Personas & Permission Sets
Pinion ships nine permission sets, each modeling a persona. You grant a user the set(s) that match their role. Every set includes the Pinion Home floor (a minimal landing-page grant), so users always have somewhere to land.
The sets
| Permission set | Persona — what it grants |
|---|---|
| Pinion Administrator | Full admin. The entire configuration surface — rules, pricing, bundles, attributes, discount schedules, licensing, config promotion, deploy logs — plus every Pinion custom permission. This is the set that lets someone administer the package. |
| Pinion User | The paid configurator seat. The standard end-user who builds deals: the configurator/QLE, rules, pricing, bundles, attributes, quotes, subscriptions. Does not include the admin-only license / config-promotion objects. |
| Pinion Approver | Approvals actor. The approval objects and platform events, plus Opportunity/Quote access — enough to review and decide approval requests. |
| Pinion Account Manager | Post-sale account owner. Accounts, contracts, subscriptions, amendment versions, contracted prices, quote templates/routing — the renewal/amendment-facing surface. Creates amendments and renewals from the Account Manager app and the Contract record actions. |
| Pinion Deal Desk | Deal-desk reviewer. The approver surface plus pricing-override objects (block price, contracted price, usage rates) for desk-level price control. |
| Pinion Quote Manager | Document/template owner. Quote templates and versions, segment templates, merge tokens, template routing and translation, generated quotes. |
| Pinion RevOps Manager | RevOps / analytics. Subscriptions, amendment versions, price dimensions, contracted prices, subscription-change events — the reporting-and-lifecycle surface that pairs with the RevOps dashboard. Runs Mass Renewal, and creates amendments and renewals from the Contract record actions. |
| Pinion MCP User | OAuth grouping only. Names the users allowed to connect through the packaged Pinion MCP External Client App. It grants no CRUD and no tool entitlement — the MCP runtime is gated separately (Pinion+). See AI Assistant Access. |
| Pinion Home | The minimal floor. Basic read on Account / Contract / Opportunity / Subscription and the Pinion Home landing page. Included by every other set. |
Apps each set opens
Each Pinion app loads on its own, so the set that owns an app is enough to open it. A user does not need Pinion User to reach a free persona’s app.
| App | Opened by |
|---|---|
| Pinion Home | Pinion Home |
| Configurator and Product Display | Pinion User |
| Pinion Admin | Pinion Administrator; Pinion Quote Manager (the Quote Template editor) |
| Product Manager | Pinion Administrator |
| Pinion Approvals | Pinion Approver, Pinion Deal Desk |
| Pinion Account Manager | Pinion Account Manager |
| Pinion RevOps | Pinion RevOps Manager |
| Pinion Deal Desk | Pinion Deal Desk |
Pinion MCP User opens no app.
The paid / free line
The dividing line is author vs monitor-and-decide, not read vs write:
- Paid seats — Pinion User (the configurator/QLE) and Pinion Administrator (authoring rules, templates, schedules) — buy the ability to build deals and configure the product.
- Free personas — Approver, Account Manager, Deal Desk, RevOps Manager, Quote Manager — give moderate, role-scoped access to monitor, decide, and triage without a configurator seat. An approver decides for free; a RevOps manager can mass-renew; an account manager runs the post-sale surface. These personas execute lifecycle actions (amend / renew / extend) through standard user-mode DML, so they carry the standard object CRUD those actions need — that’s free-tier-appropriate, not a system-mode carve-out.
Amendments and renewals on the free personas
Pinion Account Manager and Pinion RevOps Manager can each create an amendment or a renewal from a contract without a paid seat. What they get:
| Action | Account Manager | RevOps Manager |
|---|---|---|
| Amend a contract (Account Manager app, Contract record Amend) | Yes | Yes (Contract record) |
| Renew a contract (Account Manager app, Contract record Renew) | Yes | Yes (Contract record) |
| Mass Renewal (RevOps app) | — | Yes |
Pinion lays the new amendment or renewal down for them, carrying the contract’s products, quantities, and prices forward exactly as it would for an administrator. The two personas therefore carry create and edit access on Opportunity, Opportunity Product, Quote, and Quote Line Item, the Pinion line fields those records are written with (including the contract start, term and end on the Opportunity and its Quote), and read access to the product and pricing configuration the prices are resolved from.
What they still cannot do is open the configurator or quote line editor to change the products or prices on that deal afterwards. That remains a paid Pinion User seat. An account manager who needs to edit the lines of an amendment hands it to a rep, or is also assigned Pinion User.
Assigning them
Assign permission sets the standard Salesforce way (Setup → Permission Sets → Manage Assignments), or run the packaged assignment script during org setup. The Setup Wizard checks that the running admin has the required sets and flags any that are missing.
Related
- Licensing & Feature Gates — the feature-tier axis, distinct from these seats.
- Setup Wizard — verifies permission-set assignment.
- AI Assistant Access — how the MCP User set gates connections.