Soru

Zorluk: KolayRole Hierarchy and Sharing Rules

A company uses a custom object named Project_Proposal__c with an Organization-Wide Default (OWD) set to Private. The administrator needs to ensure that managers automatically gain record access to proposals created by their direct subordinates in the role hierarchy, and that all members of the Finance team have read-only access to all proposals. Which two administration settings will fulfill these requirements? (Select 2)

  1. Ensure 'Grant Access Using Hierarchies' remains enabled for the Project Proposal custom object.Cevap
  2. Create a sharing rule to share all Project Proposal records with the Finance role or public group with Read-Only access.Cevap
  3. C
    Create a permission set with Read access on the Project Proposal object and assign it to the Finance team members.
  4. D
    Deselect 'Grant Access Using Hierarchies' on the Project Proposal object to allow manager access through role assignment.

Cevap

The correct configurations are ensuring 'Grant Access Using Hierarchies' remains enabled for automatic manager access via the role hierarchy, and creating a sharing rule granting Read-Only access to the Finance role or public group.
For custom objects with Private OWD, enabling 'Grant Access Using Hierarchies' ensures managers inherit record visibility from subordinate record owners. Additionally, a sharing rule is the standard mechanism to grant access to a broader group of users like the Finance team beyond OWD.

Adım Adım Çözüm

1
Evaluate record access requirements for managers.
Manager access up the role hierarchy is provided by default when 'Grant Access Using Hierarchies' is enabled on custom objects.
This setting ensures superior roles automatically inherit record access granted to direct and indirect subordinate roles.
2
Evaluate record access requirements for the Finance team across the organization.
Creating an owner-based or criteria-based sharing rule grants Read-Only access to the designated Finance role or public group.
Sharing rules extend record-level access above OWD defaults to specified groups or roles.
3
Distinguish object-level permissions from record-level sharing.
Permission sets only open object/field access, not individual record visibility.
Object permissions allow users to view the object type, but OWD and sharing mechanisms determine which specific records are accessible.

Anahtar Kavram

Role Hierarchy and Sharing Rules record access expansion
Tahmini Süre:1m 0s
Bu soruyu puanla