I'm reading through Kevin White's "OS X Support Essentials" https://itunes.apple.com/us/book/apple-pro-training-series/id575890527?mt=11. Amazingly there's always something new to learn in those books.
In Lesson 13 he talks about using resetpassword in recovery boot to open the utility and reset home folder permissions. I did some digging and think I found the tool:
sudo /System/Library/PrivateFrameworks/Admin.framework/Versions/A/Resources/DirectoryTools -repairPermissions appleadmin
Now I can create a policy to fix System files and home folders.
