Dreamforce 2026 is 12 days away. Booth 536, Moscone Center, 15–17 Sep 2026. Details
Access control use cases

Permission handling for Salesforce files and folders

CloudFiles ships ready-made permission sets and granular control over who can create, share or delete a file. Access updates automatically the moment someone joins or leaves a team, so it's never out of step with who's actually on the account.

Loved and trusted
The gap in manual access control

Salesforce was never built to keep external file access in step with your org chart

A person joins a deal team, another one leaves, and the files they can create, share or delete outside Salesforce don't automatically follow either change.

Without CloudFiles

  • Every new hire needs someone to manually work out which files and folders they should be able to touch
  • Revoking access when someone leaves a team is a task somebody has to remember, not something that happens on its own
  • A generic access level gets applied to everyone, because building a custom permission set from scratch for every role is its own project

With CloudFiles

  • Four ready-made permission sets, Admin, Standard, External and Field Service, mean a role starts from a real default instead of a blank one
  • Nine granular permissions, from creating a folder to sharing a file externally, get assigned or removed in a few clicks, or automatically through a flow
  • Access changes the moment someone's role does, because the same permission set that grants access is the one flow automation can update
How it's built

What CloudFiles permission handling actually covers

Four ready-made permission sets

Admin, Standard, External and Field Service, so a role starts from a real default instead of a blank one.

Nine granular permissions

From connecting a folder to a record to deleting a file from external storage, each can be turned on or off individually for any user.

Auto-assigned on install

Administrators and internal users get their permission sets automatically the moment CloudFiles is installed.

Flow-automatable for everyone else

An Experience Cloud partner, a new hire or a Field Service technician can be assigned by hand from Setup, or automated with a flow.

Where teams use it

How teams already control access to Salesforce documents

Real scenarios CloudFiles' permission model is built to run, sourced from the Salesforce help center.

Starting a new hire from a real default

Assign the ready-made CloudFiles Admin, Standard, External or Field Service permission set instead of building access rules from scratch.

Separating who can view from who can share

Control "Share Files & Folders" as its own permission, independent of who can simply view or download a file.

Giving portal users a narrower default

Assign the CloudFiles External User permission set to Experience Cloud users, scoped tighter than what an internal Standard user gets.

Updating access the moment a role changes

Grant or revoke read and write access on a file or folder automatically the moment someone joins or leaves a deal team.

Controlling deletion separately from everything else

Turn "Delete Files & Folders" on or off per user, independent of upload, download or sharing permissions, since a delete also removes the file from external storage.

Deciding who can see link analytics

Grant "View Analytics" and "View Sharing Settings" separately, so a user can see who's using a share without also being able to change its settings.

Assign once, or let a flow handle every future hire

CloudFiles auto-assigns its own permission sets to administrators and internal users on install. Every other combination, including a new hire who needs External User access from day one, can be assigned by hand from Setup, or automated so it happens without anyone remembering to do it.

Stay compliant and secure.

CloudFiles is independently audited for SOC 2 Type II, certified to ISO 27001, and compliant with HIPAA and GDPR. Data residency is supported in the US, EU, UK, and AU. Your files stay in your own storage, CloudFiles never re-hosts them, and they are not used to train our AI models.

SOC 2
Type II
HIPAA
Compliant
ISO 27001
Certified
GDPR
Compliant

Permission handling, answered directly

Four: CloudFiles Admin User, CloudFiles Standard User, CloudFiles External User and CloudFiles Field Service User.

Yes, to System Administrators and internal users. Every other combination is assigned manually from Setup, or automated with a flow.

Yes. "Share Files & Folders" is its own permission, independent of view, download or upload access.

Yes. Read and write access on a file or folder can be granted or revoked automatically the moment someone joins or leaves the team it belongs to.

Yes. The CloudFiles External User permission set is the one built for Experience Cloud users, scoped separately from internal Standard access.

Yes. "Delete Files & Folders" is its own permission, and turning it off still leaves upload, download and sharing untouched for that user.

Book a demo

See how CloudFiles assigns the right access from day one and keeps it in step with your team as it changes.