If you are learning Salesforce administration, you will quickly come across three important concepts: Profiles, Roles, and Permission Sets.
At first, they can seem similar because all three are related to user access. But they solve different problems.
A simple way to remember them is:
- Profile = What can the user do?
- Role = What records can the user see?
- Permission Set = What additional permissions does the user need?
Understanding this difference is important when designing Salesforce security and troubleshooting access issues.
What Is a Salesforce Profile?
A Profile defines the basic permissions and settings assigned to a Salesforce user.
Every Salesforce user must have a profile.
A profile can control things such as:
- Object permissions
- Field-level security
- System permissions
- App access
- Tab visibility
- Record type availability
- Login hours
- Login IP ranges
- Page layout assignments
For example, suppose you have a Salesforce user who works as a Sales Representative.
Their profile might allow them to:
- Read Accounts
- Create and edit Contacts
- Create Opportunities
- View Leads
- Run reports
But the same profile may prevent them from deleting Accounts.
Think of a Profile as the user’s baseline access
For example:
Sales Representative Profile
Can create and edit Opportunities, but cannot delete Opportunities.
The profile establishes the user’s basic permissions.
What Is a Salesforce Role?
A Role is mainly related to record visibility.
Roles are part of Salesforce’s role hierarchy and help determine which records users can access based on their position in the organization.
For example, imagine this hierarchy:
VP of Sales
↓
Sales Manager
↓
Sales Representative
If Salesforce’s sharing settings allow it, a Sales Manager can generally access records owned by users below them in the role hierarchy.
A role does not normally determine whether someone can create an Account or edit an Opportunity.
Instead, it helps determine which records they can access.
Example
Imagine two Sales Representatives:
- John — West Region
- Sarah — East Region
Both users might have exactly the same profile and permissions.
However, their record visibility can differ depending on the organization’s sharing model, role hierarchy, ownership, sharing rules, teams, and other sharing mechanisms.
Think of a Role as the user’s position in the record-sharing hierarchy
A simple way to remember it:
Profile = What can I do?
Role = Which records can I potentially see?
What Is a Permission Set?
A Permission Set is used to give users additional permissions without changing their profile.
This is especially useful when only some users need extra access.
For example, suppose you have 50 Sales Representatives.
All 50 users have the same Sales Representative profile.
But only five of them need permission to use a special Salesforce app.
Instead of creating a new profile just for those five users, you can create a Permission Set.
Sales Representative Profile
+
Special App Permission Set
↓
Additional access
The user keeps their original profile while receiving the additional permissions from the Permission Set.
A user can also have multiple Permission Sets.
For example:
User
├── Sales Profile
├── Advanced Reporting Permission Set
├── Contract Management Permission Set
└── Special App Permission Set
This makes Permission Sets very useful for flexible access management.
Profile vs Role vs Permission Set
Here is the easiest comparison:
| Feature | Profile | Role | Permission Set |
|---|---|---|---|
| Main purpose | Baseline permissions | Record visibility | Additional permissions |
| Required for user | Yes | No | No |
| Controls object permissions | Yes | No | Yes |
| Controls field permissions | Yes | No | Yes |
| Controls system permissions | Yes | No | Yes |
| Controls record visibility | Not primarily | Yes | No |
| Can be assigned to users | One profile | One role or none | Multiple |
| Adds permissions | Baseline | No | Yes |
| Removes permissions | Can restrict baseline access | No | No |
The most important distinction is that Roles and Permissions are not interchangeable.
A Real-World Example
Let’s say a company has the following Salesforce users:
- Sales Representative
- Sales Manager
- Sales Director
Step 1: Profile
All Sales Representatives could have a profile that allows them to:
- Read Accounts
- Create Contacts
- Create Opportunities
- Edit their Opportunities
This establishes their baseline permissions.
Step 2: Role
The Sales Representatives can then be placed below Sales Managers in the role hierarchy:
Sales Director
↓
Sales Manager
↓
Sales Representative
This helps Salesforce determine record access through the role hierarchy and sharing model.
Step 3: Permission Set
Suppose one Sales Representative needs access to a special forecasting application.
Instead of creating another profile, you could assign:
Sales Representative Profile
+
Sales Forecasting Permission Set
That user now has the additional permissions they need.
Why Should You Use Permission Sets?
Historically, Salesforce administrators often created multiple profiles to handle different access requirements.
This can become difficult to maintain.
Imagine having:
Sales Profile
Sales Profile - Reporting
Sales Profile - Advanced App
Sales Profile - Special Objects
Sales Profile - Regional Access
As your organization grows, managing these profiles can become complicated.
A better approach is often to keep profiles relatively simple and use Permission Sets or Permission Set Groups to provide additional access.
For example:
Sales Profile
+
Reporting Permission Set
+
Contract Permission Set
+
Forecasting Permission Set
This follows a more modular approach to access management.
Can a Permission Set Remove Permissions?
This is an important point for Salesforce administrators.
Permission Sets are designed to grant additional access. They don’t work as a way to take away permissions already granted by a user’s profile.
For example:
If a user’s profile gives them permission to read an Account, assigning a Permission Set does not provide a normal mechanism to say:
“This Permission Set should remove Account Read access.”
Permission Sets are primarily additive.
So when troubleshooting access, always check the user’s profile and their assigned Permission Sets.
What About Permission Set Groups?
Salesforce also provides Permission Set Groups.
A Permission Set Group allows administrators to bundle multiple Permission Sets together.
For example:
Sales Operations Permission Set Group
├── Reporting Permission Set
├── Opportunity Management Permission Set
└── Forecasting Permission Set
You can then assign the Permission Set Group to a user instead of assigning every Permission Set individually.
This can make permission management easier in larger organizations.
The Easiest Way to Remember the Difference
If you are preparing for a Salesforce Administrator or Developer interview, remember this:
Profile
“What can this user do?”
Defines the user’s baseline permissions.
Role
“Which records can this user access through the hierarchy?”
Helps determine record visibility.
Permission Set
“What extra permissions does this user need?”
Adds additional permissions without changing the user’s profile.
Common Salesforce Interview Question
Question: What is the difference between a Profile and a Permission Set?
Answer:
A Profile provides the user’s baseline permissions and every Salesforce user must have one. A Permission Set provides additional permissions to users without requiring a separate profile.
Question: Does a Role control object permissions?
Answer:
No. Object and field permissions are primarily controlled through Profiles and Permission Sets. Roles are primarily used as part of Salesforce’s record-sharing and visibility model.
Question: Can one user have multiple Permission Sets?
Answer:
Yes. A user can be assigned multiple Permission Sets, allowing administrators to provide different combinations of additional access.
Final Takeaway
Profiles, Roles, and Permission Sets each solve a different part of Salesforce security.
The easiest mental model is:
PROFILE
↓
Baseline access
"What can I do?"
ROLE
↓
Record visibility
"Which records can I see?"
PERMISSION SET
↓
Extra access
"What additional permissions do I need?"
Once you understand this distinction, Salesforce’s security model becomes much easier to understand.
For most modern Salesforce implementations, a good approach is to use profiles for baseline access and Permission Sets/Permission Set Groups for additional permissions, while using roles and Salesforce’s sharing model to manage record visibility.
In one sentence:
Profile defines baseline capabilities, Role influences record visibility, and Permission Set adds extra capabilities.
Leave a comment