Skip to content

By vendor exposure
Seats and permission sets

Permission set licences are where
the Salesforce bill hides.

Standard licences are the number everyone watches. Permission set licences stack on top of them, are assigned by an administrator in a hurry, and are almost never removed. Both are read from the vendor and matched against who actually signs in.

Answered on one platform. One data model across ITAM, SAM, SaaS, Cloud and AI.

Salesforce licence position

Illustrative

Org · production · authoritative vendor sync

Standard licences and permission set licences

Standard licences purchased
1,200
Assigned of which 291 have not signed in for 30+ days
1,184
Permission set licences assigned across 7 types, stacked on standard licences
2,460
Permission set licences unused assigned, never exercised
148
Departed users still assigned offboarding checklist open
31

Renewal

days-to-renewal with utilisation rate

The problem

Salesforce is priced per seat and consumed per permission.

The renewal conversation is about the seat count. The overspend is one layer below it, where nobody is looking.

46%

of SaaS licences go unused — the average organisation uses 54%

Salesforce is rarely the exception, and its permission set layer is rarely counted at all.

  1. 01 stacked and forgotten

    Permission set licences are added in minutes and removed never.

    They sit on top of the standard licence, each with its own cost, granted so somebody could try a feature during a project that finished two years ago.

    Connector sync pulling authoritative user and licence lists from the vendor SaaS Management

  2. 02 granted at onboarding

    Assignment is no evidence that anybody opened it.

    A licence assigned at onboarding and untouched since is indistinguishable from an active one on any report that counts assignments.

    Unused licence detection at 30+ days of zero usage SaaS Management

  3. 03 the quote writes itself

    The renewal arrives priced on last year’s number.

    Without a utilisation figure in hand before the negotiation opens, the only available position is to agree. Days-to-renewal without usage data is just a calendar reminder.

    Upcoming renewals with days-to-renewal and utilisation rate SaaS Management

  4. 04 leavers keep their seat

    Departed users are still holding licences, and the org still bills for them.

    Disabling the directory account does not release the Salesforce seat. Only an action at the vendor does, and only a per-licence status proves it happened.

    Offboarding checklist per user with per-licence revocation status SaaS Management

  5. None of this requires a negotiation. It requires knowing, before the renewal, which seats and which permission sets are doing nothing.
How it is actually done

How the Salesforce position is built.

Read both layers from the vendor, match them to sign-ins, act before the renewal window closes.

  1. Read both licence layers from the vendor

    Both layers read from the vendor’s own API on every sync, which is the only record that counts permission set licences per type and per user.

    • Connector sync pulling authoritative user and licence lists from the vendor SaaS Management
    • Identity provider sync from Entra ID and Okta including MFA enrolment SaaS Management
    • Subscription lifecycle with purchased, assigned, available and oversubscribed SaaS Management
  2. Match entitlement to behaviour

    Sign-ins, active usage rate and power users are the evidence a renewal negotiation runs on.

    • Usage Summary with Active Usage Rate and power-user identification SaaS Management
    • Unused licence detection at 30+ days of zero usage SaaS Management
    • Cost per licensed user versus cost per active user SaaS Management
  3. Act while the number can still change

    Six actions and a bulk wizard, with the saving recorded against the quarter it landed in.

    • Actions: reclaim, reassign, downgrade tier, archive, remind, dismiss SaaS Management
    • Upcoming renewals with days-to-renewal and utilisation rate SaaS Management
    • Bulk deprovision wizard for multi-select offboarding SaaS Management
    • Realized savings, realized avoidance and ROI by fiscal quarter SaaS Management
  4. Keep it closed

    Owners, budgets and offboarding, so the position does not drift back over a year.

    • Offboarding checklist per user with per-licence revocation status SaaS Management
    • Four owner types: application, business, technical and data owner SaaS Management
    • Per-application budgets with warning and critical thresholds SaaS Management
    • Audit log covering every provisioning and deprovisioning step SaaS Management

Ask to see any one of these running in the product itself, on the screen where it happens.

The licence model

The Salesforce licence model, term by term.

Two layers of licence, one bill, and a renewal date that arrives whether or not you have looked at either.

