Soru

Zorluk: ZorRole Hierarchy and Sharing Rules

An administrator at Global Renewables sets the Organization-Wide Default (OWD) for a custom object named Facility_Inspection__c to Private and deselects the 'Grant Access Using Hierarchies' option on the object definition to prevent automatic manager access. Executive leadership now requires that users assigned to the 'Safety Director' role receive Read-Only access to all Facility_Inspection__c records owned by users in the 'Inspector' role. Which configuration should the administrator implement to fulfill this requirement without re-enabling automatic role hierarchy access for all other roles?

  1. Create an owner-based sharing rule on Facility_Inspection__c that shares records owned by members of the 'Inspector' role with members of the 'Safety Director' role.Cevap
  2. B
    Enable the 'Grant Access Using Hierarchies' checkbox on the object definition and place the 'Safety Director' role directly above the 'Inspector' role in the role hierarchy.
  3. C
    Create a criteria-based sharing rule that automatically re-enables hierarchy access specifically for users assigned to the 'Safety Director' role.
  4. D
    Assign a Permission Set containing the 'View All' object-level permission for Facility_Inspection__c to users in the 'Inspector' role.

Cevap

The administrator should create an owner-based sharing rule on Facility_Inspection__c that shares records owned by members of the 'Inspector' role with members of the 'Safety Director' role.
Creating an owner-based sharing rule allows the administrator to share records owned by users in the 'Inspector' role with users in the 'Safety Director' role with Read-Only access. This approach works when OWD is Private and operates independently of the 'Grant Access Using Hierarchies' setting on the custom object.

Adım Adım Çözüm

1
Analyze the existing Organization-Wide Default (OWD) and hierarchy access settings.
Facility_Inspection__c has a Private OWD, and automatic access roll-up via the role hierarchy is disabled.
Deselecting 'Grant Access Using Hierarchies' on custom objects stops automatic access propagation to higher roles.
2
Identify the target access requirement.
The 'Safety Director' role requires access specifically to records owned by the 'Inspector' role.
Access must be granted selectively based on record ownership without turning hierarchy access back on globally for the object.
3
Select the appropriate sharing mechanism.
Configure an owner-based sharing rule specifying the 'Inspector' role as the source owner group and the 'Safety Director' role as the target recipient group.
Owner-based sharing rules provide targeted cross-role visibility without changing overall object-level hierarchy settings.

Anahtar Kavram

Owner-Based Sharing Rules vs. Custom Object Role Hierarchy Settings
Bu soruyu puanla