Create the Administrator Permission Set Group (Clicks)
This section captures the configuration instructions for creating the Cuneiform® for CRM: Administrators Permission Set Group.
APPLIES TO | CUNEIFORM FOR CRM FIELD AND DATA MANAGEMENT
Create the Administrative Permission Sets for Application Access
TEN MINUTEs
Cuneiform for CRM provides Salesforce Admins with a permission set template supporting admin application access. As a first configuration step, you’ll create a permission set and permission set group to manage associations with our Admin and Connected App assignment permission sets.
How Cuneiform for CRM Utilizes Permission Set Groups
Administrative access to Cuneiform for CRM requires that org users manage associations to two specific permission sets within the Salesforce org:
Permission Set | Manages |
---|---|
Cuneiform for CRM: Administrative User | Manages administrative rights to all Salesforce objects and application permissions for Cuneiform for CRM. This permission set can be assigned – but cannot be extended (as it is managed). |
Cuneiform for CRM: Connected App Assignment | Manages the assignment to the Cuneiform for CRM: Connected App. This connected app is used to broker Salesforce REST API requests securely. This permission set can be assigned and extended. |
Cuneiform for CRM leverages Salesforce REST APIs (including the Metadata, Tooling, and Query APIs) to introspect the metadata of Salesforce objects and monitor the data these objects manage. These APIs must be accessed securely, leveraging Salesforce security recommendations and best practices. The most secure manner of accessing these APIs is via a connected app, and Salesforce Admins can govern which users can leverage the connected app with a permission set.
The permission sets included in Cuneiform for CRM are managed – which means that Admins cannot edit these permission set definitions. They can be assigned to users, but their configured permissions cannot be changed.
To simplify admin management activities, we recommend creating a new permission set group. Admins can use the Cuneiform for CRM: Administrators permission set group as a single configuration point for application Admins. Instead of manually assigning users to multiple-individual permission sets, you can assign users to the single Cuneiform for CRM: Administrators permission set group.
Creating a Permission Set for Cuneiform for CRM Connected App Access
Cuneiform® for CRM uses a connected app to securely broker Salesforce REST API calls. The connected app requires that approved user assignments be managed via a permission set or profile association.
Let’s create a permission set to manage this association between your org’s application Admins and the Cuneiform for CRM: Connected App.
Creating the Administrative Permission Set Group
We recommend consolidating the Cuneiform® for CRM: Administrative Users and Cuneiform for CRM: Connected App Assignment permission sets using a single permission set group.
This consolidation enables org admins to assign Cuneiform for CRM: Administrative rights through one action via a permission set group.
Assigning Users to the Cuneiform for CRM: Administrator's Permission Set Group
With the permission set group created and Cuneiform® for CRM Admin permission sets assigned, we can now assign individual users to the Cuneiform for CRM: Administrators permission set group to make them application Admins.
Use this permission-set to enable Cuneiform for CRM: Administrator access to org users.
If you’re not a fan of manual configuration – consider using our Apex Script configuration scripts. These scripts reduce configuration and setup time to under five (5) minutes. You’re in a perfect place to use our scripts – why don’t you give them a try?