# ▶️ Profiles vs permissions vs roles

Source: https://support.storeconnect.com/articles/profiles-vs-permissions-vs-roles · Last modified 21 August 2026

Video: https://vimeo.com/1177143680?fl=sv&fe=ci

### **Factory Analogy for Salesforce Access Control**

Let’s imagine **Salesforce** as a **factory**, and the users are employees. You can assign each user three different things — **Profile**, **Permission**, and **Role** — each serving a **different purpose**.

---

### **Profile = Job Title**

-   A **Profile** defines the **baseline functions** and capabilities a user has.

-   It determines:

    -   What **apps, objects, tabs**, and **system features** they can access.

    -   Whether they can **create, read, edit, delete** records in general.

-   Think of it like: "*Factory Worker”* — they can enter the building, go to their station, and do their assigned job.


**All users must have a profile.**

---

### **Permission = Keys**

-   **Permissions** are like **extra keys** or access cards.

-   They give **more specific or additional capabilities** beyond the profile.

-   You manage these using **Permission Sets** or **Permission Set Groups**.

-   Think of it like: *“Only the Supervisor has the key to the back storage room, even though they share the same profile as others.”*


**Used to fine-tune access without changing the whole profile.**

---

### **Role = Visibility in the Org**

-   A **Role** defines **who can see what** — i.e., **record-level access**.

-   Roles are part of a **hierarchy**:

    -   Users **higher up** the hierarchy can **see the data of users below** them.

-   Think of it like: *“A Manager can see their own work and the work of all Factory Workers they manage.”*


**Not about what you can do — but what you can **see**.**

---

## Follow StoreConnect

- [Email Newsletter](https://getstoreconnect.com/c/lp-newsletter)
- [LinkedIn Newsletter](https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7444956928444862464)
- [YouTube](https://www.youtube.com/channel/UCngKdP2x8l1wcbAKW3tvU8g)
- [LinkedIn](https://www.linkedin.com/company/storeconnect)
- [X / Twitter](https://x.com/storeconnecthq)

## Popular Links

- [Partners](https://getstoreconnect.com/partners)
- [News](https://getstoreconnect.com/articles/news)
- [Events](https://getstoreconnect.com/articles/events)
- [Feature Comparison](https://getstoreconnect.com/how-we-compare)
- [Download a free trial](https://appexchange.salesforce.com/appxListingDetail?listingId=a0N3A00000FMkeKUAT)
- [Book a Demo](https://getstoreconnect.com/contact)

## Documentation

- [Help documentation](https://support.storeconnect.com/help-documentation)
- [AI agents](https://support.storeconnect.com/ai)
- [Videos & tutorials](https://support.storeconnect.com/videos-tutorials)
- [Developer reference](https://support.storeconnect.com/developer-reference)
- [Release notes](https://support.storeconnect.com/release-notes)
- [Troubleshooting](https://support.storeconnect.com/troubleshooting)
- [Trust Center](https://trust.getstoreconnect.com/)
- [Status Page](https://status.storeconnect.com/)

## Contact

- info@getstoreconnect.com
- US +1 415 745 3230
- AUS +61 2 8365 2308

100 S Ashley Dr, Suite 600-2461
Tampa FL 33602-600 USA

Level 22, Sydney Place
180 George Street
Sydney, NSW, 2000, AUS

---

StoreConnect Support — https://support.storeconnect.com/articles/profiles-vs-permissions-vs-roles