Soru

Zorluk: OrtaRole Hierarchy and Sharing Rules

Apex Financial Services uses a custom object named Audit_Engagement__c with an Organization-Wide Default (OWD) set to Private. The 'Grant Access Using Hierarchies' setting is enabled for this object. Managers currently inherit access to records owned by their direct reports through the role hierarchy. The administrator must now ensure that members of the central Compliance Team, who reside in a separate branch of the role hierarchy at the same level as regional auditors, receive Read-Only access to all Audit Engagement records owned by regional auditors. Which two administrative actions should be performed to satisfy these requirements?

  1. Create an owner-based sharing rule that shares records owned by users in the Regional Auditor role with users in the Compliance Team role.Cevap
  2. B
    Deselect the 'Grant Access Using Hierarchies' option on the custom object to prevent managers from automatically inheriting access.
  3. Set the Access Level to Read-Only within the sharing rule configuration for the Compliance Team target group.Cevap
  4. D
    Assign a new Profile to Compliance Team members with 'View All' object permissions on Audit_Engagement__c.

Cevap

The administrator must create an owner-based sharing rule that shares records owned by users in the Regional Auditor role with users in the Compliance Team role, setting the rule access level to Read-Only.
To grant access across distinct role hierarchy branches when Organization-Wide Defaults are Private, an owner-based sharing rule must be configured. Setting the owner group to the Regional Auditor role, target group to the Compliance Team role, and access level to Read-Only satisfies the business requirement without granting excessive administrative permissions.

Adım Adım Çözüm

1
Analyze the baseline access settings and hierarchical behavior.
The OWD is Private, and 'Grant Access Using Hierarchies' ensures managers automatically inherit access to records owned by subordinates.
Keeping 'Grant Access Using Hierarchies' enabled satisfies the existing requirement for managerial visibility.
2
Determine the mechanism required to share records across role hierarchy branches.
Because Compliance Team members sit in a separate role hierarchy branch, automatic access via hierarchy does not apply to them. An owner-based sharing rule is required.
Sharing rules extend access laterally or across branches to roles, public groups, or territories.
3
Configure the sharing rule parameters.
Specify the owned records source (Regional Auditor role), the target group (Compliance Team role), and set the access level to Read-Only.
This grants exact lateral access without elevating administrative permissions or breaking hierarchy access.

Anahtar Kavram

Owner-Based Sharing Rules & Role Hierarchy Access propagation
Bu soruyu puanla