Published at: 2026-09-17

Configure external roles and data permissions


The upstream enterprise configures partner access and data scope in layers.

Before you start

[!IMPORTANT] - Confirm that your account can manage Enterprise Interconnection applications and external roles. - Confirm that the downstream enterprise and contacts have been added.

Set the external access scope

  1. Go to Setup > Interconnection Management > Enterprise Interconnection > Interconnected Applications > Application Information.
  2. Open External Access Scope.
  3. Select all downstream enterprises, selected downstream enterprises, or selected connected contacts in selected companies.
  4. Save the scope.

Assign roles and permissions

  1. Open the user list for the Partner Connect interconnected application.
  2. Assign the Partner User role to downstream users.
  3. If the default role is insufficient, create an external role.
  4. Configure object operation and field permissions for the role.
A downstream user without an assigned role cannot use Partner Connect correctly.

Assign record types and layouts

  1. Select an object to make available.
  2. Assign its record types to the external role.
  3. Assign its layouts to the external role.
  4. Save the configuration.

Set the data scope

Select an applicable data scope for each object: Private, Company Read Only, Company Read/Write, Public Read Only, or Public Read/Write. Then configure data sharing based on how roles need to collaborate.

Verify the configuration

Test objects, fields, records, and read/write actions with different external roles. After changing permissions, sign in again with a partner account and confirm that the home page and business objects match the intended access.

Expected result

Each role can view and modify only the objects, fields, and records it is authorized to access.
Submit Feedback