Soru

Zorluk: OrtaRole Hierarchy and Sharing Rules

An administrator at a bio-pharmaceutical organization is configuring record access for a custom object named Patent_Filing__c. The Organization-Wide Default (OWD) for Patent_Filing__c is set to Private. During initial setup, the administrator deselected the 'Grant Access Using Hierarchies' setting on the custom object to restrict visibility. Executive leadership now requests that managers automatically receive access to Patent_Filing__c records owned by their direct and indirect subordinates within the existing role hierarchy. Which action should the administrator take to meet this requirement using native security capabilities?

  1. Select the 'Grant Access Using Hierarchies' checkbox on the Patent_Filing__c object definition settings.Cevap
  2. B
    Create a permission set granting 'View All' object permissions on Patent_Filing__c and assign it to managers in the role hierarchy.
  3. C
    Change the Organization-Wide Default (OWD) setting for Patent_Filing__c from Private to Public Read/Write.
  4. D
    Create a criteria-based sharing rule that shares records with the 'All Internal Users' public group whenever the owner has a manager assigned.

Cevap

Select the 'Grant Access Using Hierarchies' checkbox on the Patent_Filing__c object definition settings.
For standard objects, access is always granted through the role hierarchy. For custom objects, administrators can toggle the 'Grant Access Using Hierarchies' setting on or off. Enabling this setting ensures that users above record owners in the role hierarchy automatically inherit access to those records.

Adım Adım Çözüm

1
Analyze the record access requirement and existing settings.
The OWD is Private, and access propagation up the role hierarchy was explicitly disabled by deselecting 'Grant Access Using Hierarchies' on the custom object.
By default, custom objects have 'Grant Access Using Hierarchies' selected. Deselecting it prevents managers from accessing records owned by subordinates.
2
Evaluate native role hierarchy capabilities vs alternate sharing mechanisms.
Re-enabling 'Grant Access Using Hierarchies' restores automatic vertical record access for users higher in the role hierarchy.
This natively satisfies the requirement without exposing records organization-wide or requiring administrative overhead like custom permission sets or manual sharing rules.

Anahtar Kavram

Role Hierarchy & Grant Access Using Hierarchies for Custom Objects
Bu soruyu puanla