Soru

Zorluk: ZorRole Hierarchy and Sharing Rules

Northern Trail Outfitters tracks joint vendor agreements using a custom object named Partner_Deal__c. The Organization-Wide Default (OWD) for Partner_Deal__c is set to Private. To prevent executive leadership from automatically viewing sensitive early-stage deal drafts created by junior staff, the administrator deselected the 'Grant Access Using Hierarchies' option on the custom object definition.

Management now requires Regional Sales Managers to view and edit all Partner_Deal__c records created by Sales Representatives in their respective territories, while continuing to restrict automatic access for executive roles above the Regional Managers in the hierarchy.

Which two configurations should the administrator implement to grant the necessary access without exposing records to upper executive roles? (Select 2)

  1. Create owner-based sharing rules on Partner_Deal__c to share records owned by Sales Representatives with the Regional Sales Managers role with Read/Write access.Cevap
  2. Keep the 'Grant Access Using Hierarchies' setting deselected on the Partner_Deal__c custom object definition.Cevap
  3. C
    Select 'Grant Access Using Hierarchies' on Partner_Deal__c and create a restriction rule to block executive roles from viewing the records.
  4. D
    Assign a custom profile with the 'Modify All' object permission on Partner_Deal__c to Regional Sales Managers.
  5. E
    Change the Organization-Wide Default (OWD) for Partner_Deal__c to Public Read/Write for Regional Sales Managers while keeping it Private for Executives.

Cevap

The administrator must create owner-based sharing rules targeting the Regional Sales Managers role and maintain 'Grant Access Using Hierarchies' as deselected on the custom object definition.
When 'Grant Access Using Hierarchies' is deselected for a custom object, record access does not automatically roll up to managers or upper executive roles. To grant Regional Sales Managers access to Sales Representatives' records without exposing them to higher executive roles, an administrator must create an owner-based sharing rule targeting the Regional Sales Managers while keeping hierarchy access disabled on the object.

Adım Adım Çözüm

1
Evaluate default hierarchy access behavior for custom objects
Disabling 'Grant Access Using Hierarchies' on a custom object stops automatic record access inheritance by superior roles in the role hierarchy.
This guarantees that executive roles above Regional Sales Managers will not inherit access automatically through the role hierarchy.
2
Establish explicit lateral/vertical sharing using sharing rules
An owner-based sharing rule grants record access from records owned by Sales Representatives directly to the Regional Sales Managers role.
Sharing rules extend access beyond OWD to specific groups or roles without enabling global hierarchy inheritance.

Anahtar Kavram

Role Hierarchy and Sharing Rules with Custom Object Access Controls
Bu soruyu puanla