Newest first. The desktop app loads its interface from Stood's hosting at startup, so most capabilities reach every installed copy the day they ship; a new installer is needed only when the shell itself changes, and the notes say when.
Since 1.3.2 in the current build
- Field usages. Three columns per process — Allowed, Visible, Unused — that say which fields a record type can see and which it never fills, measured per record type. Read the page · Illustrated guide
- Objects explorer. Every business object across the folder's orgs, biggest first, with records, writes, users, visits, API calls and a storage cost per object. Read the page
- Visited objects. From the Visits view, the objects people actually open, with views, users and screens per object, handed to the Objects explorer. Read the page
1.3.2 Marketing Cloud grows up
Marketing Cloud grows up: live send volumes, a reach picture, a connection you can diagnose, and refreshes that run in the background like the Salesforce ones. One structural change underneath, so that what we read from Marketing Cloud can improve without another installer.
Set up Marketing Cloud from Folder settings
The Marketing Cloud connection now lives in Folder settings → Marketing Cloud. An Admin with a valid licence can set it up there in any folder, including one with no Marketing Cloud graph yet. Until now the connection was only reachable from a folder that already held one, and you could not create the first graph without a connection, so a new installation had no way in.
The connection is one per machine. Setting it up once makes it available to every folder.
Connection diagnostics. The same page runs a step-by-step check: sign-in, the metadata API, the REST API, reading rows from a sample of synchronised Data Extensions, and send tracking. Each step passes or fails on its own, with a log you can copy. Reading several Data Extensions rather than one catches a permission that was only partly granted, which a single test would report as fine.
What is sent, and to whom
Live sends. Each business unit’s email volume is now read from its actual send jobs, by campaign and by month, rather than estimated. This reads one row per send job, not one per recipient, so it stays quick on large business units.
Cost & reach. Three cards side by side: how many contacts were reached in the last 90 days, what the licence covers, and what Contact Builder holds. The 90-day reached count is computed during the refresh and stored, so the dashboard opens straight onto it instead of recounting.
Data Extensions. Where each Data Extension comes from and what reads it are now one map, grouped by origin, with duplicate audiences and per-extension flags in the detail.
Refreshing
One “Refresh all”. A folder now has a single Refresh all button that covers its Salesforce orgs and its Marketing Cloud business units, in two tabs. It replaces the separate Full analysis and Refresh all MC buttons. As before, it is for Admins with a valid licence.
In the background. A Marketing Cloud refresh now runs as a background task, like the Salesforce one: close the window or move around the app and it keeps going. A banner shows progress with Cancel, Pause and Resume. Pausing keeps the business units already finished, and Resume only runs the rest.
The machine stays awake. A long Marketing Cloud refresh used to stop when the computer went to sleep. The app now keeps it awake while a refresh runs, and lets it sleep again when the refresh ends.
Salesforce field schemas are now a regular step of the Salesforce refresh, so a background or multi-org run produces them too. Before, only an interactive refresh did.
Reading Marketing Cloud: one door, still read-only
Until now, every kind of Marketing Cloud read (Data Extensions, queries, sends, and so on) was built into the application itself, so reading one more field meant shipping a new installer. The application now provides a single, generic read. The interface decides what to ask for, and improvements arrive with a normal app update.
The read stays read-only. The application only ever sends Marketing Cloud a retrieve request, so nothing can turn it into a create, update or delete. It checks object and field names before sending anything, and filters are limited to a fixed list of comparisons.
Upgrading
Install over the top; nothing to migrate. Marketing Cloud needs this installer: on 1.3.1 or earlier, Marketing Cloud screens say that the app needs updating. Everything else works on older installers as before.
1.3.1 a patch release
A patch release. One fix, for people whose company network routes traffic through a proxy — and a second one that matters to everybody, though nobody would have noticed it.
Publishing to S3 now works behind a corporate proxy
Sharing a folder to S3 failed on some corporate networks with a connection
error — ECONNRESET, or a timeout — while everything else in the app carried
on working normally. Disconnecting from the VPN made it work, which made it
look like a network fault rather than ours. It was ours.
Three parts of Stood Flows reach the network and, until now, they did not agree about proxies. The interface loads through Chromium, which follows the system proxy settings — including automatic configuration (PAC) files — by itself. The Salesforce calls go through the Salesforce CLI, which honours the standard proxy environment variables. The S3 calls went through the AWS SDK, which reads neither, and opened a direct connection no matter how the machine was configured. On a network that requires a proxy, the firewall closes that connection, so S3 — and only S3 — failed.
S3 now resolves the proxy the same way the rest of the app does, by asking the system. That covers PAC files, which is the case that matters most: on the networks where this was reported there is no proxy environment variable to read — the PAC file is the configuration. It also means a PAC that sends most traffic through a proxy while letting some destinations go direct is respected in both directions, rather than everything being forced down one route.
