Home Salesforce Admin Salesforce Profiles vs Roles vs Permission Sets: What’s the Difference?
Salesforce Admin

Salesforce Profiles vs Roles vs Permission Sets: What’s the Difference?

Share
Share

If you are learning Salesforce administration, you will quickly come across three important concepts: Profiles, Roles, and Permission Sets.

At first, they can seem similar because all three are related to user access. But they solve different problems.

A simple way to remember them is:

  • Profile = What can the user do?
  • Role = What records can the user see?
  • Permission Set = What additional permissions does the user need?

Understanding this difference is important when designing Salesforce security and troubleshooting access issues.

What Is a Salesforce Profile?

A Profile defines the basic permissions and settings assigned to a Salesforce user.

Every Salesforce user must have a profile.

A profile can control things such as:

  • Object permissions
  • Field-level security
  • System permissions
  • App access
  • Tab visibility
  • Record type availability
  • Login hours
  • Login IP ranges
  • Page layout assignments

For example, suppose you have a Salesforce user who works as a Sales Representative.

Their profile might allow them to:

  • Read Accounts
  • Create and edit Contacts
  • Create Opportunities
  • View Leads
  • Run reports

But the same profile may prevent them from deleting Accounts.

Think of a Profile as the user’s baseline access

For example:

Sales Representative Profile

Can create and edit Opportunities, but cannot delete Opportunities.

The profile establishes the user’s basic permissions.


What Is a Salesforce Role?

A Role is mainly related to record visibility.

Roles are part of Salesforce’s role hierarchy and help determine which records users can access based on their position in the organization.

For example, imagine this hierarchy:

VP of Sales
    ↓
Sales Manager
    ↓
Sales Representative

If Salesforce’s sharing settings allow it, a Sales Manager can generally access records owned by users below them in the role hierarchy.

A role does not normally determine whether someone can create an Account or edit an Opportunity.

Instead, it helps determine which records they can access.

Example

Imagine two Sales Representatives:

  • John — West Region
  • Sarah — East Region

Both users might have exactly the same profile and permissions.

However, their record visibility can differ depending on the organization’s sharing model, role hierarchy, ownership, sharing rules, teams, and other sharing mechanisms.

Think of a Role as the user’s position in the record-sharing hierarchy

A simple way to remember it:

Profile = What can I do?
Role = Which records can I potentially see?


What Is a Permission Set?

A Permission Set is used to give users additional permissions without changing their profile.

This is especially useful when only some users need extra access.

For example, suppose you have 50 Sales Representatives.

All 50 users have the same Sales Representative profile.

But only five of them need permission to use a special Salesforce app.

Instead of creating a new profile just for those five users, you can create a Permission Set.

Sales Representative Profile
        +
Special App Permission Set
        ↓
Additional access

The user keeps their original profile while receiving the additional permissions from the Permission Set.

A user can also have multiple Permission Sets.

For example:

User
 ├── Sales Profile
 ├── Advanced Reporting Permission Set
 ├── Contract Management Permission Set
 └── Special App Permission Set

This makes Permission Sets very useful for flexible access management.


Profile vs Role vs Permission Set

Here is the easiest comparison:

FeatureProfileRolePermission Set
Main purposeBaseline permissionsRecord visibilityAdditional permissions
Required for userYesNoNo
Controls object permissionsYesNoYes
Controls field permissionsYesNoYes
Controls system permissionsYesNoYes
Controls record visibilityNot primarilyYesNo
Can be assigned to usersOne profileOne role or noneMultiple
Adds permissionsBaselineNoYes
Removes permissionsCan restrict baseline accessNoNo

The most important distinction is that Roles and Permissions are not interchangeable.


A Real-World Example

Let’s say a company has the following Salesforce users:

  • Sales Representative
  • Sales Manager
  • Sales Director

Step 1: Profile

All Sales Representatives could have a profile that allows them to:

  • Read Accounts
  • Create Contacts
  • Create Opportunities
  • Edit their Opportunities

This establishes their baseline permissions.

Step 2: Role

The Sales Representatives can then be placed below Sales Managers in the role hierarchy:

Sales Director
      ↓
Sales Manager
      ↓
Sales Representative

This helps Salesforce determine record access through the role hierarchy and sharing model.

Step 3: Permission Set

Suppose one Sales Representative needs access to a special forecasting application.

Instead of creating another profile, you could assign:

Sales Representative Profile
+
Sales Forecasting Permission Set

That user now has the additional permissions they need.


Why Should You Use Permission Sets?

Historically, Salesforce administrators often created multiple profiles to handle different access requirements.

This can become difficult to maintain.

Imagine having:

Sales Profile
Sales Profile - Reporting
Sales Profile - Advanced App
Sales Profile - Special Objects
Sales Profile - Regional Access

As your organization grows, managing these profiles can become complicated.

A better approach is often to keep profiles relatively simple and use Permission Sets or Permission Set Groups to provide additional access.

For example:

Sales Profile
     +
Reporting Permission Set
     +
Contract Permission Set
     +
Forecasting Permission Set

This follows a more modular approach to access management.


Can a Permission Set Remove Permissions?

This is an important point for Salesforce administrators.

Permission Sets are designed to grant additional access. They don’t work as a way to take away permissions already granted by a user’s profile.

For example:

If a user’s profile gives them permission to read an Account, assigning a Permission Set does not provide a normal mechanism to say:

“This Permission Set should remove Account Read access.”

Permission Sets are primarily additive.

So when troubleshooting access, always check the user’s profile and their assigned Permission Sets.


What About Permission Set Groups?

Salesforce also provides Permission Set Groups.

A Permission Set Group allows administrators to bundle multiple Permission Sets together.

For example:

Sales Operations Permission Set Group
    ├── Reporting Permission Set
    ├── Opportunity Management Permission Set
    └── Forecasting Permission Set

You can then assign the Permission Set Group to a user instead of assigning every Permission Set individually.

This can make permission management easier in larger organizations.


The Easiest Way to Remember the Difference

If you are preparing for a Salesforce Administrator or Developer interview, remember this:

Profile

“What can this user do?”

Defines the user’s baseline permissions.

Role

“Which records can this user access through the hierarchy?”

Helps determine record visibility.

Permission Set

“What extra permissions does this user need?”

Adds additional permissions without changing the user’s profile.


Common Salesforce Interview Question

Question: What is the difference between a Profile and a Permission Set?

Answer:

A Profile provides the user’s baseline permissions and every Salesforce user must have one. A Permission Set provides additional permissions to users without requiring a separate profile.


Question: Does a Role control object permissions?

Answer:

No. Object and field permissions are primarily controlled through Profiles and Permission Sets. Roles are primarily used as part of Salesforce’s record-sharing and visibility model.


Question: Can one user have multiple Permission Sets?

Answer:

Yes. A user can be assigned multiple Permission Sets, allowing administrators to provide different combinations of additional access.


Final Takeaway

Profiles, Roles, and Permission Sets each solve a different part of Salesforce security.

The easiest mental model is:

PROFILE
↓
Baseline access
"What can I do?"

ROLE
↓
Record visibility
"Which records can I see?"

PERMISSION SET
↓
Extra access
"What additional permissions do I need?"

Once you understand this distinction, Salesforce’s security model becomes much easier to understand.

For most modern Salesforce implementations, a good approach is to use profiles for baseline access and Permission Sets/Permission Set Groups for additional permissions, while using roles and Salesforce’s sharing model to manage record visibility.

In one sentence:

Profile defines baseline capabilities, Role influences record visibility, and Permission Set adds extra capabilities.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *