Permissions Workbench
Compare and edit Salesforce permissions in one matrix
Put profiles and permission sets side by side, see every object and field grant in a single grid, stage changes across many of them at once, review the diff, and apply it as a background job — with Salesforce’s own dependency rules enforced as you click.
What you can do
- One matrix comparing many profiles and permission sets at once
- Object permissions (Create, Read, Edit, Delete, View All, Modify All) and field-level security in the same view
- Bulk-stage changes across multiple profiles and permission sets, then review before anything is written
- Salesforce’s dependency rules applied as you click — ticking Delete brings Read and Edit with it, so the save can’t be rejected
- Create a new permission set, optionally cloning every grant from an existing one
- Licence usage: which user and permission-set licences you hold and how many are consumed
- Applies as a background run with per-row results, so one rejected grant never discards the batch
- Profile system permissions, tab, and app visibility deploy through the Metadata API in the same run
How it works
Pick what to compare
Choose the profiles and permission sets you care about — they become columns in the matrix.
Stage your changes
Click through object CRUD and field-level security. Implied permissions come along automatically.
Review the diff
Every staged change is listed in plain language before you commit — nothing is written until you confirm.
Apply and watch
A background run writes the changes and reports per-row results. Rejections are itemised, not silent.
Why it's different
Bulk edits that respect Salesforce’s rules
Setup makes you edit one profile at a time and rejects saves that violate permission dependencies. The matrix stages changes across many at once, applies the dependency rules as you click, shows you the complete diff before committing, and writes through a client that may only ever touch permission records — object, field, and permission-set rows. A bug in the change builder physically cannot write to your business data.
Try asking
- Find out why two users with “the same access” behave differently
- Roll a new field out to six permission sets without six trips through Setup
- Strip Modify All from a profile that should never have had it
- Clone a permission set as the starting point for a new team
- Check licence consumption before promising someone a seat
Permissions Workbench — questions
Works even better with
Security Review
A 14-module org security audit — deterministic checks plus AI analysis — with severity-ranked findings, a coverage matrix, and exportable reports.
Learn moreMetadata Explorer
Your whole org, documented and searchable: objects, Apex, flows, permissions, and 50+ metadata types with an interactive relationship map.
Learn moreDevelopment Studio
An AI pair programmer that writes Apex, LWC, and Flows — then reads the real compile errors and test failures and fixes them.
Learn morePut Permissions Workbench to work on your org
Start free with the Metadata Explorer — every AI feature is free while the beta runs, and a competitive price is still being worked out.