Soru

Zorluk: OrtaPermission Sets and Permission Set Groups

A biopharmaceutical company has 150 Clinical Research Associates assigned to a single baseline profile named 'Clinical CRA'. Due to new compliance requirements, a subset of 12 Clinical Research Associates requires temporary Edit access to a custom object named 'Audit Log' for 90 days, while the remaining 138 users must maintain their existing access level. Which solution should the administrator implement to grant this access while maintaining security best practices?

  1. Create a permission set granting Read and Edit access on the Audit Log object, configure an assignment expiration date of 90 days, and assign it to the 12 Clinical Research Associates.Cevap
  2. B
    Clone the baseline 'Clinical CRA' profile, grant Read and Edit access on the Audit Log object in the cloned profile, and reassign the 12 Clinical Research Associates to the new profile.
  3. C
    Modify the baseline 'Clinical CRA' profile to grant Read and Edit access on the Audit Log object, then create a validation rule to block access for the remaining 138 users.
  4. D
    Create a standalone Muting Permission Set that revokes Edit access on the Audit Log object and assign it directly to the 138 users who do not need access.

Cevap

Create a permission set granting Read and Edit access on the Audit Log object, configure an assignment expiration date of 90 days, and assign it to the 12 Clinical Research Associates.
Permission sets are designed to extend functional access to specific users without modifying baseline profile settings. Using User Assignment Expiration allows administrators to specify an expiration period (such as 90 days), after which access automatically expires.

Adım Adım Çözüm

1
Analyze the access requirement
Identified that 12 users out of 150 require additive, temporary (90-day) object access beyond the baseline profile.
Salesforce security model recommends keeping profiles lean for baseline access and using permission sets for additive access.
2
Determine permission set functionality required
A permission set with object-level Read and Edit access for 'Audit Log' combined with User Assignment Expiration.
Permission Set User Assignment Expiration automatically revokes user access after the specified period (90 days) without manual intervention.
3
Evaluate alternative options against security best practices
Rejected profile cloning and modifying baseline profile due to administrative overhead and improper access expansion.
Profile changes impact baseline permissions unnecessarily, whereas muting permission sets only function inside Permission Set Groups.

Anahtar Kavram

Additive permissions via Permission Sets and temporary access using User Assignment Expiration
Bu soruyu puanla