How do profiles, permission sets, permission set groups, and muting permission sets fit together in a modern design?
Suggested answer
The direction of travel is a minimal profile carrying only what genuinely has to live there — license, default record types, login hours and IP ranges, page layout assignment — with everything else delivered by permission sets.
1. Permission sets express a single capability, named after what it does rather than who gets it.
2. Permission set groups bundle sets into a job function so that onboarding is one assignment rather than fifteen.
3. Muting permission sets subtract specific permissions from a group's calculated result, which is the sanctioned way to handle "this team, but without Delete on Case" without duplicating the group or editing sets other groups depend on.
The behaviour to be clear about is that object and field permissions combine as a union across the profile and every assigned set. There is no precedence and no conflict resolution. That is why auditing a user's access means enumerating every assignment, and why muting exists at all.
The payoff is fewer profiles. Forty profiles that differ in small ways is a maintenance liability; four profiles and a well-named permission set library is not.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.