Soru

Zorluk: ZorOrganization-Wide Defaults (OWD)

A healthcare company tracks sensitive employee safety compliance reports using a custom object named Safety_Incident__c. Business governance requires that baseline visibility to these records be restricted so that only the record owner and managers above them in the role hierarchy can view or edit the records. Users outside of the owner's direct role hierarchy line must have no access to these records. Which configuration of Organization-Wide Defaults (OWD) and hierarchy access settings correctly fulfills this requirement?

  1. Set the Organization-Wide Default for Safety_Incident__c to Private and ensure Grant Access Using Hierarchies is checked.Cevap
  2. B
    Set the Organization-Wide Default for Safety_Incident__c to Private and uncheck Grant Access Using Hierarchies.
  3. C
    Set the Organization-Wide Default for Safety_Incident__c to Public Read-Only and assign a profile that removes Read access to records not owned by the user.
  4. D
    Set the Organization-Wide Default for Safety_Incident__c to Public Read/Write and apply a Permission Set Group to revoke visibility from non-owners.

Cevap

Set the Organization-Wide Default for Safety_Incident__c to Private and ensure Grant Access Using Hierarchies is checked.
The correct option sets the Organization-Wide Default (OWD) to Private, which restricts default record access so non-owners cannot see the records. Keeping 'Grant Access Using Hierarchies' enabled ensures that managers higher in the role hierarchy inherit access to records owned by their subordinates.

Adım Adım Çözüm

1
Analyze the record-level security requirements.
Baseline access must restrict visibility to only the record owner and users higher in the role hierarchy.
Salesforce security architecture relies on Organization-Wide Defaults (OWD) to define the most restrictive baseline access level across the org.
2
Select the appropriate Organization-Wide Default setting.
Setting OWD to Private ensures users who do not own the record are granted no access by default.
Public Read-Only or Public Read/Write would grant record access to all users across the organization, which violates privacy requirements.
3
Evaluate hierarchy access for the custom object.
Keep 'Grant Access Using Hierarchies' checked.
For custom objects, 'Grant Access Using Hierarchies' is enabled by default and ensures users above the owner in the role hierarchy automatically inherit access to the records.

Anahtar Kavram

Organization-Wide Defaults (OWD) and Hierarchy Access
Bu soruyu puanla