What you're setting up

A record-triggered flow in Salesforce watches for changes to a record — like a new account or contact — and automatically creates a portal user linked to that record. Instead of manually creating each portal user, the flow does it the moment the record meets your conditions.

This guide walks you through building that flow step by step. You'll set up a trigger, add the logic to create the user, and test it with a real record change. No coding required.

Key Takeaways

  • Record-triggered flows start automatically when a record is created or updated, so you define the trigger event and the conditions that must be true.
  • You need a contact or account record with an email address before the flow can create a portal user, because the portal user must have a valid email.
  • The flow uses the Create Records action to generate a new User record with the portal license type and links it to the source record.
  • Test your flow with a single record change first to catch errors before it runs on hundreds of records in production.

Before you start: what you need in place

Your Salesforce org must have a portal license type already created. This is the license that portal users receive. If you do not have one, ask your Salesforce admin to create it — it is a one-time setup in Setup under Licenses.

You also need a contact or account record with a valid email address. The portal user will use that email as their username. If the email field is blank, the flow will fail when it tries to create the user.

Finally, confirm you have permission to create flows. In Setup, go to User Permissions and check that your user has "Flow User" or higher permission. If you do not, ask your admin to grant it.

Creating the flow and setting the trigger

Open Setup and search for "Flows". Click New Flow, then select Record-Triggered Flow. Choose the object you want to watch — usually Contact or Account — and click Create.

Salesforce shows you the trigger configuration. Under "Trigger these actions", select whether the flow runs when a record is created, updated, or both. For a portal user flow, "created" is common, but you might choose "updated" if you want to create a user only when a specific field changes to a certain value.

Below that, set your conditions. Click Add Condition and choose the field that must be true before the flow runs. For example, you might add "Portal User Needed" equals "True", so the flow only runs when someone checks that box on the record. If you want the flow to run every time, leave the condition blank.

Adding the action to create the portal user

After the trigger is set, click the plus icon to add an action. Search for "Create Records" and select it. Name the action something clear like "Create Portal User".

Under "Record Type to Create", choose User. Salesforce shows you the fields you must fill in. Map each field to data from the triggering record:

  • Username: Use the email field from the contact or account. Salesforce requires a unique username, and email is the standard choice.
  • Email: Map this to the same email field.
  • FirstName and LastName: Pull these from the contact record if available.
  • UserLicense: Select your portal license type from the dropdown.
  • ProfileId: Choose the profile that controls what the portal user can see and do. This is usually a custom profile you created for portal users.
  • ContactId: Map this to the contact record ID. This links the user to the contact so they can see their own data in the portal.

Leave other fields blank unless your org requires them. Click Done when you finish mapping.

Testing the flow before you activate it

Before you turn the flow on, save it and click Test. Salesforce asks you to choose a real record that matches your trigger conditions. Select a test contact or account, then click Run Test.

If the test succeeds, you see a green checkmark and the ID of the new user created. Go to Setup, search for Users, and find that user in the list to confirm the details are correct.

If the test fails, Salesforce shows an error message. Common errors include a missing email address, a username that already exists, or a profile that does not have portal license permission. Fix the issue in your flow and test again.

Activating the flow and monitoring it

Once your test passes, click Activate. The flow is now live and will run every time a record matching your trigger is created or updated.

After activation, create or update a test record in your org and watch for the portal user to appear. Check Setup > Users within a few seconds. If the user appears with the correct email and profile, the flow is working.

If nothing happens, go back to the flow, click View Details, and check the Runs tab. Salesforce logs every time the flow runs and shows any errors. Use this to troubleshoot why a record did not trigger the flow.

Common issues and how to fix them

If you see "Username already exists", the email you are using is already assigned to another user. Either use a different email or add logic to the flow that checks whether a user with that email already exists before creating one.

If the flow runs but no user appears, check that the profile you selected actually has portal license permission. Go to Setup, find the profile, and look at the User License field. It should show your portal license type, not Standard or another type.

If the flow does not run at all, verify your trigger conditions. Go back to the flow, click the trigger, and confirm the record you created actually meets the conditions you set. For example, if you required a "Portal User Needed" checkbox to be true, make sure you checked that box when you created the test record.

Frequently Asked Questions

Can I create a portal user for an account instead of a contact?

Yes, but you need to use an account-triggered flow instead of a contact-triggered one. The process is the same — set the trigger to Account, map the account email to the user email, and link the user to the account using the AccountId field instead of ContactId. Some orgs use account portal users for company-level access.

What happens if I update a record that already has a portal user?

If your flow trigger is set to "created and updated", it will try to create a new user every time the record changes. This usually fails because the username already exists. To avoid this, either set the trigger to "created only" or add a condition that checks whether a portal user already exists for that record before running the flow.

Can I send the new portal user their password automatically?

No, Salesforce does not allow flows to set passwords. After the user is created, you must send them a password reset link manually or use a separate email notification. Some orgs add a Send Email action to the flow that notifies the user their account is ready and directs them to reset their password.

How do I stop the flow from running on certain records?

Add a condition to the trigger. For example, if you only want portal users created for contacts in a specific country, add a condition "Country equals United States". The flow will then only run when that condition is true. You can add multiple conditions and choose whether all must be true or just one.

What if the email field is empty when the record is created?

The flow will fail because Salesforce requires a username for every user. To prevent this, add a condition to the trigger that checks the email field is not empty. The flow will only run if an email exists, so you avoid errors on incomplete records.