Nothing to configure. If your machine can reach the internet, the app now reaches S3 the same way.
Connection test. Folder settings → S3 → Test connection now names the proxy it went through when it used one, and a failure says which route was tried instead of reporting a bare connection error. If it still fails, that message is what to send us — it distinguishes a proxy problem from a firewall one, which are fixed by different people.
Not supported: SOCKS proxies, and proxies that require a username and password. Both are reported clearly rather than failing obscurely. Tell us if you need either.
Our test files are no longer inside the installer
The desktop build was compiling its own test files into the application bundle and shipping them. They did nothing — no code ran them — but they carried test fixtures, and some of those fixtures contained sample data taken from real orgs, including a customer name and identifiers.
They are excluded from the build as of this release. This affects every installer before 1.3.1.
Upgrading
Install over the top; nothing to migrate and no settings change. The proxy fix is in the application itself rather than the interface, so it arrives with the installer — updating the app is what picks it up.
1.3.0 Flows view and Visits
Salesforce org-analysis desktop app. Two months on from 1.2.8. This release adds two new analyses — Flows and Visits — turns the folder dashboard into something you can hand to someone, and makes a long full analysis something you can pause, resume and watch as it goes.
Highlights
Flows view — a new section
- Every active flow in the org, scored by step count and clustered by the object that triggers it. Two scopes, as in Apex: Backbone (the objects your processes run on) and Org-wide (everything).
- Runtime usage from Event Logs: how often each flow actually ran, how long it took, and how often it errored — so a heavy flow nobody triggers is visible as exactly that.
- Cold flows are listed separately: active, deployed, never executed in the analysed window.
- Process Builder is flagged in red. Salesforce stores those as flows, so they arrive looking like any other autolaunched flow. Support ended on 31 December 2025, which makes them migration candidates rather than ordinary flows.
Visits — what people actually look at (Licensing → Visits)
- The DML view can only report what a user wrote, and for a read-only population that is almost nothing. Visits reconstructs the other half: screens, navigation paths, session length and cadence, filterable by the DML category each user already falls into.
- It measures which UI event types your org emits and how much of the population each one can see, then uses only the ones that cover a real share. Classic, Lightning and portal-heavy orgs all work without configuration, and the coverage it measured is shown on every view.
- Aggregates only — no record ids, no URLs, no IP addresses are stored.
The folder dashboard, as a deliverable
- Cards per theme across every org in the folder, each with a removal or cleanup policy and the list of candidates behind it: processes untouched for 12 months, objects that are thin or idle, named users who have not logged in.
- ⭳ Export PDF — the whole dashboard, page by page, to a file you choose.
- It opens fast now. The dashboard is built from distilled per-version snapshots instead of re-reading the full version history, which took a cold open on a large folder from most of a minute to near-instant.
Full analysis: pause it, resume it, watch it
- Pause and Cancel are now two different buttons. Pause stops after the current analysis and keeps everything computed; Cancel stops and rolls back, exactly as before. Previously there was only one button and it was the destructive one.
- Resume picks a paused run up where it stopped, skipping the analyses that already finished — and the launcher now tells you honestly how many of them it can actually skip.
- A live clock on the running step. Some analyses report progress rarely; a clock is the difference between “still working” and “hung”.
- Preview the run while it runs. A full analysis commits one version, at the end — so for hours the screens showed pre-run data. You can now open the in-progress results from the version menu, clearly marked as not yet committed, and watch the KPIs fill in as each analysis lands.
- Complement, don’t redo. The launcher reads what the current version is actually missing and offers to tick only that, instead of a five-hour re-run for four analyses.
- Refresh a whole folder — every org in one batch, with a parallelism you choose.
- The Apex, Flows view and DML views refresh in place as their analyses land, instead of showing pre-run data until you navigate away and back.
Apex
- One status per class, with facets, replacing overlapping buckets that could each claim the same class.
- Cold code split into two lenses — by entry point and by verdict — so “unreachable” and “reachable but never run” stop being one pile.
- Orphan branches: whole clumps of classes that no static root reaches, as distinct from a single edgeless file.
- Sharing grants from Apex managed sharing, with test fixtures excluded.
- Per-org stacked bars showing active and cold code as parts of the total.
Licensing and DML
- DML by object and DML by package as separate views — your own data model in one, everything else in the other.
- Objects that took no DML at all are listed, with their volumes, so an unused object is visible rather than merely absent.
- Ghost records accounted for: records a stage column cannot explain are split into off-process, retired and unattributed instead of silently inflating a total.
- DML no longer needs a Licensing run first — it resolves its own users.
- A deactivation-policy chart on the licences card: what each org’s policy would actually free up.
SELA contracts
- A contract ⇄ org coverage funnel in the Mapping view — what is contracted, what is provisioned, what is used, and the gap.
