Soru

Zorluk: OrtaPermission Sets and Permission Set Groups

A financial compliance software company has 40 customer support representatives assigned to a baseline profile named 'Standard Support Specialist'. During an upcoming 30-day compliance review, 8 tier-2 representatives require temporary Read and Edit access to a custom object named Compliance Audit. The remaining support representatives must not have access to this object. What is the recommended administrative solution to satisfy this requirement while preserving a clean security model?

  1. Create a Permission Set granting Read and Edit access to the Compliance Audit object, assign it to the 8 tier-2 representatives with an assignment expiration date, and keep the baseline profile unchanged.Cevap
  2. B
    Clone the 'Standard Support Specialist' profile, grant Read and Edit access to the Compliance Audit object on the new profile, and reassign the 8 tier-2 representatives to this cloned profile.
  3. C
    Modify the baseline 'Standard Support Specialist' profile to grant Read and Edit permissions on Compliance Audit, then assign a Muting Permission Set directly to the remaining 32 representatives.
  4. D
    Adjust the Role Hierarchy to place the 8 tier-2 representatives in a higher role and grant Object-Level Security via sharing rules.

Cevap

Create a Permission Set granting Read and Edit access on the Compliance Audit object, assign it to the 8 tier-2 representatives with a specified assignment expiration date, and leave the baseline profile unchanged.
The correct approach is to keep the baseline profile intact and assign a custom Permission Set containing Read and Edit access on the Compliance Audit object to the 8 tier-2 representatives. Using assignment expiration allows the temporary access to automatically revoke after 30 days without manual intervention or profile maintenance.

Adım Adım Çözüm

1
Identify the base security architecture and requirements
All 40 representatives share a baseline profile ('Standard Support Specialist'), but only 8 require extra object permissions for a temporary 30-day period.
Profiles establish baseline access for job functions, whereas permission sets extend access for specific sub-teams or tasks.
2
Determine the appropriate tool for additive, temporary access
Create a dedicated Permission Set granting Read and Edit permissions to the Compliance Audit object.
Permission Sets provide additive permissions without requiring profile duplication or modifying broad user access.
3
Configure assignment expiration
Assign the permission set to the 8 tier-2 representatives and set an expiration date of 30 days.
Permission Set assignment expiration automatically revokes access after the audit concludes, removing the need for manual administrative cleanup.

Anahtar Kavram

Additive permissions via Permission Sets and Permission Set Expiration
Bu soruyu puanla