Soru

Zorluk: OrtaPermission Sets and Permission Set Groups

A Salesforce administrator at an educational institution is optimizing user access management across several administrative departments. Match each administrative security requirement to the appropriate Salesforce security component or feature.

  • Grant Read and Edit access on the custom Student Support object to a select group of academic advisors for a 60-day audit window without altering baseline profile settings.Permission Set Assignment with an Expiration Date
  • Bundle standard Sales and Service permission sets for regional managers while suppressing Delete permissions inherited from one of the bundled sets.Permission Set Group containing a Muting Permission Set
  • Provide ongoing, supplemental Create and Edit permissions on the Scholarship Application object to three specific financial officers who hold standard staff profiles.Standalone Permission Set assigned directly to the target users

Cevap

Temporary access for a specific window matches Permission Set Assignment with an Expiration Date; bundling permission sets with suppressed permissions matches a Permission Set Group containing a Muting Permission Set; providing specific additive permissions to targeted users matches a Standalone Permission Set assigned directly to the target users.
Each administrative requirement corresponds directly to a core capability of Salesforce's additive security model: permission set expiration dates cater to temporary access windows, Permission Set Groups with Muting Permission Sets facilitate complex bundling and selective restriction, and standalone permission sets extend baseline profile capabilities to specific subset users.

Adım Adım Çözüm

1
Analyze requirement 1 (60-day audit window without altering baseline profile settings).
Identified the need for temporary additive access.
Salesforce permits setting expiration dates on user permission set assignments to automatically revoke access after the specified time frame.
2
Analyze requirement 2 (Bundling permission sets while suppressing specific inherited permissions).
Identified the need for permission consolidation with muted access.
Permission Set Groups consolidate multiple permission sets, while Muting Permission Sets enable removing specific permissions (like Delete) within the group scope.
3
Analyze requirement 3 (Supplemental Create and Edit access for specific users holding baseline staff profiles).
Identified the need for a targeted, permanent permission extension.
Standalone permission sets grant supplemental object-level and field-level access to individual users without altering underlying profile definitions.

Anahtar Kavram

Permission Sets, Permission Set Groups, and Muting Permission Sets in Salesforce security architecture
Bu soruyu puanla