Menu

Frequently asked questions.

If you don't see your question here, get in touch — we usually reply within two business days.

Security & data

Does any user data leave Salesforce?
No. License Reclaim is a managed package that runs entirely inside your org. The only outbound traffic is the optional Slack/Teams notification webhook and the optional ITSM connector webhooks (which you configure and control). User records, login history, and audit logs never leave your Salesforce tenant.
What permissions does License Reclaim need?
A minimal permission set that grants read access to users, login history, and License Reclaim records, plus the write access needed for the freeze and deactivate actions. The package ships with a recommended permission set you can review before install.
How are manager approval links secured?
Each link is signed with a per-org SHA-256 HMAC, is single-use, and expires after a configurable window (default 72 hours). The signing key never leaves your org — it is generated on install, stored securely, and never displayed.
Is there a kill switch if something goes wrong?
Yes — a single Setup toggle halts every freeze, deactivation, and outbound email mid-cycle. Reactivate when ready; in-flight jobs check the flag before they touch a user account.

Setup & install

How long does install take?
About 5 minutes for the package install plus 15–30 minutes for first-policy configuration. Most orgs run their first dry-run scan within an hour of install.
Do we need professional services?
No. License Reclaim is built to be configured by a Salesforce admin without consultant help. The setup wizard walks through threshold selection, safety check toggles, and the first reclaim policy.
Does it work in sandboxes?
Yes — install the same package, point it at a sandbox, and run dry-run mode to validate the pipeline against production-shaped data without touching any user accounts.
Can we test against real users before flipping it on?
Yes. Dry-run mode runs the full pipeline — scans, safety checks, case creation, email simulation, ITSM ticket simulation — without changing any user account. You see exactly which seats would be touched.

ITSM integration

Which ITSM platforms are supported?
ServiceNow, Jira Service Management, Serval, and Freshservice. All four are covered by a single ITSM Connector Pack add-on — no per-platform licensing.
Can we use email approval and an ITSM ticket at the same time?
Yes — configure each reclaim policy independently. High-value teams can use ITSM tickets while seasonal workers use email approval. Or use both for the same policy to maintain a single record of decisions.
Our ticket system isn't one of the four. What do we do?
Reach out — the connector framework is platform-agnostic, and we add new providers based on customer demand. In the meantime, you can post a webhook URL to your own integration tier and bridge to your tool.
How are webhook callbacks verified?
Each provider uses its own signature scheme — HMAC-SHA256 for ServiceNow and Freshservice, signed JWT for Serval, IP allowlist + token for JSM Automation. License Reclaim verifies the signature before applying the decision.

Connected platforms & cleanup

Which SaaS platforms can License Reclaim harvest?
Nine: Asana, ClickUp, Monday.com, Wrike, Smartsheet, Airtable, Gong, DocuSign eSignature, and Outreach — the last two newly added. Each platform gets its own scan schedule, policies, and reversible actions (downgrade, deactivate, lock, or remove depending on the platform). Platforms are enabled individually for your install.
What happens to reports and dashboards owned by a deactivated user?
They keep existing but scheduled deliveries start failing silently. The Cleanup tab finds reports owned by or created by deactivated users, scheduled report subscriptions still naming them, and dashboards set to run as them — then reassigns or removes them in bulk. Every removal is written to the deactivation log, and an auto-cleanup toggle can run recipient removal on every scan.
Do platform scans respect manager approval and dry-run mode?
Yes. Platform policies support the same dry-run mode (no action taken in the external platform until you turn it off) and the same manager-approval email or ITSM flow before anything is touched externally.

Pricing & licensing

Is pricing per-user?
No. License Reclaim is priced per-org. Adding users to your Salesforce instance does not change what you pay.
Is there a free trial?
Yes — 30 days, no credit card. Request a claim code on the contact page and we'll email you the install URL plus a one-time activation token.
Are there discounts for non-profits or education?
Yes. Get in touch and we'll talk through the right tier and discount structure for your organization.

Operational

What happens if we hit a Salesforce governor limit during a scan?
Scans run in small batches that respect Salesforce platform limits. Large orgs (50k+ users) are processed across multiple runs with automatic retries — a failed run is retried and surfaced for review rather than silently skipped.
How are integration users protected from accidental reclaim?
Three layers: a per-policy exemption permission set, a username heuristic (usernames like integration@, api-, svc-), and an active-record-owner check (integration users typically own active records). System Administrator profile is a hard block — sysadmins are never auto-reclaimed.
How do we roll back a deactivation?
Each deactivation is logged in the deactivation log with the original user state. From the License Reclaim setup screen, a one-click reactivation restores the user and reverses the savings event.
Does License Reclaim work alongside our existing user lifecycle automation?
Yes. License Reclaim only acts on users that aren't already deactivated or frozen by other processes. If a manager-driven offboarding flow is already running for a user, License Reclaim respects that and skips them.

Still have questions?

Send us a note or book a 30-minute call — we'll walk you through anything we missed.