# Saelsforce leaver process deployment

**URL:** <https://developer.sailpoint.com/discuss/t/saelsforce-leaver-process-deployment/89012>\
**Category:** SHF Discussion and Questions\
**Tags:** connectors, identity-security-cloud\
**Created:** [November 8, 2024, 2:36pm UTC](https://developer.sailpoint.com/discuss/t/saelsforce-leaver-process-deployment/89012 "2024-11-08T14:36:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nandiniks](https://avatars.discourse-cdn.com/v4/letter/n/f6c823/32.png) [@nandiniks](https://developer.sailpoint.com/discuss/u/nandiniks)\
**Post date:** [November 8, 2024, 2:36pm UTC](https://developer.sailpoint.com/discuss/t/saelsforce-leaver-process-deployment/89012/1 "2024-11-08T14:36:33Z")

</div>

Hey everyone!  
I have a use case for our Salesforce connector I could use some advice on how to best try and figure out a solution. We are using the standard OOTB Salesforce connector.  
In Salesforce, we primarily use entitlements, Profiles (called groups in IDN) and PermissionSets and public groups and a custom attribute as entitlements.

Use case:  
When the user Lifecyclestatus changes from active to terminated/dormant , all his entitlements should be removed and his profile should be deactivated.

What could be the best approach to achieve this requirement.

---

<div class="post-metadata">

**Author:** ![mcheek](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/mcheek/32/23705_2.png) [@mcheek](https://developer.sailpoint.com/discuss/u/mcheek)\
**Post date:** [November 8, 2024, 2:56pm UTC](https://developer.sailpoint.com/discuss/t/saelsforce-leaver-process-deployment/89012/2 "2024-11-08T14:56:28Z")

</div>

I have linked an example below where someone has documented various workflows on how to remove ALL access from an identity on a leaver lifecycle state change.

In your case, you can take this example and adapt it to only remove entitlements for your SalesForce source

> [@Workflow to remove ALL leavers' standing access](https://developer.sailpoint.com/discuss/t/workflow-to-remove-all-leavers-standing-access/13025):
>
> Hi everyone, This workflow auto-revokes any standing access leavers have either through a micro targeted access certifications or by leveraging revoke access requests after being terminated. This should ensure that all leavers’ access is removed upon terminated and not just access assigned through birthright roles. Additionally, an audit trail is generated to document when and why the access was removed. This workflow was designed and built with the help and input of a multiple people! Thank…

---

<div class="post-metadata">

**Author:** ![mohammedfavazhrb](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/mohammedfavazhrb/32/16892_2.png) [@mohammedfavazhrb](https://developer.sailpoint.com/discuss/u/mohammedfavazhrb)\
**Post date:** [November 11, 2024, 2:25pm UTC](https://developer.sailpoint.com/discuss/t/saelsforce-leaver-process-deployment/89012/3 "2024-11-11T14:25:30Z")

</div>

Hi @nandiniks,

You can use SailPoint Roles to provide access to users for SF account. In Roles, you can add the lcs attribute as one of the conditions, so when lcs changes to terminated, the role will be removed and the corresponding entitlements will be removed from user’s SF account.  
One thing to be noted here is that, SF Profile cannot be removed from a SF account. So you will get error in tasks where sailpoint tries to remove the SF profile and fails. You can avoid that by using a before provisioning rule, in which you can check for this profile remove event (also check there is no profile add request in plan to make sure this event is not a sailpoint role change) and remove the profile removal request from the provisioning plan.  
Also if you need to provide the default portal user profile to the terminated users, you can also add that attribute request in the provisioning plan.

Thanks,  
Favaz

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [January 10, 2025, 2:26pm UTC](https://developer.sailpoint.com/discuss/t/saelsforce-leaver-process-deployment/89012/4 "2025-01-10T14:26:08Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
