You are here:
Permission Set Groups from Managed Packages
Partners can organize permissions into permission set groups to include in managed packages. Understand how to work with permission set groups installed from managed packages.
Required Editions
| Available in: both Salesforce Classic (not available in all orgs) and Lightning Experience |
| Available in: Contact Manager, Group, Essentials, Professional, Enterprise, Performance, Unlimited, Developer, and Database.com Editions |
Keep these considerations in mind when working with permission set groups installed from managed packages:
- To install or uninstall a package with permission set groups, a subscriber must have permission set groups enabled.
- Permission set groups installed from managed packages don’t count against the maximum number of groups created. The limit on the number of created and installed permission set groups varies by edition.
- Certain Salesforce editions don’t allow you to create or customize permission set groups. In these instances, permission set groups from managed packages can be installed and used.
- A permission set group installed from a managed package has the namespace of the package to avoid any naming collision with a local group that has the same name.
- To delete a permission set group from an installed managed package, first uninstall the package.
- You can add and delete local permission sets in permission set groups installed from a managed package.
- You can’t remove the permission sets included in a permission set group installed from a managed package.
Keep in mind that you can install a package with a permission set group and then add a muting permission set to it. Any permissions in the muting permission set disable those permissions for the group. Using a muting permission set with a packaged permission set group lets you easily customize permissions for a specific group of users and business needs.
Users outside of the permission set group who are assigned to the permission sets remain unaffected. And any permission sets in the group whose permissions are muted remain unaffected outside of the group.
Muting can be valuable with managed packages. Suppose you receive an automatic update from an ISV or Salesforce partner for a managed package you subscribe to. But you aren’t ready to enable a new feature now made available by a managed permission set. You can still receive the update and its benefits while muting anything in permission set groups that you’re not ready to adopt.
