Salesforce Permission Set Assignment Examples
Use these examples as a starting point when deciding which AlumnIQ Sync permission sets or permission set groups to assign in Salesforce.
These are generic role patterns. Your organization may require additional Salesforce permissions for local objects, fields, reports, automations, or constituent records that are not included in the AlumnIQ managed package.
Note
Start with the least access needed for the user’s job. The AlumnIQ permission set groups are a convenience for users who should have access across all AlumnIQ Sync modules. If a user only needs EMS records, assign the EMS-specific permission set instead of the broader group.
Quick reference
| Role | Assign | Purpose |
|---|---|---|
| Daily user of all AlumnIQ information | AlumnIQ User permission set group | View AlumnIQ data across all AlumnIQ Sync modules |
| Daily user of EMS information only | AlumnIQ EMS User permission set | View EMS/event-related AlumnIQ data only |
| AlumnIQ data manager for all modules | AlumnIQ Admin permission set group | Manage AlumnIQ records across all AlumnIQ Sync modules |
| AlumnIQ data manager for EMS only | AlumnIQ EMS Admin permission set | Manage EMS/event-related AlumnIQ records only |
| AlumnIQ system administrator | AlumnIQ System Admin permission set | Manage customer-controlled system-level AlumnIQ Sync settings |
| System user / integration user | AlumnIQ Sync Integration permission set + AlumnIQ Sync Integration Access customer-managed permission set | Run automated sync with scoped package and local-object access |
Daily user of AlumnIQ information
A daily user reviews AlumnIQ records in Salesforce as part of normal advancement, alumni relations, events, or reporting work. This user needs to see AlumnIQ records but should not normally edit records.
Assign one of the following:
- AlumnIQ User permission set group, when the user should have read-only access across all AlumnIQ Sync modules
- AlumnIQ EMS User permission set, when the user should only view EMS/event-related AlumnIQ records
Typical access:
- Read AlumnIQ Sync app records within the assigned module scope
- View events, activities, participants, gifts, mail activity, and related AlumnIQ records as available through the assigned permission set or group
- Use AlumnIQ records for reporting and day-to-day review
AlumnIQ data manager
An AlumnIQ data manager is a trusted staff member or Salesforce administrator who maintains AlumnIQ Sync records and supports operational cleanup or review. This role deals with AlumnIQ records, not system-level package configuration.
Assign one of the following:
- AlumnIQ Admin permission set group, when the user should manage records across all AlumnIQ Sync modules
- AlumnIQ EMS Admin permission set, when the user should only manage EMS/event-related AlumnIQ records
Typical access:
- Read and update AlumnIQ Sync app records within the assigned module scope
- Manage AlumnIQ package records used for operational support
- Support data review, correction, and cleanup workflows
AlumnIQ system administrator
An AlumnIQ system administrator is a trusted Salesforce administrator responsible for system-level AlumnIQ Sync configuration, such as customer-managed sync controls. This role is for managing package settings, not routine AlumnIQ “data” records.
Assign:
- AlumnIQ System Admin permission set
Typical access:
- Review and maintain customer-managed IQ System Config settings
- Manage customer-controlled sync settings, such as sync pause or disable controls
- Support configuration changes that affect AlumnIQ Sync behavior
System user / integration user
A system user is a dedicated Salesforce user used by the AlumnIQ integration. This should normally be a non-human account with the least access needed for automated sync activity.
Assign:
- AlumnIQ Sync Integration permission set
- AlumnIQ Sync Integration Access customer-managed permission set, or your organization’s equivalent customer-managed integration access permission set
Typical access:
- Read and write AlumnIQ Sync package records required by the integration
- Access local Salesforce objects and fields required for matching or synchronization, as granted by the customer-managed permission set
- Authenticate through the AlumnIQ External Client App using approved OAuth policy settings
Do not assign:
- Broad Salesforce administrative permissions that are not required for the integration