A sales representative at Cloud Kicks owns a high-value opportunity and adds a solution engineer to the Opportunity Team with Read/Write access to help close the deal. The Organization-Wide Default (OWD) for Accounts and Opportunities is set to Private. Despite being added to the team, the solution engineer receives an access denied error when attempting to open the parent Account record associated with the opportunity. What is the root cause preventing the solution engineer from viewing the Account record?
- The solution engineer lacks object-level Read permission for the Account object in their assigned profile or permission set.Cevap
- BThe Organization-Wide Default for Accounts must be updated to Public Read/Write with Grant Access Using Hierarchies disabled.
- CA new profile must be created and assigned to the solution engineer to grant Modify All Data permissions for the Sales application.
- DImplicit sharing only applies when the Opportunity Team member is placed higher than the opportunity owner in the Role Hierarchy.
Cevap
The solution engineer lacks object-level Read permission for the Account object in their assigned profile or permission set.
In Salesforce security architecture, object-level permissions (configured via Profiles or Permission Sets) override record-level sharing settings. Opportunity Teams provide implicit record-level read access to parent Account records. However, if a user does not have Read permission on the Account object at the profile or permission set level, they cannot view any Account records regardless of team membership or sharing rules.
Adım Adım Çözüm
Anahtar Kavram
Interaction between Object-Level Security (Profile/Permission Set) and Record-Level Implicit Sharing in Opportunity Teams