PermLens: find out where Salesforce access comes from.
It answers the question every admin and consultant asks every week: "why can this user see or edit this, and what grants that access?". It consolidates Profile, Permission Sets, FLS, and record access into a single panel, and shows the source of every permission. Runs 100% in your browser, nothing leaves your machine.
What PermLens does
Object access
Effective CRUD per object (Read, Create, Edit, Delete, View All, Modify All), with the Profile or Permission Set that grants each right.
Fields (FLS)
Per-field read/edit matrix, with each permission traced back to its source.
Record access
Open a record and see your effective access and who else can reach that specific record.
Compare users
Two users side by side, with differences highlighted. Perfect for "why does A see it but B doesn't?".
Export CSV
Export the access report from any grid, ready to attach to a ticket or an audit.
100% in your browser
Uses your own logged-in session to call only your org's APIs. No server, no sign-up, nothing leaves your machine.
In three steps
Open Salesforce
In any tab of your org where you are already logged in.
Click PermLens
The panel opens beside your org. Pick a user or the record open in the tab.
See the source
The access picture appears instantly, explaining where each permission comes from.
Support & contact
A question, suggestion, or bug in PermLens? Reach out and I'll answer directly. The extension is maintained by Witor Lomazzi.