Skip to main content

Profiles

Profiles define baseline access in the Salesforce Platform. Every Cloudaware user has exactly one profile. The profile controls the user’s core app access, object permissions, field-level security, login policies, and other baseline settings.

Use profiles for stable baseline access. Add role-specific or temporary privileges with Permission Sets.

What A Profile Controls

Profiles typically control:

  • App access and high-level UI availability.
  • Object permissions, including create, read, update, and delete access.
  • Field-level security for visible and editable fields.
  • Record types, page layouts, and tab visibility.
  • Login policies, such as login hours and IP ranges.
  • Selected session settings, system permissions, and administrative capabilities, depending on your Salesforce org configuration.
note

Profiles do not replace record-level visibility controls. Record access is usually governed by organization-wide defaults, roles, role hierarchy, sharing rules, and other scoping mechanisms. See Scoping & Sharing.

  1. Keep the number of profiles small and stable.
  2. Make profiles minimal and use them only for baseline access.
  3. Add persona-specific access with Permission Sets.
  4. Align profiles to hard baselines (persona + license + login policy), or service-account requirements.
  5. Use scoping and sharing to separate what a user can do (RBAC) from which records a user can see (scope).

Cloudaware Baseline Profiles

Profile names may vary by org. Use the following as reference patterns:

  • Cloudaware Administrator: Administrative access for configuring Cloudaware, managing modules, and administering the Salesforce org.
  • Cloudaware Collector Only: Limited-access profile for integration, collector, or service accounts used for background ingestion.
  • Cloudaware Read-Only/Analyst: Read-only access for users who need to view dashboards, list views, reports, and CMDB records without modifying data.

Common Salesforce Profile Examples

Availability depends on your Salesforce edition, user license, and org configuration.

  • System Administrator (often mapped to Cloudaware as Cloudaware Administrator) — or administrators who need full access to configure and manage the org.
  • Standard User (CloudAware User) — for everyday business users (sales/ops) who need broad baseline access. Add permission sets for Cloudaware-specific workflows as needed.
  • Read Only — for users who need to view records and run reports without editing most data.
  • Minimum Access - Salesforce — for users who need a restricted baseline profile with access granted primarily through permission sets.
  • Sales User — for sales users who need access to sales objects and workflows, such as Leads, Accounts, Contacts, and Opportunities, as configured.
  • Service User — for support users who need access to service objects and workflows, such as Cases, as configured.
  • Chatter Free User — for collaboration-only users who do not need full CRM access.
  • Standard Platform One App User — for users who need access to one custom app plus core platform features.

For more details, refer to the Salesforce documentation on Profiles.

When To Create A New Profile

Create a new profile only when you need a different baseline that cannot be expressed cleanly with permission sets, for example:

  • A different user license, because profiles are tied to license types.
  • Different login hours, IP ranges, or session policies.
  • A fundamentally different baseline app or UI access model.
  • A separate baseline for human users and service accounts.

Otherwise, keep the existing profile and vary access with permission sets. Where supported, assign permission sets through IdP groups or automated provisioning.

Persona Mapping

Use the following mapping as a starting point. The access areas listed below describe typical job functions and should be matched to the appropriate Cloudaware/Salesforce permission sets in your environment.

  • Admins: CloudAware Administrator, plus module-level administrative access as needed.
  • Cloud engineers: Minimal baseline access, such as Standard User or Minimum Access - Salesforce, plus access required for CMDB operations, integrations and tagging workflows.
  • Security/GRC: Minimal baseline access, plus access required for compliance, evidence management, and reporting workflows.
  • FinOps: Minimal baseline access, plus access required for cost views, cost allocation mapping, and budget workflows.
  • Read-only stakeholders (executives/analysts): CloudAware Read‑Only' or 'Analyst access, plus reporting and dashboards access only.