Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Salesforce Permission Set Assignment Examples

Use these examples as a starting point when deciding which AlumnIQ Sync permission sets or permission set groups to assign in Salesforce.

These are generic role patterns. Your organization may require additional Salesforce permissions for local objects, fields, reports, automations, or constituent records that are not included in the AlumnIQ managed package.

Note

Start with the least access needed for the user’s job. The AlumnIQ permission set groups are a convenience for users who should have access across all AlumnIQ Sync modules. If a user only needs EMS records, assign the EMS-specific permission set instead of the broader group.

Quick reference

RoleAssignPurpose
Daily user of all AlumnIQ informationAlumnIQ User permission set groupView AlumnIQ data across all AlumnIQ Sync modules
Daily user of EMS information onlyAlumnIQ EMS User permission setView EMS/event-related AlumnIQ data only
AlumnIQ data manager for all modulesAlumnIQ Admin permission set groupManage AlumnIQ records across all AlumnIQ Sync modules
AlumnIQ data manager for EMS onlyAlumnIQ EMS Admin permission setManage EMS/event-related AlumnIQ records only
AlumnIQ system administratorAlumnIQ System Admin permission setManage customer-controlled system-level AlumnIQ Sync settings
System user / integration userAlumnIQ Sync Integration permission set + AlumnIQ Sync Integration Access customer-managed permission setRun automated sync with scoped package and local-object access

Daily user of AlumnIQ information

A daily user reviews AlumnIQ records in Salesforce as part of normal advancement, alumni relations, events, or reporting work. This user needs to see AlumnIQ records but should not normally edit records.

Assign one of the following:

  • AlumnIQ User permission set group, when the user should have read-only access across all AlumnIQ Sync modules
  • AlumnIQ EMS User permission set, when the user should only view EMS/event-related AlumnIQ records

Typical access:

  • Read AlumnIQ Sync app records within the assigned module scope
  • View events, activities, participants, gifts, mail activity, and related AlumnIQ records as available through the assigned permission set or group
  • Use AlumnIQ records for reporting and day-to-day review

AlumnIQ data manager

An AlumnIQ data manager is a trusted staff member or Salesforce administrator who maintains AlumnIQ Sync records and supports operational cleanup or review. This role deals with AlumnIQ records, not system-level package configuration.

Assign one of the following:

  • AlumnIQ Admin permission set group, when the user should manage records across all AlumnIQ Sync modules
  • AlumnIQ EMS Admin permission set, when the user should only manage EMS/event-related AlumnIQ records

Typical access:

  • Read and update AlumnIQ Sync app records within the assigned module scope
  • Manage AlumnIQ package records used for operational support
  • Support data review, correction, and cleanup workflows

AlumnIQ system administrator

An AlumnIQ system administrator is a trusted Salesforce administrator responsible for system-level AlumnIQ Sync configuration, such as customer-managed sync controls. This role is for managing package settings, not routine AlumnIQ “data” records.

Assign:

  • AlumnIQ System Admin permission set

Typical access:

  • Review and maintain customer-managed IQ System Config settings
  • Manage customer-controlled sync settings, such as sync pause or disable controls
  • Support configuration changes that affect AlumnIQ Sync behavior

System user / integration user

A system user is a dedicated Salesforce user used by the AlumnIQ integration. This should normally be a non-human account with the least access needed for automated sync activity.

Assign:

  • AlumnIQ Sync Integration permission set
  • AlumnIQ Sync Integration Access customer-managed permission set, or your organization’s equivalent customer-managed integration access permission set

Typical access:

  • Read and write AlumnIQ Sync package records required by the integration
  • Access local Salesforce objects and fields required for matching or synchronization, as granted by the customer-managed permission set
  • Authenticate through the AlumnIQ External Client App using approved OAuth policy settings

Do not assign:

  • Broad Salesforce administrative permissions that are not required for the integration