The Structural Pattern Assessment & Review Kit — the grounded first pass: fitness verdicts, not defect lists, honest about what it judged and what it couldn't.
Your org data + your AI key stay in this browser. There are no servers to upload to.
Drop it below — the whole folder, or any piece: a SARIF, an Org Check CSV, a previous run's signals.json (resume) or findings.json (delta).
Drag it in ▾
Drag your evidence here — the orgspark-input folder or any single artifact.
Files are read and parsed inside this tab. Nothing is uploaded anywhere.
Wondering what happens after you drop files? See the whole journey — every step, what you get, what runs where. Or connect your org to pull the setup vitals live.
Gather your evidence
Every finding cites evidence — this is where it comes from: metadata, code-scan results, and setup vitals, exported read-only from your org. orgspark never reads your business records — the assessment is about how the org is built, not what's in it. Every command retrieves, queries, or analyzes — nothing writes — and you review every script before running it.
Connect
Two optional connections. Both stay inside your browser.
1Claude — powers the AI deep passnot connected
Bring your own Anthropic API key to unlock the architecture-fitness deep pass (the Fitness Framework judgment, per-domain, with a consent gate before every call).
Your key is stored only in this browser and sent only to api.anthropic.com — the page's security policy physically blocks every other destination. Get one at console.anthropic.com (~3 minutes; set a small spend cap while you're there).
No API key? You don't need one. A claude.ai Pro/Max subscription can't be connected here (subscription auth is licensed for individual use, not third-party tools — so orgspark won't ask for it), but the Judgment pack on the Results step runs the identical rubric on the plan you already pay for: download, paste into your own Claude, done. The connected-key lane adds the in-app pass with the adversarial verifier and consent gates.
Status
🟢 Connected
Key
Storage
Now unlocked
the AI deep pass and in-app reuse-vs-rebuild verdicts on the Results step — a consent dialog with the exact payload and worst-case cost gates every call, and everything returns through your review
What connecting Claude actually does
Unlocks: per-domain Deep pass buttons on the Results step. Nothing else changes, and nothing runs until you click one.
What runs per click: two AI calls — a Domain Assessor that judges your signals against the 79-check catalog and the Architecture Fitness Framework, then an Adversarial Verifier that tries to refute every finding it produced.
What leaves this tab: only derived signals — object/field names, counts, sharing models, verdicts (never record values). Shown to you verbatim, with a worst-case token/cost estimate, in a consent dialog before every call — and nothing is sent to Anthropic until you approve, not even a token count. Never your raw files. One honest note: a descriptive field or object name (say, one named for a medical condition) can itself be sensitive — you see the exact payload each time and decide.
What stays in this tab: a session snapshot of the parsed metadata (never your raw files, never record data) is kept in this tab's sessionStorage so an accidental refresh doesn't destroy your run — it dies when the tab closes, same as the org token.
The paper trail: every call lands in the run log (model, payload hash, actual cost) — downloadable as runlog.json.
2Salesforce org — direct connect (opt-in)not connected
File-first is deliberate — "nothing can leave this tab" is the trust model. Direct connect adds a zero-server alternative: your browser talks to your org only (login popup on a Salesforce-hosted page; the token stays in this tab and expires with it). It fetches the setup vitals — org-wide defaults, admin counts, coverage, packages. Metadata retrieve and code scans still come from the script: browsers can't speak the Metadata API, and orgspark won't pretend otherwise.
Connect a sandbox, not production. orgspark is read-only by construction — but good practice (and most client contracts) still say: assess from a sandbox or a fresh full copy. And never connect an org you don't own — a customer's production included — without written authorization to assess it. Being able to is not the same as being allowed to.
What connecting an org actually does
Unlocks: a Fetch setup vitals button on the Upload step. Nothing is fetched until you click it.
What runs per click: the read-only vitals queries (…) — the same ones the Evidence script runs via CLI. Results merge with anything you've uploaded.
What never runs: writes of any kind, and metadata retrieve (browsers can't speak the Metadata API — the Evidence script covers that half).
Independence: your org and Claude never talk to each other. Data flows org → this tab → and only through a consent gate → Anthropic. Disconnect either at any time.
Prepare your org — a 5-step admin walkthrough (one-time)
orgspark has no server, so your org has to trust this page directly: one app registration, two checkboxes, one allowlist entry. Everything below happens in Setup and only needs doing once per org.
Register orgspark as an app in your org
Setup → Quick Find → External Client App Manager → New External Client App. Give it a name (e.g. "orgspark"), API name and contact email; keep Distribution State Local.
