Profiles, Permission Sets, and Permission Set Groups Explained

A user needs access to one more object. Do you create a new profile or assign a Permission Set? The answer has a bigger impact than you might think.

 

I often see organizations trying to solve every access request by creating a new profile.

It works… until it doesn’t.

After a few years, the org ends up with dozens of profiles that are almost identical, making security difficult to understand and even harder to maintain.

 

Here’s a simple way to think about it:

 

Profiles

Every user needs one profile. It defines the baseline level of access, such as object permissions, page layouts, login hours, and other core settings.

 

Permission Sets

Permission Sets add access without changing the user’s profile. Need to grant temporary access to a custom object or a new app? A Permission Set is usually the right choice.

 

Permission Set Groups

When users regularly need the same combination of Permission Sets, group them together. This simplifies user administration and keeps security consistent across teams.

 

A good security model usually follows this pattern:

• Keep the number of profiles as small as possible.

• Use Permission Sets to grant additional access.

• Use Permission Set Groups for common job roles.

 

This approach makes it easier to onboard new users, respond to changing business requirements, and maintain your Salesforce org over time.

 

Salesforce has invested heavily in making Permission Sets and Permission Set Groups the recommended way to manage access. The fewer profiles you need to maintain, the more flexible your security model becomes.

 

Have you found that simplifying your profile strategy made your Salesforce org easier to manage, or are you still working through years of accumulated profiles?

 

SHARE:
Latest Posts