Sf rbp permission auditor
Skill SahirVhora/sf-agent-skills/skills/sf-rbp-permission-auditor
Use when you need to detect over-permissioned roles, hidden access paths, and sod risks before audit season.From its SKILL.md
npx -y skills add SahirVhora/sf-agent-skills --skill sf-rbp-permission-auditorAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its file declares
Copied from the file, not written here
The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
4.1 KB, 746 tokens by cl100k_base, as published. Nobody here has run it
RBP Permission Auditor
Audits SuccessFactors Role-Based Permissions across roles, groups, target populations, proxy settings, and sensitive admin grants. Flags excessive admin access, employee-data visibility beyond business need, toxic combinations such as compensation plus personal data export, and permission drift between sandbox and production. Produces a client-safe access-risk pack for HRIS, IT security, and audit stakeholders.
When to Use
- Detect over-permissioned roles, hidden access paths, and SoD risks before audit season.
- Client asks for an evidence-backed review in the Security area
- Preparing a workshop, release gate, audit pack, or remediation plan
- Converting raw SF configuration into a client-safe recommendation
Prerequisites
- Inputs: Role, group, target population, proxy, and permission export snapshots
- Expected outputs: Permission risk matrix, toxic-combination report, remediation plan, sign-off pack
- Confirm client audience and whether output should be board-level, technical, or mixed
- Never store credentials or employee-sensitive data in the repo or final deliverable
Workflow
- Inventory - gather evidence, classify impact, and create a client-safe output.
- Probe - gather evidence, classify impact, and create a client-safe output.
- Score - gather evidence, classify impact, and create a client-safe output.
- Remediate - gather evidence, classify impact, and create a client-safe output.
Analysis Checklist
- Confirm the configuration objects and source tenant/snapshot date
- Separate configuration evidence from assumptions
- Score findings by business impact, not just technical severity
- Group repeated findings into themes so the client gets a short action list
- Flag internal-only notes before writing the client-facing summary
- Produce remediation actions with owner, effort, dependency, and success metric
Edge Cases
- Dynamic groups with stale membership: validate explicitly before final recommendation
- Target populations that include terminated users: validate explicitly before final recommendation
- Proxy access bypassing normal manager visibility: validate explicitly before final recommendation
- Permission roles inherited through multiple groups: validate explicitly before final recommendation
- Emergency admin roles never removed: validate explicitly before final recommendation
- Country-specific data visibility exceptions: validate explicitly before final recommendation
Example Prompt
Audit our SF RBP setup and show which roles create access or segregation-of-duty risks.
Example Output Shape
126 permission roles reviewed. CRITICAL: 5, HIGH: 17. Top risk: HR Operations role grants export access to compensation and national ID fields for all employees, including countries outside support scope. Immediate action: split role by country and remove export permission pending DPO review.
Common Pitfalls
- Delivering raw technical noise: Summarise by business impact and put raw details in an appendix.
- Ignoring country or legal-entity variation: Many SF issues are only defects in one population.
- Missing downstream impact: Always map the finding to payroll, compliance, reporting, integration, or user experience.
- No rollback plan: Every remediation step needs a safe fallback.
- No validation step: Re-run the relevant check after fixing config and compare before/after evidence.
Verification Checklist
- Source evidence captured with tenant/snapshot date
- Findings scored by severity and business impact
- Edge cases reviewed explicitly
- Remediation actions include owner, effort, dependency, and success metric
- Client-safe summary produced
- Internal-only notes separated
- Follow-up validation plan included
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.