Remove guest user assignments from permission sets and require granular flow permissions for your guest users.
- Remove Guest User Assignments from Permission Sets Associated with Permission Set Licenses with Restricted Object Permissions (Release Update)
To improve the security of your data, Salesforce is removing guest user assignments from permission sets and permission set groups associated with permission set licenses that contain View All, Modify All, edit, and delete standard object permissions. You can no longer assign guest users permission sets or permission set groups that are associated with permission set licenses that contain the restricted permissions. The only standard object permissions allowed for guest users are read and create. This update was first available in Spring ’22 and is enforced in Winter ’23. - Require Granular Flow Permissions for Experience Cloud Guest Users (Release Update)
In Winter ’22, Salesforce discontinued the Run Flows permission for the Guest User profile in new orgs. The change improves site security by requiring explicit guest user permissions to run flows. Without the Run Flows permission, you’re free to use the more granular permission structure embedded in Flows and give your users the detailed access they need. In Spring ’23, Salesforce removes Run Flows from the Guest User profile in all orgs. To avoid future access issues, we recommend updating your sites to the new permission structure before Spring ’23. This update was first available in Summer ’22.