Let me provide a complete solution addressing all three focus areas:
Role Mapping Configuration:
First, understand that AEC partner portals use a different security model than your legacy system. You need to configure these components in order:
-
Partner Community Setup:
- Navigate to Setup > Communities > Partner Community
- Enable Partner Community if not already active
- Create Partner Community profiles for each tier:
- Gold_Partner_Profile
- Silver_Partner_Profile
- Bronze_Partner_Profile
-
Role Hierarchy Configuration:
Partner roles must be structured under partner account roles. Example hierarchy:
Partner Account: Acme Corp
├── Acme_Partner_Manager (account-level role)
│ ├── Acme_Gold_Partner_User
│ └── Acme_Silver_Partner_User
-
Legacy to AEC Role Mapping:
Create a mapping document:
- Legacy: Partner_Admin → AEC: Partner_Community_Manager (profile) + Partner_Account_Manager (role)
- Legacy: Gold_Partner → AEC: Gold_Partner_Profile + Gold_Partner_User (role)
- Legacy: Silver_Partner → AEC: Silver_Partner_Profile + Silver_Partner_User (role)
- Legacy: Bronze_Partner → AEC: Bronze_Partner_Profile + Bronze_Partner_User (role)
Permission Set Validation:
Create permission sets for functional capabilities:
-
Deal_Registration_Access Permission Set:
- Object: Opportunity (Create, Read, Edit)
- Object: Deal_Registration__c (All permissions)
- Field: Opportunity.Partner_Discount__c (Visible, Editable)
- Tab: Deal Registration (Visible)
-
Case_Submission_Access Permission Set:
- Object: Case (Create, Read)
- Object: Case Comment (Create, Read)
- Field: Case.Partner_Priority__c (Visible, Editable)
-
Opportunity_View_Access Permission Set:
- Object: Opportunity (Read only)
- Field: Opportunity.Amount (Visible)
- Report Folder: Partner Opportunities (Access)
Validation Process Before Migration:
1. Export partner user list with legacy roles
2. Create role mapping table (legacy role → AEC profile + role)
3. Validate each AEC profile exists: Setup > Profiles
4. Validate each permission set exists: Setup > Permission Sets
5. Test role hierarchy: Assign test user and verify record visibility
6. Test permission sets: Login as test user and verify object access
Custom Role Creation:
For each partner tier, create roles with proper naming convention:
-
Gold Partner Role Creation:
- Setup > Users > Roles > New Role
- Label: “Gold Partner User - [Account Name]”
- Report To: Partner Account Manager role
- Contact Access: Controlled by Parent
- Opportunity Access: Controlled by Parent
-
Permission Set Assignment Strategy:
- Gold Partners: All three permission sets (Deal Registration + Case Submission + Opportunity View)
- Silver Partners: Case Submission + Opportunity View
- Bronze Partners: Case Submission only
Import File Structure:
Your user import CSV must include these columns:
Username, Email, Profile, Role, PermissionSetGroup, AccountId
partner1@acme.com, partner1@acme.com, Gold_Partner_Profile, Gold_Partner_User_Acme, Gold_Partner_Permissions, 001xx000003DGHI
Post-Migration Validation Steps:
-
Role Assignment Verification:
- Run report: Users with Role = “Partner_User” (default)
- These users need role reassignment
- Use Data Loader to bulk update Role field
-
Permission Set Validation:
- Query: SELECT Id, Name, (SELECT AssigneeId FROM PermissionSetAssignments) FROM PermissionSet
- Verify each partner user has appropriate permission set assignments
- Missing assignments can be bulk-added via Data Loader
-
Access Testing:
- Login as partner user from each tier
- Verify object access matches tier permissions
- Test record visibility through role hierarchy
- Confirm tab visibility matches permission sets
Correcting Your Current Migration:
Since your 312 users are already imported with default access:
- Create all required profiles and permission sets (as detailed above)
- Create role hierarchy for each partner account
- Export current user list with their legacy role mappings
- Use Data Loader to update:
- User.ProfileId (map to correct partner profile)
- User.UserRoleId (assign correct role in hierarchy)
- Bulk assign permission sets using Setup > Permission Sets > Manage Assignments
- Validate access for 10-15 test users across different tiers
- Communicate access restoration to partner users
Best Practices:
- Always create security components (profiles, roles, permission sets) BEFORE user import
- Use permission set groups to bundle related permissions by tier
- Test role hierarchy with shared records to verify visibility
- Document role mapping for future partner onboarding
- Set up automated permission set assignment rules for new partners
This approach will restore proper access for your 312 partner users and establish a scalable security model for future partner onboarding.
This draft is based on general Adobe Experience Cloud knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.