Profiles and Permissions

Get the benefits of expanded profile and permission management. Use the power of permission set groups to configure session-based access control. Create custom profiles using the API instead of cloning existing profiles.

  • Grant Access Based on Activated User Sessions for Permission Set Groups
    To grant your users only the access that they need when they need it, combine the management power of permission set groups with session-based access control. Create a session-based permission set group to grant access to permission sets during an activated user session. Previously, you created individual session-based permission sets, but now you can set sessions at the permission set group level as well.
  • Create Custom Profiles from Scratch via the SOAP API
    It’s easier to configure custom profiles to have the permissions you need. Use the Profile SOAP API object to create custom profiles that start without any permissions enabled. Previously, to create a custom profile, you cloned an existing profile in Setup and then removed permissions that you didn’t want the assigned users to have. The Profile Metadata API type functions as before.
  • Manage Assignment Expiration in Permission Sets and Permission Set Groups (Beta)
    You can now view and update current assignment expirations for your permission sets and your permission set groups. Previously, to update assignment expirations, you recreated them with the correct expiration date.
  • Grant Access to the DeveloperName Field to Users Who Require It
    The DeveloperName field has new permission requirements for multiple Salesforce objects and types across various APIs. Following the Winter ’22 release, some users can lose access to the DeveloperName field on objects that they typically interact with. To view, group, sort, or filter the DeveloperName field on affected API objects, you must have View Setup and Configuration OR View DeveloperName permission.

Profiles and Permissions (salesforce.com)