You are here:
Delegated Access Management in Education
A self-service authorization model helps your institution meet privacy requirements and gives trusted individuals access to student data. Students grant proxies, such as parents, guardians, or other trusted individuals, access to their institutional records.
| Available in: Lightning Experience |
| Available in: Enterprise, Performance, Unlimited, and Developer Editions with Education Cloud |
Students don't understand database objects to delegate access. Instead, your Salesforce admin configures user-friendly delegated access definitions backed by data sets that map the underlying objects. Students select these definitions to authorize what their proxies view.
Your Salesforce admin defines the available access levels to govern delegation.
- A data set maps the relevant objects and defines how those records resolve to the student. Your admin structures data sets to bundle underlying records, such as billing statements, course schedules, or financial aid awards. This structure restricts proxy visibility to the intended records.
- A delegated access definition combines a delegated access data set and a permission set into an access option. Your admin configures delegation definitions to map data sets to preapproved permission sets that students can grant to proxies.
- With lifecycle policies, your admin can set system-wide rules for expiration dates and proxy invitation workflows, automating the delegated access lifecycle.
Through a dedicated self-service portal, students maintain direct control over who interacts with their data.
- Invite parents, guardians, or other trusted individuals to register on the proxy portal.
- Select the access definitions that a proxy views or manages.
- Update or terminate proxy access at any time.
