I can't even find where this report went once installed. This type of extremely important information should have been built BY SALESFORCE with this security change/release and should have been as easy as clicking a button. I do not have time for this. Salesforce will eventually and hopefully be sued for their misleading and time wasting business practices. LAZY LAZY LAZY development.
4. If I am being fair and objective, it seems that, based on your review, you have a time / prioritization problem - not an app problem (if otherwise please do share the problem). And not that I necessarily care about how many stars you leave on your review, I care more about trying to help you out with the issues that you are having if any. Although i cannot necessarily influence how your time is prioritized, but what I can say is that your stakeholders should realize that security impact from org configuration is an important topic and time should be prioritized for it. So again, if there is anything I can help guide you with in this area, please reach out via private message and let me know.
Hi David, Thanks for your feedback - I always welcome it. However, I would like to clarify a few points here. 1. Salesforce did not offload any work onto me (the developer of this app) - as a matter of fact I took it upon myself to create this app in an effort to help admins get a unified view of their org configuration, as we were trying to raise awareness around best practices and a secure by default implementation in our customers’ orgs. 2. Whether this report was built into the product or not, it would not change much on how it would run, because it would still need to run in the context of the guest user of a specific site, per site, to give you the information you need. This app is basically one visualforce page, and given that vf pages are quite and old concept, admins are usually knowledgeable in how to provision access and build the url to access a vf page. Also, the accompanying quip doc with the instructions provides how to do this just to cover all basis. (If you need help figuring out the url I would be happy to help if you private message me) 3. Salesforce is not in the position to be able to dictate how customers configure their orgs, each for their specific use case. Each customer has a different set of requirements, and thus the configuration changes, so at best Salesforce can raise awareness around best practices for various scenarios that are applicable to multiple customers at a high level. Unfortunately it is not realistic to expect an “easy” button when it comes to securely configuring an org per your business requirements. So given that we have been on this enablement mission around this topic for about two years now, I can say in fairness we have tried to create, curate, and communicate as many resources as we can to raise awareness and help customers understand the topic….
Could be friendlier
If you do not have communities this will not confirm the fact, and the instructions will be a blind alley. Either the product or the instructions could have handled that. It also doesn't handle the older "sites.com" webpages, so if you have those, this won't help. Suitable for use if you already are familiar with your setup, but less useful for anyone coming in "blind" to the all-too-typical undocumented org. My org has no Communities so I didn't run it. I imagine that logging in as the guest user to run this report is very accurate and foolproof, even if it is extra effort.
Some promises fulfilled, others not so much
The solution provides a risk assessment of various risks identified and addressed in previous releases associated with Guest Users. Fulfilled. Where it completely misses is that the emails promoting it tell you it will identify records owned by Guest Users. Either we don't have any, or it doesn't do it. Miss. Another issue is that the green "Give Us The Green Light" button is inadequately presented. It doesn't tell you anywhere that there is a flow behind it, and you're going to keep getting pestered to run these reports until you respond. Miss. And the flow - that's another story. It asks you to confirm - for apparently legal purposes - that you've addressed a bunch of expected results and security standards (that SF is trying to enforce in the releases). But nowhere do you get any explanation of what you're committing you've accomplished. Miss-Miss. Miss.
Getting Authorization required for one of the guest user
Hi Team, The app is great. However, we are getting Getting Authorization required for one of the guest user. Can you please let us know what could be the reason for this? Thank you.
Really Helpful. Needed some information.
Hi Team I am facing some issues with the report. The report shows the list of some Enabled Apex Class Access as potential risk. When I go to the guest user profile to remove the classes I am not able to see the profile have access to the class. Can you help me what could be the reason it is showing in the report but not on the profile level. Also, how can we remove access in that case? Thank you.
So the potential risk showing in the report is actually the opposite of what you're expecting. The potential risk is assuming that the guest user will need to run that apex controller, and if they don't have access to it, then they won't be able to - so that's the risk. If the guest user does not need to run the apex controller, and it is showing a potential risk that the guest user won't be able to run it, that's fine because that's what you want anyway.
going through a permission set worked, thanks