Permissions Workbench
Compare and edit Salesforce permissions in one matrix
Put profiles and permission sets side by side, see every object and field grant in a single grid, stage changes across many of them at once, review the diff, and apply it as a background job, with Salesforce’s own dependency rules enforced as you click.
| Object | CollectionsProfile | AU Sales SupportProfile | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| C | R | E | D | VA | MA | C | R | E | D | VA | MA | |
| AIInsightReason | — | — | — | — | — | — | — | — | — | — | ||
| AIRecordInsight | — | — | — | — | — | |||||||
| AITrustAttribute | — | — | — | — | — | — | — | — | — | — | ||
| Account | — | — | — | |||||||||
| AccountBrand | — | — | — | — | — | — | — | — | — | — | ||
| AccountContactRelation | — | — | — | — | — | — | — | — | — | — | — | — |
| ActionPlan | — | — | — | — | — | — | — | — | — | — | ||
| ActionPlanTemplate | — | — | — | — | — | — | — | — | — | — | ||
| ActivationPlatform | — | — | — | — | — | — | — | — | — | — | ||
| ActivationPlatformActvAttr | — | — | — | — | — | — | — | — | — | — | ||
| ActivationPlatformField | — | — | — | — | — | — | — | — | — | — | ||
What you can do
- One matrix comparing many profiles and permission sets at once
- Object permissions (Create, Read, Edit, Delete, View All, Modify All) and field-level security in the same view
- Bulk-stage changes across multiple profiles and permission sets, then review before anything is written
- Salesforce’s dependency rules applied as you click — ticking Delete brings Read and Edit with it, so the save can’t be rejected
- Create a new permission set, optionally cloning every grant from an existing one
- Licence usage: which user and permission-set licences you hold and how many are consumed
- Applies as a background run with per-row results, so one rejected grant never discards the batch
- Profile system permissions, tab, and app visibility deploy through the Metadata API in the same run
How it works
Pick what to compare
Choose the profiles and permission sets you care about. They become columns in the matrix.
Stage your changes
Click through object CRUD and field-level security. Implied permissions come along automatically.
Review the diff
Every staged change is listed in plain language before you commit — nothing is written until you confirm.
Apply and watch
A background run writes the changes and reports per-row results. Rejections are itemised, not silent.
Why it's different
Bulk edits that respect Salesforce’s rules
Setup makes you edit one profile at a time and rejects saves that violate permission dependencies. The matrix stages changes across many at once, applies the dependency rules as you click, shows you the complete diff before committing, and writes through a client that may only ever touch permission records — object, field, and permission-set rows. A bug in the change builder physically cannot write to your business data.
Try asking
- Find out why two users with “the same access” behave differently
- Roll a new field out to six permission sets without six trips through Setup
- Strip Modify All from a profile that should never have had it
- Clone a permission set as the starting point for a new team
- Check licence consumption before promising someone a seat
Permissions Workbench — questions
Read next
- How to run a Salesforce security review: a 14-point checklist
Health Check gives you a score out of 100 and almost no idea what to do next. Here is the fourteen-area sweep that actually surfaces risk.
Put Permissions Workbench to work on your org
Every AI feature on your own provider key, from A$19.95 per user per month.
- 14-day free trial
- No credit card required
- Cancel any time