Hi,
A small question regarding IAM and what’s possible.
Say, the Client had several 100 employees and wants to manage the User Groups and users.
We have created all the Roles/User groups in SF.
HOWEVER, maybe my client bought the module ‘Managing goods’ but NOT the module ‘Manage Finance’.
The problem I now face is that since the Client can manage Roles/Groups and users, he can grant access to ‘Manage Finance’ to user X. Et voila, suddenly he can do stuff he is not paying for.
What I need/want is a layer where I as a dev/PO can set which User Groups the client can see/use. And when a new module is developed, I do not want to go visit all my clients and setup this new group, and manage rights and all. I want the least amount of work on this.
Any advice on how to manage this?
Thanks!
Alex