Users, profiles and the role hierarchy
Invite teammates, define permissions with profiles, and control data access with the role hierarchy and sharing rules.
Adding users
- Open Setup > Users and click New User.
- Choose a name, e-mail and profile.
- The user receives an invitation e-mail, sets a password and logs in.
Profiles
A profile defines what a group of users can see and do:
- Per-object view / create / edit / delete permissions.
- Access to Setup screens (admin profiles only).
- Profile-based page layouts: the same record page can look different per profile.
A typical setup: Administrator (everything), Standard (daily work, Setup closed), plus department profiles when needed (for example a support profile that only sees Service360).
Role hierarchy
Under Setup > Role Hierarchy you model your org chart: a user in a higher role can see the records of those below. This is how a sales manager sees the whole team's opportunities.
Sharing
The Setup > Sharing screen sets default access per object: public, owner only, visible through the hierarchy and so on. Role and profile access is layered on top of a restrictive default.
Queues
A queue is a shared pool where unowned records wait (for example "Support Queue"). Assignment rules drop new cases into the queue; team members take ownership from it.