Permission handling for Salesforce files and folders
CloudFiles ships ready-made permission sets and granular control over who can create, share or delete a file. Access updates automatically the moment someone joins or leaves a team, so it's never out of step with who's actually on the account.
Salesforce was never built to keep external file access in step with your org chart
A person joins a deal team, another one leaves, and the files they can create, share or delete outside Salesforce don't automatically follow either change.
Without CloudFiles
- Every new hire needs someone to manually work out which files and folders they should be able to touch
- Revoking access when someone leaves a team is a task somebody has to remember, not something that happens on its own
- A generic access level gets applied to everyone, because building a custom permission set from scratch for every role is its own project
With CloudFiles
- Four ready-made permission sets, Admin, Standard, External and Field Service, mean a role starts from a real default instead of a blank one
- Nine granular permissions, from creating a folder to sharing a file externally, get assigned or removed in a few clicks, or automatically through a flow
- Access changes the moment someone's role does, because the same permission set that grants access is the one flow automation can update
What CloudFiles permission handling actually covers
Four ready-made permission sets
Admin, Standard, External and Field Service, so a role starts from a real default instead of a blank one.
Nine granular permissions
From connecting a folder to a record to deleting a file from external storage, each can be turned on or off individually for any user.
Auto-assigned on install
Administrators and internal users get their permission sets automatically the moment CloudFiles is installed.
Flow-automatable for everyone else
An Experience Cloud partner, a new hire or a Field Service technician can be assigned by hand from Setup, or automated with a flow.
How teams already control access to Salesforce documents
Real scenarios CloudFiles' permission model is built to run, sourced from the Salesforce help center.
Starting a new hire from a real default
Assign the ready-made CloudFiles Admin, Standard, External or Field Service permission set instead of building access rules from scratch.
Separating who can view from who can share
Control "Share Files & Folders" as its own permission, independent of who can simply view or download a file.
Giving portal users a narrower default
Assign the CloudFiles External User permission set to Experience Cloud users, scoped tighter than what an internal Standard user gets.
Updating access the moment a role changes
Grant or revoke read and write access on a file or folder automatically the moment someone joins or leaves a deal team.
Controlling deletion separately from everything else
Turn "Delete Files & Folders" on or off per user, independent of upload, download or sharing permissions, since a delete also removes the file from external storage.
Deciding who can see link analytics
Grant "View Analytics" and "View Sharing Settings" separately, so a user can see who's using a share without also being able to change its settings.
Permissions are one piece of a bigger sharing model
Secure datarooms and sharing→
Who can create a dataroom, add a file to one or share its link externally is decided by the same permission sets described here.
File and folder metadata updates→
Updating a folder's metadata is a permission-gated action too, controlled by the same granular permissions as every other CloudFiles action.
Document management for Salesforce→
Permission handling is one piece of CloudFiles Document Management: one permission model applied across every connected storage platform.
Stay compliant and secure.
CloudFiles is independently audited for SOC 2 Type II, certified to ISO 27001, and compliant with HIPAA and GDPR. Data residency is supported in the US, EU, UK, and AU. Your files stay in your own storage, CloudFiles never re-hosts them, and they are not used to train our AI models.
Permission handling, answered directly
Four: CloudFiles Admin User, CloudFiles Standard User, CloudFiles External User and CloudFiles Field Service User.
Yes, to System Administrators and internal users. Every other combination is assigned manually from Setup, or automated with a flow.
Yes. "Share Files & Folders" is its own permission, independent of view, download or upload access.
Yes. Read and write access on a file or folder can be granted or revoked automatically the moment someone joins or leaves the team it belongs to.
Yes. The CloudFiles External User permission set is the one built for Experience Cloud users, scoped separately from internal Standard access.
Yes. "Delete Files & Folders" is its own permission, and turning it off still leaves upload, download and sharing untouched for that user.
Book a demo
See how CloudFiles assigns the right access from day one and keeps it in step with your team as it changes.