Skip to main content

Manage permissions and access control

Control which flair features and Salesforce records each user can access. This guide covers flair permission sets, permission set groups, visibility scopes, targeted permission sets, custom permissions, and Admin Monitoring.

Who can use this?

Salesforce Admins who manage users, licenses, permission sets, objects, and sharing access in Salesforce Setup.

Before you begin

  • Assign each user a flair license.
  • Review the user's Salesforce profile and existing permission sets before adding access.
  • Use flair's maintained permission sets or permission set groups when they cover the required role.

Review flair permission sets

flair provides permission sets for different HR and Recruiting roles. Each set grants View or Modify access to selected Salesforce objects.

  1. In Salesforce Setup, open Permission Sets.
  2. Find sets with the Flair prefix.
  3. Read each description to understand its intended role.

To inspect the exact object access in a set:

  1. In Salesforce, open Setup.

    Salesforce Setup menu for reviewing permission sets

    Salesforce Setup page for permission-set access

  2. In Quick Find, enter Permission.

    Permission search in Salesforce Setup

  3. Open Permission Sets.

    Permission Sets search result in Salesforce Setup

  4. Select a set, such as Flair Engagement Manager.

    Flair permission set selected in Salesforce

  5. Click View Summary.

    View Summary action on a permission set

  6. Click Object Permissions.

    Object Permissions section of a permission-set summary

The summary shows Read, Create, Edit, Delete, View All, and Modify All access. Use it to review assignments, troubleshoot access, plan changes, or document your security configuration.

Create and assign a permission set group

Permission set groups combine modular permission sets for a role or persona. For example, a group for an HR manager who also handles payroll can combine Flair Manager and Flair Payroll Manager.

flair is moving new features to new modular permission sets and permission set groups. Existing permission sets remain unchanged for backward compatibility. Assign permission set groups for future feature access; a user can receive more than one group when roles overlap.

Permission set groups have these Salesforce constraints:

  • Permission set groups must be enabled before a subscriber installs or uninstalls a package that contains them.
  • Groups installed from managed packages do not count against the maximum number of groups created. Limits for created and installed groups vary by Salesforce edition.
  • Some Salesforce editions cannot create or customize groups, but they can install and use groups from managed packages.
  • A managed-package group uses the package namespace to avoid a naming collision with a local group.
  • To delete a group from a managed package, uninstall the package.
  • You can add and remove local permission sets in a group installed from a managed package.
warning

Do not duplicate and modify a maintained flair permission set. The copy does not receive flair permission updates and can become outdated.

Salesforce provides more information about permission set groups, and this video demonstrates the workflow:

Create the group

  1. In Salesforce, click the setup gear.

  2. Select Setup.

  3. In Quick Find, enter permission set groups.

  4. Open Permission Set Groups.

  5. Click New Permission Set Group.

    New Permission Set Group action in Salesforce Setup

  6. Enter a Label and Description.

  7. Click Save.

    Label and description for a permission set group

Add permission sets to the group

  1. In the group, click Permission Sets in Group.

  2. Click Add Permission Set.

    Add Permission Set action in a permission set group

  3. Select the permission sets to include.

  4. Click Add.

    Permission sets selected for a permission set group

Assign the group

  1. In Permission Set Groups, select the group.

  2. Click Manage Assignments.

    Manage Assignments action for a permission set group

  3. Click Add Assignment.

  4. Select the user.

  5. Click Next.

  6. Choose whether the assignment expires.

  7. Click Assign.

    User and expiration settings for a permission set group assignment

Create a muting permission set

A muting permission set removes selected access only within one permission set group. It does not change the individual sets. For example, mute Delete access when HR managers can view payroll details but must not delete them.

