Assign Permission Set
Assign Service Assurance Hub Permission Set
The Service Assurance Hub includes pre-configured permission sets to control access to the managed package features. This guide walks you through assigning the Service Assurance Hub Admin permission set to users and creating custom permission sets for end users with reduced privileges.
Overview: Assign admin permissions to configuration users, then clone and customize permissions for standard end users to enforce the principle of least privilege.
Permission Set Hierarchy
The Service Assurance Hub includes two primary permission sets:
| Permission Set | Purpose | User Type |
| Service Assurance Hub Admin | Full access to all setup, configuration, and reporting features | System administrators, implementation consultants |
| Service Assurance Hub User (cloned) | Limited access to data viewing and standard workflows; no configuration | End users, analysts, team members |
Best Practice: Follow the principle of least privilege by assigning only the permissions each user role requires.
Step 1: Access Permission Sets
Navigate to Salesforce Setup to locate the Service Assurance Hub permission sets:
- Click the Setup icon in the top-right corner
- In the Quick Find box, search for Permission Set
- A list of all available permission sets will appear
Locate the Service Assurance Hub permission sets:
- Look for 'Service Assurance Hub Admin' in the permission set list
- This is the primary admin permission set created by the managed package
The Service Assurance Hub Admin permission set listed in Permission Sets
Step 2: Assign Admin Permissions
Assign the Service Assurance Hub Admin permission set to users who will manage, configure, and administer the Service Assurance Hub in your organization.
To assign the permission set:
- Click on the 'Service Assurance Hub Admin' permission set name
- Click the Manage Assignments button
- Click Add Assignments
- Select the System Administrators and configuration users who need full access
- Click Assign to confirm
Manage Assignments interface for assigning permissions to admin users
Who Should Receive Admin Permissions:
- System administrators managing Salesforce configuration
- Implementation consultants setting up the Service Assurance Hub
- Power users who configure dashboards and reports
Step 3: Create Custom User Permission Set
For end users who should access the Service Assurance Hub but do not need full admin capabilities, clone the admin permission set and remove unnecessary permissions.
To clone the permission set:
- Open the 'Service Assurance Hub Admin' permission set
- Click the Clone button
- Enter a new name for the cloned permission set (e.g., 'Service Assurance Hub User')
- Click Save
Now customize the cloned permission set:
- Review the cloned permission set's permissions
- Remove or disable permissions that end users should not have:
- Setup and configuration object permissions
- Delete or modify permissions on critical objects
- Dashboard and report creation/modification permissions
Configuration Recommendation: Disable create/edit/delete permissions on system-critical objects and retain only read and view permissions for end users.
Permissions to Consider for End Users:
| Permission TypeEnd User Access | |
| View Service Assurance Hub Records | ✓ Enable |
| Create/Edit Records | ✓ Enable (based on role) |
| Delete Records | ✗ Disable |
| Run Reports | ✓ Enable |
| Create Reports/Dashboards | ✗ Disable |
| Modify Setup/Configuration | ✗ Disable |
Step 4: Assign User Permission Sets
Once your custom user permission set is configured, assign it to end users who should have limited Service Assurance Hub access.
- Open the 'Service Assurance Hub User' (or your custom name) permission set
- Click Manage Assignments
- Click Add Assignments
- Select end users who need access to the Service Assurance Hub
- Click Assign
Who Should Receive User Permissions:
- Service delivery team members
- Analysts viewing reports and dashboards
- Team leads monitoring service metrics
Verification Checklist
Verify that permissions have been properly configured before going live:
- ☐ Admin users can access all Service Assurance Hub features and configuration
- ☐ End users can view records and run reports
- ☐ End users cannot delete records or modify configuration
- ☐ Test user access by logging in as different user types
- ☐ Verify all necessary users have been assigned appropriate permission sets
✓ Permission configuration is complete
Your Service Assurance Hub permission sets are now assigned and configured to enforce proper access controls across your organization.
Troubleshooting
If users report access issues or missing features:
- User cannot see Service Assurance Hub app: Verify the user's profile has access to the Service Assurance Hub app in the mobile navigation settings
- Permission denied on specific objects: Check if the permission set includes the required object-level and field-level permissions
- Users missing expected features: Confirm the user has the correct permission set assigned and check for organization-wide defaults that may restrict access
For additional support, contact the CodeyLabs support team at support@codeylabs.com.