Most Salesforce orgs treat onboarding and offboarding as two unrelated problems, solved with two different sets of manual habits — and neither is well supported natively. The result is predictable: stale accounts nobody remembers to deactivate, permission sets nobody remembers to revoke, and zero audit trail when someone eventually asks "who approved this access, and when?"
AccessOps is RaptBot's answer to that gap — a single Lightning app that governs the entire user lifecycle, from the moment someone joins to the moment they leave, with a permanent record of every action taken along the way.
The Problem: Lifecycle Thinking Was Never Built In
Standard Salesforce administration wasn't designed around lifecycle thinking, and it shows:
- Onboarding a single user means navigating multiple Setup screens — profile, role, permissions, groups, queues — with no way to template or repeat the pattern.
- There's no native, safe offboarding workflow: transferring records, revoking access, and deactivating a user are three separate manual steps, easy to do out of order or skip entirely.
- Salesforce has no built-in mechanism for time-limited access — once granted, a permission stays granted until someone remembers to remove it.
- Inactive accounts, unused permission sets, and orphaned groups or queues accumulate silently, quietly wasting licenses and widening the org's security surface.
- Across all of this, there's no centralized audit trail — admin actions live in tribal memory, not in a system of record.
The User Journey: One Employee, Start to Finish
Follow one employee from their first day to their last, and everything HR and their manager needs to do in between.
| Stage | What happens | Who | Experience |
|---|---|---|---|
| Day One | HR picks the employee's role template | HR | 5 — Effortless |
| Everything they need is ready before they log in | Employee | 5 — Effortless | |
| Working Life | Joins a short-term project needing extra access | Manager | 4 — Smooth |
| Extra access expires automatically when the project ends | Manager | 5 — Effortless | |
| Takes leave, account is safely paused | HR | 4 — Smooth | |
| Returns, account picks back up instantly | Employee | 5 — Effortless | |
| Leaving the Business | HR starts the leaver process | HR | 3 — Some friction |
| Their work is handed to a teammate | HR | 4 — Smooth | |
| Access is fully switched off, nothing left behind | HR | 5 — Effortless | |
| A clean record of everything that happened is kept automatically | HR | 5 — Effortless |
Experience rating: 5 = effortless, 1 = blocked.
Behind that single journey sits a set of habits most businesses wish they had but rarely enforce: a repeatable onboarding checklist tied to each role, so nothing depends on memory; a guided leaver process so no account is ever half-closed; project access that turns itself off instead of relying on someone to remember; and a running housekeeping check that quietly flags dormant accounts and unused access before they turn into a security or licensing problem. Every one of those moments is captured automatically, so when someone later asks "who had access to what, and when," the answer is already on file.
Key Capabilities & Business Outcome
AccessOps' real-time dashboard — KPI tiles, onboarding trend charts, activity distribution, license utilization heat maps — turns lifecycle management from a reactive chore into something admins can actually monitor and forecast against.
Industry benchmarks from Peergenics' Salesforce Implementation Study point to roughly 65% process-time savings when manual Setup navigation is replaced by templated, single-form onboarding — which maps to RaptBot's own estimate of 60–75% faster user onboarding. Just as importantly, the audit trail and cleanup insights convert what used to be undocumented tribal knowledge into a defensible, reportable compliance record — a material difference the next time a security review or license audit comes around.
Start Where You Are: AccessOps MVP
Not every org needs the whole lifecycle on day one. A large share of the access work we see isn't internal seats at all — it's partners, dealers and distributors arriving through Experience Cloud, where a single missing link between a Contact, an Account and a portal license surfaces days later as a partner who simply can't log in.
AccessOps MVP is the focused edition built for exactly that work. Four tabs — Dashboard, Persona Mapping, User Management and Activity Logs — cover Partner Portal provisioning end to end. One dialog resolves the Contact and the Account (search an existing record or create a new one, with org-required fields surfaced inline) before the user is ever saved, only portal-compatible licenses appear in the dropdowns, and the profile list filters to the license you picked — so invalid combinations stop being reachable rather than failing at save. Offboarding runs the same guided four-step pass: find the user, transfer their Accounts, Opportunities, Leads, Cases and Contacts, optionally revoke access, then deactivate behind a confirmation. The search returns portal users only, so an internal account can't be deactivated by accident.
It ships as Salesforce DX source, so it lands through the same CLI and pipeline as the rest of your metadata, and the first deployment schedules its own housekeeping — a 30-day log retention default, nightly log cleanup at 2:00 AM and cleanup of revoked temporary access records at 1:00 AM. The scoping is deliberate: capabilities the full edition adds are absent from the MVP interface and documented as absent, rather than present and unreliable.
Two Editions — Pick the One That Matches Your Org
Both editions share the same underlying data model and the same audit trail. What differs is how much of the lifecycle is exposed in the interface:
AccessOps
The complete Salesforce user lifecycle — internal seats and portal users, onboarding through cleanup.
- Onboard internal, Experience Cloud or cloned users from one screen
- Time-limited access revoked automatically by a nightly job
- Freeze, unfreeze, reactivate and field-set-driven user edits
- Six cleanup surfaces for stale accounts and unused access
AccessOps MVP
Partner Portal provisioning and guided offboarding, deployed from source control.
- Four tabs: Dashboard, Persona Mapping, User Management, Activity Logs
- Contact, Account and partner enablement resolved in one dialog
- Portal-compatible licenses only, with profiles filtered to match
- Self-pruning audit trail, scheduled on the first deployment
Not sure which one? If most of the accounts you create are internal seats, start with AccessOps. If they're partner or community users, AccessOps MVP already covers the whole job — and because the objects and logs underneath are the same ones the full edition uses, stepping up later is a deployment rather than a data migration.
Each product page includes a walkthrough recorded in a live org — see AccessOps or AccessOps MVP in action, or reach out to consulting@raptbot.com.