  1. Open the permission set group.

  2. Click Muting Permission Sets in Group.

    Muting Permission Sets in Group option

  3. Click New.

  4. Enter a Label.

  5. Click Save.

    New muting permission set details

Choose permissions to mute

  1. Open the muting permission set.

  2. Click Object Settings.

    Object Settings on a muting permission set

  3. Select the object to restrict.

    Object selected in a muting permission set

  4. Review Tab Settings, Object Permissions, and Field Permissions.

  5. Click Edit.

    Edit action for object permissions in a muting permission set

  6. Select Muted next to each permission to restrict.

  7. Click Save.

    Muted object and field permissions in a permission set

  8. In the permission set group, open Object Settings to confirm that the muted access overrides the original permission.

    Restricted access in the permission set group summary

Configure visibility scopes

Visibility scopes restrict records by department, location, or entity after permission sets grant object access.

warning

Visibility scopes do not restrict users with View All or Modify All access. This includes Flair Manager, Flair Payroll Manager, Flair Recruiter, and users with the System Administrator profile.

Connect a Salesforce user to an employee

  1. In Staff or Employees (or the legacy Staff & Docs tab), open the employee record.

  2. In Salesforce User, select the matching Salesforce user.

  3. Click Save.

    Salesforce User field on an employee record

    Salesforce user connected to a flair employee

Create and assign an entity

An entity can represent a division or another employee group.

  1. In the App Launcher (⋮⋮ grid icon), open Entities.

    Entities in the Salesforce App Launcher

  2. Click New.

  3. Enter a name.

  4. Click Save.

    New Entity action in flair HR

    Saved Entity record in flair HR

  5. Open an employee record.

  6. In the contract section, select the entity in Entity.

  7. Click Save.

    Entity assigned on an employee contract

  8. Optional: Assign jobs and candidates to the entity.

    Entity assignment on a recruiting record

Create the visibility scope

  1. In the App Launcher (⋮⋮ grid icon), open Employee Visibility Scopes.

  2. Click New.

    Employee Visibility Scopes in the Salesforce App Launcher

    New Employee Visibility Scope action

  3. Enter a name.

  4. Select the employee or employee group that receives the scope.

  5. Under Scopes, select the entity to share.

  6. Optional: Select Can See Own Entity to give a user access to their own entity and another selected entity. For example, a manager can access company headquarters and their work location.

    Employees and entities on an Employee Visibility Scope

  7. Under Access, select the objects in the scope.

  8. For each object, select Read/Write or Read Only. Clear an object to hide it entirely.

    Object access levels on an Employee Visibility Scope

  9. Click Save. An Apex batch job creates the sharing records.

  10. To review or edit the scope, open its name and check the sharing-rule processing status.

    Processing status on an Employee Visibility Scope

Grant a scope access to any employee for signatories, hiring managers, and evaluators

Selecting a signatory for an e-signature request, or a hiring manager or default evaluator for a job, normally requires the same record-level read access as viewing that employee anywhere else in flair. A visibility scope that hides an employee also removes them from these pickers. Three checkboxes on the Employee Visibility Scope record let a user search for and select any employee for one of these actions, without widening their general visibility scope.

  1. Open or create an Employee Visibility Scope record.
  2. Under Scopes, next to Can See Own Entity, select the checkbox for the picker to open up:
    • Can Create Sign Request for Any Employee — search for and select any employee as a signatory when creating an e-sign request.
    • Can Add Any Employee as Hiring Manager — search for and select any employee as a job's hiring manager.
    • Can Add Any Employee as Evaluator — search for and select any employee as a job's default evaluator.
  3. Click Save.

The Scopes section of an Employee Visibility Scope record showing Can See Own Entity followed by the Can Create Sign Request for Any Employee, Can Add Any Employee as Hiring Manager, and Can Add Any Employee as Evaluator checkboxes

Each checkbox is cleared by default and affects only the matching search and selection step — it does not grant the user general read access to the employee record elsewhere in flair.

Share employee records with managers automatically

Two separate flair mechanisms share an employee's record with a manager's Salesforce user, independent of visibility scopes. Both grant Edit access, and both share only with a manager whose Salesforce user is active.

