Loading

Salesforce NPSP: Program Management Module install grants unexpected CRUD access to custom profiles

Fecha de publicación: Jul 15, 2026
Descripción

This article explains how to install the Program Management Module (PMM) managed package into a Nonprofit Success Pack (NPSP) org, what to confirm before you install, and how to remove unintended object access that the installer grants.

Customer Symptoms / Impact:

  • "I'd like to get this Program Management Module in my instance of Salesforce; at my org we use NPSP and are trying to build an engagement tracking system, and this seems to be what we need already built"

  • "Do you have a list of key terms and definitions for the Program Management Module?"

  • Program Management Module (PMM) installation gives Create, Read, Update, and Delete (CRUD) access to PMM objects to custom profiles that were not intended to have it.

Trigger Condition:

  • An administrator installs PMM through the standard installer on an org already running NPSP.

  • No specific error message is thrown; the primary symptom is that users on custom profiles unexpectedly see or can edit PMM objects such as Program, Program Engagement, Service, Service Schedule, Service Session, and Service Delivery.

  • PMM is a separate managed package from NPSP; it is not automatically present just because NPSP is installed.

Solución

Cause 1: You need to install the Program Management Module (PMM) into an existing NPSP org.

  1. Verify NPSP Status: Confirm your org already has the Nonprofit Success Pack installed and is on a current NPSP release before you install additional modules.

  2. Install PMM: Install the Program Management Module through the official MetaDeploy installer for PMM (the same delivery mechanism used for other Nonprofit managed packages).

  3. Run Installer: Complete the guided installer steps and wait for the install to finish successfully before configuring layouts or permissions.

  4. Confirm Installation: After install, confirm the following PMM objects are present under Setup > Object Manager:

    • pmdm__Program__c

    • pmdm__ProgramEngagement__c

    • pmdm__Service__c

    • pmdm__ServiceSchedule__c

    • pmdm__ServiceSession__c

    • pmdm__ServiceDelivery__c

Cause 2: After installing PMM, custom profiles have unexpected CRUD access to PMM objects.

  1. Go to Setup > Users > Profiles.

  2. Open each custom profile that should NOT have access to PMM data.

  3. Select Object Settings (or, in the enhanced profile view, the Object Permissions section).

  4. For each PMM object (pmdm__Program__c, pmdm__ProgramEngagement__c, pmdm__Service__c, pmdm__ServiceSchedule__c, pmdm__ServiceSession__c, and pmdm__ServiceDelivery__c), clear the Read, Create, Edit, and Delete checkboxes.

  5. Set Tab Visibility for the PMM tabs to Hidden on those profiles if the users do not use PMM.

  6. Click Save.

  7. Repeat this process for every affected custom profile.

  8. Best Practice Alternative: As a preferred alternative to editing profiles directly, grant PMM access through a dedicated permission set assigned only to program-management users, so that base profiles carry no PMM object permissions.

Reference: Key Terms for the Program Management Module

  • Program: The overarching initiative or offering your organization runs.

  • Program Engagement: The link between a Contact and a Program (a person's participation).

  • Service: A specific offering delivered within a Program.

  • Service Schedule and Service Session: The planned timing and individual occurrences of a Service.

  • Service Delivery: The record of a service actually provided to a participant.

Verification

Confirm the issue is resolved by logging in as a user assigned to one of the corrected custom profiles and verifying they can no longer open, create, or edit PMM object records, while a user with the PMM permission set retains full access.

Número del artículo de conocimiento

005389027

 
Cargando
Salesforce Help | Article