What is Delegated Administration?
Delegated administration allows named users to manage other users within selected roles and profiles, as well as manage fields on selected custom objects.
Why use Delegated Administration?
If you assign user administration privileges using profiles or permission sets, that user will gain the ability to administer most or all users and objects in your org.
Delegated administration allows you to specify which users (based on role/profile) and custom objects (standard objects excluded) a delegated administrator can manage.
|Profile & Permission Sets|
|Login as Any User*|
|Manage Users Assigned Any Role|
|Manage Users Assigned Any Profile*|
|Admin None/All Objects|
|Login as Users - Delegated Roles Only|
|Manage Users - Delegated Roles Only|
|Manage Users - Delegated Profiles Only|
|Admin Delegated Custom Objects Only|
*A user must have the “Modify All Data” permission to manage users/profiles with the “Modify All data” permission.
Jim is responsible for maintaining users for the marketing department, as well as the custom fields on the “Venue” object. If someone in the marketing department has a problem with Salesforce, they first contact Jim to see if he can resolve the issue. Likewise, Jim is responsible for creating new Salesforce users for the marketing team.
To meet this need, I’ve created a delegated group as follows:
Although Jim is assigned the “Standard User” profile, he can manage users within the specified roles and profiles above. Additionally he can manage the custom fields on the Venue object. However, he cannot perform any other administrative actions.