ALL: How do You Restrict the Object Level Access for Managed Permission Sets?
System administrators cannot directly alter managed permission sets from Certinia packages, as these modifications can disrupt package functionality. To restrict object-level access, administrators have two options. One option is to clone the existing permission set and then edit the new custom version. The second option is to create a muting permission set to restrict access granted by an existing set. It is a best practice to test any permission set restrictions in a sandbox environment before deploying to production.