Soru

Zorluk: OrtaDashboard Running User and Visibility Settings

Horizon Fleet Services uses a Private Organization-Wide Default (OWD) sharing model for Cases. The Director of Customer Service requests a dashboard that allows regional service managers to view real-time case metrics. However, each manager must only see case records that they own or have explicit sharing access to. Currently, when regional managers open the dashboard, they are seeing aggregated company-wide metrics across all regions. Which two configurations should the Salesforce administrator perform to resolve this issue? (Select 2 options)

  1. Configure the dashboard running user setting to 'Run as the viewing user'.Cevap
  2. Grant 'View' access on the dashboard folder to the regional service managers.Cevap
  3. C
    Change the Organization-Wide Defaults for the Case object from Private to Public Read-Only.
  4. D
    Assign the 'View All Data' permission to the regional service manager profiles.
  5. E
    Add a custom filter on the underlying source report specifying 'Run as Logged-In User'.

Cevap

To ensure that regional managers only see metrics for cases they have permissions to view, the administrator must configure the dashboard running user setting to 'Run as the viewing user' (making it a dynamic dashboard) and ensure the regional managers have 'View' access to the dashboard folder.
Configuring the dashboard to 'Run as the viewing user' (a dynamic dashboard) ensures that data displayed in dashboard components is calculated using the security context and record access of whoever is logged in and viewing the dashboard. Additionally, sharing the dashboard folder with 'View' permissions enables those users to locate and run the dashboard while respecting their individual record-level access control.

Adım Adım Çözüm

1
Identify the root cause of the unauthorized data exposure on the dashboard.
The dashboard was configured with a static running user (such as an executive or administrator with broad data access), which causes components to display data according to that static user's security permissions.
Static running users evaluate component security for all viewers based on the running user's OWD and sharing permissions.
2
Update the dashboard security settings to enforce dynamic user access.
Configuring the dashboard running user property to 'Run as the viewing user' ensures that metrics are calculated dynamically according to each individual logged-in user's record visibility.
Dynamic dashboards honor the viewing user's Organization-Wide Defaults, role hierarchy, and sharing rules.
3
Verify dashboard folder sharing permissions.
Granting 'View' access on the shared dashboard folder ensures that the intended regional service managers can access and render the dynamic dashboard.
Folder access governs who can access the dashboard file itself, independent of the record-level security within the underlying data.

Anahtar Kavram

Dynamic Dashboard Security and Running User Configuration
Tahmini Süre:1m 30s
Bu soruyu puanla