Skip to main content
New tool CRON Expression Builder — preview next run times before you schedule Apex. Open the builder →
3D model of a complex digital lock representing the Salesforce permissions u-turn.
Admin

Salesforce Permissions U-Turn: Developer and Admin Reactions

Salesforce has canceled the planned retirement of permissions from profiles, and the community reaction was mostly a lack of surprise. Developers, architects and admins had plenty to say, and the move to permission sets is still worth finishing.

Key takeaways Salesforce has reversed its decision to retire permissions from Profiles, citing customer feedback and feature gaps. Many in the developer, architect, and admin communities are not surprised, viewing it as a complex rollout issue and a potential redirection of resources towards Agentforce. The principle of least privilege still holds, and permission sets and permission set groups are still the recommended approach for granular access control. Treat permission management as part of a broader security and governance strategy rather than a standalone compliance exercise. The immediate retirement is off, but the long-term goal of modernizing permission management is likely to persist.

Salesforce has canceled the planned retirement of permissions within Profiles. The retirement was set out on a January 2023 timeline and slated for a Spring '26 rollout, and it has now been reversed.

Salesforce said customer feedback and identified feature gaps were the primary drivers for the cancellation. The reaction across the wider community, from developers to technical architects to administrators, has been more mixed.

Community sentiment: not surprised

The most common response was a lack of surprise. Many read it as a characteristic Salesforce rollout, given the complexity of a change this widespread.

"Not surprised at all," commented Sanna Siltanen, a Salesforce Solution Architect. "It’s a big mess."

David Lanham, a Salesforce Admin, said much the same: "Not surprised at all! This is pretty typical for Salesforce rollouts. I would imagine this is related to both the on-the-ground reality that many orgs are just not ready for this sort of transition, along with internal resources being shifted towards Agentforce."

His advice to administrators is to carry on regardless: "As an admin, I would try to ignore this and still treat this as a migration from profile permissions to permission sets."

Skot Nelson, a Salesforce Solutions Architect and Lead, made the case for permission sets on their own merits: "Permission sets and groups are still better for object permission, especially when combined with user access policies."

Future implications and best practices

The discussion has already moved on to the long-term roadmap and the best next steps. Many think the immediate retirement is off while the underlying goal of better permission management stays on Salesforce's agenda.

Louise Lockie, a Salesforce MVP, said the retirement is probably still "on the (very) long-term roadmap." She explained, "It is a task which involves so many different departments contributing (or at least bringing their own areas in line) that it became a task too big for a time when (let's face it) 99.9% of SF's efforts are going into Agentforce."

Lockie also pointed out that the orgs that already moved are better off for it: "What hasn't changed though is that it is best practice, and that everyone who has made the change has a more secure and scalable data access model because of it."

The approach people keep repeating is "Permission set all the things." In practice that means configuring every permission you need through permission sets and permission set groups rather than relying solely on profiles.

Beech Horn, a Salesforce Technology Manager and Architect, elaborated on this: "Make everything available via a profile configurable elsewhere, then let us assign no profile to users and delete all our profiles in preparation. Also a great time to move from inconsistent metadata where, for instance, permission set XML files don't hold all permission set details."

Simon Whight, Director Analyst of Enterprise Apps at Gartner, read the decision as Salesforce acknowledging what its customers are up against:

"The challenge is that permission modernization is often difficult to justify as a standalone initiative. Profiles become deeply embedded across an org over many years, and transitioning to a more permission-set-centric model can require significant analysis, testing, and change management. For many enterprises, this can represent months of work with little immediately visible business impact, making it a difficult investment to prioritize against revenue-generating or transformational projects. In that context, extending the deadline appears to acknowledge the realities facing larger enterprises."

Prioritizing security

Whichever approach you take to permission management, the security question does not go away. Whight's view is that profile remediation belongs inside a broader platform security and governance strategy.

"In client conversations, security remains a consistent concern, but discussions tend to focus on broader strategic issues such as governance, risk management, AI readiness, and overall platform security posture rather than specific remediation activities around profiles and permissions," he noted. "Reducing access-related blast radius should continue to be a priority for organizations seeking to improve their security posture."

Salesforce's own guidance on the topic sits in its documentation, under the Shared Responsibility Model.

Originally reported by salesforceben.com

Newsletter

One email every Tuesday

New guides, tool updates, and the release-note changes that break things.

No spam. Unsubscribe in one click.

Comments

Loading comments...

Leave a Comment