Skip to content

Glossary · Salesforce

Profiles and Permission Sets

Also known as: Permission set groups

Short answer

Profiles and permission sets control what Salesforce users can do. Every user has one profile that sets baseline access; permission sets and permission set groups add extra permissions on top. Salesforce now recommends minimal profiles with access granted mainly through permission sets.

Profiles and Permission Sets explained

A profile defines default settings such as page layouts, login hours and object permissions. Permission sets grant additional object, field, app and system permissions to specific users without creating a new profile for every role. Permission set groups bundle several permission sets into one assignable package, such as "Advisor" or "Client Service".

Orgs that have grown by cloning profiles often end up with dozens of near-identical profiles that nobody can audit. Moving to a permission-set model makes least-privilege access easier to prove to auditors.

How Vantage Point helps: we audit user access, consolidate profiles and rebuild access around permission set groups that map to real job roles.

Frequently asked questions

Should I create a new profile for each role?

Usually not. Keep a small number of minimal profiles and use permission set groups to grant role-specific access.

Do permission sets control which records a user sees?

No. Permission sets control what a user can do with objects and fields. Which records they can see is set by the sharing model: org-wide defaults, roles and sharing rules.

Last reviewed October 2, 2026 by the Vantage Point team. Browse all glossary terms →