Loading
Salesforce Enforces New Security Requirements in Summer 2026Read More
Manage Users and Data Access
Automatically Grant or Revoke Access with a User Access Policy

Automatically Grant or Revoke Access with a User Access Policy

Grant or revoke access for a specified set of users through a triggered event, such as a created or updated user record.

Required Editions

Available in: both Salesforce Classic (not available in all orgs) and Lightning Experience
Available in: Enterprise and Unlimited editions
User Permissions Needed
To modify user access policies: Manage User Access Policies

These instructions describe how to create user access policies that automatically run whenever qualified user records are created or updated. If you want to create user access policies that you run manually, such as for a user access migration or a one-time user access update, see Manually Grant or Revoke Access with a User Access Policy.

  1. From Setup, in the Quick Find box, enter User Management Settings, and then select User Management Settings. Make sure that both the User Access Policies and Enhanced Interface for User Access Policies settings are enabled.
    If Salesforce enabled user access policies for you before the Summer ’23 release, you must enable this feature again on the User Management Settings page.
  2. In the Quick Find box, enter User Access Policies, and then select User Access Policies.
  3. Click New User Access Policy.
  4. Enter a value for the Policy Name and Description. The API Name auto-populates.
  5. Add a value for the Order field. If a user meets the criteria for multiple active policies, the policy with the lowest order value is applied.
  6. Click Save.
  7. On the user access policy’s detail page, click Edit Criteria to configure the policy’s user criteria filters and actions.
  8. Under Define User Criteria, add at least one user criteria filter. Use the Equals operator for a single value and the In operator for multiple values. Policies are applied to users that meet all of the criteria filters. You can have:
    1. Up to 3 filters for applicable users
    2. Up to 10 filters on standard and custom user fields of type Checkbox, Number, Picklist, or Text
    3. Multiple roles or profiles referenced in the same filter using the In operator
  9. Under Define Actions, select Grant or Revoke from the Action picklist, then select the access mechanism that the action applies to. Access options are:
    1. Permission sets
    2. Permission set groups
    3. Permission set licenses
    4. Package licenses
    5. Public groups
    6. Queues
    User access policies support up to 20 actions.
  10. Save your changes.
  11. Click Automate Policy, then select when to trigger the policy:
    • The user access policy runs only when a user who matches the policy criteria is created.
    • The user access policy runs only when a user is updated to match the policy criteria.
    • The user access policy runs when a user who matches the policy criteria is either created or updated.
  12. Click Activate.
    After you automate the policy, the status changes to Active.

On the policy’s detail page under the Recent User Access Changes tab, you can monitor when this policy is applied and the affected users.

 
Loading
Salesforce Help | Article