{"title":"▶️ Profiles vs permissions vs roles","slug":"profiles-vs-permissions-vs-roles","url":"https://support.storeconnect.com/articles/profiles-vs-permissions-vs-roles","url_markdown":"https://support.storeconnect.com/articles/profiles-vs-permissions-vs-roles.md","subtitle":null,"summary":"Profiles set baseline access, permission sets grant additional capabilities, and roles control record visibility in a hierarchy. Each serves a distinct purpose in Salesforce security.","type":"Videos_Tutorials","video_url":"https://vimeo.com/1177143680?fl=sv\u0026fe=ci","keywords":null,"last_modified":"2026-08-21T07:12:35+0000","body_markdown":"### **Factory Analogy for Salesforce Access Control**\n\nLet’s imagine **Salesforce** as a **factory**, and the users are employees. You can assign each user three different things — **Profile**, **Permission**, and **Role** — each serving a **different purpose**.\n\n---\n\n### **Profile = Job Title**\n\n-   A **Profile** defines the **baseline functions** and capabilities a user has.\n\n-   It determines:\n\n    -   What **apps, objects, tabs**, and **system features** they can access.\n\n    -   Whether they can **create, read, edit, delete** records in general.\n\n-   Think of it like: \"*Factory Worker”* — they can enter the building, go to their station, and do their assigned job.\n\n\n**All users must have a profile.**\n\n---\n\n### **Permission = Keys**\n\n-   **Permissions** are like **extra keys** or access cards.\n\n-   They give **more specific or additional capabilities** beyond the profile.\n\n-   You manage these using **Permission Sets** or **Permission Set Groups**.\n\n-   Think of it like: *“Only the Supervisor has the key to the back storage room, even though they share the same profile as others.”*\n\n\n**Used to fine-tune access without changing the whole profile.**\n\n---\n\n### **Role = Visibility in the Org**\n\n-   A **Role** defines **who can see what** — i.e., **record-level access**.\n\n-   Roles are part of a **hierarchy**:\n\n    -   Users **higher up** the hierarchy can **see the data of users below** them.\n\n-   Think of it like: *“A Manager can see their own work and the work of all Factory Workers they manage.”*\n\n\n**Not about what you can do — but what you can **see**.**"}