Skip to main content
Security

What is Field-Level Security (FLS) in Salesforce?

FLS (Field-Level Security) controls which users can see or edit each field, set per profile or permission set. A field with no access is hidden everywhere: layouts, reports, list views and API responses.

Clientell AI, the AI Salesforce admin, audits your FLS setup in a read-only scan, then drafts the fixes for you to approve. See permission management

Try it in Clientell AI

“Audit my FLS setup: show where access is too open, list who has more than they need, and draft fixes for me to approve.”

Clientell reads your org first, drafts every change, and changes nothing until you approve. Platform deployments include rollback. How security works.

Start the 14-day free trial, no card

Term Context

Category

Security

7 terms in this category

Related Terms

4

connected concepts

Glossary

66

total definitions

How does FLS work in Salesforce?

FLS operates independently from object-level permissions and record-level access. A user might have Read access to the Account object and see a specific Account record, but FLS can hide the Annual Revenue field from their profile entirely. For each field, FLS settings are binary per profile or permission set: Visible (the user can see the field) and Read-Only (the user can see but not edit). If a field is not visible, it is completely hidden, absent from page layouts, reports, list views, and API responses for that user.

FLS is critical for compliance and data governance. Common scenarios include hiding SSN fields from non-HR users, making salary data read-only for managers, and restricting API-only integration fields from the UI. In Apex, FLS is not enforced by default unless the code uses WITH SECURITY_ENFORCED in SOQL or Security.stripInaccessible. Clientell AI audits FLS configurations across all profiles and permission sets, flagging fields that are unnecessarily exposed and generating remediation metadata.

Questions people ask

What does FLS mean in Salesforce?

FLS means Field-Level Security. For each field it sets whether a profile or permission set can see it or edit it.

What are the FLS settings?

Visible and Read-Only. If a field is not visible, it is hidden from page layouts, reports, list views and API responses for that user.

Does Apex respect field-level security?

Not by default. Add WITH SECURITY_ENFORCED to your SOQL or use Security.stripInaccessible to enforce it.

Can FLS hide a field when the user has access to the object?

Yes. FLS works apart from object and record access. A user can open an Account and still not see Annual Revenue.

How do I keep field-level security when I deploy a new field?

A new field arrives with no access unless the profile or permission set that grants it travels with it. Include that permission set in the same deployment.

Getting Started

Try this on your own org

Start the 14-day free trial, no card. Clientell scans read-only first and changes nothing until you approve.

14-day free trial  ·  No credit card required

SOC 2
HIPAA
GDPR
Salesforce Partner