Skip to main content

Profiles vs Permission Sets vs Permission Set Groups

Profiles vs Permission Sets vs Permission Set Groups

💬 In plain words:  A Profile is the base uniform every user wears — everyone has exactly one. Permission Sets are extra badges you pin on top for special access. Permission Set Groups are a ready-made bundle of badges. Modern rule: keep the profile minimal, give everything through badges.

Concept

A Profile is the mandatory 1-per-user baseline (login hours, IP ranges, page-layout assignment, default record types); Permission Sets are additive grants stacked on top; Permission Set Groups (PSGs) bundle permission sets into a user type, with Muting Permission Sets to subtract specific permissions from the bundle without editing its members. Salesforce's stated direction is the 'Minimum Access' profile plus user type-based PSGs — profiles are being progressively drained of permissions (EOL of permissions on profiles has been repeatedly signposted). This underpins Object/Field security (1.4) and interacts with licensing (1.3), since some permissions require a Permission Set License.

🧠 Access is a UNION:  Profile (1, baseline) + Permission Sets (additive) + PSG (bundle). Only MUTING subtracts — and only WITHIN its own group.

 

Profile

Permission Set

Perm Set Group

Per user

Exactly 1

Many

Many

Effect

Baseline

Additive

Bundle of sets

Subtract?

No

No

Yes (Muting)

Best for

Login policy, defaults

One capability

A user type

 

Core Q&A

Q: How would you design the permission model for a brand-new enterprise org today?

🎯 Say this first:  Minimal profile as the base, all real access through permission sets bundled into permission set groups per job function.

A: Start every user on the Minimum Access profile so the profile carries only what it must (login policy, defaults), and model access as user types: one Permission Set per capability (e.g., 'Manage Quotes', 'Run Lab Reports'), composed into Permission Set Groups per user type ('Sales Rep', 'Lab Supervisor'). Use Muting Permission Sets for the one-user type-minus-one-capability cases instead of cloning bundles. This gives you additive, auditable, reusable access where onboarding is 'assign one PSG', and it survives Salesforce's roadmap of retiring profile permissions. Govern it with a naming convention and a rule that no permission is granted in two places.

Follow-ups (scenario-based)

Q1: A permission appears in a Permission Set inside a PSG and is also muted in that PSG. A second standalone Permission Set assigned to the same user grants it too. What is the net access?

A1: The user HAS the permission. Muting only subtracts within the boundary of its own Permission Set Group — it cannot revoke a grant coming from outside the group (the standalone permission set, another PSG, or the profile). Access in Salesforce is a union of all grants; muting is the only subtractive mechanism and its scope is strictly intra-group. This is a classic trap question — the wrong answer is 'muting wins'.

Q2: In an org with 1,500+ users, how do you keep permissions maintainable — for example when business users need to configure a no-code approval app?

A2: User type-driven PSGs per implementation with a shared naming standard (APP_Persona_Capability), so an admin can audit access by reading assignment names; profile count stays in single digits. For the approval engine specifically, business users who configure approval rules get a dedicated 'Approval Config Author' permission set granting CRUD only on the config custom objects and nothing on transactional data. That separation is exactly why the engine could remove engineering as a bottleneck without becoming a security hole. Quantify it: onboarding a new business admin is one PSG assignment, zero profile changes.

Popular Posts

Must-listen songs for developers

Here are some must-listen songs for developers: "Strobe" by deadmau5 . This electronic dance music (EDM) track is perfect for getting into a flow state. The repetitive beat and simple melody are easy to focus on, and the overall mood of the song is upbeat and motivating.  "Viva la Vida" by Coldplay . This rock song has a soaring melody and powerful lyrics that can inspire you to stay focused and productive. The song's message of hope and resilience is perfect for those times when you're feeling stuck or discouraged.  "Code Monkey" by Jonathan Coulton . This tongue-in-cheek song is a hilarious and accurate portrayal of the life of a software developer. The lyrics are catchy and the song's upbeat tempo will make you want to get up and dance.  "The Sound of Silence" by Simon & Garfunkel . This classic folk song is perfect for those times when you need to focus and concentrate. The song's slow tempo and haunting melody will h...

Apex Test Class Examples for @HttpPost Exposed WebService Class

Introduction: In Salesforce, the Apex programming language allows you to create powerful web services that can be exposed to external systems for data integration. One common scenario is using the @HttpPost annotation to create a custom RESTful web service. In this blog post, we'll walk through some examples of how to write effective test classes for an @HttpPost exposed web service class in Salesforce. Writing comprehensive test classes ensures that your code is robust, functional, and ready for deployment.

Salesforce LWC Code for Multi-Select Lookup

Introduction: In Salesforce Lightning Web Components (LWC), implementing a multi-select lookup field can enhance the user experience and provide greater flexibility for selecting multiple related records. In this blog post, we will walk through the process of creating a multi-select lookup field using LWC. We will cover the required code snippets and provide step-by-step instructions to help you implement this functionality in your Salesforce org.

Uninstall all Windows 10 default apps using Powershell

Here is script to uninstall all windows 10 default modern apps. This script uninstalls xbox, xbox Game bar, Xbox App,Xbox Gaming Overlay, Get started etc from your computer. No need to run one by one commands Just copy below script, run  powershell as administrator and paste script and press enter . It will automatically uninstall all default programs.  If you do not  want to uninstall some apps than just remove " "  line from script. $packages = @( "7EE7776C.LinkedInforWindows" "C27EB4BA.DropboxOEM" "Microsoft.3DBuilder" "Microsoft.Microsoft3DViewer"

How to Save Quote PDF, Send PDF, Preview PDF in salesforce with custom functionality

Want to develop custom pdf viewer, save pdf in quote pdf related List and Send quote to customer on button click when quote is custom in salesforce . These functionality are standard from salesforce. but you can develop these functionality custom in salesforce. Here is the solution:- Custom button to save Quote PDF and send PDF  Step 1:-  First Create Two custom button. which will used for PDF preview and Save quote pdf in quotes pdf related list.                               1. PDF preview Button                              2. Save & Send Quote Button Replace "Your VF page here" to Your quote PDF cuatom page. Step 2:-  PDF preview button   pdf preview button will display the pdf's preview in standard format of salesforce. So you need to set the  following configuration (In picture). After that you have ...

Setup vs Non-Setup Objects (Mixed DML)

Core Platform & Fundamentals Module map MODULE 1 root: 'Who can do what, on which objects/fields?' ├─ Setup vs non-setup (transaction rules) ├─ Profile + Perm Sets + PSG (access = union) ├─ Licensing (the ceiling) ├─ CRUD/FLS (objects & fields) └─ Reports/Dashboards (who sees what data) 1.1 Setup vs Non-Setup Objects (Mixed DML) 💬 In plain words:   Salesforce keeps 'admin' records (like User, Group) and 'business' records (like Account, Case) in two separate rooms. One transaction cannot write to both rooms at once — that error is Mixed DML. The fix: do the second write in a separate async step. Concept

Unveiling the Power of Named Credentials in Salesforce with Comprehensive Code Examples

Introduction: Named Credentials are a powerful feature in Salesforce that allow you to securely authenticate and connect to external services and APIs without exposing sensitive information like usernames and passwords. In this blog post, we'll delve into the world of Named Credentials, understand their significance, and provide you with in-depth code examples to illustrate their implementation in various scenarios.