← Salesforce Platform Administrator: configure and operate
01 / 8 · 40 MIN

Effective access and user lifecycle

Diagnose permissions, sharing, and login restrictions without unnecessarily broadening access.

Concept and mechanism

Analyze access in layers: entering the org, object operations, fields, and specific records. A layout organizes the experience but does not replace field-level security. Grants from profiles, permission sets, and groups can accumulate. Muting a capability in one group does not remove a grant still arriving from another source.

Guided application

Start by recording the authorized task and the identity performing it. Compare expected results with effective grants, OWD, and additional sharing. Keep a restrictive baseline and add only required access. When a role changes, review old assignments; when an employee leaves, resolve deactivation dependencies and use freezing when new logins must be prevented meanwhile. To investigate unexpected access, define an observable operation, such as reading a field or exporting a report. Record the result using the affected identity and compare every grant source before changing configuration. Change an identified cause and repeat positive and negative checks. Include the assignment purpose, review owner, and condition justifying future removal in the handover. This gives the next operator enough evidence to distinguish an intended grant from an accidental one.

IN PRACTICE

An analyst moves to reading reports without exporting them. The team mutes Export Reports in a group, but the profile still grants it. Testing still permits the operation. The correction identifies that source, preserves authorized reading, and validates both capabilities separately using the analyst’s realistic context. Evidence should show who retains each capability and why.

Common pitfalls

Do not confuse an org trusted network with a profile IP restriction. Check hours and time zones when shifts change. Avoid using an administrator session as the sole proof that an operator has appropriate access.

Related topics: Data model and Lightning experience · Leads, campaigns, and commercial follow-up · Cases, queues, and operational escalation

Take this idea with you

Start with the actual operation, identify every grant, and validate both permitted access and access that must be denied.

Create account

Reference: Control Access to Objects · Platform Administrator guide Summer 25