Salesforce Cancels the “Permissions in Profiles” Retirement: What It Means for Admins and Architects

by Sudipta Deb | Jul 14, 2026 | Salesforce | 0 comments

Blog post highlighting all the cool but powerful new features that came along with the latest release of Gemini CLI.
Sudipta Deb

Sudipta Deb

Founder of Technical Potpourri, Co-Founder of Shrey Tech, Enterprise Cloud Architect

For the last few years, Salesforce administrators, architects, and security teams have been preparing for a major platform change: the retirement of permissions managed directly through Profiles. Salesforce had previously announced plans to move organizations toward a Permission Set–led security model, with enforcement expected to begin around the Spring ’26 timeframe.
However, Salesforce has now officially cancelled the planned enforcement, marking a significant shift in its security roadmap. According to Salesforce, the decision was driven by customer feedback and remaining feature gaps that made a full transition challenging for many organizations.

So, what happened, why does it matter, and what should organizations do next?

 

A Quick Refresher: The Original Plan

Back in 2023, Salesforce announced its intention to retire permissions stored within Profiles and encourage customers to adopt a Permission Set–centric security model. The vision was straightforward:

  • Profiles would handle baseline user settings.
  • Permission Sets and Permission Set Groups would manage access and permissions.
  • Organizations would gain a more flexible and scalable approach to security management.

The initiative aligned with Salesforce's broader security strategy and the industry's adoption of the Principle of Least Privilege, where users receive only the access they truly need.

What Changed?

Salesforce has now updated its guidance and confirmed that the retirement of permissions in Profiles has been cancelled. Profiles will continue to support permissions, and there is currently no mandatory end-of-life date for profile-based permissions.

According to Salesforce, two primary factors drove the decision:

1. Customer Feedback

Many customers expressed concerns about the complexity and effort required to migrate large, mature organizations away from profile-based permissions. Enterprises with hundreds or thousands of users often found the migration effort significant and time-consuming.

2. Remaining Feature Gaps

Salesforce acknowledged that some functionality and administrative experiences were not yet mature enough to support a seamless transition for every organization. As a result, enforcing the retirement could have created operational challenges for customers. 

What Does This Mean for Salesforce Customers?

At first glance, many admins may feel relieved.

The Good News

  • No immediate migration deadline.
  • Existing Profiles continue to work.
  • Organizations can avoid rushed security redesign projects.
  • Teams gain flexibility to prioritize other initiatives.

For organizations that delayed migration due to competing priorities, this announcement removes an important source of pressure.

The Reality Check

The cancellation does not mean that Salesforce has abandoned its preferred security model.

Salesforce continues to recommend a Permission Set–led approach and is continuing to invest in Permission Sets, Permission Set Groups, User Access Policies, and improved administrative tooling. Most new security enhancements are focused on these capabilities rather than Profiles

In other words, while the mandate is gone, the direction remains unchanged. 

Why Permission Sets Still Matter

Even without a forced retirement, Permission Sets remain the more scalable and maintainable approach for managing security.

Greater Flexibility

Permission Sets allow administrators to grant specific access without creating dozens of custom profiles. Instead of maintaining separate profiles for every role and exception, organizations can assemble access through reusable permission components.

Improved Governance

Permission Set Groups make it easier to align access with business roles such as:

  • Sales Representatives
  • Sales Managers
  • Service Agents
  • Business Analysts
  • System Administrators

This makes audits and compliance reviews significantly easier.

Better Alignment with Least Privilege

Modern security frameworks encourage granting only the minimum level of access required. Permission Sets provide more granular control than traditional profile-heavy designs. 

Salesforce's Recommended Future State

Although permissions can remain in Profiles, Salesforce recommends using Profiles primarily for baseline configuration such as:

  • Default apps
  • Default record types
  • Page layout assignments
  • Login hours
  • Login IP ranges
  • Password policies
  • Session settings

Access-related permissions should increasingly be managed through:

  • Permission Sets
  • Permission Set Groups
  • User Access Policies

This separation improves maintainability and supports future platform enhancements.

Recommended Actions for Admins and Architects

Rather than treating this announcement as a reason to stop modernization efforts, organizations should view it as an opportunity to move at a sustainable pace.

1. Don't Abandon Your Migration Strategy

If your organization has already started transitioning to Permission Sets, continue the journey. The work remains valuable and aligns with Salesforce best practices.

2. Conduct a Permissions Audit

Review:

  • Custom profiles
  • Object permissions
  • Field-level security
  • System permissions
  • User exceptions

Many organizations discover excessive access during these reviews. 

3. Adopt Permission Set Groups

Permission Set Groups simplify administration and reduce permission sprawl by bundling related permissions into reusable business-role packages.

4. Embrace Least-Privilege Security

Use this opportunity to ensure users receive only the permissions necessary to perform their job functions. This reduces risk while improving compliance readiness.

Final Thoughts

Salesforce's decision to cancel the retirement of permissions in Profiles is welcome news for organizations struggling with migration timelines and resource constraints. However, it should not be interpreted as a return to profile-centric security management. Salesforce has made it clear that Permission Sets remain the strategic direction for the platform and will continue receiving the majority of future investment.

The pressure of a mandatory deadline may be gone, but the business benefits of a Permission Set–led security model remain unchanged. Smart organizations will use this breathing room wisely: continuing to modernize their security architecture, improve governance, and prepare for whatever direction Salesforce takes next.

Bottom line: The retirement may be cancelled, but the shift toward Permission Sets is still the future.

Disclaimer

This article is not endorsed by Salesforce, Google, or any other company in any way. I shared my knowledge on this topic in this blog post. Please always refer to Official Documentation for the latest information.

0 Comments

Leave a Reply

Written by Sudipta Deb

Enterprise Cloud Architect, Content Creator, 20x Salesforce Certified, 1x Google Cloud Certified, 2x Copado Certified

Related Posts

New Apex Method | Extracting Picklist Values Based on Record Type Inside Apex

New Apex Method | Extracting Picklist Values Based on Record Type Inside Apex

For years, Salesforce developers have faced a common challenge: programmatically retrieving picklist values that are specific to a certain Record Type directly within Apex. The “solutions” often involved either complex SOQL queries against metadata, relying on the UI API (with its associated callout limits and serialization overhead), or maintaining clunky custom metadata/settings.

Good news, Technical Potpourri readers! The Salesforce Spring ’26 release is bringing a game-changer that will significantly simplify your Apex code and improve performance: native Apex methods to filter picklist values by Record Type!

read more...
Apex Cursor and Its Advantages Over Batch Processing

Apex Cursor and Its Advantages Over Batch Processing

Struggling with large datasets and SOQL governor limits in Salesforce? In this video, I will dive deep into Apex Cursors, the powerful new feature that revolutionizes how we process millions of records.

Apex Cursors allow developers to navigate through query results in manageable chunks within a single transaction or across Queueable jobs. In this video, I will show you the correct way to implement Apex Cursor and also when this is an exception, how to handle that and perform retry.

read more...

0 Comments

Leave a Reply