Salesforce has canceled the planned retirement of permissions within Profiles. The retirement was set out on a January 2023 timeline and slated for a Spring '26 rollout, and it has now been reversed.
Salesforce said customer feedback and identified feature gaps were the primary drivers for the cancellation. The reaction across the wider community, from developers to technical architects to administrators, has been more mixed.
Community sentiment: not surprised
The most common response was a lack of surprise. Many read it as a characteristic Salesforce rollout, given the complexity of a change this widespread.
"Not surprised at all," commented Sanna Siltanen, a Salesforce Solution Architect. "It’s a big mess."
David Lanham, a Salesforce Admin, said much the same: "Not surprised at all! This is pretty typical for Salesforce rollouts. I would imagine this is related to both the on-the-ground reality that many orgs are just not ready for this sort of transition, along with internal resources being shifted towards Agentforce."
His advice to administrators is to carry on regardless: "As an admin, I would try to ignore this and still treat this as a migration from profile permissions to permission sets."
Skot Nelson, a Salesforce Solutions Architect and Lead, made the case for permission sets on their own merits: "Permission sets and groups are still better for object permission, especially when combined with user access policies."
Future implications and best practices
The discussion has already moved on to the long-term roadmap and the best next steps. Many think the immediate retirement is off while the underlying goal of better permission management stays on Salesforce's agenda.
Louise Lockie, a Salesforce MVP, said the retirement is probably still "on the (very) long-term roadmap." She explained, "It is a task which involves so many different departments contributing (or at least bringing their own areas in line) that it became a task too big for a time when (let's face it) 99.9% of SF's efforts are going into Agentforce."
Lockie also pointed out that the orgs that already moved are better off for it: "What hasn't changed though is that it is best practice, and that everyone who has made the change has a more secure and scalable data access model because of it."
Recommended strategy: "Permission set all the things"
The approach people keep repeating is "Permission set all the things." In practice that means configuring every permission you need through permission sets and permission set groups rather than relying solely on profiles.
Beech Horn, a Salesforce Technology Manager and Architect, elaborated on this: "Make everything available via a profile configurable elsewhere, then let us assign no profile to users and delete all our profiles in preparation. Also a great time to move from inconsistent metadata where, for instance, permission set XML files don't hold all permission set details."
Simon Whight, Director Analyst of Enterprise Apps at Gartner, read the decision as Salesforce acknowledging what its customers are up against:
"The challenge is that permission modernization is often difficult to justify as a standalone initiative. Profiles become deeply embedded across an org over many years, and transitioning to a more permission-set-centric model can require significant analysis, testing, and change management. For many enterprises, this can represent months of work with little immediately visible business impact, making it a difficult investment to prioritize against revenue-generating or transformational projects. In that context, extending the deadline appears to acknowledge the realities facing larger enterprises."
Prioritizing security
Whichever approach you take to permission management, the security question does not go away. Whight's view is that profile remediation belongs inside a broader platform security and governance strategy.
"In client conversations, security remains a consistent concern, but discussions tend to focus on broader strategic issues such as governance, risk management, AI readiness, and overall platform security posture rather than specific remediation activities around profiles and permissions," he noted. "Reducing access-related blast radius should continue to be a priority for organizations seeking to improve their security posture."
Salesforce's own guidance on the topic sits in its documentation, under the Shared Responsibility Model.
Leave a Comment