  • Additional Manager sharing is always on. When an employee has an entry in their Additional Managers related list with HR Manager selected, flair shares the employee record with that additional manager's Salesforce user. Clearing HR Manager or removing the additional manager removes the share.
  • Direct Manager sharing shares the employee record with the Salesforce user of the employee's direct manager — the Manager field on the employee record. It's off by default; turn it on per organization.

Turn on direct manager sharing

  1. In Salesforce Setup, in Quick Find, enter Custom Settings.
  2. Open Custom Settings.
  3. Next to Flair Employee Settings, click Manage.
  4. Click New, or click Edit if an organization-level default already exists.
  5. Select Enable Direct Manager Sharing.
  6. Click Save.

flair shares each employee with Edit access to their direct manager's Salesforce user, and updates the share when the Manager field changes or is cleared. Additional Manager sharing does not use this setting and cannot be turned off per organization.

Limit a user to company documents

Combine a visibility scope with Flair Employee Management when a user must see company documents but no other HR data.

  1. Assign Flair Employee Management to the user.
  2. Create or edit an Employee Visibility Scope.
  3. Under Access, clear every object except Company Document.
  4. Click Save.

The user can see company documents only within the assigned scope.

Create an Inventory Manager permission set

Create a dedicated permission set when a user needs access only to these Inventory objects:

  • Inventory.
  • Inventory Attachments.
  • Inventory Items.
  • Inventory Templates.
  • Inventory Template Associations.

Create the permission set

  1. Open Salesforce Setup.

    Salesforce Setup menu for an Inventory permission set

    Salesforce Setup page for creating a permission set

  2. In Quick Find, enter permission.

    Permission search for an Inventory Manager set

  3. Open Permission Sets.

    Permission Sets result in Salesforce Setup

  4. Click New.

    New permission set action in Salesforce

  5. In Label, enter Inventory Manager.

    Inventory Manager label on a new permission set

  6. Select API Name to fill it automatically.

    Generated API Name for the Inventory Manager permission set

  7. Click Save.

    Save action for a new permission set

Configure Inventory access

  1. In the permission set, click Object Settings.

    Object Settings on the Inventory Manager permission set

  2. Search for and select Inventory.

    Inventory object search in a permission set

  3. Click Edit.

    Edit action for Inventory object settings

  4. Under Tab Settings, select Visible.

    Visible tab setting for the Inventory object

  5. Configure Read, Create, Edit, Delete, View All, and Modify All access as required.

  6. Configure the required field permissions.

  7. Click Save.

  8. Repeat the object and field setup for Inventory Attachments, Inventory Items, Inventory Templates, and Inventory Template Associations.

  9. For Inventory Items, make the tab available and configure record-type assignments when required.

Assign the permission set

  1. In the permission set, click Manage Assignments.

    Manage Assignments action on the Inventory Manager permission set

  2. Click Add Assignment.

    Add Assignment action on a permission set

  3. Select the users.

    Users selected for the Inventory Manager permission set

  4. Click Next.

  5. Click Assign.

  6. Click Done.

Enable Developer Console access

Developer Console gives a user access to debug, test, and develop Salesforce code or applications.

Create the permission set

  1. Open Salesforce Setup.

    Salesforce Setup portal

  2. Under Users, open Permission Sets.

  3. Click New.

    New permission set action for Developer Console access

  4. Enter a Label, API Name, and Description.

  5. Click Save.

    Permission set details for Developer Console access

  6. Under System, click System Permissions.

    System Permissions option on a permission set

  7. Click Edit.

    Edit action for System Permissions

  8. Enable Author Apex and View All Data.

  9. Click Save.

    Author Apex and View All Data permissions enabled

Assign the permission set

  1. In Salesforce Setup, open Users.

  2. Select the user.

    Salesforce user selected for a permission assignment

  3. Click Edit Assignments.

    Edit Assignments action on a Salesforce user

  4. Add the new set, such as For Dev Console, from Available Permission Sets.

  5. Click Save. The user can open Developer Console.

    Developer Console permission set assigned to a user

    Developer Console access available after permission assignment

Assign custom permissions

Assign flair.Can Update Locked Payroll Run to the payroll integration user so an external payroll system can add deductions when a Payroll Run is locked in a status such as Submitted.

