Course 1.2 · Curriculum 2026.1
Users, profiles, permission sets and sharing
Design record access that survives an audit. Start private, open deliberately, and verify every change as the real user.
- Estimated effort
- 5 hr
- Lessons
- 42
- Modules
- 7
- Material
- 5 hr
Estimated effort is the sum of the lesson and lab times in this version of the course. It is not video runtime, which is lower.
Canadian dollars. One learner, lifetime access to this course version. Tax extra.
1 lesson free to preview
This course does not issue a certificate on its own. It counts toward the paths listed below, and those do.
01What you will learn
7 capabilities, stated as things you can do
Each one is what you should be able to do at the end, not what the course covers. If an outcome is not testable, it is not an outcome.
- Design a permission model with an almost-empty profile and everything else in permission sets.
- Choose an organisation-wide default and defend it, rather than inheriting whatever was set in 2019.
- Predict who can see a record before you save the sharing rule, not after.
- Explain what the role hierarchy does and, more usefully, what it does not do.
- Find over-provisioned users with five reports rather than by reading profiles one at a time.
- Reproduce a permission error a user reported, using Login As under their exact access.
- Apply field-level security and know the reports that leak the field anyway.
02Curriculum
7 modules, 42 lessons
Every lesson shows its length and its type. A SCORM lesson looks like any other lesson, which is the point of ingesting packages rather than linking out to them.
7 modules · 42 lessons · 5 hr of material
A licence, a profile and a stack of permission sets. The licence is the one people forget to check first.
- VideoUsers, licences, and what a licence actually buysPreview6 min
- VideoProfiles: the baseline, and why yours should be almost empty7 min
- ReadingThe licence type you cannot just buy more of6 min
- VideoChatter-only, partner and other restricted licences, briefly7 min
- VideoReading a user record for what it actually grants6 min
- LabLab: audit ten users and list what each licence actually buys them6 min
Every permission in a profile is a permission you cannot grant to one person without cloning the profile. That is how orgs end up with forty of them.
- VideoPermission sets: the unit of access that should do the real work7 min
- VideoPermission set groups, and bundling access without a new profile6 min
- ReadingMuting permission sets, and the one case they solve7 min
- VideoCloning versus composing: why forty profiles happens6 min
- VideoAssigning permission sets at scale without a spreadsheet7 min
- LabLab: rebuild a bloated profile as an almost-empty one6 min
Access is only ever widened from here, never narrowed. Start private and open deliberately, object by object.
- VideoOrganisation-wide defaults: start private and open deliberately6 min
- VideoPublic, private and controlled by parent, chosen object by object7 min
- VideoPredicting who can see a record before you save the rule6 min
- ReadingThe default that was never revisited since it was set7 min
- VideoExternal sharing model, and the org-wide default nobody notices6 min
- LabLab: set organisation-wide defaults for a five-object model7 min
The role hierarchy grants access down its own tree. It does not replace sharing, and it does not follow the org chart automatically.
- VideoThe role hierarchy, and what it does not do6 min
- VideoRole hierarchy versus reporting hierarchy: two different trees6 min
- VideoGrant access using hierarchies, and when to switch it off7 min
- ReadingTerritories, in one paragraph, and when you actually need them6 min
- VideoPortal and community roles, briefly7 min
- LabLab: design a role hierarchy for a two-region sales team6 min
Owner-based and criteria-based sharing rules, tuned so the right people see a record without opening the whole object.
- VideoOwner-based sharing rules, and the limits on both sides7 min
- VideoCriteria-based sharing rules, and the criteria that will not fire6 min
- VideoManual sharing, and why it does not survive a data load6 min
- ReadingSharing sets and account teams, briefly7 min
- VideoApex managed sharing, mentioned so you recognise it later6 min
- LabLab: design access for a two-region sales team end to end7 min
Field-level security hides a field on a page layout. Report types, exports and the API are separate surfaces, and each needs checking.
- VideoField-level security, and the report that leaks the field anywayA field hidden from every page layout can still surface through a report type, an export or the API. Each surface needs its own check.6 min
- VideoPage layouts are not security: the confusion that causes incidents7 min
- VideoField-level security on the API and on exports6 min
- ReadingEncrypted fields, and what field-level security cannot do6 min
- VideoRestriction rules and scoping rules, briefly7 min
- LabLab: hide a field completely, then find where it still leaks6 min
A permission model you have not tested as the real user is a guess. This module is the verification discipline applied to access.
- VideoLogin As, and why every change is verified as the real user7 min
- VideoReproducing a permission error a user reported6 min
- VideoFive reports that find over-provisioned users7 min
- ReadingThe audit you run before, not after, an access review6 min
- LabLab: audit a live org for over-provisioned accessThe capstone lab. Run all five reports, reproduce one reported error as the user who reported it, and write the access changes it justifies.31 min
- QuizCheck: access and sharing12 min
03Before you start
What you need first
Assumed knowledge and setup
- Course 1.1, or the equivalent: you can find your way around Setup.
- A Developer Edition org where you hold System Administrator.
- No coding. This course is configuration only.
Courses that come first
Part of these paths
- Salesforce AdministratorShareCo Certified Administrator
- The Full StackShareCo Certified Platform Engineer
04Who teaches it
Ege Taskent
Salesforce Developer, Certified Platform Administrator
The credential, and the rollout. The half of an implementation where people actually start using the thing.
Salesforce Certified Platform Administrator
05Reviews
No learner reviews yet
This course has not been taken by enough people to publish an honest rating, and we will not print invented quotes on a page that sells verification discipline. Here is what we can evidence instead.
- Assessment
- Lesson checks onlyThis course carries lesson checks. The certificate is issued by the path assessment, not by this course.
- Curriculum version
- 2026.1You enrol into a version. Content changes do not move you mid-course, and your required-lesson count is snapshotted at enrollment.
- Refunds
- 14 daysFull refund within 14 days if you have completed under a quarter of the required lessons. Stated here rather than in a footer.
Start 1.2
Enrol as an individual, or buy seats and assign this course to your team. Progress is reported per lesson, per module and per path.
- 5 hr estimated effort, labs included
- Lifetime access to the version you enrol in
- A ShareCo certificate is not a Salesforce certification