Soru

Zorluk: OrtaRole Hierarchy and Sharing Rules

Nova Health System tracks third-party compliance assessments using a custom object named Vendor_Security_Review__c. The Organization-Wide Default (OWD) sharing setting for Vendor_Security_Review__c is set to Private. During initial object configuration, a system administrator cleared the 'Grant Access Using Hierarchies' checkbox for this object. Later, a Compliance Manager created several assessment records. The VP of Compliance, who occupies a higher position in the role hierarchy above the Compliance Manager, is unable to view or edit these records. Which configuration change should the administrator make to allow the VP of Compliance to access these records without changing the OWD to public?

  1. Select the 'Grant Access Using Hierarchies' checkbox on the Vendor_Security_Review__c custom object definition.Cevap
  2. B
    Change the Organization-Wide Default (OWD) sharing setting for Vendor_Security_Review__c from Private to Public Read/Write.
  3. C
    Create and assign a permission set containing the 'View All Data' administrative system permission to the VP of Compliance.
  4. D
    Configure an owner-based sharing rule that shares all records owned by the Compliance Manager role with the VP of Compliance role.

Cevap

Select the 'Grant Access Using Hierarchies' checkbox on the Vendor_Security_Review__c custom object definition.
For custom objects, the 'Grant Access Using Hierarchies' option determines whether users higher in the role hierarchy receive access to records owned by or shared with subordinates. Selecting this checkbox on the object definition resolves the issue while keeping Organization-Wide Defaults Private.

Adım Adım Çözüm

1
Analyze the access issue
The VP of Compliance sits above the record creator in the role hierarchy, but cannot view records despite being higher in the hierarchy.
For standard objects, hierarchy access is mandatory and cannot be disabled. For custom objects, hierarchy access can be toggled off via the 'Grant Access Using Hierarchies' setting.
2
Identify the cause of disabled access
The administrator explicitly unchecked 'Grant Access Using Hierarchies' on the custom object definition.
Deselecting this option prevents managers and executive roles from automatically receiving implicit access to records owned by subordinates.
3
Determine the optimal administrative solution
Re-enable 'Grant Access Using Hierarchies' on the object definition.
Enabling this checkbox allows users higher in the role hierarchy to inherit record access while leaving the Organization-Wide Default setting at Private.

Anahtar Kavram

Role Hierarchy Access Inheritance on Custom Objects
Bu soruyu puanla