Soru

Zorluk: OrtaOrganization-Wide Defaults (OWD)

A wealth management firm tracks sensitive private market deals using a custom object named Private_Investment__c. Executive management mandates that standard advisors should only access investment records they own. Furthermore, due to strict regulatory compliance, managers higher in the role hierarchy must NOT automatically inherit record access to investments owned by their direct reports. Which TWO configuration settings must the administrator implement to fulfill these security requirements? (Select TWO answers.)

  1. Set the Organization-Wide Default (OWD) internal access for Private_Investment__c to Private.Cevap
  2. Deselect the 'Grant Access Using Hierarchies' checkbox for the Private_Investment__c custom object in Organization-Wide Sharing Settings.Cevap
  3. C
    Create a custom profile for managers that revokes Read permission on Private_Investment__c records owned by subordinates.
  4. D
    Assign a permission set to executive managers that disables the 'Grant Access Using Hierarchies' setting for Private_Investment__c.

Cevap

To meet the compliance requirements, the administrator must set the Organization-Wide Default (OWD) for the Private_Investment__c custom object to Private and uncheck the 'Grant Access Using Hierarchies' setting on the object's organization-wide sharing default configuration.
Setting the OWD internal access to Private ensures that users have no access to records owned by others by default. For custom objects, deselecting the 'Grant Access Using Hierarchies' setting prevents higher-level roles in the hierarchy from gaining automatic record access to records owned by subordinates.

Adım Adım Çözüm

1
Determine baseline record visibility
Setting the Organization-Wide Default (OWD) to Private ensures that standard users cannot see records owned by other users.
OWD defines the most restrictive baseline level of data access across the entire organization.
2
Evaluate role hierarchy propagation for custom objects
Deselecting 'Grant Access Using Hierarchies' disables automatic access propagation up the role hierarchy.
By default, Salesforce enables hierarchy access for custom objects. Explicitly unchecking this setting prevents managers from automatically seeing records owned by lower roles.

Anahtar Kavram

Organization-Wide Defaults and Hierarchy Access for Custom Objects
Bu soruyu puanla