Security for the AlumnIQ Sync For Salesforce App
Tip
July 2025: Find AlumnIQ Sync on the Salesforce AppExchange!
The AlumnIQ Sync App uses packaged permission set groups, packaged permission sets, a customer-managed integration permission set, and an External Client App to keep access scoped to the right users.
For common role-based assignment patterns, see Permission Set Assignment Examples.
Managed Permission Set Groups
- AlumnIQ Admin Provides comprehensive read and write access to AlumnIQ custom objects for administrative users. Assign this group with caution.
- AlumnIQ User Provides read-only access to the AlumnIQ App and its records for users who need to view data without making modifications.
Managed Permission Sets
-
AlumnIQ EMS Admin This permission set will generally not be directly assigned; use the AlumnIQ Admin group instead. Provides comprehensive read and write access to AlumnIQ custom objects.
-
AlumnIQ EMS User This permission set will generally not be directly assigned; use the AlumnIQ User group instead. Provides read-only access to the AlumnIQ App and its records.
-
AlumnIQ System Admin Provides admin access to the IQ System Config object for customer-managed AlumnIQ package settings, including the ability to read and edit customer-managed configuration values. This permission set is intended for trusted Salesforce administrators who are allowed to maintain customer-controlled AlumnIQ Sync settings, such as sync pause/disable controls. It does not grant create or delete access to IQ System Config records, and system-managed records remain restricted.
-
AlumnIQ Sync Integration Grants full read/write access needed by the AlumnIQ integration user for AlumnIQ custom objects and system-managed sync operations. It is intended to be assigned to a single dedicated integration user. Use caution when assigning this permission set because it is used with the External Client App to authorize data synchronization into your org.
Customer Managed Permission Sets
- AlumnIQ Sync Integration Access
This permission set grants access to non-AlumnIQ managed objects in your org. You can name the permission set according to your standards; however, we recommend
AlumnIQ Sync Integration Accessfor consistency and clarity. It is intended to be assigned to the single user designated as the integration user, and it is also used by the External Client App authorization policy. See Customer Managed Permission Sets for more information and setup steps. If there are permission issues with the integration, this permission set is the most likely place to check for missing object or field assignments.
External Client App
The AlumnIQ Sync App includes an External Client App configured for OAuth authentication using the JWT (JSON Web Token) bearer flow. This lets the external app authenticate as a specific integration user without sharing user credentials directly.
Configure the OAuth Policies so Permitted Users is set to Admin approved users are pre-authorized. Select only the permission set intended for integration authorization, normally AlumnIQ Sync Integration Access.