Complete AI Training
Sign inGet my AI kit

Your job's AI kit

Get your AI kit

Tell us who you are and what you do. We show you your kit right away and email you the link: skills, prompts, AI agents, MCP servers and courses for your job.

500+ jobs ready, and we make a kit for any other job. No payment needed to look.

Share

AI agent for salesforce administrators

Permission Set Sprawl Cleanup Agent

Reduce permission sets and excess access without anyone losing access they need

Permission Set Sprawl Cleanup Agent: what goes in, what the agent does and what you get

What it does

Over the years profiles and permission sets pile up, and users keep access from old roles. This agent reads all assignments and recent usage: which permissions each user actually used in the last 90 days. It finds overlapping sets, sets with no users and users who hold access they never use. It proposes a consolidation: merge these three sets, retire those two, remove these permissions from those users. Before anything changes it simulates each user's access before and after and lists the differences, so nobody loses access they need. It repeats the simulation after revisions. The administrator approves each change. Edge case: a permission is unused for 90 days but is needed for year-end close, so the agent marks it as seasonal.

How it works

Follow the arrows from top to bottom. The orange dashed arrow is the loop: when a check fails, the agent goes back and tries again.

Start and resultWhat it doesA check on its own workWaits for your OKGoes back and retries
Yes, continueApprovedYes, continueNoNo 1 STARTS WHEN Quarterly review 2 USES A TOOL Read profiles, permission sets and assignments 3 USES A TOOL Read usage data for the last 90 days 4 DOES Find overlapping sets, empty sets and unused access 5 DOES Propose merges, retirements and removals 6 USES A TOOL Simulate every user's access before and after 7 CHECKS THE RESULT Does any user lose access they used or need? If not: revise the proposal to keep that access, andsimulate again. Back to step 4. 8 YOU APPROVE Administrator approves each change 9 USES A TOOL Apply changes in a sandbox, then production in smallgroups 10 CHECKS THE RESULT Do users in the first group report no lost accessafter a week? If not: restore the access and revise the proposal. Backto step 4. 11 RESULT Cleanup report with before and after counts
Read the steps as a list
  1. Quarterly review
  2. Read profiles, permission sets and assignments
  3. Read usage data for the last 90 days
  4. Find overlapping sets, empty sets and unused access
  5. Propose merges, retirements and removals
  6. Simulate every user's access before and after
  7. Does any user lose access they used or need?If not: revise the proposal to keep that access, and simulate again. Back to step 4.
  8. Administrator approves each changeThe agent waits here for your OK.
  9. Apply changes in a sandbox, then production in small groups
  10. Do users in the first group report no lost access after a week?If not: restore the access and revise the proposal. Back to step 4.
  11. Cleanup report with before and after counts

How it decides

It proposes merging sets with high overlap and removing access unused for the period, and it blocks any change that removes access a user needs.

  • Merge sets that overlap by more than 80%
  • Keep seasonal permissions on the seasonal list
  • Never remove access used in the last 90 days
  • Apply to production in groups of 10% of users

Make it yours

Every agent is a starting point. You choose these settings for your own situation.

  • Usage period (default 90 days)
  • Overlap level to merge (default 80%)
  • Seasonal permission list
  • Rollout group size (default 10%)
  • Review schedule

What keeps you in control

It always asks you first

  • Administrator approves each change
  • Security lead approves removal of admin-level access

Hard limits

  • Never remove access without a before-and-after simulation
  • Never touch admin-level permissions without the security lead

It stops when

  • Done: the set count is lower and no user lost needed access
  • Stop: roles are unclear and need an owner decision

Set it up

We guide you through the set-up, step by step

Members get the full set-up guide for this agent. No technical skills needed: you copy, paste and upload.

10 minto set it up in your AI
5 AIsChatGPT, Claude, Copilot, Gemini, Grok
  • One set of instructions to paste into your AI, with the clicks for ChatGPT, Claude, Microsoft 365 Copilot, Gemini and Grok
  • The agent then walks you through connecting your own data, one source at a time
  • A downloadable copy with the flow chart, the rules and the full guide
Get access to this agent

An example run

What happensThe org had 94 permission sets, 31 unused. The agent proposed merging 12 into 4 and retiring the 31. The simulation showed 6 finance users would lose a year-end report permission, which was unused for 90 days, so the check failed. The agent marked it as seasonal and kept it. The final plan cut sets to 51. After the first 10% group, nobody reported lost access.

More agents for salesforce administrators