

Sudipta Deb
Founder of Technical Potpourri, Co-Founder of Shrey Tech, Enterprise Cloud Architect
So, what happened, why does it matter, and what should organizations do next?
A Quick Refresher: The Original Plan
Back in 2023, Salesforce announced its intention to retire permissions stored within Profiles and encourage customers to adopt a Permission Set–centric security model. The vision was straightforward:
- Profiles would handle baseline user settings.
- Permission Sets and Permission Set Groups would manage access and permissions.
- Organizations would gain a more flexible and scalable approach to security management.
The initiative aligned with Salesforce's broader security strategy and the industry's adoption of the Principle of Least Privilege, where users receive only the access they truly need.
What Changed?
Salesforce has now updated its guidance and confirmed that the retirement of permissions in Profiles has been cancelled. Profiles will continue to support permissions, and there is currently no mandatory end-of-life date for profile-based permissions.
1. Customer Feedback
Many customers expressed concerns about the complexity and effort required to migrate large, mature organizations away from profile-based permissions. Enterprises with hundreds or thousands of users often found the migration effort significant and time-consuming.
2. Remaining Feature Gaps
Salesforce acknowledged that some functionality and administrative experiences were not yet mature enough to support a seamless transition for every organization. As a result, enforcing the retirement could have created operational challenges for customers.
What Does This Mean for Salesforce Customers?
At first glance, many admins may feel relieved.
The Good News
- No immediate migration deadline.
- Existing Profiles continue to work.
- Organizations can avoid rushed security redesign projects.
- Teams gain flexibility to prioritize other initiatives.
For organizations that delayed migration due to competing priorities, this announcement removes an important source of pressure.
The Reality Check
The cancellation does not mean that Salesforce has abandoned its preferred security model.
Salesforce continues to recommend a Permission Set–led approach and is continuing to invest in Permission Sets, Permission Set Groups, User Access Policies, and improved administrative tooling. Most new security enhancements are focused on these capabilities rather than Profiles
In other words, while the mandate is gone, the direction remains unchanged.
Why Permission Sets Still Matter
Even without a forced retirement, Permission Sets remain the more scalable and maintainable approach for managing security.
Greater Flexibility
Permission Sets allow administrators to grant specific access without creating dozens of custom profiles. Instead of maintaining separate profiles for every role and exception, organizations can assemble access through reusable permission components.
Improved Governance
Permission Set Groups make it easier to align access with business roles such as:
- Sales Representatives
- Sales Managers
- Service Agents
- Business Analysts
- System Administrators
This makes audits and compliance reviews significantly easier.
Better Alignment with Least Privilege
Modern security frameworks encourage granting only the minimum level of access required. Permission Sets provide more granular control than traditional profile-heavy designs.
Salesforce's Recommended Future State
Although permissions can remain in Profiles, Salesforce recommends using Profiles primarily for baseline configuration such as:
- Default apps
- Default record types
- Page layout assignments
- Login hours
- Login IP ranges
- Password policies
- Session settings
Access-related permissions should increasingly be managed through:
- Permission Sets
- Permission Set Groups
- User Access Policies
This separation improves maintainability and supports future platform enhancements.
Recommended Actions for Admins and Architects
Rather than treating this announcement as a reason to stop modernization efforts, organizations should view it as an opportunity to move at a sustainable pace.
1. Don't Abandon Your Migration Strategy
If your organization has already started transitioning to Permission Sets, continue the journey. The work remains valuable and aligns with Salesforce best practices.
2. Conduct a Permissions Audit
Review:
- Custom profiles
- Object permissions
- Field-level security
- System permissions
- User exceptions
Many organizations discover excessive access during these reviews.
3. Adopt Permission Set Groups
Permission Set Groups simplify administration and reduce permission sprawl by bundling related permissions into reusable business-role packages.
4. Embrace Least-Privilege Security
Use this opportunity to ensure users receive only the permissions necessary to perform their job functions. This reduces risk while improving compliance readiness.
Final Thoughts
Salesforce's decision to cancel the retirement of permissions in Profiles is welcome news for organizations struggling with migration timelines and resource constraints. However, it should not be interpreted as a return to profile-centric security management. Salesforce has made it clear that Permission Sets remain the strategic direction for the platform and will continue receiving the majority of future investment.
The pressure of a mandatory deadline may be gone, but the business benefits of a Permission Set–led security model remain unchanged. Smart organizations will use this breathing room wisely: continuing to modernize their security architecture, improve governance, and prepare for whatever direction Salesforce takes next.
Bottom line: The retirement may be cancelled, but the shift toward Permission Sets is still the future.
Disclaimer
This article is not endorsed by Salesforce, Google, or any other company in any way. I shared my knowledge on this topic in this blog post. Please always refer to Official Documentation for the latest information.



0 Comments