Core Concepts

Permissions

Access in Forge has two layers that both apply. Salesforce decides what data a user can read and write — profile, Blackthorn permission sets, field-level security, and sharing rules. A Forge role (Admin or Planner, assigned in Admin > Users & Accounts) then decides which Forge sections the user can open. Neither layer replaces the other.

How Salesforce permissions flow into Forge

When Forge reads or writes a Salesforce record, it does so using the authenticated user's Salesforce session. Salesforce enforces object-level CRUD permissions and field-level security (FLS) on every operation. If a user's Salesforce profile does not allow Read access to conference360__Attendee__c, they will not see the Attendees tab in Forge.

Blackthorn permission sets

Blackthorn provides managed permission sets that grant the minimum necessary access to the managed-package objects:

  • Blackthorn Events Admin — full CRUD on all conference360__ objects. Intended for event administrators and Salesforce Admins.
  • Blackthorn Event Organizer — day-to-day event management access. This is the standard planner-level Events set (not "Blackthorn Events User").
  • Blackthorn Events Lite User / Blackthorn Events Limited Access — narrower Events access for occasional or restricted users.
  • Blackthorn Events Read Only — view-only access to Events data.
  • Blackthorn Base Admin / Blackthorn Base User / Blackthorn Base Read Only — access to the Base package objects underlying core record access.
  • Blackthorn Payments Admin — full CRUD on bt_stripe__ objects. Required for gateway configuration and refund processing.
  • Blackthorn Payments User / Blackthorn Payments Manager — read and day-to-day transaction/fee access without gateway or refund rights.
  • Blackthorn Payments Lite User — narrower, view-oriented Payments access.

Blackthorn permission sets are assigned by a Salesforce admin in Salesforce Setup > Users > Permission Set Assignments — do this before adding someone in Forge. Forge roles are assigned separately, in Admin > Users & Accounts.

How Forge roles relate to Blackthorn permission sets

Forge does not derive a user's role from their permission sets, or the reverse; you set both. These are the typical pairings:

Forge roleTypical Salesforce permission setsWhat the user can do
AdminBlackthorn Events Admin, Blackthorn Base Admin, and Blackthorn Payments Admin if they manage gateways or refundsEverything Salesforce allows, plus the Forge Admin section.
PlannerBlackthorn Event Organizer (plus Base User and Payments User as needed)Create and manage events, attendees, sessions, forms, and communications; no Admin section.
Planner (limited)Blackthorn Events Lite User, Limited Access, or Read OnlyOnly the records those permission sets expose, even though the Forge role is Planner.

A user with the Forge Admin role but no Payments Admin permission set can open the Payment Gateways page but Salesforce will refuse gateway changes. Assign the Salesforce permission set first, then the Forge role.

Field-level security

If a Salesforce field is hidden from a user via FLS, that field will not appear in Forge — either in the UI or in exports. This is intentional and is how Forge enforces data governance. For example, if your FLS policy hides Contact.Email from a user, they will not see attendee email addresses in the Attendees tab.

Sharing rules

Salesforce sharing rules also apply. If your org uses organization-wide defaults (OWD) that restrict access to certain conference360__ records, those restrictions propagate through Forge. Users will only see events, attendees, and transactions that their Salesforce sharing configuration permits.

Admin-only features in Forge

The Admin section requires the Forge Admin role. A few actions also need a specific Salesforce permission set:

  • Payment gateway configuration (also needs Blackthorn Payments Admin).
  • Org-level fee management.
  • Beta feature opt-in (/beta page).
  • Email provider configuration.
  • Admin audit log.