Claude as Your Salesforce Admin Coach: Org Hygiene on Autopilot

A scheduled Claude job reads every Setup change in your org each week, catches misleading permission grants, and coaches your admins — automatically.

Claude as Your Salesforce Admin Coach: Org Hygiene on Autopilot

Last Thursday, a permission set called “Activate System Flows” appeared in a client’s org. Nothing about that name suggests trouble. What it actually granted — quietly, alongside the flow-related checkboxes — was View All Data: unrestricted read access to every record in an org that holds sensitive compensation data.

Nobody was up to anything. A capable team member who’s learning Salesforce administration needed to activate two flows he’d just built, hit a permissions wall, and checked boxes until the wall went away. Then he assigned the new permission set to himself and got back to work. That’s not negligence — it’s the default experience of Salesforce permissions. The platform makes granting easy and reviewing hard.

The reason I can tell you this story is that a scheduled Claude job caught it. Every Monday morning it reads the week’s Setup Audit Trail, checks what every touched permission set actually grants, and writes me a briefing. It flagged the grant, worked out why it happened, and named the single narrow permission the admin had really needed. My total effort: two minutes of reading with coffee.

The Challenge

Changes accumulate in every Salesforce org, every week — fields, flows, permission sets, user setup. In most organizations, nobody reviews them. The Setup Audit Trail records everything and explains nothing, so silent privilege grants sit unnoticed until an audit, an incident, or luck surfaces them.

The label describes the intent. The checkboxes describe reality.

Here’s the failure mode in one sentence: a permission set’s name is whatever its creator typed, and its actual grants are buried in a checklist of several hundred system permissions that nobody reads twice. I’ve now seen this same pattern three times across client work — a “Flows Run Permission” that carried View All Data, an “Email Log Files Admin” that carried Modify All Data, and last week’s example. In every case the person was solving a real problem and had no idea what came along for the ride.

This is exactly the kind of thing a periodic human review would catch — and exactly the kind of review that never survives contact with a busy calendar. Reading a thousand rows of audit log to find one dangerous checkbox is a terrible use of a person. It is a perfect use of Claude.

A permission set’s name is whatever its creator typed. Its grants are buried in checkboxes nobody reads twice. The review that catches the difference is the one that actually runs.

Eric Lovgren, lovgren.ai

The before and after

By now, plenty of teams use AI on the way in to Salesforce: drafting formulas, designing flows, building fields and automation with Claude assisting. That’s the “before,” and it’s a real accelerant — we build that way ourselves. But it covers only half the loop. The changes still land in the org unreviewed, whether they came from an AI-assisted admin, a consultant, or someone checking boxes at 6pm.

The “after” is pointing the same intelligence back at the org: Claude as a standing reviewer and coach. Not a linter shouting about naming conventions — a reader of your audit trail that knows what changed, what it affects, who did it, and what good practice looks like, and that tells you only what’s worth your attention.

What the weekly review does

The whole thing is one scheduled job, connected to the org through Salesforce’s MCP integration with read-only queries. Every Monday it runs four steps:

  1. Pull the week. Every Setup Audit Trail row from the last seven days — in a busy org, a thousand or more entries covering fields, flows, layouts, users, and permissions.
  2. Isolate what matters. Permission sets, profiles, field-level security, sharing, roles, user creation, MFA and identity settings, Apex — the changes that move data exposure or admin power.
  3. Check reality against the label. For every permission set assigned, created, or modified that week, query what it actually grants — View All Data, Modify All Data, Customize Application, Author Apex — and flag any mismatch between the name and the contents.
  4. Write the briefing. A bottom line, anything needing attention with the why, everything else rolled up in a paragraph, and concrete follow-ups. Sized to be read in two minutes.

~1,000

Audit rows reviewed

1

Silent View All Data grant caught

2 min

To read the digest

From an Actual Digest

“He created the permission set, enabled View All Data plus four other view-everything permissions, and self-assigned it two minutes later. Context suggests he was trying to activate the two flows he built that hour and checked boxes until it worked. The permission he actually needed is Manage Flow — none of the elevated grants are required. I’d strip View All Data from the set and walk him through why.”

Notice what that flag contains beyond the alarm: the diagnosis (what he was trying to do), the correct approach (the one narrow permission that solves it), and a teaching moment (walk him through reading the system-permission list before saving). The same digest also cleared his other permission set as well-scoped and summarized his week of legitimate build work in a sentence. That distinction — between risk and routine — is what makes it a coach rather than a cop, and it’s what makes a growing admin better instead of just supervised.

Key Insight

The review isn’t there to police your admins. It’s there to catch the well-intentioned mistakes Salesforce makes easy, explain the better approach, and leave a record of steadily improving practice — the feedback loop most orgs never had the staffing to run.


Where the built-in tools fall short

Salesforce ships tooling adjacent to this problem, and none of it solves it. The Setup Audit Trail captures every change faithfully — as a raw log you have to read yourself. Health Check scores your org’s baseline security settings, not what changed on Tuesday. Optimizer emits generic recommendations on its own schedule, with no knowledge of your business or your people. Event Monitoring adds richer data at added cost — and it’s still data, not judgment. Not one of them will cross-reference a permission set’s label against its actual grants, infer what its creator was attempting, or tell you the narrower permission that should have been used.

Built-in tools (Audit Trail, Health Check, Optimizer)Claude weekly review
Captures every setup change (as a raw log)
Tells you which changes matter
Checks what a permission set actually grants
Understands the intent behind a change
Suggests the narrower, better approach
Your effort per weekHours of log reading2 minutes

Why MCP is the unlock

This is one of the quiet advantages of connecting Claude to Salesforce through MCP. There’s no managed package to install, no AppExchange subscription, no code deployed into the org. The same connection that lets Claude help build your org lets it review your org — querying the audit trail and permission objects directly, on a schedule, and reporting back in plain language. Change what the review looks for by editing a paragraph of instructions, not a product backlog.

Pro Tip

Run the review connection read-only. The job’s value is judgment, not remediation — it flags, explains, and recommends, and a human makes every change. That keeps the reviewer trustworthy and the audit trail clean.

Org configuration hygiene and best practices — running on autopilot. The review costs nothing but the two minutes it takes to read, and the week it earns its keep, it really earns it.

Curious what a week of your audit trail would say?

If changes have been landing in your org faster than anyone reviews them, that’s normal — and fixable. Thirty minutes is enough to look at what a standing review would watch for in your org and what it would have caught already.

Talk to Eric

No Pitch, Just Possibilities.