Add the locked Payroll Run permission

  1. In Salesforce Setup, enter Permission Sets in Quick Find.

  2. Open Permission Sets.

  3. Click New. If the payroll integration user already has a custom permission set, open that set instead.

  4. In Label, enter a name such as Flair Payroll Deduction.

  5. Keep the generated API Name.

  6. Click Save.

    Permission set for the locked Payroll Run custom permission

  7. Under Apps, click Custom Permissions.

    Custom Permissions option on a permission set

  8. Click Edit.

  9. Move flair.Can Update Locked Payroll Run from Available Custom Permissions to Enabled Custom Permissions.

  10. Click Save.

    Locked Payroll Run permission in Enabled Custom Permissions

Assign the permission set to the integration user

  1. In Salesforce Setup, find the payroll integration user.

  2. Under Permission Set Assignments, click Edit Assignments.

    Edit Assignments action for the payroll integration user

  3. Move the permission set from Available Permission Sets to Enabled Permission Sets.

  4. Click Save.

    Payroll deduction permission set assigned to the integration user

Control who can log in as an employee

The Employee Hub card on an Employee record shows Login as this employee and Send login link to private email in its actions menu. Login as this employee opens the employee's Employee Hub session directly; Send login link to private email emails the employee a Hub login link. The flair.Flair Manager Hub Login custom permission enforces Login as this employee on the server, so a user without it cannot open another employee's Hub session. For Send login link to private email, the custom permission only controls whether the button appears in the actions menu — removing it hides the button but does not by itself prevent the underlying action, so it should not be relied on as the sole control for that action.

The Flair Manager permission set enables flair.Flair Manager Hub Login by default, so assigning Flair Manager already enables Login as this employee and shows the Send login link to private email button. To grant the same access without assigning the full Flair Manager permission set:

  1. In Salesforce Setup, enter Permission Sets in Quick Find.
  2. Open Permission Sets.
  3. Click New, or open an existing permission set for the user.
  4. Under Apps, click Custom Permissions.
  5. Click Edit.
  6. Move flair.Flair Manager Hub Login from Available Custom Permissions to Enabled Custom Permissions.
  7. Click Save.
  8. Assign the permission set to the user.

The Employee Hub card's actions menu open, showing Login as this employee and Send login link to private email

warning

flair.Flair Manager Hub Login grants Employee Hub impersonation for every employee record the user can already open, not only their own reports. Grant it only to roles that need to log in as employees for support.

Configure Admin Monitoring

Admin Monitoring is a free flair integration. It continuously checks assigned licenses, lets you allow or block Salesforce users, and alerts administrators about license changes or unauthorized access attempts.

  1. In the flair HR app, open HR AdminIntegrations.

  2. Select Admin Monitoring.

    Admin Monitoring integration in flair HR Admin

  3. Click Connect Via Integration Service.

    Connect Via Integration Service action for Admin Monitoring

  4. Under Settings, enter each notification email address. Separate multiple addresses with commas.

  5. Under Users allow to use flair, use the toggles to allow or block users.

  6. Use the search field to find a user who is not listed.

  7. Click Enable.

    Notification recipients and authorized users in Admin Monitoring

Troubleshooting

A user cannot see Employee Documents or Employee Visibility Scopes

  1. In Salesforce Setup, open the user.
  2. Confirm that the user has a flair license.
  3. Review the user's profile and default organization permissions.
  4. Confirm that a permission set grants Read access to Employee Documents.
  5. Confirm that the user can view and manage Employee Visibility Scopes.
  6. Confirm that the Employee Visibility Scope object is enabled and accessible in the Salesforce organization.