Soru

Zorluk: OrtaOrganization-Wide Defaults (OWD)

An administrator is setting up record sharing for two custom objects: Project_Milestone__c and Internal_Audit__c. The business requires that users only see their own Project_Milestone__c records, but managers in the role hierarchy must automatically inherit access to records owned by their subordinates. Conversely, for Internal_Audit__c, baseline access must be restricted so that record access does NOT automatically propagate up the role hierarchy to managers above the record owner.

Which two security configurations should the administrator implement to satisfy these requirements?

  1. Set the Organization-Wide Default for Project_Milestone__c to Private and ensure 'Grant Access Using Hierarchies' is selected.Cevap
  2. Set the Organization-Wide Default for Internal_Audit__c to Private and deselect 'Grant Access Using Hierarchies'.Cevap
  3. C
    Set the Organization-Wide Default for Internal_Audit__c to Public Read-Only and assign a restrictive profile to upper management to revoke read access.
  4. D
    Set the Organization-Wide Default for Project_Milestone__c to Public Read-Only and deselect 'Grant Access Using Hierarchies'.

Cevap

The administrator must set the Organization-Wide Default for Project_Milestone__c to Private with 'Grant Access Using Hierarchies' selected, and set the Organization-Wide Default for Internal_Audit__c to Private while deselecting 'Grant Access Using Hierarchies'.
Organization-Wide Defaults establish baseline record access for non-owners. Setting OWD to Private restricts visibility to record owners. For custom objects, 'Grant Access Using Hierarchies' is enabled by default, propagating access up the role hierarchy. To prevent managers from inheriting access to custom object records, an administrator must deselect 'Grant Access Using Hierarchies'.

Adım Adım Çözüm

1
Determine the baseline Organization-Wide Default (OWD) setting for Project_Milestone__c.
Because users must only view their own records, the baseline access must be set to Private.
OWD sets the most restrictive baseline access for records not owned by a given user.
2
Configure role hierarchy access propagation for Project_Milestone__c.
Keep 'Grant Access Using Hierarchies' enabled.
Enabling hierarchy access allows managers in the role hierarchy to inherit access to records owned by their subordinates.
3
Determine the OWD and role hierarchy settings for Internal_Audit__c.
Set OWD to Private and deselect 'Grant Access Using Hierarchies'.
Deselecting 'Grant Access Using Hierarchies' on custom objects prevents automatic access propagation to managers higher up the role hierarchy.

Anahtar Kavram

Organization-Wide Defaults and Role Hierarchy Access Control for Custom Objects
Bu soruyu puanla