Soru

Zorluk: OrtaOrganization-Wide Defaults (OWD)

A non-profit organization uses a custom object named Grant_Application__c to process confidential funding requests. Security rules dictate that staff members should only view and edit grant applications that they personally own. Additionally, because review committees operate independently, users holding higher management roles in the role hierarchy must NOT automatically receive access to records owned by their direct reports.

Which Organization-Wide Default (OWD) configuration should a Salesforce administrator implement on the Grant_Application__c object to satisfy these security mandates?

  1. Set Default Internal Access to Private and deselect the Grant Access Using Hierarchies checkbox.Cevap
  2. B
    Set Default Internal Access to Private while leaving Grant Access Using Hierarchies selected, because role hierarchy access cannot be disabled on custom objects.
  3. C
    Set Default Internal Access to Public Read-Only and create a restrictive profile to hide records from users higher in the role hierarchy.
  4. D
    Set Default Internal Access to Controlled by Parent and assign a permission set that revokes read access for manager roles.

Cevap

Set Default Internal Access to Private and deselect the Grant Access Using Hierarchies option for the custom object.
Configuring the Default Internal Access of the custom object to Private ensures that only record owners (and those explicitly shared) have access. For custom objects, Salesforce enables 'Grant Access Using Hierarchies' by default; unchecking this option stops users higher in the role hierarchy from automatically inheriting access to records owned by subordinates.

Adım Adım Çözüm

1
Determine the baseline access level required for record owners and non-owners.
Because non-owners should not automatically see or edit records owned by others, the baseline Organization-Wide Default (OWD) must be set to Private.
OWD sets the most restrictive baseline access for records across the organization.
2
Evaluate role hierarchy propagation requirements for the custom object.
By default, custom objects propagate record access up the role hierarchy via 'Grant Access Using Hierarchies'. Disabling this setting prevents manager roles from gaining access.
Unchecking 'Grant Access Using Hierarchies' stops implicit sharing roll-up to superior roles in the role hierarchy.

Anahtar Kavram

Organization-Wide Defaults (OWD) and Hierarchy Access Control on Custom Objects
Bu soruyu puanla