Why an External Client App? It's the platform's current app-registration mechanism — creating classic Connected Apps is switched off by default since Spring '26.
Point it back at this page
In the app's API section, enable OAuth and set the Callback URL to exactly:
…
Grant three scopes and no more: api (Manage user data via APIs), web (Manage user data via Web browsers), refresh_token / offline_access (Perform requests at any time).
Make it a secret-less public client
Under Flow Enablement, tick only Authorization Code and Credentials Flow. Under Security, tick Require Proof Key for Code Exchange (PKCE) and Issue JSON Web Token (JWT)-based access tokens for named users — and make sure Require secret for Web Server Flow stays unticked.
A static page can't keep a secret, so it never gets one: PKCE is what proves the login is genuine. The refresh-token policy (OAuth Policies → App Authorization) is your call — stricter just means reconnecting more often.
Let your org answer this page's calls
Setup → Quick Find → CORS: add https://salesforcebinge.github.io to the allowlist, and tick Enable CORS for OAuth endpoints in the CORS settings — it's a separate switch and off by default.
Skip either one and the login popup will succeed but the token exchange will fail — this pair is what makes a server-less login possible.
Copy the Consumer Key
Give the new app 5–10 minutes to propagate. Then open it → Settings → OAuth Settings → Consumer Key and Secret (Salesforce emails you a verification code) → copy the Consumer Key and paste it into the form above, together with your org's My Domain URL.
Connect as the right user: a read-only-admin-style profile is ideal — the minimum is API Enabled plus read access to the metadata being assessed. orgspark performs no writes, so a read-only user is exactly the right shape. And always the My Domain URL, never login.salesforce.com.
The whole journey, step by step
Click any node — what you do, what you get, what happens next. Solid = the free path · dashed grey = optional · amber = the loops.
Every claim above is testable: the About page lists the security posture, and the whole engine self-tests in your browser via selftest.html.
The Guide
Everything you need to run an assessment, door by door — and what to do when something snags.
Door 1 — the evidence script (recommended)
Run a read-only script, drag a folder in
You need: the sf CLI authenticated to the org you're assessing (a sandbox that mirrors production is the right habit).
1. Head to the Evidence page and copy the script. It's transparent by design: it describes your org first, shows every metadata type it found, writes a package.xml from what your org actually contains, and asks before retrieving anything. Read-only end to end — retrieves and queries, never a deploy.
2. Run it. You get an orgspark-input/ folder: retrieved metadata (Apex, flows, layouts, sharing rules — and, if your org has them, the Agentforce family: bots, planners, topics, actions), the setup queries as CSVs, record counts (numbers only), and the discovery file.
3. Drag the whole folder onto the Assess page. Parsing happens in this tab — watch the signal count appear, then pick your scope and run the free assessment.
4. The review gate opens: keep or kill each draft finding. Nothing reaches a report without you. Then Results.
Door 2 — connect the org live
One-time External Client App setup, then one click per scan
One-time setup (admin, ~5 minutes): in Setup, create an External Client App with OAuth enabled. Callback URL: this site's /oauth/callback/ address (shown on the Connect page). Scopes: api, web, refresh_token. Enable PKCE, and — the step everyone misses — check “Enable Cross-Origin Resource Sharing (CORS) for OAuth endpoints”. Turn on Refresh Token Rotation while you're there; the app handles rotated tokens correctly and Salesforce mandates the pair.
Connect: enter your My Domain and the app's Consumer Key on the Connect page. A popup runs the normal Salesforce login (MFA included); the token lives in this tab's sessionStorage and dies when the tab closes.
Scan: back on Assess, a banner offers Run live scan. It first counts what it would read — classes, triggers, active flows, validation rules, plus the full setup census (including Agentforce agents & bots and record volumes, counts only) — and shows the exact number of read-only API calls before you confirm. Every re-scan calls the org fresh; results are never cached.
The coverage map stays honest about what the live path can't reach (Code Analyzer depth, sharing-rule XML, profile internals) — the evidence script covers those.
Door 3 — bring exports you already have
Org Check, Code Analyzer, sfdx-hardis
Drag in Org Check exports, Salesforce Code Analyzer SARIF files, or sfdx-hardis monitoring reports — alone or alongside script evidence. Their findings are preserved and cited verbatim; orgspark's verdicts sit beside them, never overwrite them.
