Soru

Zorluk: OrtaRole Hierarchy and Sharing Rules

Aura Solar Solutions uses a custom object named Installation_Project__c to track engineering projects. The Organization-Wide Default (OWD) for Installation_Project__c is set to Private, and the 'Grant Access Using Hierarchies' setting is currently unchecked on the object definition.

Management requires the following access configuration:
1. Regional Operations Managers must regain automatic access to Installation_Project__c records owned by users below them in the role hierarchy.
2. Members of the Safety Compliance Team must receive Read access to any Installation_Project__c record where the Risk_Level__c field is set to 'High', regardless of record ownership.

Which TWO configurations should the System Administrator implement to meet these access requirements?

  1. Select the 'Grant Access Using Hierarchies' checkbox on the Installation_Project__c object definition.Cevap
  2. B
    Change the Organization-Wide Default (OWD) for Installation_Project__c from Private to Public Read/Only.
  3. Create a criteria-based sharing rule on Installation_Project__c where Risk_Level__c equals 'High' to share Read access with the Safety Compliance public group.Cevap
  4. D
    Assign a permission set with 'View All' object permission on Installation_Project__c to the Safety Compliance Team users.
  5. E
    Create an owner-based sharing rule to grant Read access to higher roles while keeping 'Grant Access Using Hierarchies' unchecked.

Cevap

The administrator must enable 'Grant Access Using Hierarchies' on the Installation_Project__c custom object and create a criteria-based sharing rule granting Read access to the Safety Compliance public group when Risk_Level__c equals 'High'.
To restore manager access up the role hierarchy, the 'Grant Access Using Hierarchies' option must be enabled on the object configuration. To conditionally share specific records based on a field value ('Risk_Level__c = High'), a criteria-based sharing rule targeting the appropriate public group is the exact recommended mechanism.

Adım Adım Çözüm

1
Address role hierarchy access for managers.
Checking 'Grant Access Using Hierarchies' on the object settings enables automatic upward access propagation along the role hierarchy for custom objects.
When unchecked, custom object records are not shared with users higher in the role hierarchy unless explicit sharing rules or OWD changes are made.
2
Address selective access based on record field values.
Configure a criteria-based sharing rule on Installation_Project__c checking if Risk_Level__c equals 'High' and sharing Read access with the Safety Compliance Team public group.
Criteria-based sharing rules evaluate field criteria on individual records to grant access to designated public groups or roles without altering baseline OWD settings.

Anahtar Kavram

Role Hierarchy propagation settings and Criteria-Based Sharing Rules
Tahmini Süre:1m 30s
Bu soruyu puanla