As part of ongoing Salesforce work for [1], a full permission structure analysis was conducted using the Salesforce API and an AI assistant. Two documents were produced and shared with the client:
Both documents are stored in the shared drive under Projects > Salesforce.
Mark used the Salesforce API to pull all permission-related data from the Quarra org (profiles, permission sets, validation rules). The raw output was fed to an AI assistant, which:
The recommendation document was framed for the client as AI-generated suggestions — not Asymmetric mandates — to keep the conversation collaborative and avoid putting Lincoln on the defensive.
The most significant finding was that Lincoln Durham (Director of Sales) holds a System Administrator profile.
Risk: Admin access allows Lincoln to:
- Modify metadata
- Delete any record
- Change automation (flows, validation rules)
- Install packages
- Make org-wide configuration changes
One accidental click in Setup can break flows, validation rules, or field mappings across the entire org.
Recommendation: Downgrade Lincoln's profile from System Administrator to Core Executive.
A user named Jessica (Mark's daughter, added during initial setup) was identified as still active in the org. She should be deactivated.
The permissions export also surfaced existing validation rules, which don't strictly relate to permissions but are useful context for understanding org-wide restrictions.
When presenting these documents to Lincoln:
"You don't want him to think that we think he's going to break everything." — Mark