Meridian Global Logistics utilizes a custom object named Supplier_Contract__c with an Organization-Wide Default (OWD) set to Private. To prevent executive roles from automatically gaining access to sensitive operational records, the System Administrator deselects the 'Grant Access Using Hierarchies' option on Supplier_Contract__c. However, Regional Directors still require Read/Write access to Supplier_Contract__c records owned by Procurement Specialists who occupy roles below them. Which configuration should the administrator implement to meet this requirement?
- ACreate a permission set with 'View All' and 'Modify All' object permissions for Supplier_Contract__c and assign it to the Regional Directors.
- Create an owner-based sharing rule that shares Supplier_Contract__c records owned by the Procurement Specialist role with the Regional Director role.Cevap
- CRe-enable 'Grant Access Using Hierarchies' on Supplier_Contract__c because sharing rules cannot grant access when hierarchy sharing is turned off.
- DUpdate the Regional Director profile to grant Read and Edit object permissions on the Supplier_Contract__c object.
Cevap
Create an owner-based sharing rule that shares Supplier_Contract__c records owned by the Procurement Specialist role with the Regional Director role.
Creating an owner-based sharing rule specifically grants Read/Write access for records owned by the Procurement Specialist role to users in the Regional Director role. This satisfies the business requirement without re-enabling automatic hierarchy access or over-granting organization-wide record permissions through permission sets.
Adım Adım Çözüm
Anahtar Kavram
Disabling 'Grant Access Using Hierarchies' on custom objects stops automatic access rollout up the role hierarchy, but sharing rules can still explicitly share records between specific roles or groups.
Tahmini Süre:1m 30s