Reading your results
Three tabs, one verdict hero
The verdict hero (plain-language forecast, Dangeometer, Well-Architected pillar scores) stays on top. Below it: Downloads & Toolkit (grab the workbook and report; the AI layer lives here), The Workbook (every sheet rendered in-page — the most detailed view: the census with greens listed, Agentforce & bots, record volumes, custom objects with their data-model shape (fields, validation rules, flows, external IDs) and a rule-based reuse baseline, and the Method & Validation sheet that grounds every rule), and Full Report (self-contained HTML; print it and it's your PDF).
Next quarter: keep findings.json. Upload it before your next run and the report computes the delta — resolved, regressed, new.
Refreshes are safe: an accidental refresh restores your session (parsed metadata only, never raw files — it dies with the tab). Closing the tab ends the session by design.
The AI layer (optional)
Two lanes, one judgment standard
Your API key: the fitness deep pass and in-app reuse-vs-rebuild verdicts, each call behind a consent dialog showing exact payload and worst-case cost, adversarially verified, returning through your review. No key: download the Judgment pack (.md) — rubric, your census data, and instructions in one file — and paste it into the claude.ai plan you already have. Either lane, verdicts apply only after your approval, and runlog.json audits every call.
When something snags
Troubleshooting
“Connect failed: Failed to fetch” — the CORS-for-OAuth checkbox on the External Client App isn't ticked. It's the classic.
Login popup never appears — your browser blocked it; allow popups for this site and retry.
Authenticator failed during MFA — approvals expire fast; retry and approve the push promptly. The failure happens inside Salesforce's login, before orgspark is involved.
Old results after an engine update — reports are artifacts of the run that produced them; hard-refresh, then run a fresh scan to re-judge under current rules.
Very large orgs — the live scan caps at 500 classes and 200 flows per pass (disclosed in the count consent); the evidence script has no such caps.
“Can't I just use a CLI token?” — no: Salesforce's CORS layer rejects session-style tokens (like the sf CLI's) from browsers. Only the External Client App's OAuth flow issues tokens that work browser-direct — which is by design, and why the popup exists.
A probe says “skipped” — that org doesn't license the feature (Experience Cloud, etc.); the coverage map records it honestly instead of guessing.
About orgspark
Judgment where scanners stop.
What it does
orgspark assesses whether a Salesforce org was built right — over-engineering, wrong-tool choices, missed platform capabilities — and maps every finding to a maturity ladder: Defect → Hygiene → Pattern → Fit → Design. The free mode is fully deterministic (parsers → rules → scorecard → report, zero AI). The optional AI deep pass applies the Architecture Fitness Framework with your own Claude key, one consented call at a time.
The trust model
Static page, no backend, no telemetry. Your exports are parsed in a Web Worker in this tab; the report is minted in your browser; the only network call the page is even allowed to make is the AI call you explicitly approve, directly to Anthropic with your key.
Where this is going
The roadmap, in the open — so you know what you're adopting:
Probe census — the live scan grows a setup census over every queryable corner of your org: Experience Cloud sites & sharing sets, profiles & permission sets (with user counts), permission set groups, Visualforce, static resources, integration endpoints, duplicate/matching rules, workflow rules, custom metadata types. One read-only query each, feature-gated orgs honestly skipped.
Reuse-vs-rebuild verdicts — the judgment layer, in two tiers. The free deterministic baseline rates each flagged component by what must change — a config fix, structural rework, "review — needs judgment", or "insufficient data" when the shape wasn't captured — and deliberately never issues a confident Rebuild (the heaviest call), reserving that for the optional AI pass, which is adversarially verified and always passes your review gate. For custom objects the same verdict also weighs data-model fitness — do these fields quietly replicate a standard object, is the object field-bloated — using the object's field shapes, folded into the one verdict so nothing contradicts itself.
Quality narrative — an AI-written executive read of the whole assessment (clearly marked as AI-generated), for the workbook and report.
Scope advisor & delta stories — what evidence to add next, and what actually changed since your last run.
The invariants never move: your data stays in this tab, every AI call is consented with its exact payload and cost, and nothing reaches a report without your review.
Where it came from
orgspark began as a theory — a piece I wrote on the Galton board, on how an org's shape is set by thousands of small decisions. This is the instrument built to read it — starting with the earliest and heaviest of those decisions, the data model, the part it looks at hardest.
The name
Yes, it stands for something: Structural Pattern Assessment & Review Kit. Giving a machine an earnest, slightly-too-long acronym is a proud engineering tradition — ask any inventor with a food replicator. And if the forecast language around here — the Dangeometer, the occasional Orgnado warning, the De-Mutation kit — feels like it owes a debt to a certain documentary about food falling from the sky, that's because it does. Orgs, like weather machines, start with the best intentions.