Soru

Zorluk: OrtaOrganization-Wide Defaults (OWD)

A corporate training firm uses a custom object named Certification_Attempt__c to track employee exam results. Executive leadership mandates that test results must remain confidential: individual employees should only see their own exam records, while managers higher in the role hierarchy must be able to view and edit records owned by their direct reports. No other users should have access to records they do not own. Which Organization-Wide Default (OWD) configuration meets these security requirements?

  1. Set the Default Internal Access for Certification_Attempt__c to Private and keep Grant Access Using Hierarchies selected.Cevap
  2. B
    Set the Default Internal Access for Certification_Attempt__c to Public Read/Write and remove Object Read permissions on profiles of non-manager users.
  3. C
    Set the Default Internal Access for Certification_Attempt__c to Private and deselect Grant Access Using Hierarchies, creating criteria-based sharing rules for managers.
  4. D
    Set the Default Internal Access for Certification_Attempt__c to Public Read-Only and assign permission sets to restrict visibility for peers.

Cevap

Set the Default Internal Access for Certification_Attempt__c to Private and keep Grant Access Using Hierarchies selected.
Setting the Organization-Wide Default (OWD) to Private restricts baseline record access so users can only view and edit records they own. Leaving 'Grant Access Using Hierarchies' enabled ensures that users higher in the role hierarchy automatically inherit the owner's access level, fulfilling the requirement for manager access without exposing data to peers.

Adım Adım Çözüm

1
Determine the most restrictive baseline access required by the business scenario.
Since employees must not see records owned by peers, the Organization-Wide Default (OWD) must be set to Private.
OWD defines the baseline level of access for all users in the org.
2
Evaluate how managerial access should be granted.
Retain the default setting 'Grant Access Using Hierarchies' enabled.
For custom objects, Grant Access Using Hierarchies is checked by default and allows users above the record owner in the role hierarchy to inherit the owner's access level.
3
Verify that profiles or permission sets are not being used to restrict baseline access.
Confirm that OWD provides the restrictive foundation, rather than attempting profile-level restrictions.
In the Salesforce security model, profiles and permission sets grant permissions and cannot revoke access provided by OWD.

Anahtar Kavram

Organization-Wide Defaults (OWD) establish the baseline record-level access. Setting an OWD to Private ensures users only access records they own, while Grant Access Using Hierarchies automatically propagates access up the role hierarchy.
Bu soruyu puanla