- Read the mapping by product or by org, whichever question you have.
- Shared licence pools handled as pools rather than per-org lines.
- Business units come from a simple CSV of email and unit.
Sharing, roles and issues
- A folder’s sharing method (None / GitHub / S3) and your role (Admin or Contributor) are now explicit choices rather than something inferred.
- Issues move through three steps — Open → Qualified → Closed — and are reported that way on the dashboard.
- Issues sync both ways over S3, so two people can work the same list.
Getting from one analysis to another
- Drill-downs across analyses: click a number and land on the view that explains it, with a way back to where you came from.
- The process impact map opens from a KPI line as well as from the canvas.
Smaller on disk
- Historic versions, audit-trail days, Event-Log aggregates and the describe cache are all stored compressed. Large workspaces shrink substantially with no change in what you see.
Quality and fixes
- A deploy landing under a running app now says relaunch instead of failing with an unexplained module error.
- The licence key is masked in Settings — it is a credential.
- The KPI table sizes itself to the widest process, not to an object’s entire picklist, so one object with 80 statuses stops stretching every row.
- A renamed picklist value is no longer counted as two separate statuses.
- The audit timeline no longer hides behind a “no data yet” prompt when it has data.
- Deactivation policy measures days-without-login to the refresh date, not to today.
- The diagram exporter, which was never wired up to anything, has been removed.
For the functional definition of each KPI and complexity component, see the
in-repo docs/ guides and the Nuclino user documentation.
1.2.8 Apex rebuilt, S3 sharing, licensing deep-dives
Salesforce org-analysis desktop app. This release lands a large batch of new analysis capabilities plus the first team-sharing backend and a read-only Viewer role.
Highlights
Apex analysis — rebuilt end to end
- Always-on Apex section with two scopes from one place: Backbone (triggers → class dependency trees) and Org-wide (every class in the org).
- Org-wide class graph surfaces entry-point roots and orphans, built from real metadata dependencies.
- Canonical dependency tree: each class appears once at its shallowest position; extra edges are shown as compact badges — outgoing “shown elsewhere” (↗), cyclic back-edges (↺), and incoming in-degree (↑), each with a tooltip and a denominator so the numbers are self-explanatory.
- Source-based classification replaces the unreliable bulk SymbolTable, so the old “Unknown” bucket is gone and every class is classified. Class bodies are stored locally for offline review.
- Per-object Apex KPIs moved into the panel (triggers, dependency count, size per object); the old Apex column left the KPI table.
Team sharing over S3
- Publish / Refresh a folder’s graphs, versions, contracts and issues to an S3 (or S3-compatible: MinIO, Cloudflare R2…) bucket.
- Keyed by a single S3 folder — machines with differently-named local folders still share the same set. Credentials are encrypted in your OS keychain and never written into the workspace.
Admin / Viewer roles
- A folder with a valid licence key is an Admin; without one it’s a Viewer.
- Viewers get a clean, browse-only experience: every Salesforce-CLI, analysis and refresh action is hidden. Admins Publish; Viewers Refresh.
KPI table refinements
- Reordered sections (Volume → Usage → Objects → Complexity → Lifecycle) with the Total column pinned while scrolling.
- Activities now sit under Objects.
- Related-object ”+” markers you can click to fetch that object’s real volume on demand.
- Complexity drill-downs: click any complexity cell to see how the score is computed and open each contributing item (flow, trigger, validation/assignment rule) directly.
Multi-org KPI dashboard
- A standalone, folder-level dashboard (licence evolution over time, business-unit vs SKU allocation) across every org in the folder — no contract required.
Licensing additions
- Policy tab — deactivation-policy preview, ready-to-run
sfcommand, enforcement log, last-modified dates and CSV export. - Cohorts tab — login-behaviour cohorts (daily / weekly / monthly / quarterly active + infrequent) streamed from Login event logs.
- Credits tab — TenantUsageEntitlement snapshots with pro-rata gauges.
- SELA contract management — editable SKU pricing, coverage buckets, a CSV-driven business-unit model, and a licence-dynamics chart.
DML & I/O (Event Log) analysis
- DML heavy-consumer analysis and Inbound / Outbound I/O analysis built from Event Log Files, joined back to backbone objects.
Background global refresh
- A “Full analysis” orchestrator runs every analysis in the background, commits at the end, and rolls back cleanly on cancel.
System-of-Systems (SoS) diagram
- In-diagram lane and process reordering via ▲▼, plus connection status (active / planned / deprecated) and a connection list view.
Quality & fixes
- Field-level-security (FLS ⚠) warnings on volume cells; more accurate custom-object volume counts; version switch now shows the selected version’s own analyses; native Save As dialog for exports; audit-trail author info.
For the functional definition of each KPI and complexity component, see the
in-repo docs/ guides and the Nuclino user documentation.