You are here:
Configure Delegated Access Automation
Automate the access delegation lifecycle with record-triggered flows and scheduled flows. The flows create delegated users and contact-contact relationships from access requests, keep request records in sync when proxy users sign up or are deactivated, and identify access delegation requests that require updates.
Required Editions
| Available in: Lightning Experience |
| Available in: Enterprise, Performance, Unlimited, and Developer Editions with Education Cloud |
| User Permissions Needed | |
|---|---|
| To configure flows: | Education Cloud Full Access permission set |
To configure record triggered and scheduled flows for delegated access:
-
Clone and activate the Create Delegated User and Contact-Contact Relation record-triggered
flow. If a contact exists with the email address that the student provided during proxy
onboarding, but doesn't have a user record, the flow creates a user record. The flow also
creates a contact-contact relationship if one doesn’t already exist.
- From Setup, in the Quick Find box, enter Flows, and then select Flows.
- Select Create Delegated User and Contact-Contact Relation.
- Click Save As New Flow.
- Enter a name and API name for the new flow.
- In the Create User element, configure the field values and conditions for creating a delegated user.
- In the Send Email to Delegated Contact element, configure the email body with the sign-up URL for the proxy portal to send a sign-up email to the specified email address.
- Save and activate the flow.
-
Clone and activate the Update Access Delegation Requests on Proxy Signup record-triggered
flow. The flow keeps access delegation requests in sync with the proxy user’s lifecycle. When a
proxy user signs up, the flow changes related requests with a status of Pending to New. When
the proxy user is deactivated, the flow changes related active requests to Revoke
Requested.
- From Setup, in the Quick Find box, enter Flows, and then select Flows.
- Select Update Access Delegation Requests on Proxy Signup.
- Click Save As New Flow.
- Enter a name and API name for the new flow.
- Save and activate the flow.
-
Clone and activate the Process Scheduled Access Delegation Requests Batch scheduled flow.
The flow identifies pending access delegation requests and updates proxy access based on the
latest request data. For example, if a student delegates access to grades, the flow shares all
records defined by the dataset. If new grade records are added after access is delegated, the
flow automatically detects and shares those records during its next scheduled run.
- From Setup, in the Quick Find box, enter Flows, and then select Flows.
- Select Process Scheduled Access Delegation Requests Batch.
- Click Save As New Flow.
- Enter a name and API name for the new flow.
- To process access delegation requests on a different schedule, edit the frequency in the Start element.
- Save and activate the flow.
-
Confirm the batch job that processes access delegation requests.
- From Setup, in the Quick Find box, enter Batch Management, and select Batch Management.
- Open, and if needed, customize Process Delegated Access Sharing.
- How Proxy Identity is Resolved For Delegated Access
When a student names a proxy, the proxy's first name, last name, and email address are matched with an existing contact and user record. If a contact record exists for the proxy, Salesforce uses the information. If no contact record exists, Salesforce sends a sign-up email. If Salesforce finds a user record for the proxy but no contact record exists, Salesforce sends a sign-up email to invite the proxy to create an Experience Cloud person account.
Did this article solve your issue?
Let us know so we can improve!
