43 capabilities, grouped by the question they answer. Every screen is the real application on the Meridian demonstration estate. Chips say when a capability arrived.
Get set up
Install, connect an org, run a first audit.
Read-only access through the user's own Salesforce CLI
shippedsince 1.0Global settings → CLI paths
Only sf data query, tooling query and REST GET are wired; no write path exists in the app.

Per-folder licence key
shippedsince 1.0Folder → licence prompt
Ed25519-signed key validated locally; gates refresh and org-calling analyses; cached data readable without one.
Everything stays on the auditor's machine
shippedsince 1.0~/StoodFlows/workspaces/<folder>
No Stood cloud. Only outbound call is the UI bundle fetch; sharing is opt-in on the customer's GitHub or S3.
Read your org
One row per process: what the matrix says and what to detect in it.
Backbone objects and record-type rows
shippedsince 1.0Graph → KPIs
One row per (object × record type × business process) for Lead, Opportunity, Case, Campaign; Account and Contact as support objects; custom objects promotable to backbone.

Stages column: Total, Ghosts, Active, 1…N
shippedsince 1.0KPIs → Volume → Stages
Stage columns sized to the widest record-type process; Σ stages + Ghosts = Total by construction; ghosts split off-process / retired / unattributed (1.3.0).

Usage columns: modified, created, actors
shippedsince 1.0KPIs → Usage → Activation
Records touched and distinct users per record type over the window; all-zero usage is the strongest retirement signal.

Lifecycle time per stage
shippedsince 1.0KPIs → Lifecycle → Time
Average dwell per stage per record type from field history over a sliding year, fetched incrementally by monthly cohort.

Complexity score and drill-down
shippedsince 1.0KPIs → Complexity → Score / Detail
Score = stages + profiles + layouts + pages + flows + triggers + rules, unweighted; each cell opens the items it counted (drill-downs since 1.2.8).

Related and custom objects per row
shippedsince 1.0KPIs → Objects → Volume / Lookups / Related
Custom objects attributed to the parent record type through the lookup back-reference; starving children and sprawl both visible; '+' markers fetch a volume on demand (1.2.8).

Field usages: Allowed → Visible → Unused
newcurrent buildKPIs → Fields → Allowed / Visible / Unused
FLS-allowed, on-layout, and filled under the policy threshold (5% default) per record type; cell reads 12 (8) = unused (deletable); three states never conflated.

Process tags and filters
shippedsince 1.2.8KPIs → Tags
Free-text tags per process that survive refreshes; filter the matrix by object, tag or text; Total column pinned while scrolling.

Process impact map
shippedsince 1.3.0KPIs row → impact map, or the canvas
Everything attached to one process (layouts, profiles, flows, rules, related objects) on one map, from a KPI line or the graph.
Mapping canvas (business process map)
shippedsince 1.0Graph → Mapping
Swimlane view of each object's processes with their stages and attached triggered flows.

History timeline
shippedsince 1.2.8Graph → History
Monthly timeline of created, modified and audited (180-day audit trail) metadata, with drill into a month.

See who uses what
Seats, logins, writes, screens and objects — the evidence behind a licence decision.
Licence inventory with cost columns
shippedsince 1.2.8Licensing → Licenses
UserLicense and PermissionSetLicense inventory, editable unit price, Provisioned $ / Assigned $.

Profiles: who sees which process, and what it costs
shippedsince 1.2.8Licensing → Profiles
Users / Logins 30d / Actors / Assigned / Unlogged / Actor $ / Non-actor $ per profile, with a click-through to the processes the profile sees.

Groups and role hierarchy
shippedsince 1.3.0Licensing → Groups
Public groups and the role hierarchy with the same cost columns as profiles.

DML analysis (event log files)
shippedsince 1.2.8Licensing → DML
Every user in one of six buckets (active / lowDml / pseudoOnly / noReal / noDml / integration); drill Bucket → Licence → Profile → User; DML by object and by package (1.3.0).

Visits: what people actually look at
shippedsince 1.3.0Licensing → Visits → Overview / Screens / Journeys / Sessions / Users
Event-log page views sessionised; sources chosen by measured coverage; every bar split by DML category; aggregates only, no record id, URL or IP.

Visited objects
newcurrent buildLicensing → Visits → Users → Visited objects
Per object: views, share, users, sessions, records, screens; custom / standard and profile filters; CSV; hands the list to the Objects explorer.

Login cohorts
shippedsince 1.2.8Licensing → Cohorts
Daily / weekly / monthly / quarterly active and infrequent cohorts from Login event logs, per licence and profile.

Deactivation policy
shippedsince 1.2.8Licensing → Policy
Policy preview (no login in N days, exempt profiles, provisioning window), ready-to-run sf command, enforcement log, CSV.

