You are here:
Set Up Permission Sets and Access for the Employee Services Portal
Before you set up your Employee Services portal site, enable the org-level features the portal depends on. Then assign employees a license and the permission sets that give them access to the IT service records and features they need.
Required Editions
| Available in: Lightning Experience |
| Available in: Enterprise, Performance, and Unlimited Editions with Agentforce IT Service. |
Prerequisites
Complete these one-time setup tasks in your Salesforce org before you create the Employee Services portal site. They apply regardless of which template you use.
- Enable Digital Experiences and select a domain name. Before you save, confirm that Allow standard external profiles for self-registration, user creation, and login is enabled.
- Enable person accounts so you can store individual employees as records.
- Set up roles in your Salesforce org. Most Experience Cloud licenses require roles to share records with groups of users.
- Turn on the Reports To field on the Person Account object so you can associate a manager with each employee for approval workflows.
After you complete these tasks, create your employee users and assign their licenses and permission sets. See Set Up Employees for IT Services.
Licenses and Permission Sets
Permission sets give employees object-level access to the IT service records and features they need. They aren't tied to a specific Experience Cloud template, so employees can sign in to either an Agentic Center or an Agentforce Employee Center portal site with either permission set. Assign each employee a license and the matching permission set.
| License | Permission Set | Description |
|---|---|---|
| Unified Employee License | ITSM Portal Uel User | Gives employees object-level access to manage and track IT issues and service requests. We recommend this license and permission set for all portal users. |
| Customer Community Plus | IT Service Agentic Center Portal User | Gives employees object-level access to manage and track IT issues and service requests. Use this license for employees who haven't yet migrated to the Unified Employee License. |
We recommend that you standardize on the Unified Employee License. To move your existing Customer Community Plus users, follow the steps in Migrate Customer Community Plus Users to Unified Employee License.
Additional Permissions
To make sure your users can access Unified Catalog items and service processes, assign the required permissions. See Request Management Permissions for IT Services.
To let employees chat with the Agentforce agent on the portal, give them access to the Agentforce agent.
To allow portal users to run prompt templates by using generative AI features, assign the Prompt Template User permission set.
To let employees use the embedded AI features in the Agentforce Employee Center portal, such as Dynamic Q&A, your org needs the AI Features For Employee Portal Add On. With the add-on, assign the AI for Employee Portal permission set license to each portal user who needs AI features.
To allow employees to acknowledge policies and submit evidence through the portal, assign the IT Compliance Policy Acknowledger and IT Compliance Submitter permission sets.

