User Access Policy - Future of Automation of User Access Management

User Access Policy - Future of Automation of User Access Management

Introduction

Salesforce introduced User Access Policies (Beta) feature with Summer'23 release.

Using this feature, you can automate your users’ assignments to managed package licenses, permission sets, and other access mechanisms based on criteria that you set. Create user access policies that automatically grant or remove access whenever users are created or updated. Or, easily migrate large sets of users to a new access setup in a single operation.

Use Case (Simplified)

Based upon user's profile and role, assign a PermissionSetGroup to give correct access and permissions to Sales Operation users.

  • Profile - Sales Ops Profile
  • Role - Sales Operation

No alt text provided for this image
Role Hierarchy








  • PermissionSetGroup - Sales Ops - PermissionSetGroup

No alt text provided for this image






Solution

  • Go to Setup >> Users >> User Management Settings and Enable?User Access Policies (Beta).

Enable User Access Policies (Beta)
Enable User Access Policies (Beta)

  • Go to Setup >> Users >>?User Access Policies?to create or manage your user access policies.

No alt text provided for this image
User Access Policies









  • Click on New and it will present a screen to setup a new user access policy

No alt text provided for this image
New User Access Policy

  • In the first section, under User Access Policy, enter following information. Detail about different options can be found here.

Label
API Name
Status
Trigger Type
No alt text provided for this image

  • In the second section, under Select Applicable Users, enter the filter criteria. In this case, filter criteria on the basis of Sales Ops profile and role as shown below.

No alt text provided for this image

  • In the third section, Select Additional User Field Filters, enter additional filters. For example, only for Active users in this case.

No alt text provided for this image

  • In the fourth and final section, Select Actions, enter the action. For example, assign/grant appropriate PermissionSetGroup as shown below.

No alt text provided for this image

Key Consideration

  • An action performed by a user access policy can’t trigger another user access policy.
  • You can have up to 20 active user access policies at a time.
  • If a user record creation or update triggers more than one user access policy, the most recently modified user access policy that matches the criteria is applied.

Detailed key considerations can be found here.

Stuart Hamilton

CEO, Ingenuity Partners. Experienced Technology Leader with a track record of building high-performing teams and driving business growth

1 年

Good info Diggy!

This could be a effort saver and would add more accuracy too, worth trying. Thank you for sharing Digamber Prasad ??

要查看或添加评论,请登录

Digamber Prasad的更多文章

社区洞察

其他会员也浏览了