Configuration and Setup
This chapter covers how administrators manage users and control access in Salesforce, from profiles and permission sets to organization-wide defaults and company settings. Getting the access model right is the foundation of a secure, well-run org.
Profiles and permission sets
A profile defines a user's baseline object and field permissions, tab and app visibility, and system permissions. Permission sets grant additional permissions to specific users on top of their profile without changing the shared profile, which supports a least-privilege approach and keeps profiles lean. Every user has exactly one profile but can have many permission sets.
Record access and org-wide defaults
Organization-Wide Defaults set the baseline level of record access for each object. A Private default means users see only records they own until access is widened by the role hierarchy, sharing rules, manual sharing, or teams. This layered model starts restrictive and opens access deliberately rather than the reverse.
Administrative tools and company settings
Administrators configure company-wide settings such as default locale, currency, and business hours in Company Information and related Setup pages. When login access is granted, the Login As feature lets an admin experience Salesforce as a specific user to troubleshoot access issues. These tools support day-to-day org administration.