Skip to main content

#Object Access0 discussing

I'm on a project that's at the beginning stages of building an Org that will ultimately have a large number of users whose access rights will vary greatly by user function/role.  

 

The current design is to use only 1 or 2 Profiles, and manage all of the access needs via Permission Sets and Public Groups.  Is this a recommended approach?  

 

My concern is that certain features which are dependent on Profiles - like Field-Level Security, Record Types, etc - don't support using Perm Sets and Pub Groups.  

 

Is there a best practice for determining how many Profiles an org needs, out of the gates, versus Perm Sets and Public Groups?    (FYI, the current design is to not use the OOTB Role Hierarchy either...in case that impacts this decision)  

 

Thanks, in advance!

 

#Best Practices  #Object Access  #Profiles  #Profile  #Best Practice  #Best Practices Advice  #Permission Set  #Service Cloud

4 answers
  1. Jul 10, 2025, 1:42 AM
    What did you ultimately decide? I’m in the same situation. Very customized record types I don’t need others to see. It’s just clutter in their view.
0/9000

Introducing BRAND 🔥  *NEW* 🔥  Getting Started with Security and Access

 (Feel Free to Download)

************************************************************************************************

Salesforce provides a flexible, layered data sharing design that allows you to expose different data sets to different sets of users, so users can do their job without seeing data they don't need to see. Use permission sets and profiles to specify the objects and fields users can access. Use organization-wide sharing settings, user roles, sharing rules to specify the individual records that users can view and edit.

 

***Be sure to Check Page 2 for our complete content catalogue. Join *Answers Connect* Group, Download the File👇 and keep blazing new trails!

 

Resource Included:

1. The Organization (Login Access, IP Restrictions) (Video)

2. Restrict Where and When User can Log In to Salesforce (Article)

3. Set Trusted IP Ranges for your Organization (Article)

4. Object Permissions (Article | Video)

  • ”View All” and “Modify All” Permissions Overview (Article)
  • Comparing Security Models (Article)
  • Field Permission (Article)

5. Profiles (Article)

  • Standard Profiles (Article)
  • Manage Profile Lists (Article)
  • Clone Profiles (Article)
  • Work in the Enhanced Profile User Interface Page (Article)
  • Work with Assigned Apps in the Enhanced Profile User Interface (Article)
  • Assign Record Type and Page Layouts in the Enhanced Profile User Interface (Article)
  • Edit Object Permissions in Profiles (Article)

6. Permission Sets (Article)

  • Create Permission Sets (Article)
  • Assign Permission Sets to a Single User (Article)
  • Standard Permission Sets (Article)
  • Use Permission Set Lists (Article)

7. Sharing Settings (Article)

  • Organization-Wide Defaults (Article)
  • Sharing Rules (Article)
  • Control Access Using Hierarchies (Article)

8. Field Level Security (Article)

  • Set Field Permission in Permission Sets and Profiles (Article)
  • Set Field-Level Security for a Single Field on All Profiles (Article)

Trailhead, and more…

6 comments
0/9000

I am the Salesforce Admin (the only one) and, for some reason, I no longer have access to any objects (Accounts, Contacts, Leads, Opportunities, etc). This happened out of the blue... How could that be ? #Sales Cloud #Object Access

7 answers
  1. Lakhan Meghani (NA) Forum Ambassador
    Aug 4, 2021, 7:01 PM

    Hi Chantal,

     

    It says that you don't have access of opportunity object.

    Are you sure you are system Administrator? If not please contact admin

     

    P S- Test the same in Salesforce classic. Also, try to create new opportunity and sew if you can access it after create. Sometimes deleted records show this error while accessing it

0/9000

Hi all, 

is there a simple way to know which rights have a profile on an object?

 

Suppose I have 1 object and 6 Profiles.

I want to know which rights have each profile on that object.

Is there a direct and simple way ora I have to loo into each profile?

 

tks

2 comments
0/9000

Hi All,

 

I cloned the system administrator profile and added a couple of users called 'guest user1' & 'guest user2'. guest user2  shouldn't access few standard and custom objects. How  I can achieve this? 

6 comments
  1. May 4, 2021, 8:27 PM
    I fixed the issue. As I copied the Administrative profile, somehow it was getting access to all objects. Now I cloned the standard profile and gave minimum access and followed the same steps did earlier. now I am able to hide standard object ex. Accounts. Thanks all for your inputs.
0/9000

Hello everyone,

 

This is my first post to anything Salesforce-related even though I've been an "Admin," for about 2 years now. I still consider myself very green. I will be on the Admin presentation later today, but here's the burning question I have at this point.

 

We use Salesforce in conjunction with a third-party vendor (Enrollment RX) to provide our application for admission. EVERY. TIME. Salesforce puts in new anything (generally security updates), the user profile permissions gets screwed up in a way that disallows our applicants from being able to do anything after they register for our portal. Whenever this happens, I have to contact the vendor who magically fixes the permissions, but my question is WHY does this need to change every time something new comes down the pike? It happens in our staging environment first, as well. It's so frustrating because it makes us dead in the water until the vendor can investigate and resolve the new security changes.

 

And yes, the vendor does have documentation on what to do to prepare for these changes, but we have such a unique instance of Salesforce, coupled with my inexperience of the "into-the-weeds," details about Salesforce in general, that the instructions largely make little sense to me. 

 

But the question remains: WHY do these changes happen EVERY release?! It's rather frustrating to keep up.

 

I know I'm asking a rather loaded question, and the answer probably is, "Depends," or something similar, but if there's a boiled-down answer, I would take that.

 

Thanks for "hearing" me out; I appreciate all you guys do and I'm trying to learn more so I don't need to ask questions like this in the future.

 

Christi Noyes

Pima Community College

Tucson, AZ

1 comment
  1. Jan 29, 2021, 3:35 PM

    Not a loaded question. It's because Salesforce is really locking down and double downing on Security, specifically when it comes to Guest Profiles, that's all.

    Salesforce does give a lot of warning when changes like this occur. First in the release notes, and preview sandboxes, before changes are made. These are also usually classified as Critical Updates as well, so you can turn them on in a sandbox before they auto activate to test for any adverse reactions.

    If you keep up with critical updates, and test them in a Sandbox environment before they are auto activated, it should minimize any downtimes.

0/9000

🎥 Learn how to how to grant users access to objects by using profiles.

 

Check out the video linked below ⬇️

Object Access

4 comments
0/9000
My Payment object (controlled by parent) with Opportunity. OWD on Opportunity is PUBLIC READ ONLY. I want all the fields on PAYMENT object READ ONLY except 2 fields which needs EDIT access. I gave EDIT access to those two fields at Field level for ABC Profile. Why user of ABC profile is unable to edit those two fields? Is it because of the Opportunity OWD setting as it is a controlling parent?
4 answers
  1. Jan 13, 2020, 12:50 PM

    Unfortunately, you can't set a separate sharing rule for Payments. It's related to Opportunity in a Master/Detail relationship. Therefore, access can't be set separate from its parent object.

0/9000

We are in audit mode and I need to run a report that shows the CRED access for all object and all profiles. I know this is a pain point for many admins and I'm hoping some awesome admins out there have figured this out.  I need to be able to export this to present to the auditors. I've looked at Workbench, but I don't see where it will let me pull just the object CRED, View All, and Modify All. We have a lot of objects, so creating a list view on the profiles and printing the view isn't efficient. Has anyone found a way to do this - preferably without purchasing a third-party app?

8 comments
0/9000