Soru

Zorluk: OrtaOrganization-Wide Defaults (OWD)

A wealth advisory firm uses a custom object named Investment_Portfolio__c to track high-net-worth client asset allocations. The company's security policy mandates that portfolio advisors should only view and edit portfolios they personally own. However, regional directors above those advisors in the role hierarchy must automatically inherit full view and edit access to all portfolios owned by their direct and indirect subordinates. Peer advisors in different branches must have no access to each other's portfolio records. Which TWO configurations must the administrator implement to establish this baseline access model? (Select TWO)

  1. Set the Default Internal Access for the Investment_Portfolio__c object to Private.Cevap
  2. Ensure the Grant Access Using Hierarchies setting remains selected for the Investment_Portfolio__c object.Cevap
  3. C
    Set the Default Internal Access to Public Read-Only and assign custom profiles to restrict record access between peer advisors.
  4. D
    Deselect the Grant Access Using Hierarchies checkbox on the Investment_Portfolio__c object and use permission sets to grant manager access.

Cevap

To enforce the required security model, the administrator must set the Default Internal Access for Investment_Portfolio__c to Private and ensure that Grant Access Using Hierarchies is checked.
Setting the Default Internal Access to Private ensures that record access is restricted to record owners by default. Keeping Grant Access Using Hierarchies enabled ensures that managers situated higher in the role hierarchy automatically inherit access to records owned by their subordinates.

Adım Adım Çözüm

1
Determine the most restrictive baseline access required for peer users.
Since peer advisors must not see each other's records, the baseline Organization-Wide Default (OWD) must be set to Private.
OWD is the only mechanism that sets the base level of record-level access across the organization.
2
Evaluate manager access requirements above record owners in the reporting structure.
Keep the 'Grant Access Using Hierarchies' checkbox selected on the custom object configuration.
For custom objects, Grant Access Using Hierarchies is checked by default and allows users above the record owner in the role hierarchy to automatically inherit access.

Anahtar Kavram

Organization-Wide Defaults (OWD) and Role Hierarchy Record Access
Bu soruyu puanla