Standard licences

How the publisher counts The base seat every user needs, purchased in a block and rarely reduced.

What the engine does Purchased, assigned, available and oversubscribed counts read straight from the vendor.

Permission set licences

How the publisher counts Feature entitlement layered on top of the base seat, priced separately and assigned ad hoc.

What the engine does Read per type and per user through connector sync, then surfaced against actual usage.

Assignment versus usage

How the publisher counts Reports and bills both follow assignment; value follows sign-ins.

What the engine does Unused licence detection at 30+ days of zero usage, with Active Usage Rate and power-user identification.

Reclamation

How the publisher counts Removing a licence is a support ticket that never quite reaches the top of the queue.

What the engine does Reclaim, reassign, downgrade tier, archive, remind or dismiss, individually or in bulk.

Renewal

How the publisher counts The quote is written against last year’s seat count unless you supply a better number.

What the engine does Upcoming renewals with days-to-renewal and utilisation rate, plus cost per active user.

Leavers

How the publisher counts A disabled directory account does not release a vendor seat.

What the engine does Offboarding checklist with per-licence revocation status and a wasted spend figure attached.

Entitlement of record

How the publisher counts Salesforce is a publisher, and its contract belongs with the rest of them.

What the engine does One of six publishers with a dedicated engine in CerteroX SAM, with agreements and transactions held centrally.

Every capability in the right-hand column ships across CerteroX SaaS Management and CerteroX SAM.

The end state

What good looks like.

You walk into the renewal with a number the vendor cannot dispute, because it came from their API.

  1. 01

    Both layers are counted.

    Standard licences and permission set licences, per type and per user, read from the vendor on every sync, which is the only place the two layers are counted together.

  2. 02

    Usage is the unit of truth.

    Active usage rate and thirty-day idle detection decide what is reclaimed, so the seat count you renew reflects the seats being used.

  3. 03

    The renewal has a date and a figure.

    Days-to-renewal alongside utilisation rate, far enough ahead that reclamation can happen before the quote is written.

  4. 04

    Leavers release their seats.

    The offboarding checklist shows the Salesforce licence with a per-licence revocation status, so the seat returns to the pool instead of the invoice.

  5. 05

    The contract lives with the others.

    Salesforce is one of six publishers with a dedicated engine, so its agreements and transactions sit beside Microsoft, Oracle, IBM, SAP and Adobe.

Salesforce, specifically

Questions worth asking us.

Not the one you came with? Ask it directly and we will answer it in writing.

Why do permission set licences matter so much?

Because they are priced separately, assigned ad hoc, and almost never reviewed. A user can hold several on top of their standard licence, each granted for a project that has since finished. Reading them per type and per user from the vendor is the only reliable way to see the layer.

How do you tell an unused licence from a seasonal one?

Thirty days of zero usage is the trigger, not the verdict. Active Usage Rate, power-user identification and cost per active user give the context, and the available actions include remind and dismiss precisely because reclaim is not always the right answer.

Does this replace our Salesforce administrator?

No, it gives them the evidence and the bulk actions. Reclaim, reassign, downgrade tier, archive, remind or dismiss can be applied individually or across a multi-select, with an audit log of every provisioning and deprovisioning step behind it.

Is Salesforce handled as SaaS or as a publisher?

Both, deliberately. CerteroX SaaS Management holds the connector, the usage evidence and the reclamation actions. CerteroX SAM treats Salesforce as one of six publishers with a dedicated licence engine, so the agreement and entitlement record sits with Microsoft, Oracle, IBM, SAP and Adobe.

How far ahead of a renewal should we start?

Far enough that reclamation completes before the quote is written; a quarter is comfortable. The renewal view shows days-to-renewal against utilisation rate specifically so the conversation starts while the number can still be changed.

Salesforce, specifically

See the permission sets
nobody has ever opened.

Standard licences and permission set licences side by side, both matched against sign-in activity, with the reclaim action attached and the renewal date already on the calendar. Tell us your licence mix and the session is built around it.

There is nothing to connect. Bring your Salesforce administrator, who will ask the better questions.