Soru

Zorluk: ZorOrganization-Wide Defaults (OWD)

Northern Trail Outfitters uses a custom object named `Supplier_Audit__c` to store sensitive internal vendor reviews. Business requirements mandate that access must be restricted so that only the record owner has access to their assigned audits. Additionally, executive managers positioned higher in the role hierarchy must NOT automatically inherit access to these sensitive record reviews.

Which TWO configuration actions must a Salesforce administrator execute in Organization-Wide Defaults (OWD) to satisfy these security requirements? (Select TWO.)

  1. Set the Default Internal Access for Supplier_Audit__c to Private.Cevap
  2. Deselect the 'Grant Access Using Hierarchies' checkbox for the Supplier_Audit__c object.Cevap
  3. C
    Configure a Permission Set that revokes Read permissions on Supplier_Audit__c for management roles.
  4. D
    Set the profile-level Object Permissions for Supplier_Audit__c to 'View All' but disable sharing rule propagation.

Cevap

To enforce the most restrictive access baseline where only record owners have access and role hierarchy inheritance is disabled for a custom object, the administrator must set the Organization-Wide Default (OWD) to Private and deselect the 'Grant Access Using Hierarchies' setting on that custom object.
Organization-Wide Defaults (OWD) establish the baseline level of access for records in Salesforce. Setting the OWD of a custom object to Private ensures that non-owners cannot see records by default. Furthermore, while standard objects always grant access to superior roles in the role hierarchy, custom objects allow administrators to deselect 'Grant Access Using Hierarchies' to stop users higher in the role hierarchy from automatically gaining access to records owned by subordinates.

Adım Adım Çözüm

1
Determine the baseline record sharing access required for record owners.
Identify that setting the Organization-Wide Default (OWD) to Private restricts record visibility exclusively to the record owner by default.
OWD is the only mechanism in Salesforce used to restrict baseline record access across the organization.
2
Evaluate role hierarchy record access behavior for custom objects.
Recognize that Grant Access Using Hierarchies is enabled by default for custom objects, allowing management higher in the role hierarchy to view subordinate records even when OWD is Private.
To prevent managers from inheriting access, the 'Grant Access Using Hierarchies' option must be explicitly unchecked.
3
Verify profile and permission set capabilities regarding record restriction.
Confirm that profiles and permission sets control object/field access permissions and can only expand access, never restrict sharing access established by OWD.
Attempting to use permission sets or object permissions to restrict visibility violates core Salesforce security architecture.

Anahtar Kavram

Organization-Wide Defaults (OWD) and Grant Access Using Hierarchies settings for custom objects
Tahmini Süre:2m 0s
Bu soruyu puanla