Credits (TenantUsageEntitlement)
shippedsince 1.2.8Licensing → Credits
Daily entitlement snapshots with pro-rata gauges: near-limit, over-limit, zero-usage.

Objects explorer
newcurrent buildFolder → Dashboard → Objects explorer
Every business object across orgs, biggest first: records, DML ops, users, visits, API calls, storage cost heuristic, last created; No DML and stale filters.

Automation and code
Triggered flows, Apex and integrations: what runs, what never does, what to retire.
Apex analysis and packaging
shippedsince 1.2.8Graph → Apex
Dependency tree from triggers, org-wide tree, cold classes (ELF), isolated branches, packages view, schema artefacts for a migration package.

Flows view
shippedsince 1.3.0Graph → Flows view
Every active flow scored by steps, Backbone vs Org-wide, ELF runtime (executions, errors, time), live / never-ran / erroring / unobservable; Process Builder in red.

I/O analysis and heavy consumers
shippedsince 1.2.8Graph → I/O → Inbound / Outbound
Inbound callers → endpoints → objects with rows written per call; outbound callouts by destination; the 1–15% band is where runaway polling hides.

Run the estate
Every org side by side, the contract, the backlog, the business case.
Folder dashboard (scorecards)
shippedsince 1.2.8Folder → Dashboard → Cards
Eight cards across every org and version: processes, backbone records, complexity, global objects, global flows, Apex, licences, connected users, issues; baselines; policy sub-sections; PDF export (1.3.0).

Dashboard policies (removal candidates)
shippedsince 1.3.0Dashboard → Policy sub-sections
processIdleMonths 12, relatedUnusedRatio 1%, objectIdleMonths 12, fieldUnusedShare 5% by default; per-folder dashboard-policy.json.

SELA contracts
shippedsince 1.2.8Folder → Contract management
SKU pricing, org record naming, Mapping (contracted / provisioned / used / Δ, by product or by org, shared pools since 1.3.0), business units from CSV, recovery view.

Issues: Open → Qualified → Closed with anchors
shippedsince 1.2.8Graph → Issues; right-click any cell
Three-step workflow (1.3.0), criticality from the stated volume, invisible anchor that survives refreshes and powers 'Go to it'; CSV, GitHub or S3 backed.

Epics and Auto-file
shippedsince 1.3.0Issues → Epics tree; Auto-file button
Fifteen built-in epics across seven cards; folder epics.json adds, renames, archives; Auto-file files unfiled issues from their anchor column and sets criticality.

Drill-downs across analyses
shippedsince 1.3.0Any number → the view that explains it
Click a dashboard or matrix number and land on the explaining view with a way back; URL carries view, tab, anchor.

Marketing Cloud
Business units next to the orgs they feed: reach, cost, data extensions.
Marketing Cloud connection and business units
shippedsince 1.3.2Folder → Settings → Marketing Cloud
Server-to-server package, credentials in the OS keychain, step-by-step diagnostics, parent MID plus child BU graphs derived from the enterprise.
Refresh all, in the background
shippedsince 1.3.2Folder → Refresh all
One button covers Salesforce orgs and MC business units; pause, resume, cancel; machine stays awake.
Cost & reach, live sends
shippedsince 1.3.2MC graph → Cost & reach
Contacts reached in 90 days vs licensed vs Contact Builder; send volumes by campaign and month from send jobs.

Data Extensions and Integrations
shippedsince 1.3.2MC graph → Data Extensions / Integrations
Origin → readers map and duplicate audiences per data extension; at the parent, the Salesforce objects synced in, their connections, audience queries and fields.

Marketing Cloud dashboard
shippedsince 1.3.2Folder → MC dashboard
Enterprise-wide rollup: 90-day sends, shared data extensions, addressed vs stored.

Work as a team
Share a folder, choose roles, run long analyses, and what stays on your machine.
Full analysis: run, pause, resume, watch
shippedsince 1.3.0Graph header → Full analysis
Background run of the missing analyses with pause / resume / cancel, progress per step, several orgs at once; keeps the machine awake.
Sharing method and roles
shippedsince 1.3.0Folder → Settings → Sharing
None / GitHub / S3 × Admin / Contributor decide which buttons exist; a Contributor's one write is the issue list.

Team sharing over S3 (with proxy support)
shippedsince 1.2.8Folder → Settings → S3
Publish and refresh a folder's views through the customer's bucket; issues merge both ways; corporate proxy supported since 1.3.1; Publisher and Reader IAM policies.
Hiding names and emails
shippedsince 1.3.0Folder → Settings → S3 → passphrase
Optional PII encryption of shared folders with a passphrase never shown again; readers without it see masked fields.
Offline mode and CLI paths
shippedsince 1.2.8Global settings
Bundled renderer fallback when stood.hway.io is unreachable; non-standard sf and gh paths; signed, notarised installers with no silent update.
