Security 101: Profiles vs Permission Sets, FLS, and Sharing

Strategy

  • Profile = baseline; Permission Sets = grants
  • Use Permission Set Groups per role; avoid custom profiles explosion

Steps to implement

  1. Inventory objects/fields and owners
  2. Define role hierarchy and OWD
  3. Create thin profiles (login hours/IPs, minimal perms)
  4. Add PS/PSGs for object/field perms and system perms

Sharing tools

  • Criteria‑based sharing, Teams, Manual sharing, Apex sharing for edge cases

Leave a Reply

Your email address will not be published.