A global aviation maintenance company has 20 Aircraft Fleet Managers assigned to a standard baseline profile named 'Fleet Operations User'. Due to new regulatory guidelines, 4 of these managers need Read and Edit access to a custom object named 'Aircraft Inspection Logs' to record compliance data, while the remaining 16 managers should not have access to this object. Which administrative solution efficiently fulfills this access requirement without granting unnecessary permissions?
- Create a Permission Set granting Read and Edit access to the Aircraft Inspection Logs object and assign it to the 4 Fleet Managers who require the access.Answer
- BClone the 'Fleet Operations User' profile, enable Read and Edit access on the new profile for Aircraft Inspection Logs, and reassign the 4 Fleet Managers to this new profile.
- CModify the baseline 'Fleet Operations User' profile to grant Read and Edit access to Aircraft Inspection Logs, then use sharing rules to restrict access for the remaining 16 managers.
- DChange the Organization-Wide Defaults (OWD) for Aircraft Inspection Logs to Public Read/Write and assign a Muting Permission Set to the 16 managers.
Answer
Create a Permission Set granting Read and Edit access to the Aircraft Inspection Logs object and assign it to the 4 Fleet Managers who require access.
Permission Sets allow administrators to grant flexible, additive permissions (such as Object-Level Read and Edit access) to individual users or subsets of users without altering their underlying profile or creating new profiles.
Step-by-Step Solution
Key Concept
Using Permission Sets to grant additive object permissions to a subset of users sharing a profile