Essential SOPs, Part 2: User Management

This is the second post in our Essential SOPs for Salesforce Admins series, based on my session at Texas Dreamin'. Part 1 made the case for routine maintenance over reactive firefighting. Now we get practical.

Here's a scenario every admin knows: someone leaves the company. IT deactivates their email within the hour. Their Salesforce license? Still active three weeks later, along with their access to two connected apps nobody remembered they had.

Nobody did anything wrong, exactly. There just wasn't a routine.

User management is where I tell most admins to start, for two reasons. First, it's the most visible: licenses cost real money, and access gaps are real risk. Second, it's the easiest to turn into a rhythm. The tasks are concrete and the schedule is obvious.

Here's the full cadence: what to do monthly, quarterly, and annually.

Monthly: The Quick Checks

These tasks should take you under an hour once they're routine.

Active users vs. the departure list. Pull your active user list and check it against HR's list of departures. Every match is a former employee who can still log in, and probably still holds a license you're paying for. This is the single fastest check on this whole list, and it catches the exact gap from the scenario above before it becomes a three-week gap. If your org is small or turnover is low, quarterly may be enough, but monthly is cheap insurance.

License consumption and threshold tracking. Pull your active seat counts by license type and compare against what you own. You're watching for two things: creeping toward your limit (so an onboarding spike doesn't catch you flat-footed) and sitting well under it (so you have leverage at renewal instead of auto-renewing seats nobody uses). Keep a simple running log. Twelve months of data turns a renewal negotiation from a guess into a spreadsheet.

Quarterly: The Sweeps

The "stale user" and last-login sweep. Run a report of users who haven't logged in within 30 to 60 days. Then ask why. Some are on leave. Some changed roles and no longer need access. Some left the company and slipped through the cracks. Deactivate or downgrade accordingly. Every stale account is a license you're paying for and a door you're leaving unlocked, and this one report addresses both.

Manager and role attribute alignment. User metadata drifts. People get promoted, teams reorganize, and the "Manager" field on the user record quietly stops matching reality. That used to be a cosmetic problem. It isn't anymore: approval processes route based on that field, and automated workflows increasingly depend on it. A quarterly cleanup against your HR system's org chart keeps your automation making decisions based on the company you actually have.

Annually: The Deep Work

Once a year, block real time for the structural reviews.

Onboarding and offboarding procedure review. The monthly departure check catches individual misses; the annual review asks whether the process itself works. Walk through your onboarding and offboarding procedures end to end. When someone joins, how do they get provisioned, and who approves what? When someone leaves, how quickly does access come down across Salesforce, integrations, and connected apps? Are the steps documented, and does the handoff between HR, IT, and you actually happen the way the document says it does? If your monthly checks keep finding the same kind of miss, that's not a people problem. It's a procedure problem, and this is where you fix it.

The zero-trust audit. Once a year, audit your profiles, permission sets, and permission set groups. Inventory what each profile still grants, translate those grants into permission sets grouped by job function, and shrink profiles toward baseline defaults. A permission-set-led model is where Salesforce continues to invest, and it makes access easier to grant, revoke, and explain. But the real reason for this audit is the question at the heart of zero trust: does this person actually need this access, or did they just inherit it?

Hierarchy validation. Companies reorganize; role hierarchies lag. Once a year, put your role hierarchy, routing rules, and visibility model next to the current org design and reconcile them. If your territories changed in Q2 and your sharing rules didn't, someone is either seeing too much or too little, and both are problems.

License optimization. Go deeper than the monthly seat count: review which kind of license each user holds. Full Salesforce licenses often sit with users who only touch custom objects and would be fine on a Platform license at a fraction of the cost. Feature licenses get assigned for a project and never revoked. This is the review that reclaims real budget, and it's most powerful timed a quarter or two before your renewal.

Making It Stick

Three tips from Salesforce professionals who actually keep this cadence:

  1. Calendar it now. Recurring blocks: one hour monthly, half a day quarterly, a full day annually. If it's not on the calendar, it's a wish.

  2. Build the reports once.  The first month is setup; every month after is review.

  3. Log what you find. A simple running doc of what you checked and what you changed becomes your audit trail, your renewal ammunition, and your case for that headcount or tool you've been asking for.

And if the full cadence feels like too much? You know the rule of this series: pick one. If I'm choosing for you, start with the stale user sweep. It's one report, it saves money the first time you run it, and it builds the habit everything else hangs on.

What's Next

In the next post we tackle Data Management & Governance: backup strategy, the rotational audit approach that beats the annual data cleanup marathon, and the deduplication routines that keep your reports trustworthy.

Next
Next

Why Every Salesforce Admin Needs SOPs (And Why "I'll Get to It" Isn't a Strategy)