Question

Difficulty: HardDashboard Running User and Visibility Settings

Apex Global Operations wants to provide regional sales managers with insights into their team's opportunity performance while maintaining strict data security. The administrator is evaluating whether to configure a static dashboard using the VP of Sales as the running user or to set up a dynamic dashboard where the running user is set to 'the logged-in user'. Which two statements accurately describe the security and data visibility implications of these dashboard running user settings? (Select 2 options)

  1. When configured as a dynamic dashboard, data displayed in components is restricted to what the logged-in user has access to based on Organization-Wide Defaults, role hierarchy, and sharing rules.Answer
  2. B
    Configuring a static dashboard with the VP of Sales as the running user grants viewing users the ability to drill down and edit underlying records that they otherwise cannot access.
  3. C
    Dynamic dashboards allow logged-in users to override organization-wide defaults and export detailed report data for records outside their assigned territory.
  4. A static dashboard set to run as the VP of Sales allows all users with access to the dashboard folder to view aggregated data on components, even for records those users cannot individually access.Answer
  5. E
    Setting a dynamic dashboard automatically overrides folder access settings, granting all internal users view access to the dashboard regardless of folder permissions.

Answer

The correct statements are that dynamic dashboards restrict displayed data strictly to what the logged-in user has access to based on OWD and sharing permissions, and static dashboards allow viewers to see summarized component metrics based on the static running user's access level without granting direct access to the underlying records.
In Salesforce, dynamic dashboards execute using the logged-in user's context, displaying only data they have security access to view. Conversely, static dashboards display component data calculated using the designated running user's context, allowing viewers to see aggregated totals while continuing to enforce standard record-level sharing when users attempt to access underlying records.

Step-by-Step Solution

1
Analyze static running user security behavior
Components display data according to the running user's data security context (e.g., VP of Sales), allowing viewers to see aggregate metric totals without elevating their permissions to view or edit individual underlying records.
Static running user configurations determine component data visibility at the dashboard level while preserving underlying record sharing controls.
2
Analyze dynamic running user security behavior
Components dynamically recalculate data based on the logged-in viewer's security credentials, adhering to OWD, role hierarchy, and sharing rules.
Dynamic dashboards ensure that users only see data they are explicitly authorized to view.
3
Evaluate folder access vs. running user settings
Folder sharing determines who can open the dashboard, while running user settings determine what data is displayed inside the dashboard.
Folder access and running user settings operate independently as distinct layers of dashboard security.

Key Concept

Dashboard Running User and Data Security
Rate this question