Short answer
Profiles and permission sets control what Salesforce users can do. Every user has one profile that sets baseline access; permission sets and permission set groups add extra permissions on top. Salesforce now recommends minimal profiles with access granted mainly through permission sets.
Profiles and Permission Sets explained
A profile defines default settings such as page layouts, login hours and object permissions. Permission sets grant additional object, field, app and system permissions to specific users without creating a new profile for every role. Permission set groups bundle several permission sets into one assignable package, such as "Advisor" or "Client Service".
Orgs that have grown by cloning profiles often end up with dozens of near-identical profiles that nobody can audit. Moving to a permission-set model makes least-privilege access easier to prove to auditors.
How Vantage Point helps: we audit user access, consolidate profiles and rebuild access around permission set groups that map to real job roles.
Frequently asked questions
Should I create a new profile for each role?
Usually not. Keep a small number of minimal profiles and use permission set groups to grant role-specific access.
Do permission sets control which records a user sees?
No. Permission sets control what a user can do with objects and fields. Which records they can see is set by the sharing model: org-wide defaults, roles and sharing rules.
